Skip to content

web: add post-quantum hybrid KEM groups to curve_preferences - #449

Open
dongjiang1989 wants to merge 1 commit into
prometheus:masterfrom
dongjiang1989:add-keyExchangeGroups
Open

dongjiang1989 wants to merge 1 commit into
prometheus:masterfrom
dongjiang1989:add-keyExchangeGroups

Conversation

@dongjiang1989

Copy link
Copy Markdown
Member

Extend the curve_preferences map with the hybrid post-quantum key exchange groups added in Go 1.24: X25519MLKEM768, SecP256r1MLKEM768, and SecP384r1MLKEM1024.

These share the same tls.CurveID registry as the existing curves, so no new config field is needed — in TLS 1.3 the registry was renamed to "Named Groups" (RFC 8446, §4.2.7) and extended beyond elliptic curves.

Documentation updated to list all available values.

Validations:

  • go build ./...
  • go vet ./...
  • go test ./...

Add X25519MLKEM768 (Go 1.24+) to the base curves map, and add
SecP256r1MLKEM768 / SecP384r1MLKEM1024 via a separate file
(tls_config_go126.go) guarded by a go1.26 build tag, so the module
keeps building cleanly on Go 1.25.

In TLS 1.3 the curve registry was renamed to "Named Groups" (RFC 8446,
Section 4.2.7) and extended beyond elliptic curves to cover hybrid
post-quantum KEMs. Documentation is updated to list all available values
and their Go version requirements.

Signed-off-by: dongjiang <dongjiang1989@users.noreply.github.com>
Signed-off-by: dongjiang1989 <dongjiang1989@126.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant