Lines Matching refs:PSS
229 # self-signed end-entity cert signed with RSA-PSS
230 openssl req -new -x509 -key ee-key.pem -subj /CN=ee-self-signed-pss -out ee-self-signed-pss.pem -days 36525 \
231 -sha256 -sigopt rsa_padding_mode:pss -sigopt rsa_pss_saltlen:digest
437 # RSA-PSS signatures
439 ./mkcert.sh genee PSS-SHA1 ee-key ee-pss-sha1-cert ca-key ca-cert \
440 -sha1 -sigopt rsa_padding_mode:pss -sigopt rsa_pss_saltlen:digest
442 ./mkcert.sh genee PSS-SHA256 ee-key ee-pss-sha256-cert ca-key ca-cert \
443 -sha256 -sigopt rsa_padding_mode:pss -sigopt rsa_pss_saltlen:digest
444 # CA-PSS
445 ./mkcert.sh genca "CA-PSS" ca-pss-key ca-pss-cert root-key root-cert \
446 -sha256 -sigopt rsa_padding_mode:pss -sigopt rsa_pss_saltlen:-1
447 ./mkcert.sh genee "EE-PSS" ee-key ee-pss-cert ca-pss-key ca-pss-cert \
448 -sha256 -sigopt rsa_padding_mode:pss -sigopt rsa_pss_saltlen:-1
450 #./mkcert.sh genee "EE-PSS-wrong1.5" ee-key ee-pss-wrong1.5-cert ca-pss-key ca-pss-cert -sha256
457 -newkey rsa-pss -keyout server-pss-restrict-key.pem \
459 ./mkcert.sh geneenocsr "Server RSA-PSS restricted cert" \
460 server-pss-restrict-cert rootkey rootcert
462 openssl req -new -noenc -subj "/CN=Client-RSA-PSS" \
463 -newkey rsa-pss -keyout client-pss-restrict-key.pem \
465 ./mkcert.sh geneenocsr -p clientAuth "Client RSA-PSS restricted cert" \
466 client-pss-restrict-cert rootkey rootcert