| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
|
Thanks for the PR! Now merged and up on https://www.bouncycastle.org/betas |
Sorry, something went wrong.
| Back | FazBrowse Home | New Git URL |
ITSExplicitCertificateBuilder.build picks the certificate's Signature CHOICE by switching a VerificationKeyIndicator CHOICE, the certificate's own when self-signing and otherwise the issuer's, against the PublicVerificationKey curve constants (ITSExplicitCertificateBuilder.java:65-75, :91-104). The two CHOICE spaces are unrelated: verificationKey = 0 and reconstructionValue = 1 (VerificationKeyIndicator.java:25-26) index ecdsaNistP256 and ecdsaBrainpoolP256r1 (PublicVerificationKey.java:24-26), so the signing key's curve never enters the decision:
Reproduced on the released bcpkix-jdk18on-1.86.jar, on current origin/main (94270ff1cb) and on the byte-identical 1.87-SNAPSHOT beta (1.87.0.20719), with the same output and the re-decoded OER carrying the same tag. build takes no curve argument, so there is no workaround; every path is fail-closed. ETSISignedDataBuilder reads the curve from the signer already (ETSISignedDataBuilder.java:104, :131, :153).
This change:
Base tree only, no overlays and no module-info change (org.bouncycastle.its is already exported). A release-note entry is included.