From cbdb57278df01e2410ffe7ec0ca78f238342fe2c Mon Sep 17 00:00:00 2001 From: Michael Brown Date: Sun, 20 Sep 2026 14:24:32 +0100 Subject: [PATCH] [crypto] Use certificate's own public key algorithm for key matching When finding the certificate corresponding to a private key, the match is currently performed using the certificate's signature algorithm (i.e. the public key algorithm of the issuer's key) rather than the certificate's own public key algorithm. This breaks key matching for heterogenous certificate chains (e.g. an ECDSA client certificate issued by an RSA intermediate certificate). Fix by using the certificate's own public key algorithm. Signed-off-by: Michael Brown --- src/crypto/x509.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/crypto/x509.c b/src/crypto/x509.c index 111c74775..a35fc3acd 100644 --- a/src/crypto/x509.c +++ b/src/crypto/x509.c @@ -1866,7 +1866,7 @@ struct x509_certificate * x509_find_key ( struct x509_chain *store, /* Check public key */ cert = link->cert; - if ( pubkey_match ( cert->signature_algorithm->pubkey, + if ( pubkey_match ( cert->subject.public_key.algorithm->pubkey, privkey_cursor ( key ), &cert->subject.public_key.raw ) == 0 ) return x509_found ( store, cert );