Skip to content

X509 support for ML-DSA and dual-alg certs - #11598

Merged
Frauschi merged 2 commits into
wolfSSL:masterfrom
sebastian-carpenter:ml-dsa-x509
Oct 9, 2026
Merged

Frauschi merged 2 commits into
wolfSSL:masterfrom
sebastian-carpenter:ml-dsa-x509

Conversation

@sebastian-carpenter

Copy link
Copy Markdown
Contributor

Description

Improve ML-DSA support for X509:

  • Translation of pkey's
  • Printing certificates
  • pubkey access

Printing:

  • Reworked X509PrintPubKey to lookup the item to print via the NID
  • Added ML-DSA print support
  • Added print for dual-alg certs
    • Unrecognized algs will not stop the print either, matching OSSL
  • Added NID's for the oid's associated with the alt extensions

pkey:

wolfSSL_X509_PUBKEY_get0_param:

  • Previously just returned a pointer, modified to return just the BIT STRING within the given spki (best effort)

zd#22316

Testing

tests/api.c, new:

  • do_dual_alg_root_certgen_mldsa, test_wolfSSL_X509_print_mldsa, test_wolfSSL_X509_print_dual_alg, test_wolfSSL_X509_print_dual_alg_mldsa, test_wolfSSL_X509_print_dual_alg_unsupported
  • Generate certs: ecc, mldsa. Test printing ECC, MLDSA, and alt sections works.
  • Unrecognized algs do not cause printing to fail. Instead that section is replaced with the alg OID.

tests/api.c, modified:

  • fix invalid date 20493112 -> 20491231.

tests/api/test_ossl_x509_pk.c:

  • New: test_wolfSSL_X509_PUBKEY_MLDSA
    • Test SPKI generation
  • Modified:
    • test_wolfSSL_X509_PUBKEY_RSA, test_wolfSSL_X509_PUBKEY_EC wrap output in spki.
    • test_wolfSSL_X509_set_pubkey test that the needed raw pubKey buffer is given, assert failure of MLDSA public key derivation (PR Added ML-DSA MakePublicKey derivation #10985 will require an API call instead of it being on-demand), dilithium OID is preserved.

Checklist

  • added tests
  • updated/added doxygen
  • updated appropriate READMEs
  • Updated manual and documentation

@sebastian-carpenter sebastian-carpenter self-assigned this Sep 29, 2026
Copilot AI balanced review requested due to automatic review settings September 29, 2026 22:55

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

ML-DSA X.509 public-key round trips fail in builds without asymmetric-key export support.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Adds ML-DSA and dual-algorithm certificate support across X.509 parsing, printing, key translation, and OpenSSL-compatible APIs.

Changes:

  • Adds ML-DSA EVP key encoding and certificate printing.
  • Adds dual-algorithm extension NIDs, OIDs, and print handling.
  • Expands tests for SPKI, PKCS#8, PEM, and X.509 workflows.
File Description
wolfssl/​wolfcrypt/​asn.h Defines dual-algorithm extension NIDs.
wolfcrypt/​src/​evp.c Prints ML-DSA public keys.
wolfcrypt/​src/​evp_pk.c Adds ML-DSA DER/SPKI and PKCS#8 handling.
wolfcrypt/​src/​asn.c Maps dual-algorithm extension OIDs.
tests/​api/​test_ossl_x509_pk.h Registers ML-DSA X.509 tests.
tests/​api/​test_ossl_x509_pk.c Tests ML-DSA SPKI and public-key handling.
tests/​api/​test_ossl_pem.h Registers ML-DSA PEM tests.
tests/​api/​test_ossl_pem.c Tests ML-DSA key round trips.
tests/​api.c Adds certificate-generation and printing tests.
src/​x509.c Implements ML-DSA and dual-algorithm X.509 support.
src/​ssl_asn1.c Registers dual-algorithm object metadata.
src/​pk.c Updates ML-DSA PKCS#8 processing.
src/​internal.c Populates parsed ML-DSA X.509 public keys.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/x509.c Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

ML-DSA public-key printing fails for EVP_PKEY objects backed by PKCS#8 private-key data.

Review effort: Balanced
Findings: 1 Medium severity · 1 Low severity

Open (2)
Resolved since last review (1)

Comment thread wolfcrypt/src/evp.c
Comment thread tests/api.c
@sebastian-carpenter
sebastian-carpenter marked this pull request as ready for review October 5, 2026 19:51
@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

@sebastian-carpenter

Copy link
Copy Markdown
Contributor Author

Jenkins retest this please

@Frauschi Frauschi left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Overall looks great, just some small issues.

Comment thread src/x509.c
Comment thread wolfssl/wolfcrypt/asn.h
Comment thread wolfcrypt/src/evp.c Outdated
Comment thread wolfcrypt/src/evp.c

@Frauschi Frauschi left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@Frauschi
Frauschi merged commit bb236b4 into wolfSSL:master Oct 9, 2026
413 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants