Merge to fips-20250107: Check hashes when parsing test-only, semi-expand ML-KEM private keys ML-KEM has two private key formats: a short seed, and an internal "semi-expanded" format that is only used in unit and ACVP testing. Only the seed form is reachable from outside the library. Seeds simplify a lot of questions, including making it impossible for components of the private key to be inconsistent with each other. The semi-expanded form has a redundancy in that it carries both the public key and the hash. Matching what https://boringssl-review.googlesource.com/c/boringssl/+/82991 did for ML-DSA, check the hash is correct as part of parsing. This somewhat defeats the point of having the hash listed explicitly. (It's an optimization for systems that parse a trusted key over and over.) But since we've now concluded this wasn't a great private key format in the first place, this codepath is test-only anyway. That means there is no optimization potential and it is better to include the check to avoid having to think about it. See https://boringssl-review.googlesource.com/c/boringssl/+/93247 (cherry picked from commit c8eb36bae607541c5c6bc518e60ba6ec44e3d10a) Change-Id: I8b5c42bf38b7f7564dc7a125c23d9aa2fa7e568d Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/100807 Reviewed-by: David Benjamin <davidben@google.com>
BoringSSL is a fork of OpenSSL that is designed to meet Google's needs.
Although BoringSSL is an open source project, it is not intended for general use, as OpenSSL is. We don't recommend that third parties depend upon it. Doing so is likely to be frustrating because there are no guarantees of API or ABI stability.
Programs ship their own copies of BoringSSL when they use it and we update everything as needed when deciding to make API changes. This allows us to mostly avoid compromises in the name of compatibility. It works for us, but it may not work for you.
BoringSSL arose because Google used OpenSSL for many years in various ways and, over time, built up a large number of patches that were maintained while tracking upstream OpenSSL. As Google's product portfolio became more complex, more copies of OpenSSL sprung up and the effort involved in maintaining all these patches in multiple places was growing steadily.
Currently BoringSSL is the SSL library in Chrome/Chromium, Android (but it's not part of the NDK) and a number of other apps/programs.
Project links:
To file a security issue, use the Chromium process and mention in the report this is for BoringSSL. You can ignore the parts of the process that are specific to Chromium/Chrome.
There are other files in this directory which might be helpful: