crypto/tls: support crypto.MessageSigner private keys

Fixes #75656

Change-Id: I6bc71c80973765ef995d17b1450ea2026a6a6964
Reviewed-on: https://go-review.googlesource.com/c/go/+/724820
Auto-Submit: Filippo Valsorda <filippo@golang.org>
Reviewed-by: Nicholas Husin <husin@google.com>
Reviewed-by: Roland Shoemaker <roland@golang.org>
LUCI-TryBot-Result: Go LUCI <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
Reviewed-by: Nicholas Husin <nsh@golang.org>
This commit is contained in:
yuhan6665
2026-09-08 21:33:46 -04:00
parent 2d3ccda21d
commit d1b0d4d0cd
8 changed files with 141 additions and 117 deletions
+6 -1
View File
@@ -1631,9 +1631,14 @@ var writerMutex sync.Mutex
type Certificate struct {
Certificate [][]byte
// PrivateKey contains the private key corresponding to the public key in
// Leaf. This must implement crypto.Signer with an RSA, ECDSA or Ed25519 PublicKey.
// Leaf. This must implement [crypto.Signer] with an RSA, ECDSA or Ed25519
// PublicKey.
//
// For a server up to TLS 1.2, it can also implement crypto.Decrypter with
// an RSA PublicKey.
//
// If it implements [crypto.MessageSigner], SignMessage will be used instead
// of Sign for TLS 1.2 and later.
PrivateKey crypto.PrivateKey
// SupportedSignatureAlgorithms is an optional list restricting what
// signature algorithms the PrivateKey can be used for.