fix(hsm): review fixes for Cosmian/kms#1210 (FIPS SHA-1 gate, hash inference, RotateName cache) - #2
Merged
Conversation
- Only infer the RSA PKCS#1 v1.5 hash from the input length when the input is a caller-supplied digest; raw messages always default to SHA-256. - Reject SHA-1 RSA signatures in FIPS mode for the pre-hashed DigestInfo path too (both in SigningAlgorithm resolution and the HSM session gate). - Reject a cryptographic_algorithm that does not match the key family. - Treat a malformed DER ECDSA signature as invalid rather than an error. - Deduplicate the CKM_EDDSA sign/verify arms; fix a stale comment. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AZtgA9JVDCciqEsKuGUJfL
…cached - Re-key eligibility (enforce_keyset_latest) and HSM latest-generation selection now use Database::find_by_rotate_name_uncached, so they are never decided on stale (e.g. other-node) keyset state. - Invalidate by keyset name across all owners and generation filters, and by member UID on update/state change/delete/label writes, so a revoked or destroyed generation is not served for the rest of the TTL. - Never cache empty results. - Document the invalidation and multi-node consistency model. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AZtgA9JVDCciqEsKuGUJfL
A signature cached by a C_Sign length query is now only reused when the follow-up call signs identical data; otherwise the module signs again instead of returning a signature computed over the earlier data. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AZtgA9JVDCciqEsKuGUJfL
- SlotManager::checkout_session no longer takes a read_write flag it ignored for pooled sessions: the pool only ever holds read-write sessions. - Document the virtual-memory implication of the 16 MiB RUST_MIN_STACK default (it also applies to the blocking pools running HSM calls) and that operators can override it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AZtgA9JVDCciqEsKuGUJfL
Manuthor
had a problem deploying
to
xks-remote-approval
September 29, 2026 05:12 — with
GitHub Actions
Failure
Gate the jobs that need upstream-only secrets or infrastructure on `github.repository == 'Cosmian/kms'`: AWS XKS remote server, google-cse, secret_vault/secret_aws/secret_azure and aws-cloudhsm. Matrix entries cannot be filtered by a job-level `if`, so they move to dedicated `test-nix-upstream` and `hsm-aws-cloudhsm` jobs; cargo-publish still runs its dry-run when those jobs are skipped. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AZtgA9JVDCciqEsKuGUJfL
…ngelog Replace the inline `#[cfg(not(feature = "non-fips"))]` block inside `rsa_pkcs1_from_hash` with a function-level gated `check_rsa_signature_hash_allowed`, per the no-inline-feature-gating rule, and add the branch CHANGELOG entry. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AZtgA9JVDCciqEsKuGUJfL
The Proteccio and Crypt2Pay jobs need upstream-only secrets and network access (Proteccio IP/password/slot, Crypt2Pay password and OpenVPN profile). On forks they ran with empty credentials and failed (`C_Login` CKR_ARGUMENTS_BAD, `C_GenerateKeyPair` CKR_MECHANISM_INVALID). Move them, together with aws-cloudhsm, into one `hsm-upstream` job gated on `github.repository == 'Cosmian/kms'`, keeping a fixed concurrency group per hardware HSM and the existing job names. The `hsm` job keeps the software/simulated HSMs (utimaco, softhsm2, kryoptic) and no longer receives hardware HSM secrets. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AZtgA9JVDCciqEsKuGUJfL
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Review fixes on top of Cosmian/kms#1210. The base branch
pr-1210-baseis that PR's head (220e0e89), so this diff contains only the fixes.Signing (
6bcbb441)digested_datawas being signed as a SHA-1DigestInfothrough rawCKM_RSA_PKCS, bypassing the FIPS gate.CryptographicAlgorithmthat doesn't match the key type (e.g. ECDSA on an RSA key) with a clear KMIP error.SignatureVerifyreports a malformed DER ECDSA signature as invalid instead of returning an error.CKM_EDDSAcode and fix a stale comment.RotateName cache (
69d9e645)find_by_rotate_name_uncached, so they never act on stale data (e.g. a rotation made by another server node).PKCS#11 (
436c48e5)C_Signlength query is reused only for the same data; different data is signed again.HSM sessions (
9a7644d1)read_writeflag).RUST_MIN_STACKdefault.Tests
rsa_oaep_encryptfails on the SoftHSM2 2.6.1 used locally, and that failure is already in feat: add key tagging for HSM keys + RotateName cache Cosmian/kms#1210.🤖 Generated with Claude Code
https://claude.ai/code/session_01AZtgA9JVDCciqEsKuGUJfL