Skip to content

CompositeML-KEM support for EnvelopedCms - #134449

Open
vcsjones wants to merge 4 commits into
dotnet:mainfrom
vcsjones:comp-ml-kem-enveloped-cms
Open

vcsjones wants to merge 4 commits into
dotnet:mainfrom
vcsjones:comp-ml-kem-enveloped-cms

Conversation

@vcsjones

Copy link
Copy Markdown
Member

This implements Composite ML-KEM for EnvelopedCms.

GetCompositeMLKemPrivateKey is not implemented at all on X509Certificate2 right now, so the only "door" that works is for folks that use the "Here is the private key" overload.

vcsjones and others added 3 commits September 22, 2026 11:19
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @bartonjs, @vcsjones, @dotnet/area-system-security
See info in area-owners.md if you want to be subscribed.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The cryptographic CMS implementation is complex and validation was not run, so final human review is required.

Review effort: Lite
Findings: None

What changed in this PR

Adds managed Composite ML-KEM encryption and explicit private-key decryption support for EnvelopedCms, with CMS test vectors and validation coverage.

Changes:

  • Implements Composite ML-KEM encapsulation and decapsulation.
  • Adds CMS encoding, algorithm identifiers, and test infrastructure.
  • Adds encryption, decryption, interoperability, and validation tests.
File Summary
src/​libraries/​System.Security.Cryptography.Pkcs/​tests/​System.Security.Cryptography.Pkcs.Tests.csproj Adds ASN.1 sources and test wiring.
src/​libraries/​System.Security.Cryptography.Pkcs/​tests/​Oids.cs Adds required Composite ML-KEM and CMS algorithm OIDs.
src/​libraries/​System.Security.Cryptography.Pkcs/​tests/​EnvelopedCms/​MLKemDecryptTests.cs Removes obsolete unsupported Composite ML-KEM tests.
src/​libraries/​System.Security.Cryptography.Pkcs/​tests/​EnvelopedCms/​CompositeMLKemEncryptTests.cs Adds Composite ML-KEM encryption coverage.
src/​libraries/​System.Security.Cryptography.Pkcs/​tests/​EnvelopedCms/​CompositeMLKemDecryptTests.cs Adds decryption and validation coverage.
src/​libraries/​System.Security.Cryptography.Pkcs/​tests/​EnvelopedCms/​CompositeMLKemCmsTestData.cs Builds Composite ML-KEM CMS test fixtures.
src/​libraries/​System.Security.Cryptography.Pkcs/​src/​System/​Security/​Cryptography/​Pkcs/​EnvelopedCms.Kem.cs Routes Composite ML-KEM decryption.
src/​libraries/​System.Security.Cryptography.Pkcs/​src/​Internal/​Cryptography/​Pal/​AnyOS/​ManagedPal.Kem.cs Implements Composite ML-KEM CMS processing.
src/​libraries/​Common/​tests/​System/​Security/​Cryptography/​AlgorithmImplementations/​CompositeMLKem/​CompositeMLKemTestVector.cs Exposes Composite ML-KEM certificate test data.

@bartonjs bartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Generally looking good

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants