Skip to content

mldsa support for pkey, pkcs8, x509 - #299

Draft
sebastian-carpenter wants to merge 1 commit into
wolfSSL:mainfrom
sebastian-carpenter:mldsa-evp
Draft

sebastian-carpenter wants to merge 1 commit into
wolfSSL:mainfrom
sebastian-carpenter:mldsa-evp

Conversation

@sebastian-carpenter

Copy link
Copy Markdown
Contributor

Most of the work is upstream and depends on: wolfSSL/wolfssl#11597 && wolfSSL/wolfssl#11598.

Basically, just tie MLDSA into the pkey side. PKCS8 remains mostly unchanged, same with X509.

Add MLDSA testing for the support added in the above PRs:

  • EVP PKEY import / export
  • PKCS8 import / export
  • X509 printing of normal ML-DSA certs and dual-alg versions

Pull in some MLDSA certs and keys from wolfSSL for testing. renew.sh updated with the paths and a new directory was added certs/mldsa/.

@sebastian-carpenter sebastian-carpenter self-assigned this Sep 29, 2026
Copilot AI balanced review requested due to automatic review settings September 29, 2026 23:10

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

ML-DSA buffers have mismatched allocation metadata, and private DER buffers are released without being wiped.

Review effort: Balanced
Findings: 2 Medium severity

Open (2)
What changed in this PR

Adds ML-DSA support to pkey workflows and tests upstream EVP, PKCS8, and X509 functionality.

Changes:

  • Adds ML-DSA private/public key serialization.
  • Adds pkey, PKCS8, and X509 test coverage.
  • Adds ML-DSA fixtures and renewal steps.
File Description
src/​pkey/​clu_pkey.c Adds ML-DSA key serialization paths.
src/​pkcs/​clu_pkcs8.c Corrects indentation.
tests/​pkey/​pkey-test.py Tests ML-DSA key conversions.
tests/​pkcs/​pkcs8-test.py Tests ML-DSA PKCS8 conversions.
tests/​x509/​x509-process-test.py Tests ML-DSA and dual-algorithm certificates.
certs/​renew.sh Imports ML-DSA fixtures.
certs/​mldsa/​mldsa44-key.pem Adds an ML-DSA private-key fixture.
certs/​mldsa/​mldsa44-cert.pem Adds an ML-DSA certificate fixture.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/pkey/clu_pkey.c
return BAD_FUNC_ARG;
}

derSz = wolfSSL_i2d_PrivateKey(pkey, out);
Comment thread src/pkey/clu_pkey.c
return BAD_FUNC_ARG;
}

derSz = wolfSSL_i2d_PUBKEY(pkey, out);
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants