From 2bb05a9668323ac2719f84cf8e9ccffc2bc99916 Mon Sep 17 00:00:00 2001 From: Richard Levitte Date: Sun, 31 Jan 2021 23:15:08 +0100 Subject: [PATCH] PROV: Fix encoding of MDWithRSAEncryption signature AlgorithmID All {MD}WithRSAEncryption signature AlgorithmID have the parameters being NULL, according to PKCS#1. We didn't. Now corrected. This bug was the topic of this thread on openssl-users@openssl.org: https://mta.openssl.org/pipermail/openssl-users/2021-January/013416.html Reviewed-by: Tomas Mraz (Merged from https://github.com/openssl/openssl/pull/14030) --- providers/common/der/der_rsa_sig.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/providers/common/der/der_rsa_sig.c b/providers/common/der/der_rsa_sig.c index 94ed60b69ff..7fb69f87b09 100644 --- a/providers/common/der/der_rsa_sig.c +++ b/providers/common/der/der_rsa_sig.c @@ -58,7 +58,9 @@ int ossl_DER_w_algorithmIdentifier_MDWithRSAEncryption(WPACKET *pkt, int tag, } return ossl_DER_w_begin_sequence(pkt, tag) - /* No parameters (yet?) */ + /* PARAMETERS, always NULL according to current standards */ + && ossl_DER_w_null(pkt, -1) + /* OID */ && ossl_DER_w_precompiled(pkt, -1, precompiled, precompiled_sz) && ossl_DER_w_end_sequence(pkt, tag); } -- 2.47.3