Repository navigation
Use OpenSSL 3 EVP_Q_mac for HMAC operations - #196
Merged
Merged
Conversation
TheStormN
force-pushed
the
replace-HMAC-with-EVP_Q_mac
branch
from
September 13, 2026 21:04
2b8b092 to
a22c207
Compare
This was referenced Sep 15, 2026
TheStormN
pushed a commit
that referenced
this pull request
Sep 15, 2026
The 1.0.0 section carried only the Breaking list that #187 wrote, so nothing merged after it was recorded: the A*GCMKW, PBES2, X25519/X448 and ML-DSA algorithms, the "crit" refusal and the JWE header disjointness, the JWK import refusals of #189, #190, #192 and #193, the NULL cjose_err crash of #191 and the EVP_Q_mac change of #196. The entries reference pull requests, as the rest of that section does, rather than the commit links the released sections use. The "crit" refusal is listed as breaking because it refuses a JWE or JWS that 0.8.0 accepted. Three more rules do the same without changing the API, so they stay under Fix and a Compatibility paragraph names them, the way the 0.8.1 notes do: the disjointness of the header locations, the refusal of a header parameter the algorithm generates, and the refusal of a valueless private member in an RSA or EC key. 0.8.1 was released from the 0.8.x branch on 2026-09-14 and its section only ever existed there, so this file jumped from the unreleased 1.0.0 straight to 0.8.0 and the release was invisible here. It is copied over unchanged. The README already describes the ML-DSA algorithms, the AKP key type and the CJOSE_ENABLE_ML_DSA option; the only thing missing was the OpenSSL requirement in the prerequisites, which named 3.0.0 alone. Signed-off-by: Hans Zandbelt <hans.zandbelt@openidc.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Replace legacy HMAC() calls in HKDF and JWE authentication-tag generation
with OpenSSL 3's one-shot EVP_Q_mac() API.
Use size_t consistently for MAC lengths, remove obsolete casts, and
preserve existing HKDF expansion and JWE tag-truncation behavior.