Repository navigation
X509 support for ML-DSA and dual-alg certs - #11598
Merged
Merged
Conversation
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
ML-DSA X.509 public-key round trips fail in builds without asymmetric-key export support.
Review effort: Balanced
Findings: 1
What changed in this PR
Adds ML-DSA and dual-algorithm certificate support across X.509 parsing, printing, key translation, and OpenSSL-compatible APIs.
Changes:
- Adds ML-DSA EVP key encoding and certificate printing.
- Adds dual-algorithm extension NIDs, OIDs, and print handling.
- Expands tests for SPKI, PKCS#8, PEM, and X.509 workflows.
| File | Description |
|---|---|
wolfssl/wolfcrypt/asn.h |
Defines dual-algorithm extension NIDs. |
wolfcrypt/src/evp.c |
Prints ML-DSA public keys. |
wolfcrypt/src/evp_pk.c |
Adds ML-DSA DER/SPKI and PKCS#8 handling. |
wolfcrypt/src/asn.c |
Maps dual-algorithm extension OIDs. |
tests/api/test_ossl_x509_pk.h |
Registers ML-DSA X.509 tests. |
tests/api/test_ossl_x509_pk.c |
Tests ML-DSA SPKI and public-key handling. |
tests/api/test_ossl_pem.h |
Registers ML-DSA PEM tests. |
tests/api/test_ossl_pem.c |
Tests ML-DSA key round trips. |
tests/api.c |
Adds certificate-generation and printing tests. |
src/x509.c |
Implements ML-DSA and dual-algorithm X.509 support. |
src/ssl_asn1.c |
Registers dual-algorithm object metadata. |
src/pk.c |
Updates ML-DSA PKCS#8 processing. |
src/internal.c |
Populates parsed ML-DSA X.509 public keys. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
sebastian-carpenter
force-pushed
the
ml-dsa-x509
branch
from
October 5, 2026 18:03
235a312 to
da46eac
Compare
sebastian-carpenter
marked this pull request as ready for review
October 5, 2026 19:51
sebastian-carpenter
force-pushed
the
ml-dsa-x509
branch
from
October 5, 2026 20:28
da46eac to
71bf72e
Compare
|
Contributor
Author
|
Jenkins retest this please |
Frauschi
requested changes
Oct 8, 2026
Frauschi
left a comment
Member
There was a problem hiding this comment.
Overall looks great, just some small issues.
sebastian-carpenter
force-pushed
the
ml-dsa-x509
branch
from
October 8, 2026 18:17
c8a0ede to
a060c5e
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Description
Improve ML-DSA support for X509:
Printing:
pkey:
wolfSSL_X509_PUBKEY_get0_param:
zd#22316
Testing
tests/api.c, new:
do_dual_alg_root_certgen_mldsa,test_wolfSSL_X509_print_mldsa,test_wolfSSL_X509_print_dual_alg,test_wolfSSL_X509_print_dual_alg_mldsa,test_wolfSSL_X509_print_dual_alg_unsupportedtests/api.c, modified:
tests/api/test_ossl_x509_pk.c:
wolfSSL_X509_PUBKEY_MLDSAtest_wolfSSL_X509_PUBKEY_RSA,test_wolfSSL_X509_PUBKEY_ECwrap output in spki.test_wolfSSL_X509_set_pubkeytest that the needed raw pubKey buffer is given, assert failure of MLDSA public key derivation (PR Added ML-DSA MakePublicKey derivation #10985 will require an API call instead of it being on-demand), dilithium OID is preserved.Checklist