Feat: TLS 1.3 certificate compression - #11615
aidankeefe2022 wants to merge 4 commits into
Conversation
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
A supported build configuration fails to compile, and one protocol error path sends the wrong RFC-mandated alert.
Review effort: Balanced
Findings: 1
Open (2)
What changed in this PR
Adds RFC 8879 certificate compression for TLS/DTLS 1.3 using zlib.
Changes:
- Adds certificate-compression negotiation, APIs, message handling, and lifecycle management.
- Introduces reusable compression-data APIs and documentation.
- Adds extensive TLS, DTLS, QUIC, parser, fragmentation, and fallback tests.
| File | Description |
|---|---|
wolfssl/wolfcrypt/compress.h |
Defines compression algorithms and data APIs. |
wolfssl/ssl.h |
Exposes certificate-compression configuration APIs. |
wolfssl/internal.h |
Adds protocol constants and internal state. |
wolfcrypt/src/compress.c |
Implements compression-data operations. |
src/tls13.c |
Implements compressed certificate send/receive handling. |
src/tls.c |
Implements extension negotiation and serialization. |
src/ssl.c |
Resets compression state on reuse. |
src/internal.c |
Manages compression resources and message validation. |
src/dtls13.c |
Supports compressed certificates in DTLS 1.3. |
tests/quic.c |
Recognizes compressed certificates in QUIC tests. |
tests/api/test_tls13_cert_compression.h |
Declares certificate-compression tests. |
tests/api/test_tls13_cert_compression.c |
Tests negotiation, malformed input, fragmentation, and fallback. |
tests/api/test_tls_parse.h |
Registers extension parser tests. |
tests/api/test_tls_parse.c |
Tests extension parsing and writing. |
tests/api/test_tls_msgtype.h |
Registers message-type tests. |
tests/api/test_tls_msgtype.c |
Tests extension placement restrictions. |
tests/api/test_compress.h |
Registers compression-data tests. |
tests/api/test_compress.c |
Tests compression-data APIs. |
tests/api/include.am |
Adds new tests to Autotools. |
tests/api.c |
Registers the new test suite. |
doc/dox_comments/header_files/ssl.h |
Documents TLS configuration APIs. |
doc/dox_comments/header_files/compress.h |
Documents compression-data APIs. |
configure.ac |
Adds the Autotools feature option. |
CMakeLists.txt |
Adds the CMake feature option and tests. |
cmake/options.h.in |
Exposes the generated feature macro. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
f7ad8de to
6e7dc71
Compare
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #11615
Scan targets checked: wolfcrypt-src, wolfcrypt-bugs, wolfssl-src, wolfssl-bugs
Coverage: 9 of 16 in-scope changed file(s) opened by the reviewer; not opened: src/dtls13.c, src/ssl_api_hs.c, tests/api.c, tests/api/test_compress.c, tests/quic.c, wolfssl/internal.h, wolfssl/ssl.h
Fenrir result: Approved ✅
No new issues found in the changed files.
Advisory only — this automated result does not count as a GitHub approval.
Review tier: Lite
|
retest this please |
|
Checkpoint of the compress_certificate work: - compress_certificate extension: build options, parsing, and offering it in ClientHello and in CertificateRequest. - Receiving CompressedCertificate: decompress with zlib, enforce the size limit and exact uncompressed length, send bad_certificate alerts, keep the buffer across async/non-blocking OCSP re-entry. - wc_CompressionData helpers in wolfCrypt. - Split the TLS 1.3 Certificate body writing into WriteTls13CertHeader and WriteTls13CertEntries, which write into any buffer. - Fix AddCertExt writing an empty extension one byte past the fragment when a record boundary falls inside it. - Unit tests, and OpenSSL interop script cert-compression-interop.sh. Sending compressed certificates is not implemented yet.
Cert Compression is now impl. Also changes compress cert api
Need to look at multi thread tests and all tests in general Move compressed cert cache to cert-compression-cache branch Remove the per-CTX compressed Certificate cache (isCacheReady, cachedCertMsg, compressedCertCache, usingCompressedCertCache) and its threaded test. Each connection compresses its own Certificate again. The cache work continues on the cert-compression-cache branch. fixed testing for compression Removed all compression extensions and cache Added docs to compression API skoll fixes and more testing + setters skoll review reverted accidental reformat finished codespell
ab524b2 to
4b626bc
Compare
1206c7e to
65e4a6e
Compare
|
jenkins retest this please |


Description
When enabled with --enable-cert-compression the feature in negotiated by all TLS1.3 handshakes and able to be turned off at runtime with setters. Looking for feedback on this.
Compression API
Added a compression api that acts on wc_CompressionData object it allows for state tracking of compressed data.
It is a part of two layers. The CompressionData API calls lower-level public algorithm specific APIs. This was to reduce complexity of adding more compression Algs over time to certificate_compression. It also is general purpose and allows for users to swap out compression Algs with out large code changes.
Certificate Compression
When enabled it is on by default and will negotiate all compiled in compression Algs currently it is only supporting zlib but can be extended in the future easily. Users can turn off tls_cert_compression per SSL object or CTX object and set custom algorithm lists via setters turn off is just setting empty list.
Receiving Compressed Cert
Checks if we requested a compressed cert and that the algorithm used is one we support/requested + other RFC checks.
Decompresses the cert and passed it right to the plain Certificate logic. If we are resuming we just go straight to passing out already uncompressed cert msg to Certificate logic.
Sending Compressed Cert
Checks if we requested a cert and if the cert we are getting was one the algorithms we negotiated + rest of RFC checks. We build the compressed cert message and then compress it with out negotiated algorithm. This is then saved in the SSL object and we go into our fragmenting loop.
Tests
Compression API (
wc_CompressionData_*) —tests/api/test_compress.cCompToBuf/DeCompToBufwork with caller-supplied buffers.Certificate Compression (RFC 8879)
Extension unit tests (
test_tls_parse.c,test_tls_msgtype.c)Handshake tests (
test_tls13_cert_compression.c, new)WANT_WRITEinjected at every write.illegal_parameter/bad_certificate).tests/quic.cnow treatscompressed_certificateas a Certificate record.Docs
all public docs are updated and added for new funcs