feat: add Ed25519 and improved ECDSA support with e2e crypto tests - #1941
Conversation
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Team Run ID: Comment |
|
/retest |
|
All PipelineRuns for this commit have already succeeded. Use |
|
/override ? |
|
@omertuc: /override requires failed status contexts, check run or a prowjob name to operate on.
Only the following failed contexts/checkruns were expected:
If you are trying to override a checkrun that has a space in it, you must put a double quote on the context. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
/override pull-ci-rh-ecosystem-edge-recert-main-e2e-aws-ovn-single-node-recert-parallel |
|
@omertuc: Overrode contexts on behalf of omertuc: ci/prow/e2e-aws-ovn-single-node-recert-parallel DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
/override pull-ci-rh-ecosystem-edge-recert-main-e2e-aws-ovn-single-node-recert-serial |
|
@omertuc: Overrode contexts on behalf of omertuc: ci/prow/e2e-aws-ovn-single-node-recert-serial DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
/override ci/prow/ibi-e2e-flow |
|
@omertuc: Overrode contexts on behalf of omertuc: ci/prow/ibi-e2e-flow DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
Includes unit tests salvaged from rh-ecosystem-edge#1817 and rh-ecosystem-edge#1829 (now closed as superseded by this PR). Co-Authored-By: Claude <noreply@anthropic.com>
sebrandon1
left a comment
There was a problem hiding this comment.
Looks good. One comment about checkout's version.
| runs-on: ubuntu-latest | ||
| timeout-minutes: 30 | ||
| steps: | ||
| - uses: actions/checkout@v4 |
There was a problem hiding this comment.
| - uses: actions/checkout@v4 | |
| - uses: actions/checkout@v7 |
|
@sebrandon1: changing LGTM is restricted to collaborators DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
/retest |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: danmanor, omertuc, sebrandon1 The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
/override ? |
|
@omertuc: /override requires failed status contexts, check run or a prowjob name to operate on.
Only the following failed contexts/checkruns were expected:
If you are trying to override a checkrun that has a space in it, you must put a double quote on the context. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
/override pull-ci-rh-ecosystem-edge-recert-main-e2e-aws-ovn-single-node-recert-parallel |
|
@omertuc: Overrode contexts on behalf of omertuc: ci/prow/e2e-aws-ovn-single-node-recert-parallel DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
/retest |
|
All PipelineRuns for this commit have already succeeded. Use |
|
/retest |
|
All PipelineRuns for this commit have already succeeded. Use |
|
/override ? |
|
@omertuc: /override requires failed status contexts, check run or a prowjob name to operate on.
Only the following failed contexts/checkruns were expected:
If you are trying to override a checkrun that has a space in it, you must put a double quote on the context. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
/override pull-ci-rh-ecosystem-edge-recert-main-e2e-aws-ovn-single-node-recert-parallel |
|
@omertuc: Overrode contexts on behalf of omertuc: ci/prow/e2e-aws-ovn-single-node-recert-parallel DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
/override pull-ci-rh-ecosystem-edge-recert-main-e2e-aws-ovn-single-node-recert-serial |
|
@omertuc: Overrode contexts on behalf of omertuc: ci/prow/e2e-aws-ovn-single-node-recert-serial DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
/override pull-ci-rh-ecosystem-edge-recert-main-baremetalds-sno-recert-cluster-rename |
|
@omertuc: Overrode contexts on behalf of omertuc: ci/prow/baremetalds-sno-recert-cluster-rename DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
/override ? |
|
@omertuc: /override requires failed status contexts, check run or a prowjob name to operate on.
Only the following failed contexts/checkruns were expected:
If you are trying to override a checkrun that has a space in it, you must put a double quote on the context. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
/override pull-ci-rh-ecosystem-edge-recert-main-ibu-e2e-flow |
|
@omertuc: Overrode contexts on behalf of omertuc: ci/prow/ibu-e2e-flow DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
/retest |
|
All PipelineRuns for this commit have already succeeded. Use |
|
/override ? |
|
@omertuc: /override requires failed status contexts, check run or a prowjob name to operate on.
Only the following failed contexts/checkruns were expected:
If you are trying to override a checkrun that has a space in it, you must put a double quote on the context. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
/override pull-ci-rh-ecosystem-edge-recert-main-e2e-aws-ovn-single-node-recert-parallel |
|
@omertuc: Overrode contexts on behalf of omertuc: ci/prow/e2e-aws-ovn-single-node-recert-parallel DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
/override pull-ci-rh-ecosystem-edge-recert-main-e2e-aws-ovn-single-node-recert-serial |
|
@omertuc: Overrode contexts on behalf of omertuc: ci/prow/e2e-aws-ovn-single-node-recert-serial DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
9db3b7f
into
rh-ecosystem-edge:main
Bring remaining Ed25519 test cleanup and SEC1 PKCS#8 helper refactor that were not included when rh-ecosystem-edge#1941 merged the crypto product code from rh-ecosystem-edge#1817 and rh-ecosystem-edge#1829. Co-authored-by: Cursor <cursoragent@cursor.com>
After rh-ecosystem-edge#1941, resign supports ES256/ES384/EdDSA and overwrites the incoming alg from the signing key. Adjust bundled JWT tests accordingly. Co-authored-by: Cursor <cursoragent@cursor.com>
… coverage Carry remaining Ed25519/P-384 leftovers after rh-ecosystem-edge#1941, port e2e-unique crypto checks into the integration suite (P-384 chain verify, multi-alg JWT, Ed25519 CA+leaf, standalone keys), light e2e failure artifacts, and document the e2e vs integration split in README. Co-authored-by: Cursor <cursoragent@cursor.com>
Add Ed25519 key generation, certificate signing, and JWT re-signing. Fix P-384 ECDSA signing to use SHA-384 and curve-agnostic public key derivation. Add a GitHub Actions workflow and Makefile target for e2e crypto regression tests covering RSA, ECDSA (P-256/P-384), and Ed25519.
Supersedes #1817 and #1829 — includes unit tests salvaged from both.
Co-Authored-By: Claude noreply@anthropic.com