Skip to content

refactor: use context aware openssl fns - #53

Draft
tofay wants to merge 2 commits into
mainfrom
context-aware-openssl-fns
Draft

tofay wants to merge 2 commits into
mainfrom
context-aware-openssl-fns

Conversation

@tofay

@tofay tofay commented Sep 29, 2026

Copy link
Copy Markdown
Owner

No description provided.

…nctions

The curve name to signature scheme mapping was inline in
ecdsa_scheme(), making it untestable without generating a real key.
Extract it into ecdsa_scheme_for_group (OpenSSL 3.0+) and
ecdsa_scheme_for_nid (OpenSSL < 3.0) so the mapping can be verified
directly.

Add comprehensive tests: every supported curve name maps to the
right scheme, unsupported and lookalike names are refused, and a
round-trip test proves a generated key signs with the scheme its
curve maps to and the signature verifies.
…hange)

Add the internal infrastructure for library-context-aware operations.
All callers pass None (default context), so there is no behavior change.

New modules in openssl_internal:
- key: d2i_PUBKEY_ex, d2i_AutoPrivateKey_ex, PKeyRefExt (moved from kem)
- mac: EVP_MAC binding for HMAC
- properties: EVP_set_default_properties and fips_enabled with libctx
- rand: RAND_priv_bytes_ex with libctx

Key changes:
- PkeyCtxExt::new_from_name now takes a libctx parameter
- HmacKey uses EVP_MAC (ossl300) or PKey (pre-300) with Zeroizing
- encapsulate_init/decapsulate_init take &mut self
- from_encoded_public_key takes a libctx parameter
- All callers pass None (default context)

This is the foundation for the public library context API and the
crypto primitive wiring that follows.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant