Skip to content

Add support for DER-to-ECDSA signature formatting in AwsKmsSign#28

Merged
ievgeniiskliarenko merged 2 commits intomasterfrom
fix-kms-sign-with-ecc
Jan 30, 2026
Merged

Add support for DER-to-ECDSA signature formatting in AwsKmsSign#28
ievgeniiskliarenko merged 2 commits intomasterfrom
fix-kms-sign-with-ecc

Conversation

@ievgeniiskliarenko
Copy link
Copy Markdown
Contributor

  • Decode ASN.1 DER-encoded signatures into raw R and S components for ECDSA algorithms.
  • Implement padding logic for ES256, ES384, and ES512 to ensure fixed-length signatures.
  • Add comprehensive unit tests to validate the changes, including edge cases for padding and negative integers.

- Decode ASN.1 DER-encoded signatures into raw R and S components for ECDSA algorithms.
- Implement padding logic for `ES256`, `ES384`, and `ES512` to ensure fixed-length signatures.
- Add comprehensive unit tests to validate the changes, including edge cases for padding and negative integers.
Copy link
Copy Markdown

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adds support for converting DER-encoded ECDSA signatures from AWS KMS to the raw R||S format required by JWT specifications. The implementation decodes ASN.1 DER signatures and applies algorithm-specific padding for ES256, ES384, and ES512.

Changes:

  • Decode DER-encoded signatures into raw R and S components for ECDSA algorithms
  • Implement fixed-length padding (32, 48, and 66 bytes) for ES256, ES384, and ES512 respectively
  • Add comprehensive unit tests covering standard cases, padding scenarios, and edge cases with negative integers

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 4 comments.

File Description
vicephp/Virtue-JWT/src/JWT/Algorithms/AwsKmsSign.php Implements DER-to-raw signature conversion with algorithm-specific padding for ECDSA signatures
vicephp/Virtue-JWT/tests/JWT/Algorithms/AwsKmsSignTest.php Adds unit tests validating ES256/ES384/ES512 signature formatting, padding behavior, and negative integer handling

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread vicephp/Virtue-JWT/src/JWT/Algorithms/AwsKmsSign.php Outdated
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
@vicephp vicephp deleted a comment from Copilot AI Jan 30, 2026
@vicephp vicephp deleted a comment from Copilot AI Jan 30, 2026
@vicephp vicephp deleted a comment from Copilot AI Jan 30, 2026
@ievgeniiskliarenko ievgeniiskliarenko marked this pull request as ready for review January 30, 2026 09:25
@ievgeniiskliarenko ievgeniiskliarenko merged commit b4764b0 into master Jan 30, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants