crypto/tls: update EncryptedClientHelloKey.Config KEM docs

The EncryptedClientHelloKey.Config struct field documented a list of
acceptable KEMs, but didn't include the recently added PQ options (pure
ML-KEM, or ML-KEM hybrids).

The ECH config processing in crypto/tls dispatches through
kem.NewKEM(id) with the config's KEM id. Since the PQ KEM ids
are supported there, this commit adds them to the
EncryptedClientHelloKey doc string as acceptable KEM choices for ECH
configs.

Change-Id: I87e81e90aedaa90d7be2a4f795f4250c8bc15525
Reviewed-on: https://go-review.googlesource.com/c/go/+/788920
Reviewed-by: Roland Shoemaker <roland@golang.org>
Auto-Submit: Daniel McCarney <daniel@binaryparadox.net>
LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
Reviewed-by: Cherry Mui <cherryyz@google.com>
This commit is contained in:
yuhan6665
2026-09-10 22:58:27 -04:00
parent ff518ab8eb
commit b0f1538eb8
+5
View File
@@ -953,6 +953,11 @@ type EncryptedClientHelloKey struct {
// - DHKEM(P-384, HKDF-SHA384) (0x0011)
// - DHKEM(P-521, HKDF-SHA512) (0x0012)
// - DHKEM(X25519, HKDF-SHA256) (0x0020)
// - ML-KEM-768 (0x0041)
// - ML-KEM-1024 (0x0042)
// - MLKEM768-P256 (0x0050)
// - MLKEM1024-P384 (0x0051)
// - MLKEM768-X25519 (0x647a)
//
// and as KDF one of
//