From b0f1538eb8d48525108e4e219e552675f818e067 Mon Sep 17 00:00:00 2001 From: yuhan6665 <1588741+yuhan6665@users.noreply.github.com> Date: Thu, 10 Sep 2026 22:58:27 -0400 Subject: [PATCH] crypto/tls: update EncryptedClientHelloKey.Config KEM docs The EncryptedClientHelloKey.Config struct field documented a list of acceptable KEMs, but didn't include the recently added PQ options (pure ML-KEM, or ML-KEM hybrids). The ECH config processing in crypto/tls dispatches through kem.NewKEM(id) with the config's KEM id. Since the PQ KEM ids are supported there, this commit adds them to the EncryptedClientHelloKey doc string as acceptable KEM choices for ECH configs. Change-Id: I87e81e90aedaa90d7be2a4f795f4250c8bc15525 Reviewed-on: https://go-review.googlesource.com/c/go/+/788920 Reviewed-by: Roland Shoemaker Auto-Submit: Daniel McCarney LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com Reviewed-by: Cherry Mui --- common.go | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/common.go b/common.go index 155bfc5..ca399db 100644 --- a/common.go +++ b/common.go @@ -953,6 +953,11 @@ type EncryptedClientHelloKey struct { // - DHKEM(P-384, HKDF-SHA384) (0x0011) // - DHKEM(P-521, HKDF-SHA512) (0x0012) // - DHKEM(X25519, HKDF-SHA256) (0x0020) + // - ML-KEM-768 (0x0041) + // - ML-KEM-1024 (0x0042) + // - MLKEM768-P256 (0x0050) + // - MLKEM1024-P384 (0x0051) + // - MLKEM768-X25519 (0x647a) // // and as KDF one of //