Skip to content

Add PQCKeyExchangeTest - #238

Open
skoshchi wants to merge 5 commits into
web-servers:mainfrom
skoshchi:new-PQC-test
Open

skoshchi wants to merge 5 commits into
web-servers:mainfrom
skoshchi:new-PQC-test

Conversation

@skoshchi

Copy link
Copy Markdown

The goal of the test is to check if JWS supports PQC key exchange, and it can be done without a change to the Operator.

@mmadzin mmadzin left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think these tests do not work if we use certificates which are created by instructions from test-scripts/TLS.md

Hence update TLS.md or create new instructions for PQC certificates. If you want to use the same "test-tls-secret" secret as other tests then please confirm that other tests work without problem.

@mmadzin

mmadzin commented Sep 24, 2026

Copy link
Copy Markdown
Collaborator

What's the difference between "X25519MLKEM768 Negotiation" and "Data Transfer Over PQC Connection" tests (except that in the first case you are using openssl client and in the second case you are using curl)?

@skoshchi

skoshchi commented Sep 24, 2026 •

Copy link
Copy Markdown
Author

I think these tests do not work if we use certificates which are created by instructions from test-scripts/TLS.md

Hence update TLS.md or create new instructions for PQC certificates. If you want to use the same "test-tls-secret" secret as other tests then please confirm that other tests work without problem.

No new certificates are required. This is the idea of the X25519MLKEM768 key exchange method. The PQC test will work with the same secret. If the X25519MLKEM768 flag is set in a request, that forces the client to request PQC key during each handshake. The usual certificates are only used for proof of identity of a service.

The minimal requirement is OpenSSL 3.5+ in RHEL 9 (it does not depend on Java version)

@skoshchi

Copy link
Copy Markdown
Author

What's the difference between "X25519MLKEM768 Negotiation" and "Data Transfer Over PQC Connection" tests (except that in the first case you are using openssl client and in the second case you are using curl)?

There is no difference. It is the same, just use different clients to check if the X25519MLKEM768 key exchange works.

@mmadzin

mmadzin commented Sep 25, 2026

Copy link
Copy Markdown
Collaborator

BTW: does go lang offer any http client which can do the request with X25519MLKEM768 key exchange?

@skoshchi

Copy link
Copy Markdown
Author

BTW: does go lang offer any http client which can do the request with X25519MLKEM768 key exchange?

I added the check with Go lang http client.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants