Skip to content

Add a CSR example using a raw ECC public key (Qx/Qy or X9.63) - #636

Open
dgarske wants to merge 1 commit into
wolfSSL:masterfrom
dgarske:csr_ecc_rawpub
Open

dgarske wants to merge 1 commit into
wolfSSL:masterfrom
dgarske:csr_ecc_rawpub

Conversation

@dgarske

@dgarske dgarske commented Oct 1, 2026

Copy link
Copy Markdown
Member

Description

A recurring support question is whether an ECC public key has to be wrapped in a DER SubjectPublicKeyInfo or PEM before it can go into a certificate signing request. It does not, and nothing in certgen/ showed the alternative - csr_example generates its own key and csr_cryptocb loads DER from a file.

What it adds

  • certgen/csr_ecc_rawpub.c - builds and signs a P-256 request from raw key material, importing the public key twice: from bare big-endian Qx/Qy with wc_ecc_import_unsigned() and from the X9.63 point 0x04||X||Y with wc_ecc_import_x963_ex(), then asserting the two request bodies are byte for byte identical. Passing d = NULL leaves the key public only, which is all wc_MakeCertReq_ex() needs.
  • certgen/Makefile - build, clean and make check entries
  • certgen/README.md - build options and output, pointing at csr_cryptocb for the case where the private key lives in a secure element and wc_SignCert_ex() routes to a crypto callback

The key material is a throw-away P-256 key in the source, standing in for whatever the device holds, so the example needs no files and no key generation.

@dgarske dgarske self-assigned this Oct 1, 2026
Copilot AI balanced review requested due to automatic review settings October 1, 2026 20:25

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Signature-verification behavior and compatibility with the documented wolfSSL configuration still need runtime confirmation.

Review effort: Balanced
Findings: None

What changed in this PR

Adds a self-contained example showing how raw ECC public keys can be used to build certificate signing requests without DER or PEM input.

Changes:

  • Imports P-256 public keys from Qx/Qy and X9.63 bytes, compares request bodies, and signs and verifies the CSR.
  • Integrates the example into build, clean, and check targets.
  • Documents build options, sample output, and hardware-signing guidance.
File Description
certgen/​README.md Documents usage and hardware-signing alternatives.
certgen/​Makefile Adds build, cleanup, and check integration.
certgen/​csr_ecc_rawpub.c Implements raw-key imports and CSR validation.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@dgarske dgarske assigned wolfSSL-Bot and aidangarske and unassigned dgarske Oct 2, 2026
@dgarske
dgarske requested a review from aidangarske October 2, 2026 00:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants