Skip to content

Support SLH-DSA server keys - #3120

Merged
drwetter merged 1 commit into
testssl:3.3devfrom
dcooper16:slhdsa
Aug 15, 2026
Merged

Support SLH-DSA server keys#3120
drwetter merged 1 commit into
testssl:3.3devfrom
dcooper16:slhdsa

Conversation

@dcooper16

Copy link
Copy Markdown
Collaborator

This PR adds support for server certificates that have SLH-DSA public keys. The code points come from https://datatracker.ietf.org/doc/draft-reddy-tls-slhdsa/. These code points were added to OpenSSL 4.1.0-dev by openssl/openssl#31248.

What is your pull request about?

  • Bug fix
  • Improvement
  • New feature (adds functionality)
  • Breaking change: bug fix, feature or improvement that would cause existing output (especially JSON, CSV) to not work as expected before
  • Typo / spelling fix
  • Documentation update
  • Update of other files

If it's a code change please check the boxes which are applicable

  • For the main program: My edits contain no tabs, indentation is five spaces and any line endings do not contain any blank chars
  • I've read CONTRIBUTING.md
  • My code follows Coding_Convention.md
  • I have tested this fix or improvement against >=2 hosts and I couldn't spot a problem
  • I have tested this new feature against >=2 hosts which show this feature and >=2 host which does not (in order to avoid side effects) . I couldn't spot a problem
  • For the new feature I have made corresponding changes to the documentation and / or to help()
  • If it's a bigger change: I added myself to CREDITS.md (alphabetical order of last name) and the change to CHANGELOG.md

AI section

  • I found a bug / an improvement using LLM version: [e.g. GPT-A.B, Claude <NAME> A.B, Gemini A.B <NAME>, Qwen<B>-Coder, DeepSeek-<A> etc.]
  • My contribution does not include any AI-generated content
  • My contribution includes AI-generated content, as disclosed below:
    • AI Tools: [e.g. GitHub CoPilot, JetBrains Junie, VS Code plugin <NAME> etc.]
    • LLMs and versions: [e.g. GPT-A.B, Claude <NAME> A.B, Gemini A.B <NAME>, Qwen<B>-Coder, DeepSeek-<A> etc.]

This commit adds support for server certificates that have SLH-DSA public keys. The code points come from https://datatracker.ietf.org/doc/draft-reddy-tls-slhdsa/. These code points were added to OpenSSL 4.1.0-dev by openssl/openssl#31248.
@drwetter
drwetter merged commit 1283aff into testssl:3.3dev Aug 15, 2026
4 of 5 checks passed
@drwetter

Copy link
Copy Markdown
Collaborator

Thanks a lot, @dcooper16 !!

The elif statements around L8570 and L9445 became a little ugly, if you want and have the opportunity a case statement would be more clean.

@dcooper16
dcooper16 deleted the slhdsa branch August 15, 2026 18:01
dcooper16 added a commit to dcooper16/testssl.sh that referenced this pull request Aug 15, 2026
This commit cleans up PR testssl#3120. It replaces two long "if" statements with "case" statements and it removes a second declaration of "nr_cert_types" in run_server_defaults().
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants