Am 14.12.21 um 17:59 schrieb selva.n...@gmail.com:
From: Selva Nair <selva.n...@gmail.com>

- Load the 'private key' handle through the provider and set it in
   SSL_CTX
- Add a sign op function to interface provider with pkcs11-helper.
   Previously we used its "OpenSSL Session" which internally sets up
   callbacks in RSA and EC key methods. Not useful for the provider
   interface, so, we directly call the PKCS#11 sign operation
   as done with mbedTLS.
- tls_libctx is made global for accessing from pkcs11_openssl.c

   Supports ECDSA and RSA_PKCS1_PADDING signatures. PSS support
   will be added when pkcs11-helper with our PR for specifying
   CK_MECHANISM variable in sign operations is released.
   (i.e., next release of pkcs11-helper).


Acked-By: Arne Schwabe <a...@rfc2549.org>



_______________________________________________
Openvpn-devel mailing list
Openvpn-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/openvpn-devel

Reply via email to