diff options
author | Nikos Mavrogiannopoulos <nmav@gnutls.org> | 2009-11-01 02:54:08 +0200 |
---|---|---|
committer | Nikos Mavrogiannopoulos <nmav@gnutls.org> | 2009-11-01 02:54:08 +0200 |
commit | 6773d2ddb01d86fa283ce154b419e989916ab3f7 (patch) | |
tree | c3e38318016acfd0c50c8a4f6d694f5aa6d6f08a /lib/gnutls_extensions.c | |
parent | 9a262d093744f37b26f45c4e74d22f3a5a425211 (diff) | |
download | gnutls-6773d2ddb01d86fa283ce154b419e989916ab3f7.tar.gz |
Improved TLS 1.2 support. Added support for the SignatureAlgorithm extension
as well for the SignatureAlgorithm in certificate request.
Limitation for TLS 1.2 clients:
Only SHA1 or SHA256 are supported for generating signatures in
certificate verify message. That is to avoid storing all handshake
messages in memory. To be reconsidered in the future.
Diffstat (limited to 'lib/gnutls_extensions.c')
-rw-r--r-- | lib/gnutls_extensions.c | 9 |
1 files changed, 9 insertions, 0 deletions
diff --git a/lib/gnutls_extensions.c b/lib/gnutls_extensions.c index b7baca28b9..5f2c47cc6b 100644 --- a/lib/gnutls_extensions.c +++ b/lib/gnutls_extensions.c @@ -36,6 +36,7 @@ #include <ext_oprfi.h> #include <ext_srp.h> #include <ext_session_ticket.h> +#include <ext_signature.h> #include <gnutls_num.h> typedef struct @@ -349,6 +350,14 @@ _gnutls_ext_init (void) return ret; #endif + ret = gnutls_ext_register (GNUTLS_EXTENSION_SIGNATURE_ALGORITHMS, + "SIGNATURE_ALGORITHMS", + GNUTLS_EXT_TLS, + _gnutls_signature_algorithm_recv_params, + _gnutls_signature_algorithm_send_params); + if (ret != GNUTLS_E_SUCCESS) + return ret; + return GNUTLS_E_SUCCESS; } |