mirror of
https://github.com/Mbed-TLS/mbedtls.git
synced 2026-07-30 16:26:33 +08:00
Merge pull request #1612 from valeriosetti/issue1569
[development] TLS 1.3 certificate chain signature algorithm policy gap
This commit is contained in:
commit
05bd7f6429
4
ChangeLog.d/security-issue1569.txt
Normal file
4
ChangeLog.d/security-issue1569.txt
Normal file
@ -0,0 +1,4 @@
|
||||
Security
|
||||
* Improved documentation of mbedtls_ssl_conf_sig_algs() to emphasize that
|
||||
this function only sets signature algorithms that are enforced during
|
||||
TLS key exchange and not on certificate verification.
|
||||
@ -3411,7 +3411,7 @@ int mbedtls_ssl_conf_cid(mbedtls_ssl_config *conf, size_t len,
|
||||
*
|
||||
* \note The restrictions are enforced for all certificates in the
|
||||
* chain. However, signatures in the handshake are not covered
|
||||
* by this setting but by \b mbedtls_ssl_conf_sig_algs().
|
||||
* by this setting but by \c mbedtls_ssl_conf_sig_algs().
|
||||
*
|
||||
* \param conf SSL configuration
|
||||
* \param profile Profile to use
|
||||
@ -3899,7 +3899,12 @@ void mbedtls_ssl_conf_groups(mbedtls_ssl_config *conf,
|
||||
#if defined(MBEDTLS_SSL_HANDSHAKE_WITH_CERT_ENABLED)
|
||||
|
||||
/**
|
||||
* \brief Configure allowed signature algorithms for use in TLS
|
||||
* \brief Configure allowed signature algorithms for use in TLS key
|
||||
* exchange.
|
||||
*
|
||||
* \note This only covers signature algorithms used in the key
|
||||
* exchange. To also enforce restrictions in certificate verification
|
||||
* refer to \c mbedtls_ssl_conf_cert_profile().
|
||||
*
|
||||
* \param conf The SSL configuration to use.
|
||||
* \param sig_algs List of allowed IANA values for TLS 1.3 signature algorithms,
|
||||
|
||||
Loading…
x
Reference in New Issue
Block a user