feat(xmldsig): add modern signature algorithms - #179
Conversation
Wire SHA-3, EdDSA and opt-in experimental PQ methods through provider dispatch, immutable policy, key inventory and CLI. Validate key encodings and authenticated contexts, preserve secret zeroization, and cover donor containers and reciprocal interoperability. Closes #178
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Important Review skippedToo many files! This PR contains 140 files, which is 40 over the limit of 100. To get a review, reduce the PR to 100 files or fewer by splitting it into smaller PRs or changing its base branch. Upgrade to a paid plan to raise the limit. This review couldn't start because sufficient usage credits or metered capacity aren't available. Add credits or update usage-based reviews in the billing tab, then retry. ⚙️ Run configuration
⛔ Files ignored due to path filters (33)
📒 Files selected for processing (140)
You can disable this status message by setting the
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 853505c22b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Derive context text limits from the operation resources, parse SHA-3 ECDSA certificate identifiers, and opt the compatibility CLI into supported PQ XML signatures. Enforce independent certificate and CRL signature permissions across KeyInfo resolution, candidate paths, and validation. Add regression and process coverage, and build an isolated modern OpenSSL test oracle for EdDSA interoperability.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3178bb3150
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Use the operation document budget for SignatureValue whitespace while retaining normalized signature bounds. Keep policy-rejected cross-certified branches local to path discovery, and explicitly permit supported certificate and CRL algorithms at the compatibility CLI boundary. Add cross-certified, exact RSA-PSS permission, whitespace-budget and CLI PQ certificate regressions; synchronize public documentation.
Summary
Implement modern XML signature methods across public APIs, CryptoProvider, key inventory/resolution and CLI:
Capability remains separate from permission. PQ methods require the experimental-pq feature and explicit immutable policy permission. The compatibility executable explicitly permits compiled PQ XML methods for both signing and verification, and independently selects AllSupported certificate/CRL permission; library defaults remain restrictive. Exact typed certificate allowlists retain RSA-PSS parameter matching. Rejected certificate alternatives do not hide a permitted path to an explicit trust anchor. Experimental XML context/method extensions are documented as such. Pure Ed448's nonempty context follows RFC 8032; the pinned native oracle does not consume its XML context parameter.
Large PQ SignatureValue payloads decode directly from borrowed XML text; fragmented classical payloads use one bounded normalization allocation. Legal Base64 whitespace is bounded by the operation document budget, independently of normalized signature width. Exported SPKI buffers transfer ownership without redundant copies. Certificate permissions are borrowed through the operation without per-candidate policy copies.
The single published package embeds a reproducible, licensed RustCrypto ML-DSA patch; Cargo overrides would not propagate to package consumers. The checked decoder has also been proposed in RustCrypto/signatures#1452.
CI builds the pinned native oracle with isolated, checksum-verified OpenSSL 3.5.9, rather than silently disabling EdDSA with an older system OpenSSL. Cache reuse verifies the required transforms. This dependency is test-only and does not replace host libraries or enter the Rust production path.
Validation
Closes #178