Namely: - Perform case-insensitive matching - Return the same extension objects every time - Only enable the extension if it's supported by the current context
verify_cast
as
RSA_PSS_EMSA
RSA_PKCS1-EMSA
Crypto::fill_with_secure_random