Conversation
35f1cd1 to
9da3791
Compare
mmadzin
left a comment
There was a problem hiding this comment.
I think these tests do not work if we use certificates which are created by instructions from test-scripts/TLS.md
Hence update TLS.md or create new instructions for PQC certificates. If you want to use the same "test-tls-secret" secret as other tests then please confirm that other tests work without problem.
|
What's the difference between "X25519MLKEM768 Negotiation" and "Data Transfer Over PQC Connection" tests (except that in the first case you are using openssl client and in the second case you are using curl)? |
No new certificates are required. This is the idea of the X25519MLKEM768 key exchange method. The PQC test will work with the same secret. If the X25519MLKEM768 flag is set in a request, that forces the client to request PQC key during each handshake. The usual certificates are only used for proof of identity of a service. The minimal requirement is OpenSSL 3.5+ in RHEL 9 (it does not depend on Java version) |
There is no difference. It is the same, just use different clients to check if the X25519MLKEM768 key exchange works. |
9da3791 to
e7fb5ab
Compare
|
BTW: does go lang offer any http client which can do the request with X25519MLKEM768 key exchange? |
I added the check with Go lang http client. |
The goal of the test is to check if JWS supports PQC key exchange, and it can be done without a change to the Operator.