Added support for RSASSA-PSS padding algorithms - #417

Draft
MasonCitywide wants to merge 6 commits into
rustls:mainfrom
MasonCitywide:main
Draft

Added support for RSASSA-PSS padding algorithms#417
MasonCitywide wants to merge 6 commits into
rustls:mainfrom
MasonCitywide:main

Conversation

@MasonCitywide

Copy link
Copy Markdown

Added algorithms to sign_algo.rsPKCS_RSA_PSS_SHA256, PKCS_RSA_PSS_SHA384, and PKCS_RSA_PSS_SHA512.

A half implemented version of PKCS_RSA_PSS_SHA256 already existed with a comment saying this doesn't work because ring hasn't implemented PSS padding (here). It seems that since then it has (here), and that comment was made before the release of aws-lc-rs.

There was also an issue in the pre-existing PKCS_RSA_PSS_SHA256 function in which the salt length was set to the default 20 instead of the recommended value of the number of octets of the hash algorithm (RFC 4055, pg. 9).

This is an important change as, if I am reading it correctly, non-PSS padding has been deprecated since RFC 8446 (pg. 70), with security concerns like ROBOT.

I was able to successfully create CSRs using all three of these algorithms using the aws-lc-rs backend. However, I'm not familiar with the unit testing of this library and I am new to contributions, so I would appreciate an independant review of these additions before they are merged.

Thank you for your time,
MC

@MasonCitywide
MasonCitywide marked this pull request as draft March 12, 2026 19:44
djc
djc approved these changes Mar 12, 2026

@djcdjc left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The changes here look okay so far, but CI doesn't pass and we'll want to make sure there some tests exercising this against a different backend (maybe OpenSSL)?

@MasonCitywide

Copy link
Copy Markdown
Author

The first build was failing because the algorithms I implemented had the same OIDs. However, RSA-PSS algorithms are supposed to have the same OIDs and are instead differentiated by their hash algorithm OIDs (RFC 4055, pgs. 8, 9, 15). So, I changed the PartialEq trait for sign_algo::SignatureAlgorithm to, if the params field is SignatureAlgorithmParams::RsaPss, differentiate based on the hash OID.

I checked CSR generation with all three algorithms, and it worked, but only with aws_lc_rs and not ring. Since the *::signature::RSA_PSS_SHA256 path is identical for each, I assumed it was a problem with ring and just gated all RSA-PSS functionality behind #[cfg(feature = "aws_lc_rs")].

After trying for several hours, I can't get the project to build with OpenSSL. Unfortunately, I don't think I have more time to dedicate to this PR. If anyone would like to take it from here, I am quite sure the code works, I just can't write proper OpenSSL tests.

@djcdjc reopened this Mar 15, 2026
@djc

djc commented Mar 15, 2026

Copy link
Copy Markdown
Member

Going to keep this open to make it easier for other interested parties to find. Thanks for your efforts!

@cpucpu mentioned this pull request Aug 10, 2026
@cpu

cpu commented Aug 11, 2026

Copy link
Copy Markdown
Member

There was also an issue in the pre-existing PKCS_RSA_PSS_SHA256 function in which the salt length was set to the default 20 instead of the recommended value of the number of octets of the hash algorithm (RFC 4055, pg. 9).

Just wanted to note I bumped into this in #445 where I noticed not only did we set the salt length to the wrong value, but we also misencoded it by writing the default that should have been elided for proper DER encoding. I removed the half implemented support in f8ef6ee and if anyone revives this work we should take care to not re-introduce that bug.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@MasonCitywide@djc@cpu
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Added support for RSASSA-PSS padding algorithms - #417

Draft
MasonCitywide wants to merge 6 commits into
rustls:mainfrom
MasonCitywide:main
Draft

Added support for RSASSA-PSS padding algorithms#417
MasonCitywide wants to merge 6 commits into
rustls:mainfrom
MasonCitywide:main

Conversation

@MasonCitywide

Copy link
Copy Markdown

Added algorithms to sign_algo.rsPKCS_RSA_PSS_SHA256, PKCS_RSA_PSS_SHA384, and PKCS_RSA_PSS_SHA512.

A half implemented version of PKCS_RSA_PSS_SHA256 already existed with a comment saying this doesn't work because ring hasn't implemented PSS padding (here). It seems that since then it has (here), and that comment was made before the release of aws-lc-rs.

There was also an issue in the pre-existing PKCS_RSA_PSS_SHA256 function in which the salt length was set to the default 20 instead of the recommended value of the number of octets of the hash algorithm (RFC 4055, pg. 9).

This is an important change as, if I am reading it correctly, non-PSS padding has been deprecated since RFC 8446 (pg. 70), with security concerns like ROBOT.

I was able to successfully create CSRs using all three of these algorithms using the aws-lc-rs backend. However, I'm not familiar with the unit testing of this library and I am new to contributions, so I would appreciate an independant review of these additions before they are merged.

Thank you for your time,
MC

@MasonCitywide
MasonCitywide marked this pull request as draft March 12, 2026 19:44
djc
djc approved these changes Mar 12, 2026

@djcdjc left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The changes here look okay so far, but CI doesn't pass and we'll want to make sure there some tests exercising this against a different backend (maybe OpenSSL)?

@MasonCitywide

Copy link
Copy Markdown
Author

The first build was failing because the algorithms I implemented had the same OIDs. However, RSA-PSS algorithms are supposed to have the same OIDs and are instead differentiated by their hash algorithm OIDs (RFC 4055, pgs. 8, 9, 15). So, I changed the PartialEq trait for sign_algo::SignatureAlgorithm to, if the params field is SignatureAlgorithmParams::RsaPss, differentiate based on the hash OID.

I checked CSR generation with all three algorithms, and it worked, but only with aws_lc_rs and not ring. Since the *::signature::RSA_PSS_SHA256 path is identical for each, I assumed it was a problem with ring and just gated all RSA-PSS functionality behind #[cfg(feature = "aws_lc_rs")].

After trying for several hours, I can't get the project to build with OpenSSL. Unfortunately, I don't think I have more time to dedicate to this PR. If anyone would like to take it from here, I am quite sure the code works, I just can't write proper OpenSSL tests.

@djcdjc reopened this Mar 15, 2026
@djc

djc commented Mar 15, 2026

Copy link
Copy Markdown
Member

Going to keep this open to make it easier for other interested parties to find. Thanks for your efforts!

@cpucpu mentioned this pull request Aug 10, 2026
@cpu

cpu commented Aug 11, 2026

Copy link
Copy Markdown
Member

There was also an issue in the pre-existing PKCS_RSA_PSS_SHA256 function in which the salt length was set to the default 20 instead of the recommended value of the number of octets of the hash algorithm (RFC 4055, pg. 9).

Just wanted to note I bumped into this in #445 where I noticed not only did we set the salt length to the wrong value, but we also misencoded it by writing the default that should have been elided for proper DER encoding. I removed the half implemented support in f8ef6ee and if anyone revives this work we should take care to not re-introduce that bug.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@MasonCitywide@djc@cpu
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Added support for RSASSA-PSS padding algorithms - #417

Draft
MasonCitywide wants to merge 6 commits into
rustls:mainfrom
MasonCitywide:main
Draft

Added support for RSASSA-PSS padding algorithms#417
MasonCitywide wants to merge 6 commits into
rustls:mainfrom
MasonCitywide:main

Conversation

@MasonCitywide

Copy link
Copy Markdown

Added algorithms to sign_algo.rsPKCS_RSA_PSS_SHA256, PKCS_RSA_PSS_SHA384, and PKCS_RSA_PSS_SHA512.

A half implemented version of PKCS_RSA_PSS_SHA256 already existed with a comment saying this doesn't work because ring hasn't implemented PSS padding (here). It seems that since then it has (here), and that comment was made before the release of aws-lc-rs.

There was also an issue in the pre-existing PKCS_RSA_PSS_SHA256 function in which the salt length was set to the default 20 instead of the recommended value of the number of octets of the hash algorithm (RFC 4055, pg. 9).

This is an important change as, if I am reading it correctly, non-PSS padding has been deprecated since RFC 8446 (pg. 70), with security concerns like ROBOT.

I was able to successfully create CSRs using all three of these algorithms using the aws-lc-rs backend. However, I'm not familiar with the unit testing of this library and I am new to contributions, so I would appreciate an independant review of these additions before they are merged.

Thank you for your time,
MC

@MasonCitywide
MasonCitywide marked this pull request as draft March 12, 2026 19:44
djc
djc approved these changes Mar 12, 2026

@djcdjc left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The changes here look okay so far, but CI doesn't pass and we'll want to make sure there some tests exercising this against a different backend (maybe OpenSSL)?

@MasonCitywide

Copy link
Copy Markdown
Author

The first build was failing because the algorithms I implemented had the same OIDs. However, RSA-PSS algorithms are supposed to have the same OIDs and are instead differentiated by their hash algorithm OIDs (RFC 4055, pgs. 8, 9, 15). So, I changed the PartialEq trait for sign_algo::SignatureAlgorithm to, if the params field is SignatureAlgorithmParams::RsaPss, differentiate based on the hash OID.

I checked CSR generation with all three algorithms, and it worked, but only with aws_lc_rs and not ring. Since the *::signature::RSA_PSS_SHA256 path is identical for each, I assumed it was a problem with ring and just gated all RSA-PSS functionality behind #[cfg(feature = "aws_lc_rs")].

After trying for several hours, I can't get the project to build with OpenSSL. Unfortunately, I don't think I have more time to dedicate to this PR. If anyone would like to take it from here, I am quite sure the code works, I just can't write proper OpenSSL tests.

@djcdjc reopened this Mar 15, 2026
@djc

djc commented Mar 15, 2026

Copy link
Copy Markdown
Member

Going to keep this open to make it easier for other interested parties to find. Thanks for your efforts!

@cpucpu mentioned this pull request Aug 10, 2026
@cpu

cpu commented Aug 11, 2026

Copy link
Copy Markdown
Member

There was also an issue in the pre-existing PKCS_RSA_PSS_SHA256 function in which the salt length was set to the default 20 instead of the recommended value of the number of octets of the hash algorithm (RFC 4055, pg. 9).

Just wanted to note I bumped into this in #445 where I noticed not only did we set the salt length to the wrong value, but we also misencoded it by writing the default that should have been elided for proper DER encoding. I removed the half implemented support in f8ef6ee and if anyone revives this work we should take care to not re-introduce that bug.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@MasonCitywide@djc@cpu
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Added support for RSASSA-PSS padding algorithms - #417

Draft
MasonCitywide wants to merge 6 commits into
rustls:mainfrom
MasonCitywide:main
Draft

Added support for RSASSA-PSS padding algorithms#417
MasonCitywide wants to merge 6 commits into
rustls:mainfrom
MasonCitywide:main

Conversation

@MasonCitywide

Copy link
Copy Markdown

Added algorithms to sign_algo.rsPKCS_RSA_PSS_SHA256, PKCS_RSA_PSS_SHA384, and PKCS_RSA_PSS_SHA512.

A half implemented version of PKCS_RSA_PSS_SHA256 already existed with a comment saying this doesn't work because ring hasn't implemented PSS padding (here). It seems that since then it has (here), and that comment was made before the release of aws-lc-rs.

There was also an issue in the pre-existing PKCS_RSA_PSS_SHA256 function in which the salt length was set to the default 20 instead of the recommended value of the number of octets of the hash algorithm (RFC 4055, pg. 9).

This is an important change as, if I am reading it correctly, non-PSS padding has been deprecated since RFC 8446 (pg. 70), with security concerns like ROBOT.

I was able to successfully create CSRs using all three of these algorithms using the aws-lc-rs backend. However, I'm not familiar with the unit testing of this library and I am new to contributions, so I would appreciate an independant review of these additions before they are merged.

