Skip to content

Add support for ML-DSA-44 log signatures - #85

Open
rgdd wants to merge 6 commits into
FiloSottile:mainfrom
rgdd:mldsa-log-sigs
Open

Add support for ML-DSA-44 log signatures#85
rgdd wants to merge 6 commits into
FiloSottile:mainfrom
rgdd:mldsa-log-sigs

Conversation

@rgdd

@rgdd rgdd commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

In addition to the tests (see commits), we've also tested this on glasklar's witness-g1 service which cosigns checkpoints from one log operator that sends ML-DSA-44 signatures. Seems to work as expected.

rgdd added 6 commits August 13, 2026 15:41
Mainly to test that ML-DSA-44 log keys are parsed correctly, but while
at it I also added a few additional sanity checks wrt. log-list format.

Worth noting that witnessctl is less opinionated and only requires vkey
as a mandatory key.  I nevertheless added all require keys in the test.
Only positive tests were included.  Because the main purpose is to
ensure that it works to add an ML-DSA-44 key with witnessctl, and to
then also process an incoming checkpoint with an ML-DSA-44 log sig.

There's no integration test for witnessctl pull-logs, but I think the
unit test in the previous commit gets us close enough wrt. testing.
@rgdd

rgdd commented Aug 14, 2026

Copy link
Copy Markdown
Contributor Author

CC @FiloSottile.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant