ffang opened a new pull request, #736:
URL: https://github.com/apache/ws-wss4j/pull/736

   Add support for the NIST post-quantum algorithms ML-DSA (FIPS 204) for 
signatures and ML-KEM (FIPS 203) for key transport, building on the matching 
Santuario XML Security support.
   
   Common / policy:
   - Add ML-DSA-44/65/87 and ML-KEM-512/768/1024 algorithm URI constants 
(WSS4JConstants, SPConstants), using the finalized 
http://www.w3.org/2026/08/xmldsig-more# URIs from 
draft-eastlake-rfc9231bis-xmlsec-uris-09.
   - Recognise the PQC algorithms in AlgorithmSuite and AlgorithmSuiteValidator 
so WS-SecurityPolicy checks accept them.
   - Add KeyUtils helpers for the ML-KEM generic hybrid cipher key handling.
   
   DOM:
   - WSSecSignature / WSSecSignatureSAML: sign with ML-DSA keys.
   - WSSecEncrypt / WSSecEncryptedKey: encrypt the session key with ML-KEM 
using the generic hybrid cipher structure.
   - EncryptedKeyProcessor: decrypt ML-KEM protected EncryptedKey.
   
   StAX:
   - Support ML-DSA signatures and ML-KEM key transport on the outbound 
(EncryptedKeyOutputProcessor, OutboundWSSec) and inbound 
(WSSEncryptedKeyInputHandler, WSSSignatureInputHandler, 
SecurityTokenFactoryImpl) paths.
   - Update the xenc schemas to allow the new key transport content.
   
   Tests: PQCSignatureTest, PQCEncryptionTest and PQCEncryptionStaxTest. The 
tests require JDK 21+ and Bouncy Castle providing ML-DSA/ML-KEM.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to