Skip to content

feat(xmldsig): add modern signature algorithms - #179

Merged
polaz merged 3 commits into
mainfrom
feat/#178-modern-signatures
Oct 3, 2026
Merged

polaz merged 3 commits into
mainfrom
feat/#178-modern-signatures

Conversation

@polaz

@polaz polaz commented Oct 3, 2026 •

Copy link
Copy Markdown
Member

Summary

Implement modern XML signature methods across public APIs, CryptoProvider, key inventory/resolution and CLI:

  • SHA-3 reference digests and curve-independent ECDSA SHA-3, including certificate AlgorithmIdentifier parsing.
  • All five EdDSA variants, including authenticated context parameters and RFC known-answer vectors. XML context text consumes the operation document budget; decoded context retains its protocol ceiling.
  • Opt-in experimental ML-DSA and SHA-2 SLH-DSA with strict PKCS#8/SPKI imports. ML-DSA supports checked seed-only, expanded-only and seed-plus-expanded representations.
  • Complete protected-container loading with exact public-key identity matching and atomic wrong-password rejection.
  • Independent typed certificate/CRL algorithm permissions in KeyTrustPolicy, checked during candidate path construction and full path/CRL validation before provider dispatch.

Capability remains separate from permission. PQ methods require the experimental-pq feature and explicit immutable policy permission. The compatibility executable explicitly permits compiled PQ XML methods for both signing and verification, and independently selects AllSupported certificate/CRL permission; library defaults remain restrictive. Exact typed certificate allowlists retain RSA-PSS parameter matching. Rejected certificate alternatives do not hide a permitted path to an explicit trust anchor. Experimental XML context/method extensions are documented as such. Pure Ed448's nonempty context follows RFC 8032; the pinned native oracle does not consume its XML context parameter.

Large PQ SignatureValue payloads decode directly from borrowed XML text; fragmented classical payloads use one bounded normalization allocation. Legal Base64 whitespace is bounded by the operation document budget, independently of normalized signature width. Exported SPKI buffers transfer ownership without redundant copies. Certificate permissions are borrowed through the operation without per-candidate policy copies.

The single published package embeds a reproducible, licensed RustCrypto ML-DSA patch; Cargo overrides would not propagate to package consumers. The checked decoder has also been proposed in RustCrypto/signatures#1452.

CI builds the pinned native oracle with isolated, checksum-verified OpenSSL 3.5.9, rather than silently disabling EdDSA with an older system OpenSSL. Cache reuse verifies the required transforms. This dependency is test-only and does not replace host libraries or enter the Rust production path.

Validation

  • Full workspace all-feature nextest, clippy with warnings denied, build, formatting and doctests.
  • Existing alloc-only host and bare-metal checks.
  • Modern roxmltree-only integration coverage, including PQ CLI sign/verify/tamper cases.
  • All 66 donor key containers, including encrypted PKCS#8 and standard/Windows PKCS#12; wrong-password and atomic-state checks.
  • Native reciprocal signature interoperability with the isolated OpenSSL-backed oracle.
  • Certificate allowlist default-deny, exact RSA-PSS parameters, explicit compatibility opt-in and restricted-policy tests, including a real mixed classical/PQ certificate chain and cross-certified alternatives in both traversal orders.
  • CLI PQ-signed certificate-path verification and tamper rejection; legal fragmented SignatureValue whitespace and tightened document-budget rejection.
  • Largest fragmented PQ signature exact-limit/oversized tests and reproducible embedded-source verification.
  • Independent packaged all-feature build verified.

Closes #178

Wire SHA-3, EdDSA and opt-in experimental PQ methods through provider dispatch, immutable policy, key inventory and CLI. Validate key encodings and authenticated contexts, preserve secret zeroization, and cover donor containers and reciprocal interoperability.

Closes #178
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-03T07:35:20.533106Z c4cb459 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Too many files!

This PR contains 140 files, which is 40 over the limit of 100.

To get a review, reduce the PR to 100 files or fewer by splitting it into smaller PRs or changing its base branch.

Upgrade to a paid plan to raise the limit.

This review couldn't start because sufficient usage credits or metered capacity aren't available. Add credits or update usage-based reviews in the billing tab, then retry.

