50e2b60
From 2317ce4b0ed7d8c4b0c684e2d47bff5006bd1178 Mon Sep 17 00:00:00 2001
50e2b60
From: "djm@openbsd.org" <djm@openbsd.org>
50e2b60
Date: Fri, 14 Jun 2019 03:51:47 +0000
50e2b60
Subject: [PATCH] upstream: process agent requests for RSA certificate private
50e2b60
 keys using
50e2b60
50e2b60
correct signature algorithm when requested. Patch from Jakub Jelen in bz3016
50e2b60
ok dtucker markus
50e2b60
50e2b60
OpenBSD-Commit-ID: 61f86efbeb4a1857a3e91298c1ccc6cf49b79624
50e2b60
---
50e2b60
 ssh-agent.c | 7 ++++++-
50e2b60
 1 file changed, 6 insertions(+), 1 deletion(-)
50e2b60
50e2b60
diff --git a/ssh-agent.c b/ssh-agent.c
50e2b60
index 034f31387..4669b679c 100644
50e2b60
--- a/ssh-agent.c
50e2b60
+++ b/ssh-agent.c
50e2b60
@@ -269,6 +269,11 @@ agent_decode_alg(struct sshkey *key, u_int flags)
50e2b60
 			return "rsa-sha2-256";
50e2b60
 		else if (flags & SSH_AGENT_RSA_SHA2_512)
50e2b60
 			return "rsa-sha2-512";
50e2b60
+	} else if (key->type == KEY_RSA_CERT) {
50e2b60
+		if (flags & SSH_AGENT_RSA_SHA2_256)
50e2b60
+			return "rsa-sha2-256-cert-v01@openssh.com";
50e2b60
+		else if (flags & SSH_AGENT_RSA_SHA2_512)
50e2b60
+			return "rsa-sha2-512-cert-v01@openssh.com";
50e2b60
 	}
50e2b60
 	return NULL;
50e2b60
 }
50e2b60