Merge to fips-20250107: Check hashes when parsing test-only, semi-expand ML-KEM private keys

ML-KEM has two private key formats: a short seed, and an internal
"semi-expanded" format that is only used in unit and ACVP testing. Only
the seed form is reachable from outside the library. Seeds simplify a
lot of questions, including making it impossible for components of the
private key to be inconsistent with each other.

The semi-expanded form has a redundancy in that it carries both the
public key and the hash. Matching what
https://boringssl-review.googlesource.com/c/boringssl/+/82991 did for
ML-DSA, check the hash is correct as part of parsing. This somewhat
defeats the point of having the hash listed explicitly. (It's an
optimization for systems that parse a trusted key over and over.) But
since we've now concluded this wasn't a great private key format in the
first place, this codepath is test-only anyway. That means there is no
optimization potential and it is better to include the check to avoid
having to think about it.

See https://boringssl-review.googlesource.com/c/boringssl/+/93247
(cherry picked from commit c8eb36bae607541c5c6bc518e60ba6ec44e3d10a)
Change-Id: I8b5c42bf38b7f7564dc7a125c23d9aa2fa7e568d
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/100807
Reviewed-by: David Benjamin <davidben@google.com>
2 files changed
tree: 14cfcc12de863448fca2db5469fddf9299cefc50
  1. .bcr/
  2. .github/
  3. cmake/
  4. crypto/
  5. decrepit/
  6. docs/
  7. fuzz/
  8. gen/
  9. include/
  10. infra/
  11. pki/
  12. rust/
  13. ssl/
  14. third_party/
  15. tool/
  16. util/
  17. .bazelignore
  18. .bazelrc
  19. .bazelversion
  20. .clang-format
  21. .gitignore
  22. API-CONVENTIONS.md
  23. AUTHORS
  24. BREAKING-CHANGES.md
  25. BUILD.bazel
  26. build.json
  27. BUILDING.md
  28. CMakeLists.txt
  29. codereview.settings
  30. CONTRIBUTING.md
  31. FUZZING.md
  32. go.mod
  33. go.sum
  34. INCORPORATING.md
  35. LICENSE
  36. MODULE.bazel
  37. MODULE.bazel.lock
  38. PORTING.md
  39. PrivacyInfo.xcprivacy
  40. README.md
  41. SANDBOXING.md
  42. STYLE.md
README.md

BoringSSL

BoringSSL is a fork of OpenSSL that is designed to meet Google's needs.

Although BoringSSL is an open source project, it is not intended for general use, as OpenSSL is. We don't recommend that third parties depend upon it. Doing so is likely to be frustrating because there are no guarantees of API or ABI stability.

Programs ship their own copies of BoringSSL when they use it and we update everything as needed when deciding to make API changes. This allows us to mostly avoid compromises in the name of compatibility. It works for us, but it may not work for you.

BoringSSL arose because Google used OpenSSL for many years in various ways and, over time, built up a large number of patches that were maintained while tracking upstream OpenSSL. As Google's product portfolio became more complex, more copies of OpenSSL sprung up and the effort involved in maintaining all these patches in multiple places was growing steadily.

Currently BoringSSL is the SSL library in Chrome/Chromium, Android (but it's not part of the NDK) and a number of other apps/programs.

Project links:

To file a security issue, use the Chromium process and mention in the report this is for BoringSSL. You can ignore the parts of the process that are specific to Chromium/Chrome.

There are other files in this directory which might be helpful: