Add OID and NID definitions for SLH-DSA (RFC 9909). This change adds Object Identifiers and NIDs for pure SLH-DSA and HashSLH-DSA: - id-slh-dsa-sha2-128s (RFC 9909 Section 3, OID 2.16.840.1.101.3.4.3.20) - id-slh-dsa-shake-256f (RFC 9909 Section 3, OID 2.16.840.1.101.3.4.3.31) - id-hash-slh-dsa-sha2-128s-with-sha256 (RFC 9909 Section 3, OID 2.16.840.1.101.3.4.3.35) Regenerated nid.h and obj_dat.h via objects.go. Change-Id: If264a28da22f9a9d7128b827f4177ebebadf5614 Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/102607 Presubmit-BoringSSL-Verified: boringssl-scoped@luci-project-accounts.iam.gserviceaccount.com <boringssl-scoped@luci-project-accounts.iam.gserviceaccount.com> Reviewed-by: David Benjamin <davidben@google.com> Commit-Queue: Matt Etemad <metemad@google.com>
diff --git a/crypto/obj/obj_dat.h b/crypto/obj/obj_dat.h index 2243ba0..ced3582 100644 --- a/crypto/obj/obj_dat.h +++ b/crypto/obj/obj_dat.h
@@ -16,7 +16,7 @@ BSSL_NAMESPACE_BEGIN -#define NUM_NID 979 +#define NUM_NID 982 static const uint8_t kObjectData[] = { /* NID_rsadsi */ @@ -7179,6 +7179,36 @@ 0x4b, 0x2f, 0x02, + /* NID_SLH_DSA_SHA2_128s */ + 0x60, + 0x86, + 0x48, + 0x01, + 0x65, + 0x03, + 0x04, + 0x03, + 0x14, + /* NID_SLH_DSA_SHAKE_256f */ + 0x60, + 0x86, + 0x48, + 0x01, + 0x65, + 0x03, + 0x04, + 0x03, + 0x1f, + /* NID_SLH_DSA_SHA2_128s_WITH_SHA256 */ + 0x60, + 0x86, + 0x48, + 0x01, + 0x65, + 0x03, + 0x04, + 0x03, + 0x23, }; static const ASN1_OBJECT kObjects[NUM_NID] = { @@ -8844,6 +8874,12 @@ NID_rdna_trustAnchorID_draft, 10, &kObjectData[6251], 0}, {"pe-mtcCertificationAuthority-draft", "pe-mtcCertificationAuthority-draft", NID_pe_mtcCertificationAuthority_draft, 10, &kObjectData[6261], 0}, + {"id-slh-dsa-sha2-128s", "SLH-DSA-SHA2-128s", NID_SLH_DSA_SHA2_128s, 9, + &kObjectData[6271], 0}, + {"id-slh-dsa-shake-256f", "SLH-DSA-SHAKE-256f", NID_SLH_DSA_SHAKE_256f, 9, + &kObjectData[6280], 0}, + {"id-hash-slh-dsa-sha2-128s-with-sha256", "SLH-DSA-SHA2-128s-WITH-SHA256", + NID_SLH_DSA_SHA2_128s_WITH_SHA256, 9, &kObjectData[6289], 0}, }; static const uint16_t kNIDsInShortNameOrder[] = { @@ -9318,6 +9354,7 @@ 331 /* id-cmc-transactionId */, 787 /* id-ct-asciiTextWithCRLF */, 408 /* id-ecPublicKey */, + 981 /* id-hash-slh-dsa-sha2-128s-with-sha256 */, 508 /* id-hex-multipart-message */, 507 /* id-hex-partial-message */, 260 /* id-it */, @@ -9389,6 +9426,8 @@ 322 /* id-regInfo-certReq */, 321 /* id-regInfo-utf8Pairs */, 512 /* id-set */, + 979 /* id-slh-dsa-sha2-128s */, + 980 /* id-slh-dsa-shake-256f */, 191 /* id-smime-aa */, 215 /* id-smime-aa-contentHint */, 218 /* id-smime-aa-contentIdentifier */, @@ -9916,6 +9955,9 @@ 2 /* RSA Data Security, Inc. PKCS */, 188 /* S/MIME */, 167 /* S/MIME Capabilities */, + 979 /* SLH-DSA-SHA2-128s */, + 981 /* SLH-DSA-SHA2-128s-WITH-SHA256 */, + 980 /* SLH-DSA-SHAKE-256f */, 387 /* SNMPv2 */, 512 /* Secure Electronic Transactions */, 386 /* Security */, @@ -11493,6 +11535,9 @@ 967 /* 2.16.840.1.101.3.4.3.17 (OBJ_ML_DSA_44) */, 968 /* 2.16.840.1.101.3.4.3.18 (OBJ_ML_DSA_65) */, 969 /* 2.16.840.1.101.3.4.3.19 (OBJ_ML_DSA_87) */, + 979 /* 2.16.840.1.101.3.4.3.20 (OBJ_SLH_DSA_SHA2_128s) */, + 980 /* 2.16.840.1.101.3.4.3.31 (OBJ_SLH_DSA_SHAKE_256f) */, + 981 /* 2.16.840.1.101.3.4.3.35 (OBJ_SLH_DSA_SHA2_128s_WITH_SHA256) */, 970 /* 2.16.840.1.101.3.4.4.2 (OBJ_ML_KEM_768) */, 966 /* 2.16.840.1.101.3.4.4.3 (OBJ_ML_KEM_1024) */, 71 /* 2.16.840.1.113730.1.1 (OBJ_netscape_cert_type) */,
diff --git a/crypto/obj/obj_mac.num b/crypto/obj/obj_mac.num index 70b8399..5824120 100644 --- a/crypto/obj/obj_mac.num +++ b/crypto/obj/obj_mac.num
@@ -962,3 +962,6 @@ alg_mtcProof_draft 976 rdna_trustAnchorID_draft 977 pe_mtcCertificationAuthority_draft 978 +SLH_DSA_SHA2_128s 979 +SLH_DSA_SHAKE_256f 980 +SLH_DSA_SHA2_128s_WITH_SHA256 981
diff --git a/crypto/obj/objects.txt b/crypto/obj/objects.txt index 05aaa35..fa4bd64 100644 --- a/crypto/obj/objects.txt +++ b/crypto/obj/objects.txt
@@ -913,6 +913,9 @@ sigAlgs 17 : id-ml-dsa-44 : ML-DSA-44 sigAlgs 18 : id-ml-dsa-65 : ML-DSA-65 sigAlgs 19 : id-ml-dsa-87 : ML-DSA-87 +sigAlgs 20 : id-slh-dsa-sha2-128s : SLH-DSA-SHA2-128s +sigAlgs 31 : id-slh-dsa-shake-256f : SLH-DSA-SHAKE-256f +sigAlgs 35 : id-hash-slh-dsa-sha2-128s-with-sha256 : SLH-DSA-SHA2-128s-WITH-SHA256 !Alias nistKems nistAlgorithms 4 nistKems 2 : id-alg-ml-kem-768 : ML-KEM-768
diff --git a/include/openssl/nid.h b/include/openssl/nid.h index 216c066..9ca8e67 100644 --- a/include/openssl/nid.h +++ b/include/openssl/nid.h
@@ -5531,6 +5531,28 @@ #define OBJ_ENC_pe_mtcCertificationAuthority_draft \ 0x2b, 0x06, 0x01, 0x04, 0x01, 0x82, 0xda, 0x4b, 0x2f, 0x02 +#define SN_SLH_DSA_SHA2_128s "id-slh-dsa-sha2-128s" +#define LN_SLH_DSA_SHA2_128s "SLH-DSA-SHA2-128s" +#define NID_SLH_DSA_SHA2_128s 979 +#define OBJ_SLH_DSA_SHA2_128s 2L, 16L, 840L, 1L, 101L, 3L, 4L, 3L, 20L +#define OBJ_ENC_SLH_DSA_SHA2_128s \ + 0x60, 0x86, 0x48, 0x01, 0x65, 0x03, 0x04, 0x03, 0x14 + +#define SN_SLH_DSA_SHAKE_256f "id-slh-dsa-shake-256f" +#define LN_SLH_DSA_SHAKE_256f "SLH-DSA-SHAKE-256f" +#define NID_SLH_DSA_SHAKE_256f 980 +#define OBJ_SLH_DSA_SHAKE_256f 2L, 16L, 840L, 1L, 101L, 3L, 4L, 3L, 31L +#define OBJ_ENC_SLH_DSA_SHAKE_256f \ + 0x60, 0x86, 0x48, 0x01, 0x65, 0x03, 0x04, 0x03, 0x1f + +#define SN_SLH_DSA_SHA2_128s_WITH_SHA256 "id-hash-slh-dsa-sha2-128s-with-sha256" +#define LN_SLH_DSA_SHA2_128s_WITH_SHA256 "SLH-DSA-SHA2-128s-WITH-SHA256" +#define NID_SLH_DSA_SHA2_128s_WITH_SHA256 981 +#define OBJ_SLH_DSA_SHA2_128s_WITH_SHA256 \ + 2L, 16L, 840L, 1L, 101L, 3L, 4L, 3L, 35L +#define OBJ_ENC_SLH_DSA_SHA2_128s_WITH_SHA256 \ + 0x60, 0x86, 0x48, 0x01, 0x65, 0x03, 0x04, 0x03, 0x23 + #if defined(__cplusplus) } /* extern C */