SECENG-13957: feat: add ML-DSA-44/65/87 post-quantum key support - #1445
Conversation
ang-cloudflare
left a comment
There was a problem hiding this comment.
Scout Review
Comment — 3 findings worth addressing, none blocking.
The core ML-DSA support (key generation, sig algo mapping, PKCS#8 serialization, DER parsing) is correctly implemented. These are cross-boundary gaps in subsystems the PR doesn't touch yet — fixing them here keeps the feature internally consistent.
See inline comments for details.
0dd8d19 to
27fff9e
Compare
|
Could we get a release with this feature? It would be super helpful for the Kubernetes project. |
mitch292
left a comment
There was a problem hiding this comment.
lgtm, but can you please squash the commits
|
Also can we update the readme now that latest requires go1.27 - https://github.com/cloudflare/cfssl/blob/master/README.md - there are a few references to go 1.20 |
0d541b3 to
a1d3f61
Compare
Add ML-DSA (FIPS 204) key generation and X.509 signature support using Go 1.27 crypto/mldsa for the explicit mldsa44, mldsa65, and mldsa87 KeyRequest algorithms. - Marshal ML-DSA private keys as seed-only PKCS#8 and parse them through derhelpers. - Support ML-DSA in bundling, CA renewal, key metadata, and display helpers. Bundles with an ML-DSA key get an ML-DSA ubiquity warning instead of the ECDSA one. - Drop the key usages RFC 9881 forbids for ML-DSA keys, and fail with NoKeyUsages when none of the profile's key usages remain. - Return an error instead of panicking on unexpected CSR key types. - multirootca rejects ML-DSA roots at startup instead of registering a nil signer. Go 1.27 migration: - Raise the module minimum to Go 1.27 and pin godebug x509negativeserial=1 so the negative-serial root in cfssl_trust still parses. - Build the Docker images and CI with Go 1.27, migrate the golangci-lint config to v2, add a FIPS 140 ML-DSA test step, and update the README minimum. - Replace the README's `go get` install for mkbundle, which fails outside a module, with `go install ...@latest`, and drop the go.rice static-build steps now that the web assets use go:embed. - Map -min-tls-version 1.3 to TLS 1.3 and document the Go 1.27 TLS 1.2 default.
a1d3f61 to
05f2d4f
Compare
|
Squashed into one commit (05f2d4f). The README's Go 1.20 references now say 1.27. I also fixed the mkbundle install command ( |
Summary
Add ML-DSA (FIPS 204) key generation and signature algorithm support using Go 1.27 crypto/mldsa. This enables the explicit mldsa44, mldsa65, and mldsa87 KeyRequest algorithm values for post-quantum certificate authority generation.
ML-DSA-44 is the downstream default when an ML-DSA variant is omitted. cfssl continues to accept only explicit parameter-set names; the omitted-selection default belongs in the calling service.
Changes
Core ML-DSA support
loadSignersreturns an error instead of registering a nil signer.Verification
Go 1.27 migration
//go:build go1.27split with stub files could keep an older floor, but it needs paired files across seven packages. This PR takes the simpler 1.27 floor. Maintainers, please say if you would prefer the split.godebug x509negativeserial=1in go.mod. Raising the go line flips this default, and the EC-ACC root in cloudflare/cfssl_trust has a negative serial. Without the pin,cfssl bundlefails with "Failed to parse root certificate" andcfssl servedisables its sign, newcert, and bundle endpoints. The pin applies only to cfssl's own binaries and tests; library importers follow their own go line.-min-tls-versionhelp text to the Go 1.27 default (1.2). Map "1.3" to TLS 1.3 inhelpers.StringTLSVersion; it used to fall through to TLS 1.0.Release notes
cfssl serveand multirootca now require TLS 1.2 by default and no longer offer RSA key exchange or 3DES.cfssl serve -min-tls-version 1.0still allows TLS 1.0 and 1.1, but nothing restores RSA key exchange or 3DES. Outbound TLS (cfssl bundle -domain,cfssl certinfo -domain) changes the same way.-min-tls-version 1.3now sets TLS 1.3. It used to set TLS 1.0.signer.KeyUsageForPublicKeyis new, andhelpers.StringTLSVersionnow maps "1.3" to TLS 1.3.Context