You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Although optional, and not necessary for the cross-platform verification of signatures, we should use a salt length equal to MAX_LENGTH for the maximum provable security when creating these signatures.
We should use a salt length equal to AUTO so that we can automatically verify these signatures regardless of the input salt length.
The text was updated successfully, but these errors were encountered:
Description of issue or feature request:
There are two related issues:
Current behavior:
crypto/rsa
packages, which uses a different salt length by default as described below; see Allow configuring the possible salt lengths for RSA PSS signatures hashicorp/vault#16549).Expected behavior:
The text was updated successfully, but these errors were encountered: