ssh: report verified signature format to callback#364
Conversation
|
This PR (HEAD: 1a4acd4) has been imported to Gerrit for code review. Please visit Gerrit at https://go-review.googlesource.com/c/crypto/+/800740. Important tips:
|
|
Message from Gopher Robot: Patch Set 1: (1 comment) Please don’t reply on this GitHub thread. Visit golang.org/cl/800740. |
|
Message from Gopher Robot: Patch Set 1: Congratulations on opening your first change. Thank you for your contribution! Next steps: Most changes in the Go project go through a few rounds of revision. This can be During May-July and Nov-Jan the Go project is in a code freeze, during which Please don’t reply on this GitHub thread. Visit golang.org/cl/800740. |
|
Message from Vinicius Akira Imaizumi: Patch Set 2: (1 comment) Please don’t reply on this GitHub thread. Visit golang.org/cl/800740. |
|
Message from Nicola Murino: Patch Set 2: Code-Review+2 Please don’t reply on this GitHub thread. Visit golang.org/cl/800740. |
|
Message from Nicola Murino: Patch Set 2: Commit-Queue+1 Please don’t reply on this GitHub thread. Visit golang.org/cl/800740. |
|
Message from golang-scoped@luci-project-accounts.iam.gserviceaccount.com: Patch Set 2: Dry run: CV is trying the patch. Bot data: {"action":"start","triggered_at":"2026-07-16T09:28:02Z","revision":"ca36abaeca502caf10edb2d90f7f7066405445d6"} Please don’t reply on this GitHub thread. Visit golang.org/cl/800740. |
|
Message from Nicola Murino: Patch Set 2: -Commit-Queue (Performed by <GERRIT_ACCOUNT_60063> on behalf of <GERRIT_ACCOUNT_35201>) Please don’t reply on this GitHub thread. Visit golang.org/cl/800740. |
|
Message from golang-scoped@luci-project-accounts.iam.gserviceaccount.com: Patch Set 2: This CL has passed the run Please don’t reply on this GitHub thread. Visit golang.org/cl/800740. |
|
Message from golang-scoped@luci-project-accounts.iam.gserviceaccount.com: Patch Set 2: LUCI-TryBot-Result+1 Please don’t reply on this GitHub thread. Visit golang.org/cl/800740. |
|
Message from Michael Pratt: Patch Set 2: Auto-Submit+1 Code-Review+1 Please don’t reply on this GitHub thread. Visit golang.org/cl/800740. |
VerifiedPublicKeyCallback currently receives the public-key algorithm declared in the outer authentication request. For RSA authentication, that value can differ from the format of the signature that was successfully verified because compatible RSA algorithm combinations are accepted. This can cause post-verification policy or audit decisions to use the request algorithm instead of the signature format actually verified. Pass sig.Format to VerifiedPublicKeyCallback so signatureAlgorithm identifies the successfully verified signature format. Clarify the callback documentation and add a regression test covering compatible but different RSA request algorithms and signature formats. Fixes golang/go#80411 Change-Id: Ib405378d75367a90536e0814c9d26d4dec9aaa25 GitHub-Last-Rev: 1a4acd4 GitHub-Pull-Request: #364 Reviewed-on: https://go-review.googlesource.com/c/crypto/+/800740 Reviewed-by: Michael Pratt <mpratt@google.com> Reviewed-by: Nicola Murino <nicola.murino@gmail.com> Reviewed-by: David Chase <drchase@google.com> Auto-Submit: Michael Pratt <mpratt@google.com> LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
|
This PR is being closed because golang.org/cl/800740 has been merged. |
VerifiedPublicKeyCallback currently receives the public-key algorithm
declared in the outer authentication request. For RSA authentication,
that value can differ from the format of the signature that was
successfully verified because compatible RSA algorithm combinations are
accepted.
This can cause post-verification policy or audit decisions to use the
request algorithm instead of the signature format actually verified.
Pass sig.Format to VerifiedPublicKeyCallback so signatureAlgorithm
identifies the successfully verified signature format. Clarify the
callback documentation and add a regression test covering compatible
but different RSA request algorithms and signature formats.
Fixes golang/go#80411