Rust CI / cargo clippy (push) Successful in 1m23s
Rust CI / cargo fmt (push) Successful in 3s
Rust CI / test (1.90.0 / no backend / no frontend) (push) Successful in 2m24s
Publish / publish (release) Successful in 57s
Rust CI / test (stable / no backend / no frontend) (push) Successful in 2m24s
Rust CI / test (1.90.0 / no backend / --features serde) (push) Successful in 2m51s
Rust CI / test (1.90.0 / no backend / --features argon2) (push) Successful in 2m32s
Rust CI / test (stable / no backend / --features argon2) (push) Successful in 2m33s
Rust CI / test (1.90.0 / --features curve25519 / no frontend) (push) Successful in 2m30s
Rust CI / test (stable / no backend / --features serde) (push) Successful in 2m53s
Rust CI / test (stable / --features curve25519 / no frontend) (push) Successful in 2m28s
Rust CI / test (1.90.0 / --features curve25519 / --features argon2) (push) Successful in 2m35s
Rust CI / test (stable / --features curve25519 / --features argon2) (push) Successful in 2m37s
Rust CI / test (1.90.0 / --features curve25519 / --features serde) (push) Successful in 2m57s
Rust CI / test (stable / --features curve25519 / --features serde) (push) Successful in 2m58s
Rust CI / test (1.90.0 / --features ecdsa / no frontend) (push) Successful in 2m50s
Rust CI / test (stable / --features ecdsa / no frontend) (push) Successful in 2m49s
Rust CI / test (1.90.0 / --features ecdsa / --features argon2) (push) Successful in 2m58s
Rust CI / test (stable / --features ecdsa / --features serde) (push) Successful in 3m20s
Rust CI / test (stable / --features ecdsa / --features argon2) (push) Successful in 2m59s
Rust CI / test (1.90.0 / --features ecdsa / --features serde) (push) Successful in 3m19s
Rust CI / test (1.90.0 / --features ed25519 / no frontend) (push) Successful in 2m52s
Rust CI / test (1.90.0 / --features ed25519 / --features argon2) (push) Successful in 2m58s
Rust CI / test (stable / --features ed25519 / no frontend) (push) Successful in 2m53s
Rust CI / test (stable / --features ed25519 / --features argon2) (push) Successful in 3m0s
Rust CI / test (1.90.0 / --features ed25519 / --features serde) (push) Successful in 3m20s
Rust CI / test (stable / --features ed25519 / --features serde) (push) Successful in 3m18s
Rust CI / test (1.90.0 / --features ristretto255 / no frontend) (push) Successful in 2m59s
Rust CI / test (stable / --features ristretto255 / no frontend) (push) Successful in 3m3s
Rust CI / test (1.90.0 / --features ristretto255 / --features argon2) (push) Successful in 3m8s
Rust CI / test (stable / --features ristretto255 / --features argon2) (push) Successful in 3m13s
Rust CI / test (1.90.0 / --features ristretto255 / --features serde) (push) Successful in 3m28s
Rust CI / test (stable / --features ristretto255 / --features serde) (push) Successful in 3m32s
Rust CI / test (1.90.0 / --features ristretto255,curve25519,ecdsa,ed25519 / no frontend) (push) Successful in 5m20s
Rust CI / test (stable / --features ristretto255,curve25519,ecdsa,ed25519 / no frontend) (push) Successful in 5m9s
Rust CI / test (1.90.0 / --features ristretto255,curve25519,ecdsa,ed25519 / --features argon2) (push) Successful in 5m29s
Rust CI / test (stable / --features ristretto255,curve25519,ecdsa,ed25519 / --features argon2) (push) Successful in 5m12s
Rust CI / test (1.90.0 / --features ristretto255,curve25519,ecdsa,ed25519 / --features serde) (push) Successful in 5m53s
Rust CI / test (1.90.0 / --features ristretto255,kem / no frontend) (push) Successful in 3m54s
Rust CI / test (stable / --features ristretto255,curve25519,ecdsa,ed25519 / --features serde) (push) Successful in 5m45s
Rust CI / test (stable / --features ristretto255,kem / no frontend) (push) Successful in 3m51s
Rust CI / test (1.90.0 / --features ristretto255,kem / --features argon2) (push) Successful in 4m1s
Rust CI / test (stable / --features ristretto255,kem / --features argon2) (push) Successful in 3m58s
Rust CI / test (1.90.0 / --features ristretto255,kem / --features serde) (push) Successful in 4m25s
Rust CI / test (stable / --features ristretto255,kem / --features serde) (push) Successful in 4m23s
Rust CI / test simple_login example (push) Successful in 18s
Rust CI / test digital_locker example (push) Successful in 17s
Rust CI / cargo bench compilation () (push) Successful in 1m44s
Rust CI / cargo bench compilation (--features ristretto255) (push) Successful in 1m54s
Rust CI / cargo bench compilation (--features ristretto255,kem) (push) Successful in 2m28s
Rust CI / cargo audit (push) Successful in 8s
Rust CI / no-std (wasm32-unknown-unknown / curve25519) (push) Successful in 18s
Rust CI / no-std (thumbv6m-none-eabi / ed25519) (push) Successful in 30s
Rust CI / no-std (wasm32-unknown-unknown / ed25519) (push) Successful in 29s
Rust CI / no-std (thumbv6m-none-eabi / no backend) (push) Successful in 17s
Rust CI / no-std (wasm32-unknown-unknown / ecdsa) (push) Successful in 18s
Rust CI / no-std (thumbv6m-none-eabi / ristretto255) (push) Successful in 18s
Rust CI / no-std (thumbv6m-none-eabi / ristretto255,curve25519,ecdsa,ed25519) (push) Successful in 29s
Rust CI / no-std (wasm32-unknown-unknown / ristretto255) (push) Successful in 28s
Rust CI / no-std (wasm32-unknown-unknown / ristretto255,curve25519,ecdsa,ed25519) (push) Successful in 19s
Rust CI / no-std (thumbv6m-none-eabi / curve25519) (push) Successful in 27s
Rust CI / no-std (wasm32-unknown-unknown / no backend) (push) Successful in 19s
Rust CI / no-std (thumbv6m-none-eabi / ecdsa) (push) Successful in 27s
- Add ZeroizeOnDrop bound to Hash trait - Replace manual Drop impls on Ke2Builder and KemKe2Builder with derive_where - Migrate KEM decapsulation key serialization from expanded form to 64-byte seed (KeyInit/KeyExport) - Fix voprf deserialization to pass exact-length slices - Bump voprf-vx to 1.0.0-rc.1 - Regenerate test vectors Reviewed-on: #7 Co-authored-by: UneBaguette <[email protected]> Co-committed-by: UneBaguette <[email protected]>
9.3 KiB
9.3 KiB
Changelog
1.0.0-rc.0 (July 3, 2026)
- Fixed doc showing incorrect MSRV
- Fixed readme incorrect doc link
- Bump
ecdsato0.17 - Bump
voprf-vxto1.0.0-rc.1 - Added
ZeroizeOnDropbound toHashtrait - Replaced manual
Dropimpls onKe2BuilderandKemKe2Builderwith#[derive_where(ZeroizeOnDrop)] - Replaced deprecated
ExpandedKeyEncodingwith seed-based serialization (KeyInit/KeyExport) for KEM decapsulation keys - Fixed deserialization of
voprftypes to pass exact-length slices (compatibility withvoprftrailing bytes rejection) - Regenerated test vectors
1.0.0-pre.1 (July 2, 2026)
- Fixed README package name
- Implement
zeroizefeature onargon2,ed25519-dalek,hmac,chacha20poly1305andsha2 - Removed
rand_coredependency to use it throughrandre-export
1.0.0-pre.0 (July 1, 2026)
Forked from facebook/opaque-ke at 4.1.0-pre.2.
- Upgraded dependencies:
ml-kem:0.3.0-rc.0to0.3digest:0.10to0.11elliptic-curve:0.13to0.14curve25519-dalek:4to5.0.0-rced25519-dalek:2to3.0.0-rcecdsa:0.16to0.17.0-rc.23hkdf:0.12to0.13hmac:0.12to0.13rand:0.8to0.10rand_chacha:0.3to0.10rfc6979:0.4to0.6(now internal toecdsa)sha2:0.10to0.11getrandom:0.2to0.4(WASM target)p256/p384/p521:0.13to0.14.0-rc.15(dev-dependency)cryptoki:0.9to0.12(dev-dependency)rustyline:17to18(dev-dependency)scrypt:0.11to0.12(dev-dependency)voprfreplaced byvoprf-vx 1.0.0-pre.0
- Bump
generic-array 0.14togeneric-array 1.4withhybrid-array 0.4interop - Added
hybrid-array 0.4for interop - Added
ConcatExttrait to disambiguate from[T]::concat - Added
cryptographytocategoriesinCargo.toml - Replaced
HmacwithSimpleHmacthroughout fordigest 0.11compatibility - Replaced
bincodewithpostcardforno_stdserialization - Replaced license appendix in files while keeping original copyright
- Re-exported
hybrid_arrayfrom crate root - Updated
Hashtrait to removeBlockSizeUserbounds incompatible withdigest 0.11 - Updated
GroupEncoding Reprbound tohybrid_array::Array - Fixed
MaskedResponse::serializefield ordering to match deserialization - Increased MSRV to 1.90
- Renamed crate to
opaque-vx - Removed direct
rfc6979dependency (handled byecdsainternally) - Removed unstable
rustfmtconfigurations for Rust stable compatibility - Removed Facebook-specific contributions (CLA, bounty program) from
CONTRIBUTING.md - Removed
v3tov4migration test (no longer relevant for fork)
4.1.0-pre.2 (March 26, 2026)
- Upgraded ml-kem from 0.2 to 0.3.0-rc.0
- Increased MSRV to 1.87
4.1.0-pre.1 (November 17, 2025)
- Added ml-kem re-export behind the kem feature
4.1.0-pre.0 (November 11, 2025)
- Fixed dependency exporting for the rand crate
- Added TripleDhKem key exchange protocol
4.0.1 (October 30, 2025)
- Fixing docs building issue
4.0.0 (October 23, 2025)
- Increased MSRV to 1.83
- Synced implementation with RFC 9807 (no core protocol changes)
- Added a SIGMA-I key exchange implementation
- Removed KeGroup type from the Ciphersuite trait (now part of KeyExchange type)
- Breaking: existing Ciphersuite trait definitions need to be updated
- Ensured that dummy record is always created to avoid timing attack issues
- Modified the dummy registration file to only contain the public key
instead of the keypair
- Breaking: existing
ServerSetups need to be updated// Given `old` is a `ServerSetup` from `opaque-ke` v3. let old_serialized = old.serialize(); type OldSeedLen = <<<OldCipherSuite as opaque_ke_3::CipherSuite>::OprfCs as voprf::CipherSuite>::Hash as OutputSizeUser>::OutputSize; type OldSkLen = <<OldCipherSuite as opaque_ke_3::CipherSuite>::KeGroup as opaque_ke_3::key_exchange::group::KeGroup>::SkLen; let (old_serialied_rest, old_fake_keypair_serialized): ( GenericArray<u8, Sum<OldSeedLen, OldSkLen>>, _, ) = old_serialized.split(); let old_fake_keypair = KeyPair::<<OldCipherSuite as opaque_ke_3::CipherSuite>::KeGroup>::from_private_key_slice( &old_fake_keypair_serialized, ) .unwrap(); let old_fake_pk_serialized = old_fake_keypair.public().serialize(); let new_serialized = old_serialied_rest.concat(old_fake_pk_serialized); // Given `NewCipherSuite` is a `CipherSuite` implementation equivalent to `OldCipherSuite`. ServerSetup::<NewCipherSuite>::deserialize(&new_serialized).unwrap()
- Breaking: existing
- Added remote OPRF seed support
- Replace remote private key trait with a state machine, facilitating async support.
