• src/xptls/test_xp_keyset.c xp_keyset.c xp_keyset.hsrc/xptls/CMakeLists

    From Deucе@VERT to Git commit to main/sbbs/master on Wed Aug 5 17:47:31 2026
    https://gitlab.synchro.net/main/sbbs/-/commit/beb18e922b876685c2f30ced
    Added Files:
    src/xptls/test_xp_keyset.c xp_keyset.c xp_keyset.h
    Modified Files:
    src/xptls/CMakeLists.txt test_xp_ca.c test_xp_crypto_none.c test_xp_tls.cpp xp_ca.h xp_ca_botan3.cpp xp_ca_file.h xp_ca_none.c xp_ca_openssl.c xp_ca_policy.h xp_tls.h xp_tls_botan3.cpp xp_tls_credentials.c xp_tls_internal.h xp_tls_openssl.c
    Log Message:
    xptls: complete Cryptlib replacement primitives

    Synchronet's remaining Cryptlib consumers need stored client keys,
    richer certificate inspection, and labelled persistence without exposing
    either provider's native objects.

    Add TLS client identities backed by retained xp_key handles and counted certificate chains. Extend xp_ca with typed subject fields and arbitrary
    CSR extensions, portable CSR and certificate encodings, PKCS#7 bundles,
    and certificate metadata.

    Add a common xp_keyset implementation with an atomic multi-label
    manifest and authenticated PKCS#12. Support OpenSSL 3 PBES2/AES files
    and legacy PKCS#12 3DES imports under both providers, reject mismatched identities, preserve non-exportable references, and sync complete
    replacements.

    Cover the contracts with shared OpenSSL and Botan tests plus
    disabled-provider behavior.

    Co-Authored-By: OpenAI Codex <noreply@openai.com>

    ---
    ■ Synchronet ■ Vertrauen ■ Home of Synchronet ■ [vert/cvs/bbs].synchro.net