master
tests: add round-trip test of ML-DSA keys
tests/cert-tests: add tests for #1825
certtool: avoid 1-byte write buffer overrun when parsing template
configure: fix faketime detection
tests: use SH_LOG_COMPILER in cert-tests
test/cert-tests: use --attime in more tests
tests: add test for RSA-OAEP cert generation with certtool
tests: use template file for generating long DNS certificate request
Add configuration option to disable/enable DSA signing and verification
doc: fix typos found by codespell
nettle: support deriving ML-DSA public key from expanded secret key
pkcs12: enable PBMAC1 by default in FIPS mode
x509: support PBES1-DES-SHA1
tests: add negative serial number test
Fix typos