Skip to content

Add support for OpenTitan defined KeyLabels - #336

Merged
willyzha merged 1 commit into
lowRISC:mainfrom
willyzha:pqc-task6-ft-sival-pqc
Sep 22, 2026
Merged

willyzha merged 1 commit into
lowRISC:mainfrom
willyzha:pqc-task6-ft-sival-pqc

Conversation

@willyzha

Copy link
Copy Markdown
Collaborator

OpenTitan repo defined key labels "PQ_UDS_44" and "PQ_UDS_87" for the PQ keys.

Update ATE personalization blob unpacking, JSON commands, and ft.cc:
- Inspect the ASN.1 DER X.509 TBSCertificate signature AlgorithmIdentifier
  OID using BoringSSL CBS and OBJ_cbs2nid() in PackX509TbsCertStruct() to
  populate signing algorithm parameters for NID_ecdsa_with_SHA256,
  NID_ML_DSA_44, and NID_ML_DSA_87, and return an error logging the OID on
  invalid DER or unsupported algorithms.
- Add optional dice_mldsa_auth_key_key_id to CaSubjectKeysJSON proto and
  CaSubjectKeysToJson() to match OpenTitan manuf_certgen_inputs_t (PR #31202),
  omitting the field when ML-DSA DICE is disabled.
- Pass kDiceMldsaCaSk to CaSubjectKeysToJson() in ft.cc and explicitly reject
  --enable_mldsa_dice on the pi01 SKU.
- Add unit tests in ate_perso_blob_test.cc and ate_api_json_commands_test.cc.

Ref: lowRISC#310 (TASK-6)
@willyzha
willyzha force-pushed the pqc-task6-ft-sival-pqc branch from 28a6ed3 to 46ad90f Compare September 22, 2026 06:56
@willyzha
willyzha merged commit 7ee13ef into lowRISC:main Sep 22, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants