Radar · Go · Archive · Week 45 · Nov 3 – 9, 2025
crypto/tls: support crypto.MessageSigner
Worth knowingstdlib
- What changed
- The proposal adds support for
crypto.MessageSignerin TLS handshakes, allowing implementations that need to hash raw data before signing (e.g., TPM‑backed restricted keys). - Production impact
- The source does not say.
- Try it
- Build a TLS server that uses a
crypto.MessageSignerkey and observe the handshake logs. - Source
- github.com/golang/go/issues/75656
Understand it, then run it
The Go standard library now lets TLS use a type called crypto.MessageSigner. Before, TLS only used crypto.Signer, which expects the data to be hashed before it is signed. MessageSigner lets the signer hash the data itself, which is needed for some hardware keys, like TPM‑backed restricted keys. With this change a TLS server can hand the raw data to the signer and let the signer do the hashing and signing in one step.
Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed