https://gitlab.synchro.net/main/sbbs/-/commit/beb18e922b876685c2f30ced
Added Files:
src/xptls/test_xp_keyset.c xp_keyset.c xp_keyset.h
Modified Files:
src/xptls/CMakeLists.txt test_xp_ca.c test_xp_crypto_none.c test_xp_tls.cpp xp_ca.h xp_ca_botan3.cpp xp_ca_file.h xp_ca_none.c xp_ca_openssl.c xp_ca_policy.h xp_tls.h xp_tls_botan3.cpp xp_tls_credentials.c xp_tls_internal.h xp_tls_openssl.c
Log Message:
xptls: complete Cryptlib replacement primitives
Synchronet's remaining Cryptlib consumers need stored client keys,
richer certificate inspection, and labelled persistence without exposing
either provider's native objects.
Add TLS client identities backed by retained xp_key handles and counted certificate chains. Extend xp_ca with typed subject fields and arbitrary
CSR extensions, portable CSR and certificate encodings, PKCS#7 bundles,
and certificate metadata.
Add a common xp_keyset implementation with an atomic multi-label
manifest and authenticated PKCS#12. Support OpenSSL 3 PBES2/AES files
and legacy PKCS#12 3DES imports under both providers, reject mismatched identities, preserve non-exportable references, and sync complete
replacements.
Cover the contracts with shared OpenSSL and Botan tests plus
disabled-provider behavior.
Co-Authored-By: OpenAI Codex <
noreply@openai.com>
---
■ Synchronet ■ Vertrauen ■ Home of Synchronet ■ [vert/cvs/bbs].synchro.net