Skip to content

Use OpenSSL 3 EVP_Q_mac for HMAC operations - #196

Merged
TheStormN merged 1 commit into
masterfrom
replace-HMAC-with-EVP_Q_mac
Sep 13, 2026
Merged

TheStormN merged 1 commit into
masterfrom
replace-HMAC-with-EVP_Q_mac

Conversation

@TheStormN

Copy link
Copy Markdown
Contributor

Replace legacy HMAC() calls in HKDF and JWE authentication-tag generation
with OpenSSL 3's one-shot EVP_Q_mac() API.

Use size_t consistently for MAC lengths, remove obsolete casts, and
preserve existing HKDF expansion and JWE tag-truncation behavior.

@TheStormN
TheStormN force-pushed the replace-HMAC-with-EVP_Q_mac branch from 2b8b092 to a22c207 Compare September 13, 2026 21:04
@TheStormN
TheStormN merged commit fc56eaa into master Sep 13, 2026
27 checks passed
@TheStormN
TheStormN deleted the replace-HMAC-with-EVP_Q_mac branch September 13, 2026 21:17
TheStormN pushed a commit that referenced this pull request Sep 15, 2026
The 1.0.0 section carried only the Breaking list that #187 wrote, so nothing
merged after it was recorded: the A*GCMKW, PBES2, X25519/X448 and ML-DSA
algorithms, the "crit" refusal and the JWE header disjointness, the JWK import
refusals of #189, #190, #192 and #193, the NULL cjose_err crash of #191 and the
EVP_Q_mac change of #196. The entries reference pull requests, as the rest of
that section does, rather than the commit links the released sections use.

The "crit" refusal is listed as breaking because it refuses a JWE or JWS that
0.8.0 accepted. Three more rules do the same without changing the API, so they
stay under Fix and a Compatibility paragraph names them, the way the 0.8.1
notes do: the disjointness of the header locations, the refusal of a header
parameter the algorithm generates, and the refusal of a valueless private
member in an RSA or EC key.

0.8.1 was released from the 0.8.x branch on 2026-09-14 and its section only
ever existed there, so this file jumped from the unreleased 1.0.0 straight to
0.8.0 and the release was invisible here. It is copied over unchanged.

The README already describes the ML-DSA algorithms, the AKP key type and the
CJOSE_ENABLE_ML_DSA option; the only thing missing was the OpenSSL requirement
in the prerequisites, which named 3.0.0 alone.

Signed-off-by: Hans Zandbelt <hans.zandbelt@openidc.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant