yuhan6665
2026-09-20 21:57:26 +00:00
committed by RPRX
parent 8cdf7bf9c7
commit 9124ee149d
25 changed files with 1491 additions and 1118 deletions
+10
View File
@@ -10,6 +10,7 @@ import (
"crypto/ecdsa"
"crypto/ed25519"
"crypto/elliptic"
"crypto/mldsa"
"crypto/rsa"
"crypto/x509"
)
@@ -32,6 +33,9 @@ var (
}
allowedCurvePreferencesFIPS = []CurveID{
X25519MLKEM768,
SecP256r1MLKEM768,
SecP384r1MLKEM1024,
MLKEM1024,
CurveP256,
CurveP384,
CurveP521,
@@ -40,6 +44,9 @@ var (
PSSWithSHA256,
ECDSAWithP256AndSHA256,
Ed25519,
MLDSA44,
MLDSA65,
MLDSA87,
PSSWithSHA384,
PSSWithSHA512,
PKCS1WithSHA256,
@@ -70,6 +77,9 @@ func isCertificateAllowedFIPS(c *x509.Certificate) bool {
return k.Curve == elliptic.P256() || k.Curve == elliptic.P384() || k.Curve == elliptic.P521()
case ed25519.PublicKey:
return true
case *mldsa.PublicKey:
// Only for the native module.
return true //!boring.Enabled
default:
return false
}