crypto/tls: add SecP256r1/SecP384r1MLKEM1024 hybrid post-quantum key exchanges

Fixes #71206

Change-Id: If3cf75261c56828b87ae6805bd2913f56a6a6964
Reviewed-on: https://go-review.googlesource.com/c/go/+/722140
Auto-Submit: Filippo Valsorda <filippo@golang.org>
Reviewed-by: Cherry Mui <cherryyz@google.com>
Reviewed-by: Roland Shoemaker <roland@golang.org>
LUCI-TryBot-Result: Go LUCI <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
This commit is contained in:
yuhan6665
2026-09-08 21:33:46 -04:00
parent 4f3d2f8139
commit 2d3ccda21d
9 changed files with 291 additions and 151 deletions
+13 -3
View File
@@ -13,14 +13,24 @@ import (
// them to apply local policies.
//var tlsmlkem = godebug.New("tlsmlkem")
//var tlssecpmlkem = godebug.New("tlssecpmlkem")
// defaultCurvePreferences is the default set of supported key exchanges, as
// well as the preference order.
func defaultCurvePreferences() []CurveID {
if false {
return []CurveID{X25519, CurveP256, CurveP384, CurveP521}
switch {
// // tlsmlkem=0 restores the pre-Go 1.24 default.
// case tlsmlkem.Value() == "0":
// return []CurveID{X25519, CurveP256, CurveP384, CurveP521}
// // tlssecpmlkem=0 restores the pre-Go 1.26 default.
// case tlssecpmlkem.Value() == "0":
// return []CurveID{X25519MLKEM768, X25519, CurveP256, CurveP384, CurveP521}
default:
return []CurveID{
X25519MLKEM768, SecP256r1MLKEM768, SecP384r1MLKEM1024,
X25519, CurveP256, CurveP384, CurveP521,
}
}
return []CurveID{X25519MLKEM768, X25519, CurveP256, CurveP384, CurveP521}
}
// defaultSupportedSignatureAlgorithms returns the signature and hash algorithms that