Skip to content

Fix mldsa hostkey derive - #1277

Open
stenslae wants to merge 4 commits into
wolfSSL:masterfrom
stenslae:fix-mldsa-hostkey-derive
Open

stenslae wants to merge 4 commits into
wolfSSL:masterfrom
stenslae:fix-mldsa-hostkey-derive

Conversation

@stenslae

Copy link
Copy Markdown
Member

Added support for loading private-only ML-DSA host keys. Uses wc_MlDsaKey_MakePublicKey() (wolfSSL/wolfssl#10985) to derive the public key when parsing private-only ML-DSA DER bytes. Extends WOLFSSH_PVT_KEY struct to cache raw ML-DSA public key. Updated SendKexGetSigningKey() to copy cached public key. Added ClearMlDsaHostPubKey() to manage chached public key.

Added tests for ML-DSA key derivation in end-to-end authentication, and coverage for load time derivcation and CTX caching and clearing.

For issue #1120

@stenslae stenslae self-assigned this Sep 28, 2026

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #1277

Scan targets checked: wolfssh-src, wolfssh-bugs
Coverage: 2 of 5 in-scope changed file(s) opened by the reviewer; not opened: src/ssh.c, tests/auth.c, wolfssh/internal.h

Findings: 1
1 finding(s) posted as inline comments (see file-level comments below)

This review was generated automatically by Fenrir. Reported findings require changes before merge.

Review tier: Lite

Comment thread tests/unit.c Outdated
Copilot AI balanced review requested due to automatic review settings September 30, 2026 21:25
@stenslae
stenslae force-pushed the fix-mldsa-hostkey-derive branch from b62a9b9 to 1739412 Compare September 30, 2026 21:25

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #1277

Scan targets checked: wolfssh-src, wolfssh-bugs
Coverage: 2 of 5 in-scope changed file(s) opened by the reviewer; not opened: tests/auth.c, tests/unit.c, wolfssh/internal.h

Fenrir result: Approved ✅

No new issues found in the changed files.

Advisory only — this automated result does not count as a GitHub approval.

Review tier: Lite

@wolfSSL-Fenrir-bot
wolfSSL-Fenrir-bot dismissed their stale review September 30, 2026 21:28

Fenrir's latest completed scan found no issues; clearing the prior automated change request.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Cryptographic key handling and extensive compile-time configuration paths warrant final human review.

Review effort: Balanced
Findings: None

What changed in this PR

Adds private-only ML-DSA key support by deriving and caching the public key during loading.

Changes:

  • Detects and documents ML-DSA public-key derivation support.
  • Caches derived host public keys for KEX and manages their lifecycle.
  • Adds unit and authentication regression coverage.
File Description
wolfssh/​internal.h Adds capability detection and cache fields.
src/​internal.c Derives, caches, uses, and clears ML-DSA public keys.
src/​ssh.c Clears caches when replacing certificate-store slots.
configure.ac Detects the wolfSSL derivation API.
README.md Documents private-only key behavior.
tests/​unit.c Tests derivation, caching, failures, and disabled levels.
tests/​auth.h Extends authentication test arguments for host certificates.
tests/​auth.c Adds end-to-end key, certificate, and user-auth tests.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants