Skip to content

fix: decode SubjectPublicKeyInfo without crypto.ecdsa's DER parser - #5

Merged
nepinhum merged 2 commits into
masterfrom
fix/decode-public-key-without-openssl
Sep 11, 2026
Merged

nepinhum merged 2 commits into
masterfrom
fix/decode-public-key-without-openssl

Conversation

@nepinhum

Copy link
Copy Markdown
Member

Since V 414d5eb, crypto.ecdsa defaults to an mbedTLS backend that does not implement pubkey_from_bytes. Every identity assertion failed to verify, so a listener refused every client that sent one and a dialer couldn't verify the server token.

decode_public_key now takes the SubjectPublicKeyInfo apart itself, the reverse of encode_public_key and hands only the point to PublicKey.from_uncompressed_bytes which both backends implement and which checks the point is on the curve.

@nepinhum

Copy link
Copy Markdown
Member Author
image what the hell is this 🤣 , impressive

@nepinhum
nepinhum merged commit a4f4360 into master Sep 11, 2026
9 of 10 checks passed
@nepinhum
nepinhum deleted the fix/decode-public-key-without-openssl branch September 11, 2026 14:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant