Skip to content

Feat: TLS 1.3 certificate compression - #11615

Open
aidankeefe2022 wants to merge 4 commits into
wolfSSL:masterfrom
aidankeefe2022:cert-compression
Open

aidankeefe2022 wants to merge 4 commits into
wolfSSL:masterfrom
aidankeefe2022:cert-compression

Conversation

@aidankeefe2022

@aidankeefe2022 aidankeefe2022 commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Description

When enabled with --enable-cert-compression the feature in negotiated by all TLS1.3 handshakes and able to be turned off at runtime with setters. Looking for feedback on this.

Compression API

Added a compression api that acts on wc_CompressionData object it allows for state tracking of compressed data.
It is a part of two layers. The CompressionData API calls lower-level public algorithm specific APIs. This was to reduce complexity of adding more compression Algs over time to certificate_compression. It also is general purpose and allows for users to swap out compression Algs with out large code changes.

Certificate Compression

When enabled it is on by default and will negotiate all compiled in compression Algs currently it is only supporting zlib but can be extended in the future easily. Users can turn off tls_cert_compression per SSL object or CTX object and set custom algorithm lists via setters turn off is just setting empty list.

Receiving Compressed Cert

Checks if we requested a compressed cert and that the algorithm used is one we support/requested + other RFC checks.
Decompresses the cert and passed it right to the plain Certificate logic. If we are resuming we just go straight to passing out already uncompressed cert msg to Certificate logic.

Sending Compressed Cert

Checks if we requested a cert and if the cert we are getting was one the algorithms we negotiated + rest of RFC checks. We build the compressed cert message and then compress it with out negotiated algorithm. This is then saved in the SSL object and we go into our fragmenting loop.

Tests

Compression API (wc_CompressionData_*) — tests/api/test_compress.c

  • RoundTrip: compress → decompress restores the original data, and the compressed output is smaller.
  • InitWithCompressedData: known-answer zlib vector decompresses to the expected plaintext.
  • ToBuffer: CompToBuf / DeCompToBuf work with caller-supplied buffers.
  • BadArgs: NULL inputs, zero lengths, unknown algorithm IDs and use after a failed init are all rejected.

Certificate Compression (RFC 8879)

Extension unit tests (test_tls_parse.c, test_tls_msgtype.c)

  • Parsing picks zlib when offered (even after unsupported IDs), accepts lists with no supported algorithm, and rejects malformed lists.
  • Size and write passes agree, and the exact wire bytes are emitted in ClientHello and CertificateRequest.
  • The extension is allowed only in ClientHello and CertificateRequest.

Handshake tests (test_tls13_cert_compression.c, new)

  • roundTrip: server-auth and mutual-auth handshakes, with a size check showing compression was actually used.
  • turnoff: setting the algorithm list to NULL disables the extension at the CTX or SSL level, and it can be re-enabled.
  • fragment: CompressedCertificate split across records via max_fragment_length, with WANT_WRITE injected at every write.
  • dtls13: the same coverage over DTLS 1.3.
  • pha: the reply to a post-handshake CertificateRequest is compressed.
  • malformed: each header field is broken in turn, checking the expected error and alert (illegal_parameter / bad_certificate).
  • fallback: when compression fails to allocate, a plain Certificate is sent instead, and OCSP staples are kept.

tests/quic.c now treats compressed_certificate as a Certificate record.

Docs

all public docs are updated and added for new funcs

Copilot AI balanced review requested due to automatic review settings September 30, 2026 22:04

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

A supported build configuration fails to compile, and one protocol error path sends the wrong RFC-mandated alert.

Review effort: Balanced
Findings: 1 High severity · 1 Medium severity

Open (2)
What changed in this PR

Adds RFC 8879 certificate compression for TLS/DTLS 1.3 using zlib.

Changes:

  • Adds certificate-compression negotiation, APIs, message handling, and lifecycle management.
  • Introduces reusable compression-data APIs and documentation.
  • Adds extensive TLS, DTLS, QUIC, parser, fragmentation, and fallback tests.
File Description
wolfssl/​wolfcrypt/​compress.h Defines compression algorithms and data APIs.
wolfssl/​ssl.h Exposes certificate-compression configuration APIs.
wolfssl/​internal.h Adds protocol constants and internal state.
wolfcrypt/​src/​compress.c Implements compression-data operations.
src/​tls13.c Implements compressed certificate send/receive handling.
src/​tls.c Implements extension negotiation and serialization.
src/​ssl.c Resets compression state on reuse.
src/​internal.c Manages compression resources and message validation.
src/​dtls13.c Supports compressed certificates in DTLS 1.3.
tests/​quic.c Recognizes compressed certificates in QUIC tests.
tests/​api/​test_tls13_cert_compression.h Declares certificate-compression tests.
tests/​api/​test_tls13_cert_compression.c Tests negotiation, malformed input, fragmentation, and fallback.
tests/​api/​test_tls_parse.h Registers extension parser tests.
tests/​api/​test_tls_parse.c Tests extension parsing and writing.
tests/​api/​test_tls_msgtype.h Registers message-type tests.
tests/​api/​test_tls_msgtype.c Tests extension placement restrictions.
tests/​api/​test_compress.h Registers compression-data tests.
tests/​api/​test_compress.c Tests compression-data APIs.
tests/​api/​include.am Adds new tests to Autotools.
tests/​api.c Registers the new test suite.
doc/​dox_comments/​header_files/​ssl.h Documents TLS configuration APIs.
doc/​dox_comments/​header_files/​compress.h Documents compression-data APIs.
configure.ac Adds the Autotools feature option.
CMakeLists.txt Adds the CMake feature option and tests.
cmake/​options.h.in Exposes the generated feature macro.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread wolfcrypt/src/compress.c
Comment thread src/tls13.c

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

RFC duplicate handling, user-settings prerequisites, and split read/write PHA state propagation remain incomplete.

Review effort: Balanced
Findings: 1 High severity · 2 Medium severity

Open (3)
Resolved since last review (2)

Comment thread wolfssl/internal.h Outdated
Comment thread src/tls.c
Comment thread src/tls13.c

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #11615

Scan targets checked: wolfcrypt-src, wolfcrypt-bugs, wolfssl-src, wolfssl-bugs
Coverage: 9 of 16 in-scope changed file(s) opened by the reviewer; not opened: src/dtls13.c, src/ssl_api_hs.c, tests/api.c, tests/api/test_compress.c, tests/quic.c, wolfssl/internal.h, wolfssl/ssl.h

Fenrir result: Approved ✅

No new issues found in the changed files.

Advisory only — this automated result does not count as a GitHub approval.

Review tier: Lite

@aidankeefe2022
aidankeefe2022 marked this pull request as ready for review October 1, 2026 17:53
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

retest this please

@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

MemBrowse Memory Report

gcc-arm-cortex-m3

  • FLASH: .text +8 B (+0.0%, 127,953 B / 262,144 B, total: 49% used)

gcc-arm-cortex-m4-dtls13

  • FLASH: .text -192 B (-0.1%, 190,916 B / 1,048,576 B, total: 18% used)

gcc-arm-cortex-m4-openssl-compat

  • FLASH: .text -256 B (-0.0%, 788,892 B / 1,048,576 B, total: 75% used)

gcc-arm-cortex-m4-pq

  • FLASH: .text -256 B (-0.1%, 306,800 B / 1,048,576 B, total: 29% used)

gcc-arm-cortex-m4-rsa-only

  • FLASH: .text -192 B (-0.1%, 337,008 B / 1,048,576 B, total: 32% used)

gcc-arm-cortex-m4-tls13

  • FLASH: .text -256 B (-0.1%, 245,726 B / 262,144 B, total: 94% used)

gcc-arm-cortex-m7

  • FLASH: .text +64 B (+0.0%, 206,700 B / 262,144 B, total: 79% used)

gcc-arm-cortex-m7-pq

  • FLASH: .text -256 B (-0.1%, 307,760 B / 1,048,576 B, total: 29% used)

gcc-arm-cortex-m7-tls13

Checkpoint of the compress_certificate work:
- compress_certificate extension: build options, parsing, and offering it
  in ClientHello and in CertificateRequest.
- Receiving CompressedCertificate: decompress with zlib, enforce the size
  limit and exact uncompressed length, send bad_certificate alerts, keep
  the buffer across async/non-blocking OCSP re-entry.
- wc_CompressionData helpers in wolfCrypt.
- Split the TLS 1.3 Certificate body writing into WriteTls13CertHeader and
  WriteTls13CertEntries, which write into any buffer.
- Fix AddCertExt writing an empty extension one byte past the fragment
  when a record boundary falls inside it.
- Unit tests, and OpenSSL interop script cert-compression-interop.sh.

Sending compressed certificates is not implemented yet.
Cert Compression is now impl.

Also changes compress cert api
Need to look at multi thread tests and all tests in general

Move compressed cert cache to cert-compression-cache branch

Remove the per-CTX compressed Certificate cache (isCacheReady,
cachedCertMsg, compressedCertCache, usingCompressedCertCache) and its
threaded test. Each connection compresses its own Certificate again.
The cache work continues on the cert-compression-cache branch.

fixed testing for compression

Removed all compression extensions and cache

Added docs to compression API

skoll fixes and more testing + setters

skoll review

reverted accidental reformat

finished

codespell
@aidankeefe2022 aidankeefe2022 self-assigned this Oct 1, 2026
@aidankeefe2022 aidankeefe2022 changed the title Cert compression Feat: TLS 1.3 certificate compression Oct 1, 2026
@padelsbach

Copy link
Copy Markdown
Contributor

jenkins retest this please

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants