Skip to content

Fix mldsa hostkey derive - #1277

Open
stenslae wants to merge 2 commits into
wolfSSL:masterfrom
stenslae:fix-mldsa-hostkey-derive
Open

stenslae wants to merge 2 commits into
wolfSSL:masterfrom
stenslae:fix-mldsa-hostkey-derive

Conversation

@stenslae

Copy link
Copy Markdown
Member

Added support for loading private-only ML-DSA host keys. Uses wc_MlDsaKey_MakePublicKey() (wolfSSL/wolfssl#10985) to derive the public key when parsing private-only ML-DSA DER bytes. Extends WOLFSSH_PVT_KEY struct to cache raw ML-DSA public key. Updated SendKexGetSigningKey() to copy cached public key. Added ClearMlDsaHostPubKey() to manage chached public key.

Added tests for ML-DSA key derivation in end-to-end authentication, and coverage for load time derivcation and CTX caching and clearing.

For issue #1120

@stenslae stenslae self-assigned this Sep 28, 2026

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #1277

Scan targets checked: wolfssh-src, wolfssh-bugs
Coverage: 2 of 5 in-scope changed file(s) opened by the reviewer; not opened: src/ssh.c, tests/auth.c, wolfssh/internal.h

Findings: 1
1 finding(s) posted as inline comments (see file-level comments below)

This review was generated automatically by Fenrir. Reported findings require changes before merge.

Review tier: Lite

Comment thread tests/unit.c
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants