mldsa support for pkey, pkcs8, x509 - #299
Draft
sebastian-carpenter wants to merge 1 commit into
Draft
sebastian-carpenter wants to merge 1 commit into
sebastian-carpenter wants to merge 1 commit into
Conversation
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
ML-DSA buffers have mismatched allocation metadata, and private DER buffers are released without being wiped.
Review effort: Balanced
Findings: 2
Open (2)
What changed in this PR
Adds ML-DSA support to pkey workflows and tests upstream EVP, PKCS8, and X509 functionality.
Changes:
- Adds ML-DSA private/public key serialization.
- Adds pkey, PKCS8, and X509 test coverage.
- Adds ML-DSA fixtures and renewal steps.
| File | Description |
|---|---|
src/pkey/clu_pkey.c |
Adds ML-DSA key serialization paths. |
src/pkcs/clu_pkcs8.c |
Corrects indentation. |
tests/pkey/pkey-test.py |
Tests ML-DSA key conversions. |
tests/pkcs/pkcs8-test.py |
Tests ML-DSA PKCS8 conversions. |
tests/x509/x509-process-test.py |
Tests ML-DSA and dual-algorithm certificates. |
certs/renew.sh |
Imports ML-DSA fixtures. |
certs/mldsa/mldsa44-key.pem |
Adds an ML-DSA private-key fixture. |
certs/mldsa/mldsa44-cert.pem |
Adds an ML-DSA certificate fixture. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| return BAD_FUNC_ARG; | ||
| } | ||
|
|
||
| derSz = wolfSSL_i2d_PrivateKey(pkey, out); |
| return BAD_FUNC_ARG; | ||
| } | ||
|
|
||
| derSz = wolfSSL_i2d_PUBKEY(pkey, out); |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Most of the work is upstream and depends on: wolfSSL/wolfssl#11597 && wolfSSL/wolfssl#11598.
Basically, just tie MLDSA into the pkey side. PKCS8 remains mostly unchanged, same with X509.
Add MLDSA testing for the support added in the above PRs:
Pull in some MLDSA certs and keys from wolfSSL for testing.
renew.shupdated with the paths and a new directory was addedcerts/mldsa/.