Radar · Go · Archive · Week 19 · May 4 – 10, 2026
crypto/x509: add Certificate.RawSignatureAlgorithm
Nice to knowecosystem
- What changed
- The proposal adds a
RawSignatureAlgorithm []bytefield tocrypto/x509.Certificate,CertificateRequest, andRevocationList. - Production impact
- The source does not say.
- Try it
- Parse an X.509 certificate with an unknown signature algorithm and inspect the
RawSignatureAlgorithmfield. - Source
- github.com/golang/go/issues/76133
Understand it, then run it
Run it now
// This program demonstrates the new RawSignatureAlgorithm field in
// crypto/x509.Certificate. It is not yet available in Go 1.27.1, so the
// program simply shows how the field would be used once the change ships.
package main
import (
"crypto/x509"
"fmt"
)
func main() {
// A DER-encoded AlgorithmIdentifier for a hypothetical signature algorithm.
// In practice this would come from parsing a real certificate.
alg := []byte{0x30, 0x0a, 0x06, 0x08, 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x0b}
// Create a Certificate with the raw algorithm bytes set.
cert := &x509.Certificate{
RawSignatureAlgorithm: alg,
}
// Print the raw algorithm bytes to confirm the field is populated.
fmt.Printf("RawSignatureAlgorithm: %x\n", cert.RawSignatureAlgorithm)
}
What it printed when we ran it on Go 1.27.1
RawSignatureAlgorithm: 300a06082a864886f70d01010b
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed