tls: wolfssl: fixes for PQC key shares#22030
Closed
Frauschi wants to merge 1 commit into
Closed
Conversation
This PR makes the wolfssl TLS backend work properly for PQC key exchanges. The following issues are fixed: * WOLFSSL_HAVE_KYBER is not present anymore in upstream wolfssl (for a long time actually), so it has no use and the ML-KEM functionality was never turned on properly. * Key share group selection (via --curves) is now handled via the generic wolfSSL_CTX_set1_groups_list() method instead of the prior wolfSSL_CTX_set1_curves_list() and the additonal PQC handling. This removes a lot of PQC related special handling and the behavior now matches the OpenSSL backend. * The default QUIC group setting has been removed. For QUIC, the key share as well as the list in the supported_groups extension is now handled all within wolfssl. This also supports --curves properly now.
vszakats
approved these changes
Jun 15, 2026
Member
|
Thanks! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR makes the wolfssl TLS backend work properly for PQC key exchanges. The following issues are fixed:
WOLFSSL_HAVE_KYBERis not present anymore in upstream wolfssl (for a long time actually), so it has no use and the ML-KEM functionality was never turned on properly.--curves) is now handled via the genericwolfSSL_CTX_set1_groups_list()method instead of the priorwolfSSL_CTX_set1_curves_list()+ additional PQC handling. This removes a lot of PQC-related special handling and the behavior now matches the OpenSSL backend.--curvesproperly now.This fixes wolfssl issue #10670.