Skip to content

Expose Composite ML-DSA CNG identifiers - #132353

Merged
PranavSenthilnathan merged 1 commit into
dotnet:mainfrom
PranavSenthilnathan:pranavsenthilnathan-composite-mldsa-cng-apis
Aug 18, 2026
Merged

PranavSenthilnathan merged 1 commit into
dotnet:mainfrom
PranavSenthilnathan:pranavsenthilnathan-composite-mldsa-cng-apis

Conversation

@PranavSenthilnathan

Copy link
Copy Markdown
Member

Fixes #130052

Note

This PR description was generated with GitHub Copilot.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 5676db47-d54b-4946-97ec-7fc0a7392c30
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @bartonjs, @vcsjones, @dotnet/area-system-security
See info in area-owners.md if you want to be subscribed.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR exposes Composite ML-DSA identifiers for Windows CNG by promoting existing internal constants to public CngAlgorithm / CngAlgorithmGroup properties, marked as experimental to align with the PQC API posture.

Changes:

  • Make CngAlgorithm.CompositeMLDsa and CngAlgorithmGroup.CompositeMLDsa public and annotate them with Experimental(SYSLIB5006).
  • Update the System.Security.Cryptography reference assembly to include the new public properties.
  • Remove the test-only CngAlgorithm extension shim now that the identifiers are available publicly.

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated no comments.

File Description
src/libraries/System.Security.Cryptography/src/System/Security/Cryptography/CngAlgorithm.cs Exposes CompositeMLDsa as a public experimental algorithm identifier.
src/libraries/System.Security.Cryptography/src/System/Security/Cryptography/CngAlgorithmGroup.cs Exposes CompositeMLDsa as a public experimental algorithm-group identifier.
src/libraries/System.Security.Cryptography/ref/System.Security.Cryptography.cs Adds the new public properties to the ref contract with Experimental("SYSLIB5006").
src/libraries/Common/tests/System/Security/Cryptography/AlgorithmImplementations/CompositeMLDsa/CompositeMLDsaTestHelpers.Cng.cs Removes the internal test-only extension helper; tests now use the public API.

@PranavSenthilnathan

Copy link
Copy Markdown
Member Author

/ba-g #132336

@PranavSenthilnathan
PranavSenthilnathan merged commit 663c457 into dotnet:main Aug 18, 2026
76 of 80 checks passed
@PranavSenthilnathan
PranavSenthilnathan deleted the pranavsenthilnathan-composite-mldsa-cng-apis branch August 18, 2026 09:15
@PranavSenthilnathan PranavSenthilnathan added this to the 11.0.0 milestone Aug 18, 2026
@dotnet-milestone-bot dotnet-milestone-bot Bot modified the milestones: 11.0.0, 12.0-preview1 Aug 21, 2026
@bartonjs bartonjs added the cryptographic-docs-impact Issues impacting cryptographic docs. Cleared and reused after documentation is updated each release. label Sep 11, 2026
artl93 pushed a commit that referenced this pull request Sep 19, 2026
main PR: #132353

# Description

Expose the experimental Composite ML-DSA CNG identifiers in .NET 11 RC2.
Straight backport; no additional code changes. Stack layer 1/4,
targeting
`release/11.0`.

# Customer Impact

Completes the new PQC API surface so callers can use named CNG
identifiers
instead of provider-specific strings.

# Regression

No. New APIs.

# Testing

Windows Release build passed. Full crypto suite: 17,454 total, 1 failed,
407 skipped. The X509 key-file cleanup test failed; its targeted rerun
passed all 6 cases. The initial failure's cause is undetermined.
Cherry-pick equivalence verified.

# Risk

Low. Exposes existing identifiers as new experimental APIs without
changing the cryptographic implementation.

> [!NOTE]
> This PR description was generated with GitHub Copilot.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 5676db47-d54b-4946-97ec-7fc0a7392c30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-System.Security cryptographic-docs-impact Issues impacting cryptographic docs. Cleared and reused after documentation is updated each release.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[API Proposal]: Add CompositeMLDsa property to CngAlgorithm and CngAlgorithmGroup

3 participants