Thank you for your time,
MC

@MasonCitywide
MasonCitywide marked this pull request as draft March 12, 2026 19:44
djc
djc approved these changes Mar 12, 2026

@djcdjc left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The changes here look okay so far, but CI doesn't pass and we'll want to make sure there some tests exercising this against a different backend (maybe OpenSSL)?

@MasonCitywide

Copy link
Copy Markdown
Author

The first build was failing because the algorithms I implemented had the same OIDs. However, RSA-PSS algorithms are supposed to have the same OIDs and are instead differentiated by their hash algorithm OIDs (RFC 4055, pgs. 8, 9, 15). So, I changed the PartialEq trait for sign_algo::SignatureAlgorithm to, if the params field is SignatureAlgorithmParams::RsaPss, differentiate based on the hash OID.

I checked CSR generation with all three algorithms, and it worked, but only with aws_lc_rs and not ring. Since the *::signature::RSA_PSS_SHA256 path is identical for each, I assumed it was a problem with ring and just gated all RSA-PSS functionality behind #[cfg(feature = "aws_lc_rs")].

After trying for several hours, I can't get the project to build with OpenSSL. Unfortunately, I don't think I have more time to dedicate to this PR. If anyone would like to take it from here, I am quite sure the code works, I just can't write proper OpenSSL tests.

@djcdjc reopened this Mar 15, 2026
@djc

djc commented Mar 15, 2026

Copy link
Copy Markdown
Member

Going to keep this open to make it easier for other interested parties to find. Thanks for your efforts!

@cpucpu mentioned this pull request Aug 10, 2026
@cpu

cpu commented Aug 11, 2026

Copy link
Copy Markdown
Member

There was also an issue in the pre-existing PKCS_RSA_PSS_SHA256 function in which the salt length was set to the default 20 instead of the recommended value of the number of octets of the hash algorithm (RFC 4055, pg. 9).

Just wanted to note I bumped into this in #445 where I noticed not only did we set the salt length to the wrong value, but we also misencoded it by writing the default that should have been elided for proper DER encoding. I removed the half implemented support in f8ef6ee and if anyone revives this work we should take care to not re-introduce that bug.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@MasonCitywide@djc@cpu
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Added support for RSASSA-PSS padding algorithms - #417

Draft
MasonCitywide wants to merge 6 commits into
rustls:mainfrom
MasonCitywide:main
Draft

Added support for RSASSA-PSS padding algorithms#417
MasonCitywide wants to merge 6 commits into
rustls:mainfrom
MasonCitywide:main

Conversation

@MasonCitywide

Copy link
Copy Markdown

Added algorithms to sign_algo.rsPKCS_RSA_PSS_SHA256, PKCS_RSA_PSS_SHA384, and PKCS_RSA_PSS_SHA512.

A half implemented version of PKCS_RSA_PSS_SHA256 already existed with a comment saying this doesn't work because ring hasn't implemented PSS padding (here). It seems that since then it has (here), and that comment was made before the release of aws-lc-rs.

There was also an issue in the pre-existing PKCS_RSA_PSS_SHA256 function in which the salt length was set to the default 20 instead of the recommended value of the number of octets of the hash algorithm (RFC 4055, pg. 9).

This is an important change as, if I am reading it correctly, non-PSS padding has been deprecated since RFC 8446 (pg. 70), with security concerns like ROBOT.

I was able to successfully create CSRs using all three of these algorithms using the aws-lc-rs backend. However, I'm not familiar with the unit testing of this library and I am new to contributions, so I would appreciate an independant review of these additions before they are merged.

Thank you for your time,
MC

@MasonCitywide
MasonCitywide marked this pull request as draft March 12, 2026 19:44
djc
djc approved these changes Mar 12, 2026

@djcdjc left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The changes here look okay so far, but CI doesn't pass and we'll want to make sure there some tests exercising this against a different backend (maybe OpenSSL)?

@MasonCitywide

Copy link
Copy Markdown
Author

The first build was failing because the algorithms I implemented had the same OIDs. However, RSA-PSS algorithms are supposed to have the same OIDs and are instead differentiated by their hash algorithm OIDs (RFC 4055, pgs. 8, 9, 15). So, I changed the PartialEq trait for sign_algo::SignatureAlgorithm to, if the params field is SignatureAlgorithmParams::RsaPss, differentiate based on the hash OID.

