Add post-quantum key agreement X25519MLKEM768 #271
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Builds on PR #269.
X25519MLKEM768 is the successor of X25519Kyber768Draft00 now that NIST has released ML-KEM.
IANA has assigned the codepoint
0x11ec
.Upstream BoringSSL support landed in this commit. The version of BoringSSL we patch does not include it, so we add it manually.
Chrome and Firefox are planning to enable in October.
This PR is based on the IPD-Wing PR. There are two changes. First we simplify the patch a bit as we do not need IPD-Wing. Secondly, we perform the encapsulation key check, which was a last minute addition of NIST. We perform this check also for Kyber.