- Serde de/serialization formats have been simplified
- Breaking: existing
ServerRegistrations may need to be updated// Given `old` is a `ServerRegistration` from `opaque-ke` v3. let old_serialized = old.serialize(); // Given `NewCipherSuite` is a `CipherSuite` implementation equivalent to the old cipher suite. ServerRegistration::<NewCipherSuite>::deserialize(&old_serialized).unwrap()
- Breaking: existing
3.0.0 (October 10, 2024)
- Synced implementation with draft-irtf-cfrg-opaque-16
- Breaking: protocol context string changed from
RFCXXXXtoOPAQUEv1-
- Breaking: protocol context string changed from
- Dropped unmaintained json crate in favor of serde_json
- Updated dependencies
- Increased MSRV to 1.74
- Adjusted curve25519 support logic
- Adjusted key generation logic to be in line with commit 727b9ac of https://github.com/cfrg/draft-irtf-cfrg-opaque
- Updated VOPRF to draft 19
- Breaking: backwards-incompatible changes introduced in OPRF protocol
- Added P384 testing support
- Renaming of X25519 to Curve25519
2.0.0 (September 21, 2022)
- Synced implementation with draft-irtf-cfrg-opaque-10
- Changed argon2 salt length to recommended value (16 bytes)
- Fixed issue from 2.0.0-pre.2 not pinning voprf dependency correctly
- Split out VOPRF implementation into its own crate
- Added support for running the API without performing allocations
- Revamped the way the Group trait was used, so as to be more easily extendable to other groups
- Added support for p256 as the group and x25519 as the key exchange group
- Added common traits for each public-facing struct, including serde support
1.2.0 (October 7, 2021)
- Added explicit support for the thumbv6m-none-eabi target (no-std)
1.1.0 (August 18, 2021)
- Updated dependencies and bumped MSRV to 1.51
- Added no_std support
1.0.0 (July 19, 2021)
- Branched from v0.5.0
- Various security improvements: non-zero scalars, zeroizing on drop, constant-time operations, reflected value check, and adding an i2osp error condition
0.6.0 (June 30, 2021)
- Synced implementation with draft-irtf-cfrg-opaque-05, which changes the envelope structure and introduces a ServerSetup object to be maintained by the server
- Various security improvements: non-zero scalars, zeroizing on drop, constant-time operations
- Adding serde support behind a feature
- Supporting common traits (
eb59676) - Swapping out scrypt for argon2 (
535b9b8) for the slow-hash feature - Adding support for common traits on public structs
- Updated dependencies
0.5.1 (July 16, 2021)
- Various security improvements: non-zero scalars, zeroizing on drop, constant-time operations, reflected value check, and adding an i2osp error condition
0.5.0 (March 1, 2021)
- Removed dependency on generic-bytes-derive package
0.4.0 (February 26, 2021)
- Adherence to protocol format described in https://tools.ietf.org/html/draft-irtf-cfrg-opaque-03
- Renamed to_bytes() and try_from() to serialize() and deserialize() for top-level structs
- Conformed all message type parameters to be parameterized in the Ciphersuite object
0.3.1 (February 11, 2021)
- Re-exporting the rand library (and including it as a dependency instead of just rand_core)
- Exposing a convenience function for converting from byte array to Key type
0.3.0 (February 8, 2021)
- General API and documentation improvements, including the support of custom identifiers, optional result parameters, and the use of the export key
- Compliance with RFC 8017 on data serialization functions (I2OSP / OS2IP)
- Adherence to protocol format described in https://tools.ietf.org/html/draft-irtf-cfrg-opaque-02
- Added parameters for key exchange additional data
- Added simple_login and digital_locker examples
0.2.1 (October 22, 2020)
- Changed visibility of hash module to be public
0.2.0 (September 3, 2020)
- Added CipherSuite API for specifying underlying primitives
- Added support for specifying a slow password hashing function
- Collapsed SignalKeyPair to X25519KeyPair
- Updated the envelope implementation to match the suggested XOR-based construction in https://tools.ietf.org/html/draft-krawczyk-cfrg-opaque-06
- Included randomized tests for testing try_from crashes
- Implemented Elligator2 map instead of try-and-increment for hash-to-curve
- Added extensibility for supporting different key exchange protocols
- Added benchmarks for the OPRF & switchable dalek backend depending on platform
0.1.0 (June 5, 2020)
- Initial release