-
Notifications
You must be signed in to change notification settings - Fork 6.2k
8347938: Add Support for the Latest ML-KEM and ML-DSA Private Key Encodings #24969
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
|
👋 Welcome back weijun! A progress list of the required criteria for merging this PR into |
|
❗ This change is not yet ready to be integrated. |
|
/issue add JDK-8347941 |
|
@wangweij The following labels will be automatically applied to this pull request:
When this pull request is ready to be reviewed, an "RFR" email will be sent to the corresponding mailing lists. If you would like to change these labels, use the /label pull request command. |
|
@wangweij |
|
/label remove core-libs |
|
@wangweij |
|
@wangweij |
… braces to if blocks
|
@wangweij this pull request can not be integrated into git checkout 8347938
git fetch https://git.openjdk.org/jdk.git master
git merge FETCH_HEAD
# resolve conflicts and follow the instructions given by git merge
git commit -m "Merge master"
git push |
src/java.base/share/classes/sun/security/provider/NamedKeyPairGenerator.java
Outdated
Show resolved
Hide resolved
src/java.base/share/classes/sun/security/provider/NamedKeyFactory.java
Outdated
Show resolved
Hide resolved
|
@wangweij This pull request has been inactive for more than 4 weeks and will be automatically closed if another 4 weeks passes without any activity. To avoid this, simply issue a |
|
@wangweij This pull request has been inactive for more than 8 weeks and will now be automatically closed. If you would like to continue working on this pull request in the future, feel free to reopen it! This can be done using the |
|
/open |
|
@wangweij This pull request is now open |
overheadhunter
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
If my understanding is correct, we have now up to three byte[] in the NamedPKCS8Key class:
- the encoded format
- the raw expanded format
- the raw seed
With getRawBytes() either returning the encoded or the expanded format, depending on whether the encoded format and the expanded key are the same.
getEncoded() on the other hand always wraps the raw key in its ASN.1 structure.
Shouldn't engineTranslateKey() rely on the latter, then?
|
@wangweij This pull request has been inactive for more than 4 weeks and will be automatically closed if another 4 weeks passes without any activity. To avoid this, simply issue a |
|
/issue remove JDK-8347941 |
|
@wangweij |
The private key encoding formats of ML-KEM and ML-DSA are updated to match the latest IETF drafts at: https://datatracker.ietf.org/doc/html/draft-ietf-lamps-dilithium-certificates-11 and https://datatracker.ietf.org/doc/html/draft-ietf-lamps-kyber-certificates-10. New security/system properties are introduced to determine which CHOICE a private key is encoded when a new key pair is generated or when
KeyFactory::translateKeyis called.By default, the choice is "seed".
Both the encoding and the expanded format are stored inside a
NamedPKCS8Keynow. When loading from a PKCS #8 key, the expanded format is calculated from the input if it's seed only.Progress
Issues
Reviewers
Reviewing
Using
gitCheckout this PR locally:
$ git fetch https://git.openjdk.org/jdk.git pull/24969/head:pull/24969$ git checkout pull/24969Update a local copy of the PR:
$ git checkout pull/24969$ git pull https://git.openjdk.org/jdk.git pull/24969/headUsing Skara CLI tools
Checkout this PR locally:
$ git pr checkout 24969View PR using the GUI difftool:
$ git pr show -t 24969Using diff file
Download this PR as a diff file:
https://git.openjdk.org/jdk/pull/24969.diff
Using Webrev
Link to Webrev Comment