Skip to content
Discussion options

You must be logged in to vote

I've added experimental (and non standard) support for Pure ML-DSA to xmlsec-openssl:

  • Main change with all the plumbing PR #1002
  • Added context string support PR #1003

A bit of plumbing was needed to add new keys and algos (as usual) but the rest was trivial. I might add SLH-DSA to OpenSSL as well and also support both on GnuTLS (currently some features are missing namely reading pkcs12 files).

Based on my experience, I think "pure" versions is a way to go for XML Dsig purposes and it's similar to how other XMLDsig signatures actually operate. There is a downside that pre-signed buffer needs to be in memory but for XMLDSig it is only node (https://www.w3.org/TR/xmldsig-core1/#sec-Signatu…

Replies: 9 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
1 reply
@lsh123
Comment options

Comment options

You must be logged in to vote
0 replies
Answer selected by lsh123
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
4 participants