#1142662 TLS 1.3 handshake issue with openjdk

Package:
libgnutls30t64
Source:
libgnutls30t64
Description:
GNU TLS library - main runtime library
Submitter:
Romain Tartière
Date:
2026-07-23 21:21:02 UTC
Severity:
normal
Tags:
#1142662#5
Date:
2026-07-23 21:08:41 UTC
From:
To:
Dear Maintainer,

About one year ago, OpenJDK fixed handling of signature scheme
constraints in TLS by differentiating between handshake signatures and
certificate signatures (https://bugs.openjdk.org/browse/JDK-8349583).
The corresponding packages for OpenJDK were updated in Debian and we
immediately experienced a regression in Debian packages that relied on
GnuTLS for mutual TLS: connection failed to establish with spurious
error messages.

More recently, I could find the root cause and fix the issue causing
this regression in GnuTLS, and this fix was part of GnuTLS 3.8.13:
https://gitlab.com/gnutls/gnutls/-/merge_requests/2095/

The version of GnuTLS in Debian testing is now working correctly, but I
would like the fix to be backported to Debian 12 and 13 where the issue
still exists today.

I opened two merge requests to include this patch on what I think are
the correct branches in the salsa project:
  - https://salsa.debian.org/gnutls-team/gnutls/-/merge_requests/6
  - https://salsa.debian.org/gnutls-team/gnutls/-/merge_requests/7

I was not able to find the correct commands I should run to build
packages from this repository, and would appreciate some guidance to
help me improve these merge requests.  In-line comments in gitlab are
probably the most convenient for me.

Thank you!