Skip to content

Accept PKCS#8 v2 Ed25519 keys in Jwk::from_encoding_key - #545

Open
ucsurf wants to merge 1 commit into
Keats:masterfrom
ucsurf:jwk-ed25519-pkcs8-v2
Open

ucsurf wants to merge 1 commit into
Keats:masterfrom
ucsurf:jwk-ed25519-pkcs8-v2

Conversation

@ucsurf

@ucsurf ucsurf commented Oct 3, 2026

Copy link
Copy Markdown

Jwk::from_encoding_key worked out the EdDSA curve from the length of the PKCS#8 DER document, and only accepted 48 bytes. That is the size of a PKCS#8 v1 Ed25519 key. A PKCS#8 v2 (RFC 5958) key also carries the public key, so it is 83 bytes and was rejected with InvalidEddsaKey. For example, keys from aws_lc_rs::signature::Ed25519KeyPair::generate_pkcs8 are v2.

Ed25519 is the only supported Edwards curve, so this drops the length check. The provider's ed_pub_components_from_private_key already parses the key with Ed25519KeyPair::from_pkcs8 or SigningKey::from_pkcs8_der, both of which accept v1 and v2 and validate the key. Anything that isn't a valid Ed25519 PKCS#8 key still returns InvalidEddsaKey.

This is the minimal fix. It doesn't conflict with the broader idea in the #506 discussion of normalizing keys in EncodingKey/DecodingKey.

Tests:

  • New fixtures tests/eddsa/private_ed25519_v2_key.{pem,pk8}: the existing test key re-encoded as PKCS#8 v2, checked with openssl asn1parse/openssl pkey.
  • New tests ed_jwk_from_ed25519_pkcs8_v2_key (PEM) and ed_jwk_from_ed25519_pkcs8_v2_der_key (DER) check that both produce the same x as the v1 key. They fail on master and pass with this change. ed_jwk_from_invalid_der_key checks that invalid input still returns InvalidEddsaKey.
  • cargo fmt --check passes. cargo clippy --all-targets --features {rust_crypto,aws_lc_rs} -- -D warnings is clean. cargo test passes with and without default features, for both backends (stable toolchain). I didn't run the wasm tests.

Also added a CHANGELOG entry under Unreleased.

Fixes #544

The EdDSA branch inferred the curve from the DER length, which only
matches PKCS#8 v1 keys (48 bytes). PKCS#8 v2 (RFC 5958) keys also carry
the public key and were rejected with InvalidEddsaKey. Ed25519 is the only
supported Edwards curve, so let the crypto provider parse the key and
reject invalid ones instead.

Fixes Keats#544
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Jwk::from_encoding_key rejects PKCS#8 v2 (RFC 5958) Ed25519 private keys

1 participant