]> Cypherpunks repositories - gostls13.git/commit
[release-branch.go1.24] crypto/internal/fips140: remove key import PCTs, make keygen...
authorFilippo Valsorda <filippo@golang.org>
Fri, 5 Sep 2025 02:19:18 +0000 (22:19 -0400)
committerJunyang Shao <shaojunyang@google.com>
Thu, 25 Sep 2025 19:14:05 +0000 (12:14 -0700)
commitc2097c7cc732918d854cae92a94c7f5c39f22138
tree2d438f8a572d980ca2ad8313118c206bb9b8683e
parentc78ec927ee89d61c010425d9e74cb9cdc949f596
[release-branch.go1.24] crypto/internal/fips140: remove key import PCTs, make keygen PCTs fatal

CMVP clarified with the September 2nd changes to IG 10.3.A that PCTs
don't need to run on imported keys.

However, PCT failure must enter the error state (which for us is fatal).

Thankfully, now that PCTs only run on key generation, we can be assured
they will never fail.

This change should only affect FIPS 140-3 mode.

While at it, make the CAST/PCT testing more robust, checking
TestConditional is terminated by a fatal error (and not by t.Fatal).

Fixes #74947
Updates #75523
Updates #69536

Change-Id: I6a6a696439e1560c10f3cce2cb208fd40c5bc641
Reviewed-on: https://go-review.googlesource.com/c/go/+/701438
Reviewed-by: Junyang Shao <shaojunyang@google.com>
TryBot-Bypass: Filippo Valsorda <filippo@golang.org>
Commit-Queue: Junyang Shao <shaojunyang@google.com>
Reviewed-by: Roland Shoemaker <roland@golang.org>
src/crypto/internal/fips140/cast.go
src/crypto/internal/fips140/ecdh/ecdh.go
src/crypto/internal/fips140/ecdsa/cast.go
src/crypto/internal/fips140/ecdsa/ecdsa.go
src/crypto/internal/fips140/ed25519/cast.go
src/crypto/internal/fips140/ed25519/ed25519.go
src/crypto/internal/fips140/mlkem/mlkem1024.go
src/crypto/internal/fips140/mlkem/mlkem768.go
src/crypto/internal/fips140/rsa/keygen.go
src/crypto/internal/fips140/rsa/rsa.go
src/crypto/internal/fips140test/cast_test.go