Skip to content

fixes #608 -- added mldsa cert tests - #644

Merged
woodruffw merged 1 commit into
mainfrom
mldsa
Jul 26, 2026
Merged

fixes #608 -- added mldsa cert tests#644
woodruffw merged 1 commit into
mainfrom
mldsa

Conversation

@alex

@alex alex commented Jul 26, 2026

Copy link
Copy Markdown
Collaborator

No description provided.

@github-actions

Copy link
Copy Markdown
Contributor

:shipit: No regressions found.

@github-actions

Copy link
Copy Markdown
Contributor

New testcases

There are new testcases in this change.

openssl-3.0.20

Testcase Expected Result Actual Result Context
rfc9881::ml-dsa-87 SUCCESS FAILURE EE certificate key too weak
rfc9881::ml-dsa-44-key-encipherment FAILURE FAILURE EE certificate key too weak
rfc9881::ml-dsa-44-bad-signature FAILURE FAILURE EE certificate key too weak
rfc9881::ml-dsa-44-key-agreement FAILURE FAILURE EE certificate key too weak
rfc9881::ml-dsa-65 SUCCESS FAILURE EE certificate key too weak
rfc9881::ml-dsa-44 SUCCESS FAILURE EE certificate key too weak

openssl-3.2.6

Testcase Expected Result Actual Result Context
rfc9881::ml-dsa-87 SUCCESS FAILURE EE certificate key too weak
rfc9881::ml-dsa-44-key-encipherment FAILURE FAILURE EE certificate key too weak
rfc9881::ml-dsa-44-bad-signature FAILURE FAILURE EE certificate key too weak
rfc9881::ml-dsa-44-key-agreement FAILURE FAILURE EE certificate key too weak
rfc9881::ml-dsa-65 SUCCESS FAILURE EE certificate key too weak
rfc9881::ml-dsa-44 SUCCESS FAILURE EE certificate key too weak

gnutls-certtool-3.8.3

Testcase Expected Result Actual Result Context
rfc9881::ml-dsa-87 SUCCESS FAILURE Chain verification output: Not verified. The certificate is NOT trusted.
rfc9881::ml-dsa-44-key-encipherment FAILURE FAILURE Chain verification output: Not verified. The certificate is NOT trusted.
rfc9881::ml-dsa-44-bad-signature FAILURE FAILURE Chain verification output: Not verified. The certificate is NOT trusted.
rfc9881::ml-dsa-44-key-agreement FAILURE FAILURE Chain verification output: Not verified. The certificate is NOT trusted.
rfc9881::ml-dsa-65 SUCCESS FAILURE Chain verification output: Not verified. The certificate is NOT trusted.
rfc9881::ml-dsa-44 SUCCESS FAILURE Chain verification output: Not verified. The certificate is NOT trusted.

certvalidator-0.11.1

Testcase Expected Result Actual Result Context
rfc9881::ml-dsa-87 SUCCESS FAILURE Hash algorithm not known for 2.16.840.1.101.3.4.3.19
rfc9881::ml-dsa-44-key-encipherment FAILURE FAILURE Hash algorithm not known for 2.16.840.1.101.3.4.3.17
rfc9881::ml-dsa-44-bad-signature FAILURE FAILURE Hash algorithm not known for 2.16.840.1.101.3.4.3.17
rfc9881::ml-dsa-44-key-agreement FAILURE FAILURE Hash algorithm not known for 2.16.840.1.101.3.4.3.17
rfc9881::ml-dsa-65 SUCCESS FAILURE Hash algorithm not known for 2.16.840.1.101.3.4.3.18
rfc9881::ml-dsa-44 SUCCESS FAILURE Hash algorithm not known for 2.16.840.1.101.3.4.3.17

openssl-3.6.2

Testcase Expected Result Actual Result Context
rfc9881::ml-dsa-87 SUCCESS SUCCESS None
rfc9881::ml-dsa-44-key-encipherment FAILURE SUCCESS None
rfc9881::ml-dsa-44-bad-signature FAILURE FAILURE certificate signature failure
rfc9881::ml-dsa-44-key-agreement FAILURE SUCCESS None
rfc9881::ml-dsa-65 SUCCESS SUCCESS None
rfc9881::ml-dsa-44 SUCCESS SUCCESS None

rust-webpki

Testcase Expected Result Actual Result Context
rfc9881::ml-dsa-87 SUCCESS FAILURE UnknownIssuer
rfc9881::ml-dsa-44-key-encipherment FAILURE FAILURE UnknownIssuer
rfc9881::ml-dsa-44-bad-signature FAILURE FAILURE UnknownIssuer
rfc9881::ml-dsa-44-key-agreement FAILURE FAILURE UnknownIssuer
rfc9881::ml-dsa-65 SUCCESS FAILURE UnknownIssuer
rfc9881::ml-dsa-44 SUCCESS FAILURE UnknownIssuer

libressl-4.3.1

Testcase Expected Result Actual Result Context
rfc9881::ml-dsa-87 SUCCESS FAILURE EE certificate key too weak
rfc9881::ml-dsa-44-key-encipherment FAILURE FAILURE EE certificate key too weak
rfc9881::ml-dsa-44-bad-signature FAILURE FAILURE EE certificate key too weak
rfc9881::ml-dsa-44-key-agreement FAILURE FAILURE EE certificate key too weak
rfc9881::ml-dsa-65 SUCCESS FAILURE EE certificate key too weak
rfc9881::ml-dsa-44 SUCCESS FAILURE EE certificate key too weak

libressl-4.1.2

Testcase Expected Result Actual Result Context
rfc9881::ml-dsa-87 SUCCESS FAILURE EE certificate key too weak
rfc9881::ml-dsa-44-key-encipherment FAILURE FAILURE EE certificate key too weak
rfc9881::ml-dsa-44-bad-signature FAILURE FAILURE EE certificate key too weak
rfc9881::ml-dsa-44-key-agreement FAILURE FAILURE EE certificate key too weak
rfc9881::ml-dsa-65 SUCCESS FAILURE EE certificate key too weak
rfc9881::ml-dsa-44 SUCCESS FAILURE EE certificate key too weak

openssl-3.5.6

Testcase Expected Result Actual Result Context
rfc9881::ml-dsa-87 SUCCESS SUCCESS None
rfc9881::ml-dsa-44-key-encipherment FAILURE SUCCESS None
rfc9881::ml-dsa-44-bad-signature FAILURE FAILURE certificate signature failure
rfc9881::ml-dsa-44-key-agreement FAILURE SUCCESS None
rfc9881::ml-dsa-65 SUCCESS SUCCESS None
rfc9881::ml-dsa-44 SUCCESS SUCCESS None

libressl-4.2.1

Testcase Expected Result Actual Result Context
rfc9881::ml-dsa-87 SUCCESS FAILURE EE certificate key too weak
rfc9881::ml-dsa-44-key-encipherment FAILURE FAILURE EE certificate key too weak
rfc9881::ml-dsa-44-bad-signature FAILURE FAILURE EE certificate key too weak
rfc9881::ml-dsa-44-key-agreement FAILURE FAILURE EE certificate key too weak
rfc9881::ml-dsa-65 SUCCESS FAILURE EE certificate key too weak
rfc9881::ml-dsa-44 SUCCESS FAILURE EE certificate key too weak

boringssl-legacy-40

Testcase Expected Result Actual Result Context
rfc9881::ml-dsa-87 SUCCESS SUCCESS None
rfc9881::ml-dsa-44-key-encipherment FAILURE SUCCESS None
rfc9881::ml-dsa-44-bad-signature FAILURE FAILURE certificate signature failure
rfc9881::ml-dsa-44-key-agreement FAILURE SUCCESS None
rfc9881::ml-dsa-65 SUCCESS SUCCESS None
rfc9881::ml-dsa-44 SUCCESS SUCCESS None

aws-lc-1.72.0

Testcase Expected Result Actual Result Context
rfc9881::ml-dsa-87 SUCCESS SUCCESS None
rfc9881::ml-dsa-44-key-encipherment FAILURE SUCCESS None
rfc9881::ml-dsa-44-bad-signature FAILURE FAILURE certificate signature failure
rfc9881::ml-dsa-44-key-agreement FAILURE SUCCESS None
rfc9881::ml-dsa-65 SUCCESS SUCCESS None
rfc9881::ml-dsa-44 SUCCESS SUCCESS None

openssl-1.1

Testcase Expected Result Actual Result Context
rfc9881::ml-dsa-87 SUCCESS FAILURE EE certificate key too weak
rfc9881::ml-dsa-44-key-encipherment FAILURE FAILURE EE certificate key too weak
rfc9881::ml-dsa-44-bad-signature FAILURE FAILURE EE certificate key too weak
rfc9881::ml-dsa-44-key-agreement FAILURE FAILURE EE certificate key too weak
rfc9881::ml-dsa-65 SUCCESS FAILURE EE certificate key too weak
rfc9881::ml-dsa-44 SUCCESS FAILURE EE certificate key too weak

gocryptox509-go1.26.5

Testcase Expected Result Actual Result Context
rfc9881::ml-dsa-87 SUCCESS FAILURE validation: x509: certificate signed by unknown authority
rfc9881::ml-dsa-44-key-encipherment FAILURE FAILURE
rfc9881::ml-dsa-44-bad-signature FAILURE FAILURE
rfc9881::ml-dsa-44-key-agreement FAILURE FAILURE
rfc9881::ml-dsa-65 SUCCESS FAILURE validation: x509: certificate signed by unknown authority
rfc9881::ml-dsa-44 SUCCESS FAILURE validation: x509: certificate signed by unknown authority

openssl-3.4.5

Testcase Expected Result Actual Result Context
rfc9881::ml-dsa-87 SUCCESS FAILURE EE certificate key too weak
rfc9881::ml-dsa-44-key-encipherment FAILURE FAILURE EE certificate key too weak
rfc9881::ml-dsa-44-bad-signature FAILURE FAILURE EE certificate key too weak
rfc9881::ml-dsa-44-key-agreement FAILURE FAILURE EE certificate key too weak
rfc9881::ml-dsa-65 SUCCESS FAILURE EE certificate key too weak
rfc9881::ml-dsa-44 SUCCESS FAILURE EE certificate key too weak

rustls-webpki

Testcase Expected Result Actual Result Context
rfc9881::ml-dsa-87 SUCCESS FAILURE UnsupportedSignatureAlgorithmContext(UnsupportedSignatureAlgorithmContext { signature_algorithm_id: [6, 9, 96, 134, 72, 1, 101, 3, 4, 3, 19], supported_algorithms: [0x06082a8648ce3d040302, 0x06082a8648ce3d040303, 0x06092a864886f70d01010b0500, 0x06092a864886f70d01010c0500, 0x06092a864886f70d01010d0500, 0x06092a864886f70d01010a3034a00f300d06096086480165030402010500a11c301a06092a864886f70d010108300d06096086480165030402010500a203020120, 0x06092a864886f70d01010a3034a00f300d06096086480165030402020500a11c301a06092a864886f70d010108300d06096086480165030402020500a203020130, 0x06092a864886f70d01010a3034a00f300d06096086480165030402030500a11c301a06092a864886f70d010108300d06096086480165030402030500a203020140] })
rfc9881::ml-dsa-44-key-encipherment FAILURE FAILURE UnsupportedSignatureAlgorithmContext(UnsupportedSignatureAlgorithmContext { signature_algorithm_id: [6, 9, 96, 134, 72, 1, 101, 3, 4, 3, 17], supported_algorithms: [0x06082a8648ce3d040302, 0x06082a8648ce3d040303, 0x06092a864886f70d01010b0500, 0x06092a864886f70d01010c0500, 0x06092a864886f70d01010d0500, 0x06092a864886f70d01010a3034a00f300d06096086480165030402010500a11c301a06092a864886f70d010108300d06096086480165030402010500a203020120, 0x06092a864886f70d01010a3034a00f300d06096086480165030402020500a11c301a06092a864886f70d010108300d06096086480165030402020500a203020130, 0x06092a864886f70d01010a3034a00f300d06096086480165030402030500a11c301a06092a864886f70d010108300d06096086480165030402030500a203020140] })
rfc9881::ml-dsa-44-bad-signature FAILURE FAILURE UnsupportedSignatureAlgorithmContext(UnsupportedSignatureAlgorithmContext { signature_algorithm_id: [6, 9, 96, 134, 72, 1, 101, 3, 4, 3, 17], supported_algorithms: [0x06082a8648ce3d040302, 0x06082a8648ce3d040303, 0x06092a864886f70d01010b0500, 0x06092a864886f70d01010c0500, 0x06092a864886f70d01010d0500, 0x06092a864886f70d01010a3034a00f300d06096086480165030402010500a11c301a06092a864886f70d010108300d06096086480165030402010500a203020120, 0x06092a864886f70d01010a3034a00f300d06096086480165030402020500a11c301a06092a864886f70d010108300d06096086480165030402020500a203020130, 0x06092a864886f70d01010a3034a00f300d06096086480165030402030500a11c301a06092a864886f70d010108300d06096086480165030402030500a203020140] })
rfc9881::ml-dsa-44-key-agreement FAILURE FAILURE UnsupportedSignatureAlgorithmContext(UnsupportedSignatureAlgorithmContext { signature_algorithm_id: [6, 9, 96, 134, 72, 1, 101, 3, 4, 3, 17], supported_algorithms: [0x06082a8648ce3d040302, 0x06082a8648ce3d040303, 0x06092a864886f70d01010b0500, 0x06092a864886f70d01010c0500, 0x06092a864886f70d01010d0500, 0x06092a864886f70d01010a3034a00f300d06096086480165030402010500a11c301a06092a864886f70d010108300d06096086480165030402010500a203020120, 0x06092a864886f70d01010a3034a00f300d06096086480165030402020500a11c301a06092a864886f70d010108300d06096086480165030402020500a203020130, 0x06092a864886f70d01010a3034a00f300d06096086480165030402030500a11c301a06092a864886f70d010108300d06096086480165030402030500a203020140] })
rfc9881::ml-dsa-65 SUCCESS FAILURE UnsupportedSignatureAlgorithmContext(UnsupportedSignatureAlgorithmContext { signature_algorithm_id: [6, 9, 96, 134, 72, 1, 101, 3, 4, 3, 18], supported_algorithms: [0x06082a8648ce3d040302, 0x06082a8648ce3d040303, 0x06092a864886f70d01010b0500, 0x06092a864886f70d01010c0500, 0x06092a864886f70d01010d0500, 0x06092a864886f70d01010a3034a00f300d06096086480165030402010500a11c301a06092a864886f70d010108300d06096086480165030402010500a203020120, 0x06092a864886f70d01010a3034a00f300d06096086480165030402020500a11c301a06092a864886f70d010108300d06096086480165030402020500a203020130, 0x06092a864886f70d01010a3034a00f300d06096086480165030402030500a11c301a06092a864886f70d010108300d06096086480165030402030500a203020140] })
rfc9881::ml-dsa-44 SUCCESS FAILURE UnsupportedSignatureAlgorithmContext(UnsupportedSignatureAlgorithmContext { signature_algorithm_id: [6, 9, 96, 134, 72, 1, 101, 3, 4, 3, 17], supported_algorithms: [0x06082a8648ce3d040302, 0x06082a8648ce3d040303, 0x06092a864886f70d01010b0500, 0x06092a864886f70d01010c0500, 0x06092a864886f70d01010d0500, 0x06092a864886f70d01010a3034a00f300d06096086480165030402010500a11c301a06092a864886f70d010108300d06096086480165030402010500a203020120, 0x06092a864886f70d01010a3034a00f300d06096086480165030402020500a11c301a06092a864886f70d010108300d06096086480165030402020500a203020130, 0x06092a864886f70d01010a3034a00f300d06096086480165030402030500a11c301a06092a864886f70d010108300d06096086480165030402030500a203020140] })

openssl-3.3.7

Testcase Expected Result Actual Result Context
rfc9881::ml-dsa-87 SUCCESS FAILURE EE certificate key too weak
rfc9881::ml-dsa-44-key-encipherment FAILURE FAILURE EE certificate key too weak
rfc9881::ml-dsa-44-bad-signature FAILURE FAILURE EE certificate key too weak
rfc9881::ml-dsa-44-key-agreement FAILURE FAILURE EE certificate key too weak
rfc9881::ml-dsa-65 SUCCESS FAILURE EE certificate key too weak
rfc9881::ml-dsa-44 SUCCESS FAILURE EE certificate key too weak

libressl-3.9.2

Testcase Expected Result Actual Result Context
rfc9881::ml-dsa-87 SUCCESS FAILURE EE certificate key too weak
rfc9881::ml-dsa-44-key-encipherment FAILURE FAILURE EE certificate key too weak
rfc9881::ml-dsa-44-bad-signature FAILURE FAILURE EE certificate key too weak
rfc9881::ml-dsa-44-key-agreement FAILURE FAILURE EE certificate key too weak
rfc9881::ml-dsa-65 SUCCESS FAILURE EE certificate key too weak
rfc9881::ml-dsa-44 SUCCESS FAILURE EE certificate key too weak

pyca-cryptography-49.0.0

Testcase Expected Result Actual Result Context
rfc9881::ml-dsa-87 SUCCESS FAILURE validation failed: candidates exhausted: Forbidden public key algorithm: AlgorithmIdentifier { oid: DefinedByMarker(PhantomDataasn1::object_identifier::ObjectIdentifier), params: MlDsa87 }
rfc9881::ml-dsa-44-key-encipherment FAILURE SKIPPED testcase skipped (explicit unsupported feature)
rfc9881::ml-dsa-44-bad-signature FAILURE FAILURE validation failed: candidates exhausted: Forbidden public key algorithm: AlgorithmIdentifier { oid: DefinedByMarker(PhantomDataasn1::object_identifier::ObjectIdentifier), params: MlDsa44 }
rfc9881::ml-dsa-44-key-agreement FAILURE SKIPPED testcase skipped (explicit unsupported feature)
rfc9881::ml-dsa-65 SUCCESS FAILURE validation failed: candidates exhausted: Forbidden public key algorithm: AlgorithmIdentifier { oid: DefinedByMarker(PhantomDataasn1::object_identifier::ObjectIdentifier), params: MlDsa65 }
rfc9881::ml-dsa-44 SUCCESS FAILURE validation failed: candidates exhausted: Forbidden public key algorithm: AlgorithmIdentifier { oid: DefinedByMarker(PhantomDataasn1::object_identifier::ObjectIdentifier), params: MlDsa44 }

libressl-4.0.1

Testcase Expected Result Actual Result Context
rfc9881::ml-dsa-87 SUCCESS FAILURE EE certificate key too weak
rfc9881::ml-dsa-44-key-encipherment FAILURE FAILURE EE certificate key too weak
rfc9881::ml-dsa-44-bad-signature FAILURE FAILURE EE certificate key too weak
rfc9881::ml-dsa-44-key-agreement FAILURE FAILURE EE certificate key too weak
rfc9881::ml-dsa-65 SUCCESS FAILURE EE certificate key too weak
rfc9881::ml-dsa-44 SUCCESS FAILURE EE certificate key too weak

openssl-4.0.0

Testcase Expected Result Actual Result Context
rfc9881::ml-dsa-87 SUCCESS SUCCESS None
rfc9881::ml-dsa-44-key-encipherment FAILURE SUCCESS None
rfc9881::ml-dsa-44-bad-signature FAILURE FAILURE certificate signature failure
rfc9881::ml-dsa-44-key-agreement FAILURE SUCCESS None
rfc9881::ml-dsa-65 SUCCESS SUCCESS None
rfc9881::ml-dsa-44 SUCCESS SUCCESS None

@woodruffw woodruffw left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Noice. I guess we probably need to allow-list these key identifiers in x509_validation, now.

@woodruffw
woodruffw merged commit 1252c30 into main Jul 26, 2026
9 checks passed
@woodruffw
woodruffw deleted the mldsa branch July 26, 2026 18:43
@cpu

cpu commented Jul 27, 2026

Copy link
Copy Markdown
Member

Thanks for adding these.

rustls-webpki
...
UnsupportedSignatureAlgorithmContext(UnsupportedSignatureAlgorithmContext { signature_algorithm_id: [6, 9, 96, 134, 72, 1, 101, 3, 4, 3, 17],

We do support this alg, but the harness needs an update. E.g. something like rustls/webpki#517. I'll take a look at backporting that here once it lands. With that change 4 of the 6 new MLDSA tests pass. The remaining two deviations are expected based on the very minimal KU enforcement we do in that verifier to date.

gocryptox509-go1.26.5

This one will need Go 1.27, but I've folded the new testcases into the stdlib in the meantime. Like rustls-webpki the only deviations are the two KU ones, for similar reasons.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants