Post B7WoRBXLdlTDs2NLsm by filippo@abyssdomain.expert
(DIR) More posts by filippo@abyssdomain.expert
(DIR) Post #B7WoRBXLdlTDs2NLsm by filippo@abyssdomain.expert
1 likes, 0 repeats
In 2020, OpenSSL had a vulnerability in handling the signature_algorithms_cert extension. https://openssl-library.org/news/secadv/20200421.txtPalo Alto apparently "solved" this in their IPS by blocking connections with "unknown" algs in signature_algorithms_cert.Six years later, we can't add ML-DSA to signature_algorithms_cert in Go. signature_algorithms_cert is dead.Sigh.Thanks to @cks for diagnosing this. Sometimes it takes us months to figure out things like this.https://github.com/golang/go/issues/79626#issuecomment-4754225610