I checked CSR generation with all three algorithms, and it worked, but only with aws_lc_rs and not ring. Since the *::signature::RSA_PSS_SHA256 path is identical for each, I assumed it was a problem with ring and just gated all RSA-PSS functionality behind #[cfg(feature = "aws_lc_rs")].

After trying for several hours, I can't get the project to build with OpenSSL. Unfortunately, I don't think I have more time to dedicate to this PR. If anyone would like to take it from here, I am quite sure the code works, I just can't write proper OpenSSL tests.

@djcdjc reopened this Mar 15, 2026
@djc

djc commented Mar 15, 2026

Copy link
Copy Markdown
Member

Going to keep this open to make it easier for other interested parties to find. Thanks for your efforts!

@cpucpu mentioned this pull request Aug 10, 2026
@cpu

cpu commented Aug 11, 2026

Copy link
Copy Markdown
Member

There was also an issue in the pre-existing PKCS_RSA_PSS_SHA256 function in which the salt length was set to the default 20 instead of the recommended value of the number of octets of the hash algorithm (RFC 4055, pg. 9).

Just wanted to note I bumped into this in #445 where I noticed not only did we set the salt length to the wrong value, but we also misencoded it by writing the default that should have been elided for proper DER encoding. I removed the half implemented support in f8ef6ee and if anyone revives this work we should take care to not re-introduce that bug.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@MasonCitywide@djc@cpu
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Added support for RSASSA-PSS padding algorithms - #417

Draft
MasonCitywide wants to merge 6 commits into
rustls:mainfrom
MasonCitywide:main
Draft

Added support for RSASSA-PSS padding algorithms#417
MasonCitywide wants to merge 6 commits into
rustls:mainfrom
MasonCitywide:main

Conversation

@MasonCitywide

Copy link
Copy Markdown

Added algorithms to sign_algo.rsPKCS_RSA_PSS_SHA256, PKCS_RSA_PSS_SHA384, and PKCS_RSA_PSS_SHA512.

A half implemented version of PKCS_RSA_PSS_SHA256 already existed with a comment saying this doesn't work because ring hasn't implemented PSS padding (here). It seems that since then it has (here), and that comment was made before the release of aws-lc-rs.

There was also an issue in the pre-existing PKCS_RSA_PSS_SHA256 function in which the salt length was set to the default 20 instead of the recommended value of the number of octets of the hash algorithm (RFC 4055, pg. 9).

This is an important change as, if I am reading it correctly, non-PSS padding has been deprecated since RFC 8446 (pg. 70), with security concerns like ROBOT.

I was able to successfully create CSRs using all three of these algorithms using the aws-lc-rs backend. However, I'm not familiar with the unit testing of this library and I am new to contributions, so I would appreciate an independant review of these additions before they are merged.

Thank you for your time,
MC

@MasonCitywide
MasonCitywide marked this pull request as draft March 12, 2026 19:44
djc
djc approved these changes Mar 12, 2026

@djcdjc left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The changes here look okay so far, but CI doesn't pass and we'll want to make sure there some tests exercising this against a different backend (maybe OpenSSL)?

@MasonCitywide

Copy link
Copy Markdown
Author

The first build was failing because the algorithms I implemented had the same OIDs. However, RSA-PSS algorithms are supposed to have the same OIDs and are instead differentiated by their hash algorithm OIDs (RFC 4055, pgs. 8, 9, 15). So, I changed the PartialEq trait for sign_algo::SignatureAlgorithm to, if the params field is SignatureAlgorithmParams::RsaPss, differentiate based on the hash OID.

I checked CSR generation with all three algorithms, and it worked, but only with aws_lc_rs and not ring. Since the *::signature::RSA_PSS_SHA256 path is identical for each, I assumed it was a problem with ring and just gated all RSA-PSS functionality behind #[cfg(feature = "aws_lc_rs")].

After trying for several hours, I can't get the project to build with OpenSSL. Unfortunately, I don't think I have more time to dedicate to this PR. If anyone would like to take it from here, I am quite sure the code works, I just can't write proper OpenSSL tests.

@djcdjc reopened this Mar 15, 2026
@djc

djc commented Mar 15, 2026

Copy link
Copy Markdown
Member

Going to keep this open to make it easier for other interested parties to find. Thanks for your efforts!

@cpucpu mentioned this pull request Aug 10, 2026
@cpu

cpu commented Aug 11, 2026

Copy link
Copy Markdown
Member

There was also an issue in the pre-existing PKCS_RSA_PSS_SHA256 function in which the salt length was set to the default 20 instead of the recommended value of the number of octets of the hash algorithm (RFC 4055, pg. 9).

Just wanted to note I bumped into this in #445 where I noticed not only did we set the salt length to the wrong value, but we also misencoded it by writing the default that should have been elided for proper DER encoding. I removed the half implemented support in f8ef6ee and if anyone revives this work we should take care to not re-introduce that bug.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@MasonCitywide@djc@cpu
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Added support for RSASSA-PSS padding algorithms - #417

Draft
MasonCitywide wants to merge 6 commits into
rustls:mainfrom
MasonCitywide:main
Draft

Added support for RSASSA-PSS padding algorithms#417
MasonCitywide wants to merge 6 commits into
rustls:mainfrom
MasonCitywide:main

Conversation

@MasonCitywide

Copy link
Copy Markdown

Added algorithms to sign_algo.rsPKCS_RSA_PSS_SHA256, PKCS_RSA_PSS_SHA384, and PKCS_RSA_PSS_SHA512.

A half implemented version of PKCS_RSA_PSS_SHA256 already existed with a comment saying this doesn't work because ring hasn't implemented PSS padding (here). It seems that since then it has (here), and that comment was made before the release of aws-lc-rs.

There was also an issue in the pre-existing PKCS_RSA_PSS_SHA256 function in which the salt length was set to the default 20 instead of the recommended value of the number of octets of the hash algorithm (RFC 4055, pg. 9).

This is an important change as, if I am reading it correctly, non-PSS padding has been deprecated since RFC 8446 (pg. 70), with security concerns like ROBOT.

I was able to successfully create CSRs using all three of these algorithms using the aws-lc-rs backend. However, I'm not familiar with the unit testing of this library and I am new to contributions, so I would appreciate an independant review of these additions before they are merged.

Thank you for your time,
MC

@MasonCitywide
MasonCitywide marked this pull request as draft March 12, 2026 19:44
djc
djc approved these changes Mar 12, 2026

@djcdjc left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The changes here look okay so far, but CI doesn't pass and we'll want to make sure there some tests exercising this against a different backend (maybe OpenSSL)?

@MasonCitywide

Copy link
Copy Markdown
Author

The first build was failing because the algorithms I implemented had the same OIDs. However, RSA-PSS algorithms are supposed to have the same OIDs and are instead differentiated by their hash algorithm OIDs (RFC 4055, pgs. 8, 9, 15). So, I changed the PartialEq trait for sign_algo::SignatureAlgorithm to, if the params field is SignatureAlgorithmParams::RsaPss, differentiate based on the hash OID.

I checked CSR generation with all three algorithms, and it worked, but only with aws_lc_rs and not ring. Since the *::signature::RSA_PSS_SHA256 path is identical for each, I assumed it was a problem with ring and just gated all RSA-PSS functionality behind #[cfg(feature = "aws_lc_rs")].

After trying for several hours, I can't get the project to build with OpenSSL. Unfortunately, I don't think I have more time to dedicate to this PR. If anyone would like to take it from here, I am quite sure the code works, I just can't write proper OpenSSL tests.

@djcdjc reopened this Mar 15, 2026
@djc

djc commented Mar 15, 2026

Copy link
Copy Markdown
Member

Going to keep this open to make it easier for other interested parties to find. Thanks for your efforts!

@cpucpu mentioned this pull request Aug 10, 2026
@cpu

cpu commented Aug 11, 2026

Copy link
Copy Markdown
Member

There was also an issue in the pre-existing PKCS_RSA_PSS_SHA256 function in which the salt length was set to the default 20 instead of the recommended value of the number of octets of the hash algorithm (RFC 4055, pg. 9).

Just wanted to note I bumped into this in #445 where I noticed not only did we set the salt length to the wrong value, but we also misencoded it by writing the default that should have been elided for proper DER encoding. I removed the half implemented support in f8ef6ee and if anyone revives this work we should take care to not re-introduce that bug.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@MasonCitywide@djc@cpu
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Added support for RSASSA-PSS padding algorithms - #417

Draft
MasonCitywide wants to merge 6 commits into
rustls:mainfrom
MasonCitywide:main
Draft

Added support for RSASSA-PSS padding algorithms#417
MasonCitywide wants to merge 6 commits into
rustls:mainfrom
MasonCitywide:main

Conversation

@MasonCitywide

Copy link
Copy Markdown

Added algorithms to sign_algo.rsPKCS_RSA_PSS_SHA256, PKCS_RSA_PSS_SHA384, and PKCS_RSA_PSS_SHA512.

A half implemented version of PKCS_RSA_PSS_SHA256 already existed with a comment saying this doesn't work because ring hasn't implemented PSS padding (here). It seems that since then it has (here), and that comment was made before the release of aws-lc-rs.

There was also an issue in the pre-existing PKCS_RSA_PSS_SHA256 function in which the salt length was set to the default 20 instead of the recommended value of the number of octets of the hash algorithm (RFC 4055, pg. 9).

This is an important change as, if I am reading it correctly, non-PSS padding has been deprecated since RFC 8446 (pg. 70), with security concerns like ROBOT.

I was able to successfully create CSRs using all three of these algorithms using the aws-lc-rs backend. However, I'm not familiar with the unit testing of this library and I am new to contributions, so I would appreciate an independant review of these additions before they are merged.

Thank you for your time,
MC

@MasonCitywide
MasonCitywide marked this pull request as draft March 12, 2026 19:44
djc
djc approved these changes Mar 12, 2026

@djcdjc left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The changes here look okay so far, but CI doesn't pass and we'll want to make sure there some tests exercising this against a different backend (maybe OpenSSL)?

@MasonCitywide

Copy link
Copy Markdown
Author

The first build was failing because the algorithms I implemented had the same OIDs. However, RSA-PSS algorithms are supposed to have the same OIDs and are instead differentiated by their hash algorithm OIDs (RFC 4055, pgs. 8, 9, 15). So, I changed the PartialEq trait for sign_algo::SignatureAlgorithm to, if the params field is SignatureAlgorithmParams::RsaPss, differentiate based on the hash OID.

I checked CSR generation with all three algorithms, and it worked, but only with aws_lc_rs and not ring. Since the *::signature::RSA_PSS_SHA256 path is identical for each, I assumed it was a problem with ring and just gated all RSA-PSS functionality behind #[cfg(feature = "aws_lc_rs")].

After trying for several hours, I can't get the project to build with OpenSSL. Unfortunately, I don't think I have more time to dedicate to this PR. If anyone would like to take it from here, I am quite sure the code works, I just can't write proper OpenSSL tests.

@djcdjc reopened this Mar 15, 2026
@djc

djc commented Mar 15, 2026

Copy link
Copy Markdown
Member

Going to keep this open to make it easier for other interested parties to find. Thanks for your efforts!

@cpucpu mentioned this pull request Aug 10, 2026
@cpu

cpu commented Aug 11, 2026

Copy link
Copy Markdown
Member

There was also an issue in the pre-existing PKCS_RSA_PSS_SHA256 function in which the salt length was set to the default 20 instead of the recommended value of the number of octets of the hash algorithm (RFC 4055, pg. 9).

Just wanted to note I bumped into this in #445 where I noticed not only did we set the salt length to the wrong value, but we also misencoded it by writing the default that should have been elided for proper DER encoding. I removed the half implemented support in f8ef6ee and if anyone revives this work we should take care to not re-introduce that bug.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@MasonCitywide@djc@cpu