[go] crypto/tls: wrap ML-KEM hybrids in fips140.WithoutEnforcement

0 views
Skip to first unread message

Gopher Robot (Gerrit)

unread,
Apr 28, 2026, 2:19:14 PM (2 days ago) Apr 28
to Filippo Valsorda, goph...@pubsubhelper.golang.org, golang-...@googlegroups.com, golang...@luci-project-accounts.iam.gserviceaccount.com, Mark Freeman, David Chase, Daniel McCarney, Roland Shoemaker, golang-co...@googlegroups.com

Gopher Robot submitted the change

Unreviewed changes

1 is the latest approved patch-set.
No files were changed between the latest approved patch-set and the submitted one.

Change information

Commit message:
crypto/tls: wrap ML-KEM hybrids in fips140.WithoutEnforcement

Fixes #78298
Fixes #78178
Fixes #75528
Fixes #75166
Fixes #76112
Change-Id: Ie78f3bf5f0b232482da44aba28a0f6d66a6a6964
Reviewed-by: David Chase <drc...@google.com>
Reviewed-by: Daniel McCarney <dan...@binaryparadox.net>
Reviewed-by: Mark Freeman <markf...@google.com>
Auto-Submit: Filippo Valsorda <fil...@golang.org>
Files:
  • M src/crypto/tls/fips140_test.go
  • M src/crypto/tls/key_schedule.go
  • M src/crypto/tls/tls_test.go
Change size: M
Delta: 3 files changed, 50 insertions(+), 3 deletions(-)
Branch: refs/heads/master
Submit Requirements:
Open in Gerrit
Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
Gerrit-MessageType: merged
Gerrit-Project: go
Gerrit-Branch: master
Gerrit-Change-Id: Ie78f3bf5f0b232482da44aba28a0f6d66a6a6964
Gerrit-Change-Number: 759383
Gerrit-PatchSet: 8
Gerrit-Owner: Filippo Valsorda <fil...@golang.org>
Gerrit-Reviewer: Daniel McCarney <dan...@binaryparadox.net>
Gerrit-Reviewer: David Chase <drc...@google.com>
Gerrit-Reviewer: Filippo Valsorda <fil...@golang.org>
Gerrit-Reviewer: Gopher Robot <go...@golang.org>
Gerrit-Reviewer: Mark Freeman <markf...@google.com>
Gerrit-Reviewer: Roland Shoemaker <rol...@golang.org>
open
diffy
satisfied_requirement

Gopher Robot (Gerrit)

unread,
Apr 29, 2026, 3:36:05 PM (21 hours ago) Apr 29
to Filippo Valsorda, goph...@pubsubhelper.golang.org, golang-...@googlegroups.com, Michael Pratt, golang...@luci-project-accounts.iam.gserviceaccount.com, Roland Shoemaker, Daniel McCarney, Kevin Burke, golang-co...@googlegroups.com

Gopher Robot submitted the change

Unreviewed changes

2 is the latest approved patch-set.

No files were changed between the latest approved patch-set and the submitted one.

Change information

Commit message:
[release-branch.go1.26] crypto/tls: wrap ML-KEM hybrids in fips140.WithoutEnforcement

To avoid excessive backports, this CL copies rerunWithFIPS140Enforced
from CL 759382, and overrides the certificates used for FIPS-140 tests
to avoid requiring the entirety of CL 759380 and CL 759381.

Fixes #78372
Updates #78298
Updates #78178
Updates #75528
Updates #75166
Updates #76112


Change-Id: Ie78f3bf5f0b232482da44aba28a0f6d66a6a6964
Reviewed-on: https://go-review.googlesource.com/c/go/+/759383
Reviewed-by: David Chase <drc...@google.com>
LUCI-TryBot-Result: golang...@luci-project-accounts.iam.gserviceaccount.com <golang...@luci-project-accounts.iam.gserviceaccount.com>
Reviewed-by: Daniel McCarney <dan...@binaryparadox.net>
Reviewed-by: Mark Freeman <markf...@google.com>
Auto-Submit: Filippo Valsorda <fil...@golang.org>
(cherry picked from commit 3103a2312445c8d0a1c3ad1c787b9c1c90fbf77a)
Reviewed-on: https://go-review.googlesource.com/c/go/+/771961
Reviewed-by: Michael Pratt <mpr...@google.com>
Commit-Queue: Michael Pratt <mpr...@google.com>
Reviewed-by: Roland Shoemaker <rol...@golang.org>
Auto-Submit: Michael Pratt <mpr...@google.com>
Files:
  • M src/crypto/tls/fips140_test.go
  • M src/crypto/tls/handshake_test.go
  • M src/crypto/tls/key_schedule.go
  • M src/crypto/tls/tls_test.go
Change size: M
Delta: 4 files changed, 91 insertions(+), 17 deletions(-)
Branch: refs/heads/release-branch.go1.26
Submit Requirements:
  • requirement satisfiedCode-Review: +2 by Roland Shoemaker, +1 by Michael Pratt
Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
Gerrit-MessageType: merged
Gerrit-Project: go
Gerrit-Branch: release-branch.go1.26
Gerrit-Change-Id: Ie78f3bf5f0b232482da44aba28a0f6d66a6a6964
Gerrit-Change-Number: 771961
Gerrit-PatchSet: 4
Gerrit-Owner: Filippo Valsorda <fil...@golang.org>
Gerrit-Reviewer: Daniel McCarney <dan...@binaryparadox.net>
Gerrit-Reviewer: Filippo Valsorda <fil...@golang.org>
Gerrit-Reviewer: Gopher Robot <go...@golang.org>
Gerrit-Reviewer: Michael Pratt <mpr...@google.com>
Gerrit-CC: Kevin Burke <ke...@burke.dev>
open
diffy
satisfied_requirement
Reply all
Reply to author
Forward
0 new messages