From: djm@openbsd.org Date: Fri, 14 Jun 2019 03:51:47 +0000 (+0000) Subject: upstream: process agent requests for RSA certificate private keys using X-Git-Url: http://git.ipfire.org/gitweb/?a=commitdiff_plain;h=refs%2Fremotes%2Fanongit%2FV_8_0;p=thirdparty%2Fopenssh-portable.git upstream: process agent requests for RSA certificate private keys using correct signature algorithm when requested. Patch from Jakub Jelen in bz3016 ok dtucker markus OpenBSD-Commit-ID: 61f86efbeb4a1857a3e91298c1ccc6cf49b79624 --- diff --git a/ssh-agent.c b/ssh-agent.c index d06ecfd98..8e5550ac3 100644 --- a/ssh-agent.c +++ b/ssh-agent.c @@ -269,6 +269,11 @@ agent_decode_alg(struct sshkey *key, u_int flags) return "rsa-sha2-256"; else if (flags & SSH_AGENT_RSA_SHA2_512) return "rsa-sha2-512"; + } else if (key->type == KEY_RSA_CERT) { + if (flags & SSH_AGENT_RSA_SHA2_256) + return "rsa-sha2-256-cert-v01@openssh.com"; + else if (flags & SSH_AGENT_RSA_SHA2_512) + return "rsa-sha2-512-cert-v01@openssh.com"; } return NULL; }