Skip to content

Conversation

johubertj
Copy link
Contributor

Release Summary:

Resolved issues:

Partially addresses #5152

Description of changes:

-Registered ML-DSA-87 as an allowed certificate public key type (will be used as a certificate key for security policies cnsa_2 and cnsa_1_2_hybrid)

Call-outs:

-https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.204.ipd.pdf (Section 4 states mldsa_87 public key size is 2592 bytes or 20736 bits)

Testing:

How is this change tested (unit tests, fuzz tests, etc.)? What manual testing was performed? Are there any testing steps to be verified by the reviewer?
How can you convince your reviewers that this PR is safe and effective?
Is this a refactor change? If so, how have you proved that the intended behavior hasn't changed?

Remember:

  • Any change to the library source code should at least include unit tests.
  • Any change to the core stuffer or blob methods should include CBMC proofs.
  • Any change to the CI or tests should:
    1. prove that the test succeeds for good input
    2. prove that the test fails for bad input (eg, a test for memory leaks fails when a memory leak is committed)

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

@github-actions github-actions bot added the s2n-core team label Jun 24, 2025
@johubertj johubertj changed the title feature: add mldsa 87 certificate public key feat: add mldsa 87 certificate public key Jun 24, 2025
Copy link

This PR has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant