Skip to content

Use RFC 7093 SHA-512 truncated SKIs - #551

Open
pzduniak wants to merge 1 commit into
letsencrypt:mainfrom
zoom:pzduniak/fips-safe-ski
Open

pzduniak wants to merge 1 commit into
letsencrypt:mainfrom
zoom:pzduniak/fips-safe-ski

Conversation

@pzduniak

@pzduniak pzduniak commented Aug 4, 2026

Copy link
Copy Markdown

Always generate Subject Key Identifiers according to RFC 7093 Section 2 method 3: the leftmost 160 bits of the SHA-512 hash of the subjectPublicKey BIT STRING.

This removes Pebble's use of SHA-1, so it can run with GOFIPS140=v1.0.0 / GODEBUG=fips140=only. It also stays distinct from Boulder, which uses RFC 7093 Section 2 method 1 (truncated SHA-256).

No configuration or library options: Pebble is a test harness and does not need SHA-1 legacy compatibility.

Tests:

  • go test ./ca ./cmd/pebble
  • GOFIPS140=v1.0.0 go test ./ca
  • GODEBUG=fips140=only GOFIPS140=v1.0.0 go test ./ca

@pzduniak pzduniak changed the title Make key identifier hashing selectable Make key identifier hashing selectable (FIPS mode support) Aug 4, 2026

@aarongable aarongable left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No need for legacy, optionality, or backwards compatibility. Pebble is not intended as a long-lived system for issuing trusted certificates, it is intended as a test harness.

I think the correct action here should be simply changing Pebble to always produce Subject Key Identifiers which are produced according to RFC 7093, Section 2, Paragraph (3). In other words, they should be the leftmost 160 bits of the SHA512 hash of the subjectPublicKey bit string. This should allow Pebble to do away with all use of SHA1, which still behaving differently from Boulder to ensure flexibility in the ecosystem.

Always generate subject key identifiers as the leftmost 160 bits of SHA-512 so Pebble can run in FIPS mode and stays distinct from Boulder's truncated SHA-256 method.

Co-authored-by: Cursor <cursoragent@cursor.com>
@pzduniak
pzduniak force-pushed the pzduniak/fips-safe-ski branch from 5a4924f to e3adc27 Compare September 11, 2026 18:37
@pzduniak pzduniak changed the title Make key identifier hashing selectable (FIPS mode support) Use RFC 7093 SHA-512 truncated SKIs Sep 11, 2026
@pzduniak
pzduniak requested a review from aarongable September 11, 2026 18:49
Comment thread ca/ca_test.go
if err != nil {
t.Fatal(err)
}
x, y := elliptic.Unmarshal(elliptic.P256(), publicKeyBytes)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

See lint finding: use crypto/ecdh instead of elliptic.Unmarshal

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants