AWS-LC-FIPS module updated to 4.x
This release switches aws-lc-fips-sys (used via the fips feature) from the AWS-LC-FIPS 3.x branch to AWS-LC-FIPS 4.0.
- If your project requires FIPS compliance, please consult your local FIPS compliance experts before upgrading. The FIPS v3 module shipped in aws-lc-rs v1.17.x is FIPS 140-3 validated (Certificate #5314 static, Certificate #5298 dynamic). The 4.x module has completed validation testing by an accredited lab and has been submitted to NIST for certification. Refer to the CMVP Modules In Progress List for its current status, and to FIPS.md for security policies and supported operating environments.
- Consumers who need to remain on the FIPS 3.x module should pin
aws-lc-rsto<1.18.0. See the Cargo Book on Specifying Dependencies.
| AWS-LC-FIPS module | aws-lc-rs |
|---|---|
| 2.0.x | <1.12.0 |
| 3.0.x | <1.18.0 |
| 4.x | latest |
What's Changed
- Switch
aws-lc-fips-systo AWS-LC's "FIPS 4.0" branch by @justsmth in #1185aws-lc-fips-sysv0.13.16 -> v0.14.0. Please see the call-out above.
- The ML-DSA signature APIs are now stable 🎉 by @justsmth in #1188 and #1189
PqdsaKeyPair,PqdsaPublicKey,PqdsaPrivateKey,PqdsaSigningAlgorithm,PqdsaVerificationAlgorithm, and theML_DSA_44/ML_DSA_65/ML_DSA_87algorithms (and their_SIGNINGcounterparts) now live inaws_lc_rs::signature. ML-DSA no longer requires theunstablefeature, and is now available underfips-- the FIPS 4.0 module provides ML-DSA, which is what had kept these APIs unstable. See our updated API documentation.- Please migrate any use of
aws_lc_rs::unstable::signaturetoaws_lc_rs::signature. Theunstable::signaturemodule remains as deprecated aliases and will be removed in a future release. PqdsaKeyPair::to_pkcs8has been renamed toto_pkcs8v1, since elsewhere in the module an unqualifiedto_pkcs8means PKCS#8 v2. A deprecatedto_pkcs8alias remains available under theunstablefeature.- Existing
unstableconsumers continue to compile, with deprecation warnings. Two cases need a source change: builds using#![deny(warnings)], and code that glob-imports bothsignature::*andunstable::signature::*, which now needs an explicit import to disambiguate. - Behavior change:
PqdsaVerificationAlgorithm::parsed_verify_digest_signow always returnsUnspecified. Digest-then-verify is not an operation defined by FIPS 204 -- pure ML-DSA signs the message itself, and the pre-hash variant (HashML-DSA) uses a distinct domain separator that this API does not implement.
- Add out-of-place AEAD sealing by @iainmcgin in #1183
- Adds
seal_separate_out_of_placetoLessSafeKeyandTlsRecordSealingKey. Every sealing entry point was previously in-place, so a caller whose plaintext was borrowed or shared had to copy it into a scratch buffer purely to make it mutable. This mirrors the existingopen_separate_gather, so the sealing and opening directions now match.
- Adds
- Add
rsa::KeyPair::from_componentsfor constructing RSA key pairs from raw components by @justsmth in #1175- Adds
rsa::KeyPairComponentsandrsa::KeyPair::from_components, matching ring 0.17, so a signing key can be built from formats such as JWK without first encoding the components as DER. Unlike ring,dand the CRT parameters are validated at construction usingRSA_check_key, so keys with inconsistent or placeholder values that ring accepts may be rejected. Unnecessary generic bounds were also removed fromPublicKeyComponents.
- Adds
- Automatically optimize aws-lc for size when opt-level is "s" or "z" by @justsmth in #1159
- The builder now enables AWS-LC's size-optimized configuration (
OPENSSL_SMALL, and no AVX-512 assembly on x86_64) whenever Cargo is already building for size. In CI, a small binary exercising SHA-256, AES-256-GCM, and ECDSA P-256 is 36-50% smaller atopt-level=zthan atopt-level=3: 50% on x86_64 Linux, 48% on aarch64 macOS, 39% on x86_64 Windows, 36% on aarch64 Linux. Your own savings depend on how much of AWS-LC your binary retains. - No algorithms are removed and outputs are unchanged; the trade-off is slower elliptic-curve performance. Set
AWS_LC_SYS_SMALL=1/=0to force it on or off independently of opt-level. - FIPS builds do not opt in automatically:
aws-lc-fips-sysrequires an explicitAWS_LC_FIPS_SYS_SMALL=1, and warns when it is set. - Partially addresses #745; the default size under
opt-level=3footprint is unchanged.
- The builder now enables AWS-LC's size-optimized configuration (
- Export native library build metadata from the -sys crates by @justsmth in #1187, including original commits from @glebpom in #1184
- Downstream build scripts compiling C code against AWS-LC can now locate our artifacts via
DEP_AWS_LC_*/DEP_AWS_LC_FIPS_*(libdir,libcrypto_path,link_kind, andlibssl_pathwithssl), consistently across the CC, CMake, and system-library build paths. Existing linker directives are unchanged. On Windows, the*_pathvalues are the link-time artifact (import library), not the runtime DLL.
- Downstream build scripts compiling C code against AWS-LC can now locate our artifacts via
- Key wrap hardening by @justsmth in #1190 and #1191
KeyEncryptionKey::unwrapno longer underflows on ciphertexts shorter than 8 bytes. Since the ciphertext is untrusted input, builds withoverflow-checks = truewould panic instead of returning the documentedErr(Unspecified); default release builds were unaffected.KeyEncryptionKeynow zeroizes its key material on drop, consistent with the other key types in this crate.
- docs(signature): correct outdated note about signing a separate digest by @WesleyRosenblum in #1186
Upstream AWS-LC (v5.5.0)
aws-lc-sys v0.44.0 aligns with AWS-LC v5.5.0 (previously v5.2.0). See also the release notes for v5.3.0 and v5.4.0.
Build Improvements
- Fix bindings copy from read-only prebuilt AWS-LC install by @justsmth in #1194
- Copies into
OUT_DIRnow remove any stale destination first and leave the fresh copy writable, so building against a read-only prebuilt install (e.g. the Nix store) no longer fails withPermission deniedon a build-script rerun. AnOUT_DIRalready poisoned by an earlier build now recovers without acargo clean.
- Copies into
Issues Being Closed
- ML-DSA stabilization? -- #964
- Expose out-of-place AEAD sealing -- #1182
- Construct an RSA Key pair from raw private components -- #791
- aws-lc-sys build script fails to copy bindings from read only prebuild aws-lc on repeat runs -- #1193
Other Merged PRs
- ci: fix mdbook test failure and run docs checks on PRs by @justsmth in #1181
- Publish script fixes: cargo clean failure, and verify aws-lc-rs against minimum published sys crates by @justsmth in #1179
- Prepare aws-lc-sys v0.44.0 by @justsmth in #1199
- Prepare aws-lc-rs v1.18.0 by @justsmth in #1200
New Contributors
- @iainmcgin made their first contribution in #1183
- @glebpom made their first contribution in #1184 (landed via #1187)
Full Changelog: v1.17.3...v1.18.0