Conversation
Contributor
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Signature-verification behavior and compatibility with the documented wolfSSL configuration still need runtime confirmation.
Review effort: Balanced
Findings: None
What changed in this PR
Adds a self-contained example showing how raw ECC public keys can be used to build certificate signing requests without DER or PEM input.
Changes:
- Imports P-256 public keys from Qx/Qy and X9.63 bytes, compares request bodies, and signs and verifies the CSR.
- Integrates the example into build, clean, and check targets.
- Documents build options, sample output, and hardware-signing guidance.
| File | Description |
|---|---|
| certgen/README.md | Documents usage and hardware-signing alternatives. |
| certgen/Makefile | Adds build, cleanup, and check integration. |
| certgen/csr_ecc_rawpub.c | Implements raw-key imports and CSR validation. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
A recurring support question is whether an ECC public key has to be wrapped in a DER SubjectPublicKeyInfo or PEM before it can go into a certificate signing request. It does not, and nothing in
certgen/showed the alternative -csr_examplegenerates its own key andcsr_cryptocbloads DER from a file.What it adds
certgen/csr_ecc_rawpub.c- builds and signs a P-256 request from raw key material, importing the public key twice: from bare big-endianQx/Qywithwc_ecc_import_unsigned()and from the X9.63 point0x04||X||Ywithwc_ecc_import_x963_ex(), then asserting the two request bodies are byte for byte identical. Passingd = NULLleaves the key public only, which is allwc_MakeCertReq_ex()needs.certgen/Makefile- build, clean andmake checkentriescertgen/README.md- build options and output, pointing atcsr_cryptocbfor the case where the private key lives in a secure element andwc_SignCert_ex()routes to a crypto callbackThe key material is a throw-away P-256 key in the source, standing in for whatever the device holds, so the example needs no files and no key generation.