Repository navigation
internal: sign without server-sig-algs - #1291
Conversation
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The fallback correctly distinguishes omission from explicit incompatibility and is well covered by regression tests.
Review effort: Balanced
Findings: None
What changed in this PR
Allows public-key authentication when optional server-sig-algs is absent while preserving explicit mismatch failures.
Changes:
- Tracks whether
server-sig-algswas received. - Falls back to client algorithm preferences when absent.
- Adds RSA, ECDSA, certificate, and replacement regression coverage.
| File | Description |
|---|---|
wolfssh/internal.h |
Adds extension-presence state. |
src/internal.c |
Implements fallback signature selection. |
tests/regress.c |
Tests absent, unusable, and superseded lists. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
EXT_INFO is optional, RFC 8308 section 2.2. When the server has sent no server-sig-algs, a publickey USERAUTH_REQUEST now picks the key's signature algorithm from the client's canned list, and an OpenSSH RSA certificate follows the same order. A list that names nothing usable still fails with WS_MATCH_KEY_ALGO_E. - record in peerSigAlgsSeen that server-sig-algs arrived - ClientOsshRsaCertSigId() picks the certificate's name and hash - regress: publickey requests with and without server-sig-algs - regress: the signature is named for the offered algorithm - regress: a list superseding a usable one still refuses Issue: wolfSSL#1286
edff53c to
ccaaa6d
Compare
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #1291
Scan targets checked: wolfssh-src, wolfssh-bugs
Coverage: 1 of 3 in-scope changed file(s) opened by the reviewer; not opened: tests/regress.c, wolfssh/internal.h
Fenrir result: Approved ✅
No new issues found in the changed files.
Advisory only — this automated result does not count as a GitHub approval.
Review tier: Lite
EXT_INFO is optional, RFC 8308 section 2.2. With no server-sig-algs, a publickey request now signs using the client's canned order instead of failing with WS_MATCH_KEY_ALGO_E; an OpenSSH RSA certificate follows it too.
Issue: #1286