Skip to content

Upgrade RustCrypto ASN.1 dependencies and use upstream ML-DSA OID constants #224

Description

@wolfv

Follow-up to #207. Replace the hardcoded ML-DSA OIDs in crates/sigstore-crypto/src/verification.rs with const_oid::db::fips204::{ID_ML_DSA_44, ID_ML_DSA_65, ID_ML_DSA_87}. These constants are available in const-oid 0.10 but not our current 0.9 dependency.

This requires a coordinated dependency migration rather than an isolated version bump:

  • const-oid 0.10
  • der 0.8
  • spki 0.8
  • x509-cert 0.3
  • A compatible cms release (currently only 0.3.0-pre.2 is available).

Revisit when a stable compatible cms release is available. Account for breaking certificate APIs across crypto, TSA, verification, examples, and tests.

Acceptance criteria:

  • Upgrade the compatible ASN.1/X.509 dependency set while preserving the supported MSRV.
  • Use upstream ML-DSA OID constants in matching and tests; reuse the upstream Ed25519 constant as well.
  • Preserve algorithm/parameter validation and pass workspace all-feature tests and strict all-target Clippy.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions