Skip to content

internal: sign without server-sig-algs - #1291

Draft
ejohnstown wants to merge 1 commit into
wolfSSL:masterfrom
ejohnstown:issue-1286-no-server-sig-algs
Draft

ejohnstown wants to merge 1 commit into
wolfSSL:masterfrom
ejohnstown:issue-1286-no-server-sig-algs

Conversation

@ejohnstown

@ejohnstown ejohnstown commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

EXT_INFO is optional, RFC 8308 section 2.2. With no server-sig-algs, a publickey request now signs using the client's canned order instead of failing with WS_MATCH_KEY_ALGO_E; an OpenSSH RSA certificate follows it too.

  • peerSigAlgsSeen tells an absent list from one naming nothing usable, which still fails
  • regress: requests with, without, and with a superseded server-sig-algs

Issue: #1286

EXT_INFO is optional, RFC 8308 section 2.2. When the server has sent no
server-sig-algs, a publickey USERAUTH_REQUEST now picks the key's
signature algorithm from the client's canned list, and an OpenSSH RSA
certificate follows the same order. A list that names nothing usable
still fails with WS_MATCH_KEY_ALGO_E.

- record in peerSigAlgsSeen that server-sig-algs arrived
- ClientOsshRsaCertSigId() picks the certificate's name and hash
- regress: publickey requests with and without server-sig-algs
- regress: the signature is named for the offered algorithm
- regress: a list superseding a usable one still refuses

Issue: wolfSSL#1286
Copilot AI balanced review requested due to automatic review settings September 30, 2026 23:24

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The fallback correctly distinguishes omission from explicit incompatibility and is well covered by regression tests.

Review effort: Balanced
Findings: None

What changed in this PR

Allows public-key authentication when optional server-sig-algs is absent while preserving explicit mismatch failures.

Changes:

  • Tracks whether server-sig-algs was received.
  • Falls back to client algorithm preferences when absent.
  • Adds RSA, ECDSA, certificate, and replacement regression coverage.
File Description
wolfssh/​internal.h Adds extension-presence state.
src/​internal.c Implements fallback signature selection.
tests/​regress.c Tests absent, unusable, and superseded lists.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants