Files
opaque-vx/CHANGELOG.md
breakingbread 09286d34fc
Rust CI / cargo clippy (push) Successful in 1m23s
Rust CI / cargo fmt (push) Successful in 3s
Rust CI / test (1.90.0 / no backend / no frontend) (push) Successful in 2m24s
Publish / publish (release) Successful in 57s
Rust CI / test (stable / no backend / no frontend) (push) Successful in 2m24s
Rust CI / test (1.90.0 / no backend / --features serde) (push) Successful in 2m51s
Rust CI / test (1.90.0 / no backend / --features argon2) (push) Successful in 2m32s
Rust CI / test (stable / no backend / --features argon2) (push) Successful in 2m33s
Rust CI / test (1.90.0 / --features curve25519 / no frontend) (push) Successful in 2m30s
Rust CI / test (stable / no backend / --features serde) (push) Successful in 2m53s
Rust CI / test (stable / --features curve25519 / no frontend) (push) Successful in 2m28s
Rust CI / test (1.90.0 / --features curve25519 / --features argon2) (push) Successful in 2m35s
Rust CI / test (stable / --features curve25519 / --features argon2) (push) Successful in 2m37s
Rust CI / test (1.90.0 / --features curve25519 / --features serde) (push) Successful in 2m57s
Rust CI / test (stable / --features curve25519 / --features serde) (push) Successful in 2m58s
Rust CI / test (1.90.0 / --features ecdsa / no frontend) (push) Successful in 2m50s
Rust CI / test (stable / --features ecdsa / no frontend) (push) Successful in 2m49s
Rust CI / test (1.90.0 / --features ecdsa / --features argon2) (push) Successful in 2m58s
Rust CI / test (stable / --features ecdsa / --features serde) (push) Successful in 3m20s
Rust CI / test (stable / --features ecdsa / --features argon2) (push) Successful in 2m59s
Rust CI / test (1.90.0 / --features ecdsa / --features serde) (push) Successful in 3m19s
Rust CI / test (1.90.0 / --features ed25519 / no frontend) (push) Successful in 2m52s
Rust CI / test (1.90.0 / --features ed25519 / --features argon2) (push) Successful in 2m58s
Rust CI / test (stable / --features ed25519 / no frontend) (push) Successful in 2m53s
Rust CI / test (stable / --features ed25519 / --features argon2) (push) Successful in 3m0s
Rust CI / test (1.90.0 / --features ed25519 / --features serde) (push) Successful in 3m20s
Rust CI / test (stable / --features ed25519 / --features serde) (push) Successful in 3m18s
Rust CI / test (1.90.0 / --features ristretto255 / no frontend) (push) Successful in 2m59s
Rust CI / test (stable / --features ristretto255 / no frontend) (push) Successful in 3m3s
Rust CI / test (1.90.0 / --features ristretto255 / --features argon2) (push) Successful in 3m8s
Rust CI / test (stable / --features ristretto255 / --features argon2) (push) Successful in 3m13s
Rust CI / test (1.90.0 / --features ristretto255 / --features serde) (push) Successful in 3m28s
Rust CI / test (stable / --features ristretto255 / --features serde) (push) Successful in 3m32s
Rust CI / test (1.90.0 / --features ristretto255,curve25519,ecdsa,ed25519 / no frontend) (push) Successful in 5m20s
Rust CI / test (stable / --features ristretto255,curve25519,ecdsa,ed25519 / no frontend) (push) Successful in 5m9s
Rust CI / test (1.90.0 / --features ristretto255,curve25519,ecdsa,ed25519 / --features argon2) (push) Successful in 5m29s
Rust CI / test (stable / --features ristretto255,curve25519,ecdsa,ed25519 / --features argon2) (push) Successful in 5m12s
Rust CI / test (1.90.0 / --features ristretto255,curve25519,ecdsa,ed25519 / --features serde) (push) Successful in 5m53s
Rust CI / test (1.90.0 / --features ristretto255,kem / no frontend) (push) Successful in 3m54s
Rust CI / test (stable / --features ristretto255,curve25519,ecdsa,ed25519 / --features serde) (push) Successful in 5m45s
Rust CI / test (stable / --features ristretto255,kem / no frontend) (push) Successful in 3m51s
Rust CI / test (1.90.0 / --features ristretto255,kem / --features argon2) (push) Successful in 4m1s
Rust CI / test (stable / --features ristretto255,kem / --features argon2) (push) Successful in 3m58s
Rust CI / test (1.90.0 / --features ristretto255,kem / --features serde) (push) Successful in 4m25s
Rust CI / test (stable / --features ristretto255,kem / --features serde) (push) Successful in 4m23s
Rust CI / test simple_login example (push) Successful in 18s
Rust CI / test digital_locker example (push) Successful in 17s
Rust CI / cargo bench compilation () (push) Successful in 1m44s
Rust CI / cargo bench compilation (--features ristretto255) (push) Successful in 1m54s
Rust CI / cargo bench compilation (--features ristretto255,kem) (push) Successful in 2m28s
Rust CI / cargo audit (push) Successful in 8s
Rust CI / no-std (wasm32-unknown-unknown / curve25519) (push) Successful in 18s
Rust CI / no-std (thumbv6m-none-eabi / ed25519) (push) Successful in 30s
Rust CI / no-std (wasm32-unknown-unknown / ed25519) (push) Successful in 29s
Rust CI / no-std (thumbv6m-none-eabi / no backend) (push) Successful in 17s
Rust CI / no-std (wasm32-unknown-unknown / ecdsa) (push) Successful in 18s
Rust CI / no-std (thumbv6m-none-eabi / ristretto255) (push) Successful in 18s
Rust CI / no-std (thumbv6m-none-eabi / ristretto255,curve25519,ecdsa,ed25519) (push) Successful in 29s
Rust CI / no-std (wasm32-unknown-unknown / ristretto255) (push) Successful in 28s
Rust CI / no-std (wasm32-unknown-unknown / ristretto255,curve25519,ecdsa,ed25519) (push) Successful in 19s
Rust CI / no-std (thumbv6m-none-eabi / curve25519) (push) Successful in 27s
Rust CI / no-std (wasm32-unknown-unknown / no backend) (push) Successful in 19s
Rust CI / no-std (thumbv6m-none-eabi / ecdsa) (push) Successful in 27s
feat: replace deprecated ExpandedKeyEncoding with seed serialization, derive ZeroizeOnDrop (#7)
- Add ZeroizeOnDrop bound to Hash trait
- Replace manual Drop impls on Ke2Builder and KemKe2Builder with derive_where
- Migrate KEM decapsulation key serialization from expanded form to 64-byte seed (KeyInit/KeyExport)
- Fix voprf deserialization to pass exact-length slices
- Bump voprf-vx to 1.0.0-rc.1
- Regenerate test vectors

Reviewed-on: #7
Co-authored-by: UneBaguette <[email protected]>
Co-committed-by: UneBaguette <[email protected]>
2026-07-03 13:06:30 +02:00

9.3 KiB

Changelog

1.0.0-rc.0 (July 3, 2026)

  • Fixed doc showing incorrect MSRV
  • Fixed readme incorrect doc link
  • Bump ecdsa to 0.17
  • Bump voprf-vx to 1.0.0-rc.1
  • Added ZeroizeOnDrop bound to Hash trait
  • Replaced manual Drop impls on Ke2Builder and KemKe2Builder with #[derive_where(ZeroizeOnDrop)]
  • Replaced deprecated ExpandedKeyEncoding with seed-based serialization (KeyInit / KeyExport) for KEM decapsulation keys
  • Fixed deserialization of voprf types to pass exact-length slices (compatibility with voprf trailing bytes rejection)
  • Regenerated test vectors

1.0.0-pre.1 (July 2, 2026)

  • Fixed README package name
  • Implement zeroize feature on argon2, ed25519-dalek, hmac, chacha20poly1305 and sha2
  • Removed rand_core dependency to use it through rand re-export

1.0.0-pre.0 (July 1, 2026)

Forked from facebook/opaque-ke at 4.1.0-pre.2.

  • Upgraded dependencies:
    • ml-kem: 0.3.0-rc.0 to 0.3
    • digest: 0.10 to 0.11
    • elliptic-curve: 0.13 to 0.14
    • curve25519-dalek: 4 to 5.0.0-rc
    • ed25519-dalek: 2 to 3.0.0-rc
    • ecdsa: 0.16 to 0.17.0-rc.23
    • hkdf: 0.12 to 0.13
    • hmac: 0.12 to 0.13
    • rand: 0.8 to 0.10
    • rand_chacha: 0.3 to 0.10
    • rfc6979: 0.4 to 0.6 (now internal to ecdsa)
    • sha2: 0.10 to 0.11
    • getrandom: 0.2 to 0.4 (WASM target)
    • p256/p384/p521: 0.13 to 0.14.0-rc.15 (dev-dependency)
    • cryptoki: 0.9 to 0.12 (dev-dependency)
    • rustyline: 17 to 18 (dev-dependency)
    • scrypt: 0.11 to 0.12 (dev-dependency)
    • voprf replaced by voprf-vx 1.0.0-pre.0
  • Bump generic-array 0.14 to generic-array 1.4 with hybrid-array 0.4 interop
  • Added hybrid-array 0.4 for interop
  • Added ConcatExt trait to disambiguate from [T]::concat
  • Added cryptography to categories in Cargo.toml
  • Replaced Hmac with SimpleHmac throughout for digest 0.11 compatibility
  • Replaced bincode with postcard for no_std serialization
  • Replaced license appendix in files while keeping original copyright
  • Re-exported hybrid_array from crate root
  • Updated Hash trait to remove BlockSizeUser bounds incompatible with digest 0.11
  • Updated GroupEncoding Repr bound to hybrid_array::Array
  • Fixed MaskedResponse::serialize field ordering to match deserialization
  • Increased MSRV to 1.90
  • Renamed crate to opaque-vx
  • Removed direct rfc6979 dependency (handled by ecdsa internally)
  • Removed unstable rustfmt configurations for Rust stable compatibility
  • Removed Facebook-specific contributions (CLA, bounty program) from CONTRIBUTING.md
  • Removed v3 to v4 migration test (no longer relevant for fork)

4.1.0-pre.2 (March 26, 2026)

  • Upgraded ml-kem from 0.2 to 0.3.0-rc.0
  • Increased MSRV to 1.87

4.1.0-pre.1 (November 17, 2025)

  • Added ml-kem re-export behind the kem feature

4.1.0-pre.0 (November 11, 2025)

  • Fixed dependency exporting for the rand crate
  • Added TripleDhKem key exchange protocol

4.0.1 (October 30, 2025)

  • Fixing docs building issue

4.0.0 (October 23, 2025)

  • Increased MSRV to 1.83
  • Synced implementation with RFC 9807 (no core protocol changes)
  • Added a SIGMA-I key exchange implementation
  • Removed KeGroup type from the Ciphersuite trait (now part of KeyExchange type)
    • Breaking: existing Ciphersuite trait definitions need to be updated
  • Ensured that dummy record is always created to avoid timing attack issues
  • Modified the dummy registration file to only contain the public key instead of the keypair
    • Breaking: existing ServerSetups need to be updated
      // Given `old` is a `ServerSetup` from `opaque-ke` v3.
      let old_serialized = old.serialize();
      
      type OldSeedLen = <<<OldCipherSuite as opaque_ke_3::CipherSuite>::OprfCs as voprf::CipherSuite>::Hash as OutputSizeUser>::OutputSize;
      type OldSkLen = <<OldCipherSuite as opaque_ke_3::CipherSuite>::KeGroup as opaque_ke_3::key_exchange::group::KeGroup>::SkLen;
      
      let (old_serialied_rest, old_fake_keypair_serialized): (
          GenericArray<u8, Sum<OldSeedLen, OldSkLen>>,
          _,
      ) = old_serialized.split();
      
      let old_fake_keypair =
          KeyPair::<<OldCipherSuite as opaque_ke_3::CipherSuite>::KeGroup>::from_private_key_slice(
              &old_fake_keypair_serialized,
          )
          .unwrap();
      let old_fake_pk_serialized = old_fake_keypair.public().serialize();
      
      let new_serialized = old_serialied_rest.concat(old_fake_pk_serialized);
      // Given `NewCipherSuite` is a `CipherSuite` implementation equivalent to `OldCipherSuite`.
      ServerSetup::<NewCipherSuite>::deserialize(&new_serialized).unwrap()
      
  • Added remote OPRF seed support
  • Replace remote private key trait with a state machine, facilitating async support.
  • Serde de/serialization formats have been simplified
    • Breaking: existing ServerRegistrations may need to be updated
      // Given `old` is a `ServerRegistration` from `opaque-ke` v3.
      let old_serialized = old.serialize();
      // Given `NewCipherSuite` is a `CipherSuite` implementation equivalent to the old cipher suite.
      ServerRegistration::<NewCipherSuite>::deserialize(&old_serialized).unwrap()
      

3.0.0 (October 10, 2024)

  • Synced implementation with draft-irtf-cfrg-opaque-16
    • Breaking: protocol context string changed from RFCXXXX to OPAQUEv1-
  • Dropped unmaintained json crate in favor of serde_json
  • Updated dependencies
  • Increased MSRV to 1.74
  • Adjusted curve25519 support logic
  • Adjusted key generation logic to be in line with commit 727b9ac of https://github.com/cfrg/draft-irtf-cfrg-opaque
  • Updated VOPRF to draft 19
    • Breaking: backwards-incompatible changes introduced in OPRF protocol
  • Added P384 testing support
  • Renaming of X25519 to Curve25519

2.0.0 (September 21, 2022)

  • Synced implementation with draft-irtf-cfrg-opaque-10
  • Changed argon2 salt length to recommended value (16 bytes)
  • Fixed issue from 2.0.0-pre.2 not pinning voprf dependency correctly
  • Split out VOPRF implementation into its own crate
  • Added support for running the API without performing allocations
  • Revamped the way the Group trait was used, so as to be more easily extendable to other groups
  • Added support for p256 as the group and x25519 as the key exchange group
  • Added common traits for each public-facing struct, including serde support

1.2.0 (October 7, 2021)

  • Added explicit support for the thumbv6m-none-eabi target (no-std)

1.1.0 (August 18, 2021)

  • Updated dependencies and bumped MSRV to 1.51
  • Added no_std support

1.0.0 (July 19, 2021)

  • Branched from v0.5.0
  • Various security improvements: non-zero scalars, zeroizing on drop, constant-time operations, reflected value check, and adding an i2osp error condition

0.6.0 (June 30, 2021)

  • Synced implementation with draft-irtf-cfrg-opaque-05, which changes the envelope structure and introduces a ServerSetup object to be maintained by the server
  • Various security improvements: non-zero scalars, zeroizing on drop, constant-time operations
  • Adding serde support behind a feature
  • Supporting common traits (eb59676)
  • Swapping out scrypt for argon2 (535b9b8) for the slow-hash feature
  • Adding support for common traits on public structs
  • Updated dependencies

0.5.1 (July 16, 2021)

  • Various security improvements: non-zero scalars, zeroizing on drop, constant-time operations, reflected value check, and adding an i2osp error condition

0.5.0 (March 1, 2021)

  • Removed dependency on generic-bytes-derive package

0.4.0 (February 26, 2021)

  • Adherence to protocol format described in https://tools.ietf.org/html/draft-irtf-cfrg-opaque-03
  • Renamed to_bytes() and try_from() to serialize() and deserialize() for top-level structs
  • Conformed all message type parameters to be parameterized in the Ciphersuite object

0.3.1 (February 11, 2021)

  • Re-exporting the rand library (and including it as a dependency instead of just rand_core)
  • Exposing a convenience function for converting from byte array to Key type

0.3.0 (February 8, 2021)

  • General API and documentation improvements, including the support of custom identifiers, optional result parameters, and the use of the export key
  • Compliance with RFC 8017 on data serialization functions (I2OSP / OS2IP)
  • Adherence to protocol format described in https://tools.ietf.org/html/draft-irtf-cfrg-opaque-02
  • Added parameters for key exchange additional data
  • Added simple_login and digital_locker examples

0.2.1 (October 22, 2020)

  • Changed visibility of hash module to be public

0.2.0 (September 3, 2020)

  • Added CipherSuite API for specifying underlying primitives
  • Added support for specifying a slow password hashing function
  • Collapsed SignalKeyPair to X25519KeyPair
  • Updated the envelope implementation to match the suggested XOR-based construction in https://tools.ietf.org/html/draft-krawczyk-cfrg-opaque-06
  • Included randomized tests for testing try_from crashes
  • Implemented Elligator2 map instead of try-and-increment for hash-to-curve
  • Added extensibility for supporting different key exchange protocols
  • Added benchmarks for the OPRF & switchable dalek backend depending on platform

0.1.0 (June 5, 2020)

  • Initial release