[gnutls-devel] GnuTLS | pkcs11: ensure C_SignInit is called before C_Sign (!2016)

Read-only notification of GnuTLS library development activities gnutls-devel at lists.gnutls.org
Mon Sep 8 12:13:38 CEST 2025




Di Wang commented on a discussion: https://gitlab.com/gnutls/gnutls/-/merge_requests/2016#note_2735846191


Sorry for these two rubbish MRs, I closed it because I found that it would cause pkcs11 tests to fail. However, it's the case when we were testing on a pkcs11 device "Feitian ePass3000GM".

I noticed that the PKCS#11 functionality of GnuTLS is tested using SoftHSM. May I ask if you have ever encountered similar issues when using GnuTLS PKCS#11 functionality with actual hardware devices? Since this code has remain unchanged for 12 years with seemingly no related bug reports, this might be an issue specific to the device we are using.

-- 
Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/merge_requests/2016#note_2735846191
You're receiving this email because of your account on gitlab.com.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.gnupg.org/pipermail/gnutls-devel/attachments/20250908/f63d338c/attachment.html>


More information about the Gnutls-devel mailing list