ffang opened a new pull request, #736: URL: https://github.com/apache/ws-wss4j/pull/736
Add support for the NIST post-quantum algorithms ML-DSA (FIPS 204) for signatures and ML-KEM (FIPS 203) for key transport, building on the matching Santuario XML Security support. Common / policy: - Add ML-DSA-44/65/87 and ML-KEM-512/768/1024 algorithm URI constants (WSS4JConstants, SPConstants), using the finalized http://www.w3.org/2026/08/xmldsig-more# URIs from draft-eastlake-rfc9231bis-xmlsec-uris-09. - Recognise the PQC algorithms in AlgorithmSuite and AlgorithmSuiteValidator so WS-SecurityPolicy checks accept them. - Add KeyUtils helpers for the ML-KEM generic hybrid cipher key handling. DOM: - WSSecSignature / WSSecSignatureSAML: sign with ML-DSA keys. - WSSecEncrypt / WSSecEncryptedKey: encrypt the session key with ML-KEM using the generic hybrid cipher structure. - EncryptedKeyProcessor: decrypt ML-KEM protected EncryptedKey. StAX: - Support ML-DSA signatures and ML-KEM key transport on the outbound (EncryptedKeyOutputProcessor, OutboundWSSec) and inbound (WSSEncryptedKeyInputHandler, WSSSignatureInputHandler, SecurityTokenFactoryImpl) paths. - Update the xenc schemas to allow the new key transport content. Tests: PQCSignatureTest, PQCEncryptionTest and PQCEncryptionStaxTest. The tests require JDK 21+ and Bouncy Castle providing ML-DSA/ML-KEM. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