⚙️ Run configuration
  • Configuration used: Repository: structured-world/xml-sec/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: aa987277-a40d-4384-b9a4-9752d775e796
📥 Commits

Reviewing files that changed from the base of the PR and between f3afff7 and c4cb459.

⛔ Files ignored due to path filters (33)
  • tests/fixtures/xmldsig/keys/eddsa/eddsa-ed25519-cert.pem is excluded by !**/*.pem
  • tests/fixtures/xmldsig/keys/eddsa/eddsa-ed25519-key.pem is excluded by !**/*.pem
  • tests/fixtures/xmldsig/keys/eddsa/eddsa-ed25519-pubkey.pem is excluded by !**/*.pem
  • tests/fixtures/xmldsig/keys/eddsa/eddsa-ed448-cert.pem is excluded by !**/*.pem
  • tests/fixtures/xmldsig/keys/eddsa/eddsa-ed448-key.pem is excluded by !**/*.pem
  • tests/fixtures/xmldsig/keys/eddsa/eddsa-ed448-pubkey.pem is excluded by !**/*.pem
  • tests/fixtures/xmldsig/keys/ml-dsa/ml-dsa-44-cert.pem is excluded by !**/*.pem
  • tests/fixtures/xmldsig/keys/ml-dsa/ml-dsa-44-key.pem is excluded by !**/*.pem
  • tests/fixtures/xmldsig/keys/ml-dsa/ml-dsa-44-pubkey.pem is excluded by !**/*.pem
  • tests/fixtures/xmldsig/keys/ml-dsa/ml-dsa-65-cert.pem is excluded by !**/*.pem
  • tests/fixtures/xmldsig/keys/ml-dsa/ml-dsa-65-key.pem is excluded by !**/*.pem
  • tests/fixtures/xmldsig/keys/ml-dsa/ml-dsa-65-pubkey.pem is excluded by !**/*.pem
  • tests/fixtures/xmldsig/keys/ml-dsa/ml-dsa-87-cert.pem is excluded by !**/*.pem
  • tests/fixtures/xmldsig/keys/ml-dsa/ml-dsa-87-key.pem is excluded by !**/*.pem
  • tests/fixtures/xmldsig/keys/ml-dsa/ml-dsa-87-pubkey.pem is excluded by !**/*.pem
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-128f-cert.pem is excluded by !**/*.pem
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-128f-key.pem is excluded by !**/*.pem
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-128f-pubkey.pem is excluded by !**/*.pem
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-128s-cert.pem is excluded by !**/*.pem
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-128s-key.pem is excluded by !**/*.pem
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-128s-pubkey.pem is excluded by !**/*.pem
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-192f-cert.pem is excluded by !**/*.pem
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-192f-key.pem is excluded by !**/*.pem
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-192f-pubkey.pem is excluded by !**/*.pem
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-192s-cert.pem is excluded by !**/*.pem
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-192s-key.pem is excluded by !**/*.pem
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-192s-pubkey.pem is excluded by !**/*.pem
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-256f-cert.pem is excluded by !**/*.pem
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-256f-key.pem is excluded by !**/*.pem
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-256f-pubkey.pem is excluded by !**/*.pem
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-256s-cert.pem is excluded by !**/*.pem
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-256s-key.pem is excluded by !**/*.pem
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-256s-pubkey.pem is excluded by !**/*.pem
📒 Files selected for processing (140)
  • .github/workflows/ci.yml
  • Cargo.toml
  • LICENSE-THIRD-PARTY
  • README.md
  • docs/cli.md
  • docs/ml-dsa-patch.md
  • docs/xmldsig.md
  • scripts/import-rustcrypto-ml-dsa.sh
  • scripts/install-xmlsec1.sh
  • scripts/patches/ml-dsa-0.1.1.patch
  • src/key_manager.rs
  • src/lib.rs
  • src/policy.rs
  • src/provider.rs
  • src/rustcrypto_ml_dsa/LICENSE-APACHE
  • src/rustcrypto_ml_dsa/LICENSE-MIT
  • src/rustcrypto_ml_dsa/README.md
  • src/rustcrypto_ml_dsa/algebra.rs
  • src/rustcrypto_ml_dsa/crypto.rs
  • src/rustcrypto_ml_dsa/encode.rs
  • src/rustcrypto_ml_dsa/hint.rs
  • src/rustcrypto_ml_dsa/lib.rs
  • src/rustcrypto_ml_dsa/ntt.rs
  • src/rustcrypto_ml_dsa/param.rs
  • src/rustcrypto_ml_dsa/pkcs8.rs
  • src/rustcrypto_ml_dsa/sampling.rs
  • src/rustcrypto_ml_dsa/signing.rs
  • src/rustcrypto_ml_dsa/verifying.rs
  • src/xmldsig/builder.rs
  • src/xmldsig/digest.rs
  • src/xmldsig/keys.rs
  • src/xmldsig/mod.rs
  • src/xmldsig/modern.rs
  • src/xmldsig/parse.rs
  • src/xmldsig/post_quantum.rs
  • src/xmldsig/pq_algorithm.rs
  • src/xmldsig/sign.rs
  • src/xmldsig/signature.rs
  • src/xmldsig/trust.rs
  • src/xmldsig/verify.rs
  • src/xmldsig/x509.rs
  • tests/donor_negative_vectors.rs
  • tests/fixtures/xmldsig/README.md
  • tests/fixtures/xmldsig/keys/eddsa/eddsa-ed25519-cert.der
  • tests/fixtures/xmldsig/keys/eddsa/eddsa-ed25519-key-win.p12
  • tests/fixtures/xmldsig/keys/eddsa/eddsa-ed25519-key.der
  • tests/fixtures/xmldsig/keys/eddsa/eddsa-ed25519-key.p12
  • tests/fixtures/xmldsig/keys/eddsa/eddsa-ed25519-key.p8-der
  • tests/fixtures/xmldsig/keys/eddsa/eddsa-ed25519-key.p8-pem
  • tests/fixtures/xmldsig/keys/eddsa/eddsa-ed25519-pubkey.crt
  • tests/fixtures/xmldsig/keys/eddsa/eddsa-ed25519-pubkey.der
  • tests/fixtures/xmldsig/keys/eddsa/eddsa-ed448-cert.der
  • tests/fixtures/xmldsig/keys/eddsa/eddsa-ed448-key-win.p12
  • tests/fixtures/xmldsig/keys/eddsa/eddsa-ed448-key.der
  • tests/fixtures/xmldsig/keys/eddsa/eddsa-ed448-key.p12
  • tests/fixtures/xmldsig/keys/eddsa/eddsa-ed448-key.p8-der
  • tests/fixtures/xmldsig/keys/eddsa/eddsa-ed448-key.p8-pem
  • tests/fixtures/xmldsig/keys/eddsa/eddsa-ed448-pubkey.crt
  • tests/fixtures/xmldsig/keys/eddsa/eddsa-ed448-pubkey.der
  • tests/fixtures/xmldsig/keys/ml-dsa/ml-dsa-44-cert.der
  • tests/fixtures/xmldsig/keys/ml-dsa/ml-dsa-44-key-win.p12
  • tests/fixtures/xmldsig/keys/ml-dsa/ml-dsa-44-key.der
  • tests/fixtures/xmldsig/keys/ml-dsa/ml-dsa-44-key.p12
  • tests/fixtures/xmldsig/keys/ml-dsa/ml-dsa-44-key.p8-der
  • tests/fixtures/xmldsig/keys/ml-dsa/ml-dsa-44-key.p8-pem
  • tests/fixtures/xmldsig/keys/ml-dsa/ml-dsa-44-pubkey.crt
  • tests/fixtures/xmldsig/keys/ml-dsa/ml-dsa-44-pubkey.der
  • tests/fixtures/xmldsig/keys/ml-dsa/ml-dsa-65-cert.der
  • tests/fixtures/xmldsig/keys/ml-dsa/ml-dsa-65-key-win.p12
  • tests/fixtures/xmldsig/keys/ml-dsa/ml-dsa-65-key.der
  • tests/fixtures/xmldsig/keys/ml-dsa/ml-dsa-65-key.p12
  • tests/fixtures/xmldsig/keys/ml-dsa/ml-dsa-65-key.p8-der
  • tests/fixtures/xmldsig/keys/ml-dsa/ml-dsa-65-key.p8-pem
  • tests/fixtures/xmldsig/keys/ml-dsa/ml-dsa-65-pubkey.crt
  • tests/fixtures/xmldsig/keys/ml-dsa/ml-dsa-65-pubkey.der
  • tests/fixtures/xmldsig/keys/ml-dsa/ml-dsa-87-cert.der
  • tests/fixtures/xmldsig/keys/ml-dsa/ml-dsa-87-key-win.p12
  • tests/fixtures/xmldsig/keys/ml-dsa/ml-dsa-87-key.der
  • tests/fixtures/xmldsig/keys/ml-dsa/ml-dsa-87-key.p12
  • tests/fixtures/xmldsig/keys/ml-dsa/ml-dsa-87-key.p8-der
  • tests/fixtures/xmldsig/keys/ml-dsa/ml-dsa-87-key.p8-pem
  • tests/fixtures/xmldsig/keys/ml-dsa/ml-dsa-87-pubkey.crt
  • tests/fixtures/xmldsig/keys/ml-dsa/ml-dsa-87-pubkey.der
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-128f-cert.der
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-128f-key-win.p12
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-128f-key.der
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-128f-key.p12
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-128f-key.p8-der
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-128f-key.p8-pem
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-128f-pubkey.crt
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-128f-pubkey.der
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-128s-cert.der
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-128s-key-win.p12
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-128s-key.der
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-128s-key.p12
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-128s-key.p8-der
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-128s-key.p8-pem
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-128s-pubkey.crt
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-128s-pubkey.der
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-192f-cert.der
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-192f-key-win.p12
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-192f-key.der
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-192f-key.p12
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-192f-key.p8-der
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-192f-key.p8-pem
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-192f-pubkey.crt
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-192f-pubkey.der
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-192s-cert.der
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-192s-key-win.p12
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-192s-key.der
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-192s-key.p12
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-192s-key.p8-der
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-192s-key.p8-pem
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-192s-pubkey.crt
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-192s-pubkey.der
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-256f-cert.der
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-256f-key-win.p12
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-256f-key.der
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-256f-key.p12
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-256f-key.p8-der
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-256f-key.p8-pem
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-256f-pubkey.crt
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-256f-pubkey.der
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-256s-cert.der
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-256s-key-win.p12
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-256s-key.der
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-256s-key.p12
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-256s-key.p8-der
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-256s-key.p8-pem
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-256s-pubkey.crt
  • tests/fixtures/xmldsig/keys/slh-dsa/slh-dsa-sha2-256s-pubkey.der
  • tests/fixtures_smoke.rs
  • tests/install_xmlsec1.rs
  • tests/modern_algorithms.rs
  • tests/signature_pipeline_integration.rs
  • tests/x509_chain_integration.rs
  • tools/xmlsec1/src/capabilities.rs
  • tools/xmlsec1/src/commands.rs
  • tools/xmlsec1/src/key_material.rs
  • tools/xmlsec1/tests/process_contract.rs

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 853505c22b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/xmldsig/parse.rs Outdated
Comment thread src/provider.rs
Comment thread src/policy.rs
Comment thread src/provider.rs
Derive context text limits from the operation resources, parse SHA-3 ECDSA certificate identifiers, and opt the compatibility CLI into supported PQ XML signatures.

Enforce independent certificate and CRL signature permissions across KeyInfo resolution, candidate paths, and validation. Add regression and process coverage, and build an isolated modern OpenSSL test oracle for EdDSA interoperability.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3178bb3150

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/xmldsig/verify.rs Outdated
Comment thread src/xmldsig/parse.rs
Comment thread tools/xmlsec1/src/commands.rs
Use the operation document budget for SignatureValue whitespace while retaining normalized signature bounds. Keep policy-rejected cross-certified branches local to path discovery, and explicitly permit supported certificate and CRL algorithms at the compatibility CLI boundary.

Add cross-certified, exact RSA-PSS permission, whitespace-budget and CLI PQ certificate regressions; synchronize public documentation.
@polaz
polaz enabled auto-merge (squash) October 3, 2026 07:39
@polaz
polaz merged commit 9f7f4aa into main Oct 3, 2026
26 checks passed
@polaz
polaz deleted the feat/#178-modern-signatures branch October 3, 2026 07:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat: support modern XML signature algorithms

1 participant