Post B7WoRBXLdlTDs2NLsm by filippo@abyssdomain.expert
 (DIR) More posts by filippo@abyssdomain.expert
 (DIR) Post #B7WoRBXLdlTDs2NLsm by filippo@abyssdomain.expert
       1 likes, 0 repeats
       
       In 2020, OpenSSL had a vulnerability in handling the signature_algorithms_cert extension. https://openssl-library.org/news/secadv/20200421.txtPalo Alto apparently "solved" this in their IPS by blocking connections with "unknown" algs in signature_algorithms_cert.Six years later, we can't add ML-DSA to signature_algorithms_cert in Go. signature_algorithms_cert is dead.Sigh.Thanks to @cks for diagnosing this. Sometimes it takes us months to figure out things like this.https://github.com/golang/go/issues/79626#issuecomment-4754225610