Viktor Dukhovni a5f98e6da5 Fix sigalg corner cases
- Tolerate RSA PKCS#1 *certificate* signatures when
  the peer sigals include RSA PSS with the same digest.

  Now that we're more strict about not sending sigalgs that are out of
  protocol range, when the client supports TLS 1.3 only, we might refuse
  to return an RSA PKCS#1-signed cert.

- Don't send TLS 1.3 sigalgs when requesting client certs from
  a TLS 1.2 client.

Fixes: #1144
Fixes: #25277

Reviewed-by: Tim Hudson <tjh@openssl.org>
Reviewed-by: Matt Caswell <matt@openssl.org>
Reviewed-by: Tomas Mraz <tomas@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/27166)
2025-03-31 14:07:56 +02:00
..
2025-03-25 20:22:23 +01:00
2025-03-12 13:35:59 +00:00
2025-03-31 14:07:56 +02:00
2025-03-12 13:35:59 +00:00
2025-03-01 14:46:03 -05:00
2025-03-12 13:35:59 +00:00
2025-03-12 13:35:59 +00:00
2025-03-12 13:35:59 +00:00
2024-09-05 09:35:49 +02:00
2025-03-12 13:35:59 +00:00
2025-03-12 13:35:59 +00:00
2023-03-28 13:49:54 -04:00
2025-03-12 13:35:59 +00:00
2023-11-27 07:51:33 +00:00
2025-03-12 13:35:59 +00:00
2025-03-12 13:35:59 +00:00
2025-03-12 13:35:59 +00:00
2025-03-12 13:35:59 +00:00
2025-03-12 13:35:59 +00:00
2025-03-31 14:07:56 +02:00
2024-09-05 09:35:49 +02:00
2025-03-12 13:35:59 +00:00
2025-03-12 13:35:59 +00:00
2025-03-12 13:35:59 +00:00
2025-03-12 13:35:59 +00:00
2024-09-05 09:35:49 +02:00
2025-03-12 13:35:59 +00:00
2025-03-31 14:07:56 +02:00
2025-03-12 13:35:59 +00:00
2025-03-12 13:35:59 +00:00
2025-03-12 13:35:59 +00:00
2025-03-12 13:35:59 +00:00