Skip to content

cmd/litewitness: do multiple cosigs, add new -mldsa-key flag - #90

Draft
quite wants to merge 1 commit into
FiloSottile:mainfrom
quite:mldsa44
Draft

cmd/litewitness: do multiple cosigs, add new -mldsa-key flag#90
quite wants to merge 1 commit into
FiloSottile:mainfrom
quite:mldsa44

Conversation

@quite

@quite quite commented Sep 3, 2026

Copy link
Copy Markdown

The ML-DSA-44 key (-mldsa-key) is optional. Only SSH-fingerprint format.
The old deprecated "hex-encoded SHA-256 hash of the public key" is not
supported for this key.

An Ed25519 key (-key) is still required, but more explicitly. It is like
before used for authenticating with any bastion.

@quite quite changed the title Support cosigning with additional ML-DSA-44 key using new -mldsa-key … Create multiple cosigs; with ML-DSA-44 using new -mldsa-key flag Sep 3, 2026
@quite
quite force-pushed the mldsa44 branch 3 times, most recently from 7375fe7 to 88bc34f Compare September 3, 2026 08:25
@quite quite changed the title Create multiple cosigs; with ML-DSA-44 using new -mldsa-key flag Create multiple cosigs; add ML-DSA-44 using new -mldsa-key flag Sep 3, 2026
@quite quite changed the title Create multiple cosigs; add ML-DSA-44 using new -mldsa-key flag cmd/litewitness: do multiple cosigs; add using new -mldsa-key flag Sep 3, 2026
The ML-DSA-44 key (-mldsa-key) is optional. Only SSH-fingerprint format.
The old deprecated "hex-encoded SHA-256 hash of the public key" is not
supported for this key.

An Ed25519 key (-key) is still required, but more explicitly. It is like
before used for authenticating with any bastion.
@quite quite changed the title cmd/litewitness: do multiple cosigs; add using new -mldsa-key flag cmd/litewitness: do multiple cosigs, add new -mldsa-key flag Sep 3, 2026
@quite

quite commented Sep 3, 2026

Copy link
Copy Markdown
Author

Draft for mldsa44 in sigsum-agent: https://git.glasklar.is/sigsum/core/key-mgmt/-/merge_requests/38

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant