This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Radar · Go · Archive · Week 45 · Nov 3 – 9, 2025

crypto/tls: support crypto.MessageSigner

Worth knowingstdlib

What changed
The proposal adds support for crypto.MessageSigner in TLS handshakes, allowing implementations that need to hash raw data before signing (e.g., TPM‑backed restricted keys).
Production impact
The source does not say.
Try it
Build a TLS server that uses a crypto.MessageSigner key and observe the handshake logs.
Source
github.com/golang/go/issues/75656

Understand it, then run it

The Go standard library now lets TLS use a type called crypto.MessageSigner. Before, TLS only used crypto.Signer, which expects the data to be hashed before it is signed. MessageSigner lets the signer hash the data itself, which is needed for some hardware keys, like TPM‑backed restricted keys. With this change a TLS server can hand the raw data to the signer and let the signer do the hashing and signing in one step.

Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed