feat: upgrade crypto ecosystem to latest RustCrypto stack (#1)
Rust CI / cargo audit (push) Successful in 6s
Rust CI / cargo fmt (push) Successful in 4s
Rust CI / test (1.90.0 / no backend / no frontend) (push) Successful in 2m25s
Rust CI / test (stable / no backend / no frontend) (push) Successful in 2m27s
Rust CI / cargo clippy (push) Successful in 1m25s
Rust CI / test (1.90.0 / no backend / --features argon2) (push) Successful in 2m35s
Rust CI / test (stable / no backend / --features argon2) (push) Successful in 2m34s
Rust CI / test (stable / no backend / --features serde) (push) Successful in 2m55s
Rust CI / test (stable / --features curve25519 / no frontend) (push) Successful in 2m31s
Rust CI / test (1.90.0 / no backend / --features serde) (push) Successful in 2m52s
Rust CI / test (1.90.0 / --features curve25519 / no frontend) (push) Successful in 2m29s
Rust CI / test (1.90.0 / --features curve25519 / --features argon2) (push) Successful in 2m37s
Rust CI / test (stable / --features curve25519 / --features argon2) (push) Successful in 2m36s
Rust CI / test (1.90.0 / --features curve25519 / --features serde) (push) Successful in 2m59s
Rust CI / test (stable / --features curve25519 / --features serde) (push) Successful in 3m1s
Rust CI / test (1.90.0 / --features ecdsa / no frontend) (push) Successful in 2m52s
Rust CI / test (stable / --features ecdsa / no frontend) (push) Successful in 2m51s
Rust CI / test (1.90.0 / --features ecdsa / --features argon2) (push) Successful in 2m57s
Rust CI / test (stable / --features ecdsa / --features argon2) (push) Successful in 2m58s
Rust CI / test (1.90.0 / --features ecdsa / --features serde) (push) Successful in 3m19s
Rust CI / test (1.90.0 / --features ristretto255 / no frontend) (push) Successful in 3m2s
Rust CI / test (stable / --features ecdsa / --features serde) (push) Successful in 3m19s
Rust CI / test (1.90.0 / --features ed25519 / no frontend) (push) Successful in 2m53s
Rust CI / test (stable / --features ed25519 / no frontend) (push) Successful in 2m54s
Rust CI / test (1.90.0 / --features ed25519 / --features argon2) (push) Successful in 3m3s
Rust CI / test (stable / --features ed25519 / --features argon2) (push) Successful in 3m0s
Rust CI / test (1.90.0 / --features ed25519 / --features serde) (push) Successful in 3m22s
Rust CI / test (stable / --features ed25519 / --features serde) (push) Successful in 3m22s
Rust CI / test (1.90.0 / --features ristretto255 / --features argon2) (push) Successful in 3m9s
Rust CI / test (stable / --features ristretto255 / no frontend) (push) Successful in 3m4s
Rust CI / test (stable / --features ristretto255 / --features argon2) (push) Successful in 3m11s
Rust CI / test (1.90.0 / --features ristretto255 / --features serde) (push) Successful in 3m28s
Rust CI / test (stable / --features ristretto255 / --features serde) (push) Successful in 3m32s
Rust CI / test (1.90.0 / --features ristretto255,curve25519,ecdsa,ed25519 / no frontend) (push) Successful in 5m26s
Rust CI / test (stable / --features ristretto255,curve25519,ecdsa,ed25519 / no frontend) (push) Successful in 5m17s
Rust CI / test (1.90.0 / --features ristretto255,curve25519,ecdsa,ed25519 / --features argon2) (push) Successful in 5m27s
Rust CI / test (stable / --features ristretto255,curve25519,ecdsa,ed25519 / --features serde) (push) Successful in 5m43s
Rust CI / test (stable / --features ristretto255,curve25519,ecdsa,ed25519 / --features argon2) (push) Successful in 5m20s
Rust CI / test (1.90.0 / --features ristretto255,curve25519,ecdsa,ed25519 / --features serde) (push) Successful in 6m1s
Rust CI / test (stable / --features ristretto255,kem / no frontend) (push) Successful in 4m0s
Rust CI / test (1.90.0 / --features ristretto255,kem / --features argon2) (push) Successful in 4m5s
Rust CI / test (1.90.0 / --features ristretto255,kem / no frontend) (push) Successful in 4m2s
Rust CI / test (stable / --features ristretto255,kem / --features argon2) (push) Successful in 4m3s
Rust CI / test (stable / --features ristretto255,kem / --features serde) (push) Successful in 4m32s
Rust CI / test (1.90.0 / --features ristretto255,kem / --features serde) (push) Successful in 4m31s
Rust CI / test simple_login example (push) Successful in 19s
Rust CI / test digital_locker example (push) Successful in 18s
Rust CI / cargo bench compilation () (push) Successful in 1m47s
Rust CI / cargo bench compilation (--features ristretto255) (push) Successful in 1m55s
Rust CI / cargo bench compilation (--features ristretto255,kem) (push) Successful in 2m35s
Rust CI / no-std (thumbv6m-none-eabi / no backend) (push) Successful in 28s
Rust CI / no-std (wasm32-unknown-unknown / no backend) (push) Successful in 28s
Rust CI / no-std (thumbv6m-none-eabi / curve25519) (push) Successful in 18s
Rust CI / no-std (wasm32-unknown-unknown / curve25519) (push) Successful in 28s
Rust CI / no-std (thumbv6m-none-eabi / ecdsa) (push) Successful in 29s
Rust CI / no-std (wasm32-unknown-unknown / ecdsa) (push) Successful in 28s
Rust CI / no-std (thumbv6m-none-eabi / ed25519) (push) Successful in 29s
Rust CI / no-std (wasm32-unknown-unknown / ed25519) (push) Successful in 30s
Rust CI / no-std (thumbv6m-none-eabi / ristretto255) (push) Successful in 28s
Rust CI / no-std (wasm32-unknown-unknown / ristretto255) (push) Successful in 28s
Rust CI / no-std (thumbv6m-none-eabi / ristretto255,curve25519,ecdsa,ed25519) (push) Successful in 29s
Rust CI / no-std (wasm32-unknown-unknown / ristretto255,curve25519,ecdsa,ed25519) (push) Successful in 19s
Rust CI / cargo audit (push) Successful in 6s
Rust CI / cargo fmt (push) Successful in 4s
Rust CI / test (1.90.0 / no backend / no frontend) (push) Successful in 2m25s
Rust CI / test (stable / no backend / no frontend) (push) Successful in 2m27s
Rust CI / cargo clippy (push) Successful in 1m25s
Rust CI / test (1.90.0 / no backend / --features argon2) (push) Successful in 2m35s
Rust CI / test (stable / no backend / --features argon2) (push) Successful in 2m34s
Rust CI / test (stable / no backend / --features serde) (push) Successful in 2m55s
Rust CI / test (stable / --features curve25519 / no frontend) (push) Successful in 2m31s
Rust CI / test (1.90.0 / no backend / --features serde) (push) Successful in 2m52s
Rust CI / test (1.90.0 / --features curve25519 / no frontend) (push) Successful in 2m29s
Rust CI / test (1.90.0 / --features curve25519 / --features argon2) (push) Successful in 2m37s
Rust CI / test (stable / --features curve25519 / --features argon2) (push) Successful in 2m36s
Rust CI / test (1.90.0 / --features curve25519 / --features serde) (push) Successful in 2m59s
Rust CI / test (stable / --features curve25519 / --features serde) (push) Successful in 3m1s
Rust CI / test (1.90.0 / --features ecdsa / no frontend) (push) Successful in 2m52s
Rust CI / test (stable / --features ecdsa / no frontend) (push) Successful in 2m51s
Rust CI / test (1.90.0 / --features ecdsa / --features argon2) (push) Successful in 2m57s
Rust CI / test (stable / --features ecdsa / --features argon2) (push) Successful in 2m58s
Rust CI / test (1.90.0 / --features ecdsa / --features serde) (push) Successful in 3m19s
Rust CI / test (1.90.0 / --features ristretto255 / no frontend) (push) Successful in 3m2s
Rust CI / test (stable / --features ecdsa / --features serde) (push) Successful in 3m19s
Rust CI / test (1.90.0 / --features ed25519 / no frontend) (push) Successful in 2m53s
Rust CI / test (stable / --features ed25519 / no frontend) (push) Successful in 2m54s
Rust CI / test (1.90.0 / --features ed25519 / --features argon2) (push) Successful in 3m3s
Rust CI / test (stable / --features ed25519 / --features argon2) (push) Successful in 3m0s
Rust CI / test (1.90.0 / --features ed25519 / --features serde) (push) Successful in 3m22s
Rust CI / test (stable / --features ed25519 / --features serde) (push) Successful in 3m22s
Rust CI / test (1.90.0 / --features ristretto255 / --features argon2) (push) Successful in 3m9s
Rust CI / test (stable / --features ristretto255 / no frontend) (push) Successful in 3m4s
Rust CI / test (stable / --features ristretto255 / --features argon2) (push) Successful in 3m11s
Rust CI / test (1.90.0 / --features ristretto255 / --features serde) (push) Successful in 3m28s
Rust CI / test (stable / --features ristretto255 / --features serde) (push) Successful in 3m32s
Rust CI / test (1.90.0 / --features ristretto255,curve25519,ecdsa,ed25519 / no frontend) (push) Successful in 5m26s
Rust CI / test (stable / --features ristretto255,curve25519,ecdsa,ed25519 / no frontend) (push) Successful in 5m17s
Rust CI / test (1.90.0 / --features ristretto255,curve25519,ecdsa,ed25519 / --features argon2) (push) Successful in 5m27s
Rust CI / test (stable / --features ristretto255,curve25519,ecdsa,ed25519 / --features serde) (push) Successful in 5m43s
Rust CI / test (stable / --features ristretto255,curve25519,ecdsa,ed25519 / --features argon2) (push) Successful in 5m20s
Rust CI / test (1.90.0 / --features ristretto255,curve25519,ecdsa,ed25519 / --features serde) (push) Successful in 6m1s
Rust CI / test (stable / --features ristretto255,kem / no frontend) (push) Successful in 4m0s
Rust CI / test (1.90.0 / --features ristretto255,kem / --features argon2) (push) Successful in 4m5s
Rust CI / test (1.90.0 / --features ristretto255,kem / no frontend) (push) Successful in 4m2s
Rust CI / test (stable / --features ristretto255,kem / --features argon2) (push) Successful in 4m3s
Rust CI / test (stable / --features ristretto255,kem / --features serde) (push) Successful in 4m32s
Rust CI / test (1.90.0 / --features ristretto255,kem / --features serde) (push) Successful in 4m31s
Rust CI / test simple_login example (push) Successful in 19s
Rust CI / test digital_locker example (push) Successful in 18s
Rust CI / cargo bench compilation () (push) Successful in 1m47s
Rust CI / cargo bench compilation (--features ristretto255) (push) Successful in 1m55s
Rust CI / cargo bench compilation (--features ristretto255,kem) (push) Successful in 2m35s
Rust CI / no-std (thumbv6m-none-eabi / no backend) (push) Successful in 28s
Rust CI / no-std (wasm32-unknown-unknown / no backend) (push) Successful in 28s
Rust CI / no-std (thumbv6m-none-eabi / curve25519) (push) Successful in 18s
Rust CI / no-std (wasm32-unknown-unknown / curve25519) (push) Successful in 28s
Rust CI / no-std (thumbv6m-none-eabi / ecdsa) (push) Successful in 29s
Rust CI / no-std (wasm32-unknown-unknown / ecdsa) (push) Successful in 28s
Rust CI / no-std (thumbv6m-none-eabi / ed25519) (push) Successful in 29s
Rust CI / no-std (wasm32-unknown-unknown / ed25519) (push) Successful in 30s
Rust CI / no-std (thumbv6m-none-eabi / ristretto255) (push) Successful in 28s
Rust CI / no-std (wasm32-unknown-unknown / ristretto255) (push) Successful in 28s
Rust CI / no-std (thumbv6m-none-eabi / ristretto255,curve25519,ecdsa,ed25519) (push) Successful in 29s
Rust CI / no-std (wasm32-unknown-unknown / ristretto255,curve25519,ecdsa,ed25519) (push) Successful in 19s
Upgrade all core cryptographic dependencies to their latest versions: Dependencies: - digest: 0.10 to 0.11 - elliptic-curve: 0.13 to 0.14 - hkdf: 0.12 to 0.13 - hmac: 0.12 to 0.13 - rand: 0.8 to 0.10 - rand_chacha: 0.3 to 0.10 - sha2: 0.10 to 0.11 - getrandom: 0.2 to 0.4 (WASM) - ml-kem: 0.3.0-rc.0 to 0.3 - ecdsa: 0.16 to 0.17.0-rc.23 - rfc6979: 0.4 to 0.6 (now internal to ecdsa) - p256/p384/p521: 0.13 to 0.14.0-rc.15 - curve25519-dalek: 4 to 5.0.0-rc - ed25519-dalek: 2 to 3.0.0-rc - cryptoki: 0.9 to 0.12 - rustyline: 17 to 18 - scrypt: 0.11 to 0.12 - voprf replaced by voprf-vx 1.0.0-pre.0 Migration changes: - generic-array 0.14 to 1.4 with hybrid-array 0.4 interop - ArrayLength<u8> to ArrayLength (generic-array 1.x) - Added ConcatExt trait to disambiguate from [T]::concat - Replaced Hmac with SimpleHmac for digest 0.11 compatibility - Added OutputSize<H>: ArrayLength bounds throughout Hash trait - Converted hybrid_array::Array between GenericArray at API boundaries - Updated GroupEncoding Repr bound to hybrid_array::Array - ECDSA sign now uses ecdsa::hazmat::sign_prehashed_rfc6979 - Removed direct rfc6979 dependency (handled by ecdsa internally) - Replaced bincode with postcard for no_std serialization - Re-exported hybrid_array from crate root Other changes: - Renamed crate to opaque-vx - Increased MSRV to 1.89 - Added cryptography to Cargo.toml categories - Removed Facebook-specific contributions from CONTRIBUTING.md - Removed v3 to v4 migration test - Removed unstable rustfmt configurations for stable compatibility Reviewed-on: #1 Co-authored-by: UneBaguette <[email protected]> Co-committed-by: UneBaguette <[email protected]>
This commit was merged in pull request #1.
This commit is contained in:
+81
-35
@@ -1,67 +1,112 @@
|
||||
# Changelog
|
||||
|
||||
## 1.0.0-pre.0 (June 29, 2026)
|
||||
|
||||
Forked from [facebook/opaque-ke](https://github.com/facebook/opaque-ke/) at `4.1.0-pre.2`.
|
||||
|
||||
* Upgraded dependencies:
|
||||
* `ml-kem`: `0.3.0-rc.0` to `0.3`
|
||||
* `digest`: `0.10` to `0.11`
|
||||
* `elliptic-curve`: `0.13` to `0.14`
|
||||
* `curve25519-dalek`: `4` to `5.0.0-rc`
|
||||
* `ed25519-dalek`: `2` to `3.0.0-rc`
|
||||
* `ecdsa`: `0.16` to `0.17.0-rc.23`
|
||||
* `hkdf`: `0.12` to `0.13`
|
||||
* `hmac`: `0.12` to `0.13`
|
||||
* `rand`: `0.8` to `0.10`
|
||||
* `rand_chacha`: `0.3` to `0.10`
|
||||
* `rfc6979`: `0.4` to `0.6` (now internal to `ecdsa`)
|
||||
* `sha2`: `0.10` to `0.11`
|
||||
* `getrandom`: `0.2` to `0.4` (WASM target)
|
||||
* `p256`/`p384`/`p521`: `0.13` to `0.14.0-rc.15` (dev-dependency)
|
||||
* `cryptoki`: `0.9` to `0.12` (dev-dependency)
|
||||
* `rustyline`: `17` to `18` (dev-dependency)
|
||||
* `scrypt`: `0.11` to `0.12` (dev-dependency)
|
||||
* `voprf` replaced by `voprf-vx 1.0.0-pre.0`
|
||||
* Bump `generic-array 0.14` to `generic-array 1.4` with `hybrid-array 0.4` interop
|
||||
* Added `hybrid-array 0.4` for interop
|
||||
* Added `ConcatExt` trait to disambiguate from `[T]::concat`
|
||||
* Added **`cryptography`** to `categories` in `Cargo.toml`
|
||||
* Replaced `Hmac` with `SimpleHmac` throughout for `digest 0.11` compatibility
|
||||
* Replaced `bincode` with `postcard` for `no_std` serialization
|
||||
* Re-exported `hybrid_array` from crate root
|
||||
* Updated `Hash` trait to remove `BlockSizeUser` bounds incompatible with `digest 0.11`
|
||||
* Updated `GroupEncoding Repr` bound to `hybrid_array::Array`
|
||||
* Fixed `MaskedResponse::serialize` field ordering to match deserialization
|
||||
* Increased **MSRV** to **1.90**
|
||||
* Renamed crate to `opaque-vx`
|
||||
* Removed direct `rfc6979` dependency (handled by `ecdsa` internally)
|
||||
* Removed unstable `rustfmt` configurations for **Rust stable** compatibility
|
||||
* Removed Facebook-specific contributions (CLA, bounty program) from `CONTRIBUTING.md`
|
||||
* Removed `v3` to `v4` migration test (no longer relevant for fork)
|
||||
|
||||
## 4.1.0-pre.2 (March 26, 2026)
|
||||
|
||||
* Upgraded ml-kem from 0.2 to 0.3.0-rc.0
|
||||
* Increased MSRV to 1.87
|
||||
|
||||
## 4.1.0-pre.1 (November 17, 2025)
|
||||
|
||||
* Added ml-kem re-export behind the kem feature
|
||||
|
||||
## 4.1.0-pre.0 (November 11, 2025)
|
||||
|
||||
* Fixed dependency exporting for the rand crate
|
||||
* Added TripleDhKem key exchange protocol
|
||||
|
||||
## 4.0.1 (October 30, 2025)
|
||||
|
||||
* Fixing docs building issue
|
||||
|
||||
## 4.0.0 (October 23, 2025)
|
||||
|
||||
* Increased MSRV to 1.83
|
||||
* Synced implementation with RFC 9807 (no core protocol changes)
|
||||
* Added a SIGMA-I key exchange implementation
|
||||
* Removed KeGroup type from the Ciphersuite trait (now part of KeyExchange type)
|
||||
* **Breaking: existing Ciphersuite trait definitions need to be updated**
|
||||
* **Breaking: existing Ciphersuite trait definitions need to be updated**
|
||||
* Ensured that dummy record is always created to avoid timing attack issues
|
||||
* Modified the dummy registration file to only contain the public key
|
||||
instead of the keypair
|
||||
* **Breaking: existing `ServerSetup`s need to be updated**
|
||||
```rust
|
||||
// Given `old` is a `ServerSetup` from `opaque-ke` v3.
|
||||
let old_serialized = old.serialize();
|
||||
|
||||
type OldSeedLen = <<<OldCipherSuite as opaque_ke_3::CipherSuite>::OprfCs as voprf::CipherSuite>::Hash as OutputSizeUser>::OutputSize;
|
||||
type OldSkLen = <<OldCipherSuite as opaque_ke_3::CipherSuite>::KeGroup as opaque_ke_3::key_exchange::group::KeGroup>::SkLen;
|
||||
|
||||
let (old_serialied_rest, old_fake_keypair_serialized): (
|
||||
GenericArray<u8, Sum<OldSeedLen, OldSkLen>>,
|
||||
_,
|
||||
) = old_serialized.split();
|
||||
|
||||
let old_fake_keypair =
|
||||
KeyPair::<<OldCipherSuite as opaque_ke_3::CipherSuite>::KeGroup>::from_private_key_slice(
|
||||
&old_fake_keypair_serialized,
|
||||
)
|
||||
.unwrap();
|
||||
let old_fake_pk_serialized = old_fake_keypair.public().serialize();
|
||||
|
||||
let new_serialized = old_serialied_rest.concat(old_fake_pk_serialized);
|
||||
// Given `NewCipherSuite` is a `CipherSuite` implementation equivalent to `OldCipherSuite`.
|
||||
ServerSetup::<NewCipherSuite>::deserialize(&new_serialized).unwrap()
|
||||
```
|
||||
* **Breaking: existing `ServerSetup`s need to be updated**
|
||||
```rust
|
||||
// Given `old` is a `ServerSetup` from `opaque-ke` v3.
|
||||
let old_serialized = old.serialize();
|
||||
|
||||
type OldSeedLen = <<<OldCipherSuite as opaque_ke_3::CipherSuite>::OprfCs as voprf::CipherSuite>::Hash as OutputSizeUser>::OutputSize;
|
||||
type OldSkLen = <<OldCipherSuite as opaque_ke_3::CipherSuite>::KeGroup as opaque_ke_3::key_exchange::group::KeGroup>::SkLen;
|
||||
|
||||
let (old_serialied_rest, old_fake_keypair_serialized): (
|
||||
GenericArray<u8, Sum<OldSeedLen, OldSkLen>>,
|
||||
_,
|
||||
) = old_serialized.split();
|
||||
|
||||
let old_fake_keypair =
|
||||
KeyPair::<<OldCipherSuite as opaque_ke_3::CipherSuite>::KeGroup>::from_private_key_slice(
|
||||
&old_fake_keypair_serialized,
|
||||
)
|
||||
.unwrap();
|
||||
let old_fake_pk_serialized = old_fake_keypair.public().serialize();
|
||||
|
||||
let new_serialized = old_serialied_rest.concat(old_fake_pk_serialized);
|
||||
// Given `NewCipherSuite` is a `CipherSuite` implementation equivalent to `OldCipherSuite`.
|
||||
ServerSetup::<NewCipherSuite>::deserialize(&new_serialized).unwrap()
|
||||
```
|
||||
* Added remote OPRF seed support
|
||||
* Replace remote private key trait with a state machine, facilitating async support.
|
||||
* Serde de/serialization formats have been simplified
|
||||
* **Breaking: existing `ServerRegistration`s may need to be updated**
|
||||
```rust
|
||||
// Given `old` is a `ServerRegistration` from `opaque-ke` v3.
|
||||
let old_serialized = old.serialize();
|
||||
// Given `NewCipherSuite` is a `CipherSuite` implementation equivalent to the old cipher suite.
|
||||
ServerRegistration::<NewCipherSuite>::deserialize(&old_serialized).unwrap()
|
||||
```
|
||||
|
||||
* **Breaking: existing `ServerRegistration`s may need to be updated**
|
||||
```rust
|
||||
// Given `old` is a `ServerRegistration` from `opaque-ke` v3.
|
||||
let old_serialized = old.serialize();
|
||||
// Given `NewCipherSuite` is a `CipherSuite` implementation equivalent to the old cipher suite.
|
||||
ServerRegistration::<NewCipherSuite>::deserialize(&old_serialized).unwrap()
|
||||
```
|
||||
|
||||
## 3.0.0 (October 10, 2024)
|
||||
|
||||
* Synced implementation with draft-irtf-cfrg-opaque-16
|
||||
* **Breaking: protocol context string changed from `RFCXXXX` to `OPAQUEv1-`**
|
||||
* **Breaking: protocol context string changed from `RFCXXXX` to `OPAQUEv1-`**
|
||||
* Dropped unmaintained json crate in favor of serde_json
|
||||
* Updated dependencies
|
||||
* Increased MSRV to 1.74
|
||||
@@ -69,11 +114,12 @@
|
||||
* Adjusted key generation logic to be in line with commit 727b9ac of
|
||||
https://github.com/cfrg/draft-irtf-cfrg-opaque
|
||||
* Updated VOPRF to draft 19
|
||||
* **Breaking: backwards-incompatible changes introduced in OPRF protocol**
|
||||
* **Breaking: backwards-incompatible changes introduced in OPRF protocol**
|
||||
* Added P384 testing support
|
||||
* Renaming of X25519 to Curve25519
|
||||
|
||||
## 2.0.0 (September 21, 2022)
|
||||
|
||||
* Synced implementation with draft-irtf-cfrg-opaque-10
|
||||
* Changed argon2 salt length to recommended value (16 bytes)
|
||||
* Fixed issue from 2.0.0-pre.2 not pinning voprf dependency correctly
|
||||
|
||||
Reference in New Issue
Block a user