Skip to content

Add Composite ML-KEM certificate key accessors - #134259

Merged
PranavSenthilnathan merged 1 commit into
dotnet:mainfrom
PranavSenthilnathan:ps-composite-ml-kem-certificate-keys
Sep 19, 2026
Merged

PranavSenthilnathan merged 1 commit into
dotnet:mainfrom
PranavSenthilnathan:ps-composite-ml-kem-certificate-keys

Conversation

@PranavSenthilnathan

Copy link
Copy Markdown
Member

Add cert accessor stubs like we did for Composite ML-DSA.

I've omitted PublicKey changes but am going to mark the Composite ML-KEM API as implemented anyway (we can add it in the future if we need it):

Fixes #129633

Add public-key extraction and validated PlatformNotSupportedException private-key retrieval and copy APIs to System.Security.Cryptography and Microsoft.Bcl.Cryptography, matching Composite ML-DSA conventions.

AI-assisted change generated with GitHub Copilot.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 7e308cd1-67b1-4bd6-a16d-2cada6f92de8
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @bartonjs, @vcsjones, @dotnet/area-system-security
See info in area-owners.md if you want to be subscribed.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

One or more issues must be addressed before approval.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 Low severity

Open (1)
What changed in this PR

Adds experimental Composite ML-KEM certificate key accessors, following the existing Composite ML-DSA pattern.

Changes:

  • Adds X509Certificate2 accessors and private-key association stub.
  • Adds Microsoft.Bcl.Cryptography compatibility extensions.
  • Updates the reference API.
File Description
src/​libraries/​System.Security.Cryptography/​src/​System/​Security/​Cryptography/​X509Certificates/​X509Certificate2.cs Updated as part of this pull request.
src/​libraries/​System.Security.Cryptography/​ref/​System.Security.Cryptography.cs Updated as part of this pull request.
src/​libraries/​Microsoft.Bcl.Cryptography/​src/​System/​Security/​Cryptography/​X509Certificates/​X509CertificateKeyAccessors.cs Updated as part of this pull request.

@PranavSenthilnathan
PranavSenthilnathan merged commit 1f59bb7 into dotnet:main Sep 19, 2026
90 of 93 checks passed
@PranavSenthilnathan

Copy link
Copy Markdown
Member Author

/backport to release/11.0

@github-actions

Copy link
Copy Markdown
Contributor

Started backporting to release/11.0 (link to workflow run)

@PranavSenthilnathan
PranavSenthilnathan deleted the ps-composite-ml-kem-certificate-keys branch September 19, 2026 23:39
artl93 pushed a commit that referenced this pull request Sep 21, 2026
Backport of #134259 to release/11.0

Add Composite ML-KEM certificate key accessors.

/cc @PranavSenthilnathan

## Customer Impact

New PQC API.

## Regression

- [ ] Yes
- [x] No

## Risk

Low, new API.

Co-authored-by: Pranav Senthilnathan <pranas@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 7e308cd1-67b1-4bd6-a16d-2cada6f92de8
@bartonjs bartonjs added the cryptographic-docs-impact Issues impacting cryptographic docs. Cleared and reused after documentation is updated each release. label Sep 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-System.Security cryptographic-docs-impact Issues impacting cryptographic docs. Cleared and reused after documentation is updated each release.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[API Proposal] Composite ML-KEM

3 participants