boring 0.3.0
boring: ^0.3.0 copied to clipboard
High-performance cryptography and PKI powered by BoringSSL with Dart Native Assets.
0.3.0 #
Expanded cryptographic primitives to match modern native application and
package:webcrypto capabilities:
- X25519 Key Agreement: Added
BoringX25519(generateKeyPair,publicKeyFromPrivate,computeSharedSecret),KeyType.x25519,BoringPrivateKey.generateX25519(), andderiveSharedSecret/deriveBitssupport for X25519 keys. - Constant-Time Verification: Added
BoringCrypto.timingSafeEqual(wrappingCRYPTO_memcmp),BoringHmac.verify, andBoringHmac.verifyStream. - Key Generation & Raw Key Import/Export: Added
BoringPrivateKey.generateEd25519(),BoringPrivateKey.fromRawKey(),BoringPublicKey.fromRawKey(), and.toRawBytes()for 32-byte Ed25519/X25519 keys, plus optionalpasswordsupport onBoringPrivateKey.fromPemandtoPemfor encrypted PKCS#8 PEM keys. Also allowedBoringEd25519.signto accept a 32-byte seed directly. - PBKDF2: Added
BoringPbkdf2.deriveBitsandderiveKeyfor password-based key derivation (RFC 2898 / PKCS #5 v2.0) across all supported hash algorithms. - Symmetric Ciphers (AES-CBC & AES-CTR): Added
BoringCipherandCipherAlgorithmsupporting AES-128/192/256 in CBC mode (with PKCS#7 padding) and CTR mode (standard 128-bit counter stream). - AES Key Wrap: Added
BoringAesKeyWrap.wrapandunwrapfor RFC 3394 / NIST SP 800-38F key wrapping. - RSA-PSS: Added Probabilistic Signature Scheme support to
BoringPrivateKey.signandBoringPublicKey.verifyviaRsaSignaturePadding.pssand configurablepssSaltLength. - RSA-OAEP: Added
BoringPublicKey.encryptOaepandBoringPrivateKey.decryptOaepfor RFC 8017 asymmetric encryption with configurable OAEP hash, MGF1 hash, and optional labels. - ECDH Key Agreement: Added
BoringPrivateKey.deriveSharedSecretandderiveBitsfor elliptic-curve Diffie-Hellman key agreement across P-256, P-384, and P-521. - Streaming APIs: Added stream-based operations:
BoringDigest.hashStreamandsha1Stream/sha224Stream/sha256Stream/sha384Stream/sha512Stream/blake2b256Stream.BoringHmac.computeStream,verifyStream, andsha256Stream/sha384Stream/sha512Stream.BoringPrivateKey.signStreamandBoringPublicKey.verifyStreamfor RSA, ECDSA, and Ed25519.
- Deterministic Disposal & Memory Cleansing: Added
.dispose()toBoringPrivateKey,BoringPublicKey,X509Certificate,X509Verifier,DigestContext, andHmacContext, and ensured ephemeral secret buffers in FFI arenas are scrubbed viaOPENSSL_cleansebefore deallocation. - Wycheproof Conformance: Added conformance test suites for AES-CBC, AES Key Wrap, PBKDF2, RSA-PSS, RSA-OAEP, and ECDH.
X509Verifier can now check peer identity, key usage and chain length, and the
package is validated against the x509-limbo path
validation suite.
- Breaking:
X509Certificate.keyUsagenow returnsint?(nullwhen the certificate does not carry akeyUsageextension) instead of0xFFFFFFFF. X509Certificategainedsha256Fingerprint,authorityKeyIdentifier,signatureAlgorithm(OID), andsignatureAlgorithmName.X509VerifiergainedaddTrustedCertificatesandaddTrustedCertificatesPem.X509Verifier.verifygained seven options:peerNames: names the leaf must assert, asX509PeerName.dnsName,X509PeerName.ipAddressorX509PeerName.emailAddress. Several DNS names are matched with OR semantics.hostnameFlags:X509HostnameFlag.neverCheckSubject(the default, which suppresses BoringSSL's legacy subject common name fallback) andX509HostnameFlag.noWildcards.purpose: anX509Purposeenabling key usage and extended key usage checks, e.g.X509Purpose.tlsServer.maxIntermediates: a chain length limit, excluding leaf and trust anchor.insecurelyAllowWeakSignatureDigests: opts out of the weak digest rejection described below.insecurelyAllowWeakKeysandminimumRsaKeyBits: opt out of, and tune, the key strength rejection described below.
- Behaviour change:
X509Verifier.verifynow rejects a chain containing a certificate signed with MD4, MD5 or SHA-1.X509_verify_certapplies no signature algorithm policy of its own — BoringSSL has neither OpenSSL'sX509_VERIFY_PARAM_set_auth_levelnor itsset1_sigalgs— so the verified chain is walked afterwards. The trust anchor is exempt, since its self-signature is never verified. PassinsecurelyAllowWeakSignatureDigests: trueto restore the old behaviour. - Behaviour change: the same walk now also rejects weak public keys: RSA
below
minimumRsaKeyBits(2048 by default, as the CA/Browser Forum baseline requirements demand), EC on any curve other than P-256, P-384 and P-521, DSA, and keys BoringSSL cannot decode at all such as P-192. Unlike the digest check this includes the trust anchor, whose key signs the certificate below it. Ed25519, ML-DSA and future algorithms are deliberately left alone rather than rejected as unrecognised. PassinsecurelyAllowWeakKeys: trueto restore the old behaviour. X509VerificationResultgainederrorDepth, the position in the chain at which verification failed.- Added the x509-limbo conformance suite (
./tool/run_x509_limbo_tests.sh), covering 9,770 chain building and validation testcases. 94.5% agree with the suite; the remainder are listed with an explanation intest/conformance/x509_limbo_expected_failures.txt.
This release also removes hand-written parsing logic from the Dart layer. Every
ASN.1 operation is now delegated to BoringSSL, keeping package:boring a thin
wrapper rather than a reimplementation.
- Breaking:
Asn1Value.identifier(the raw DER identifier octet) is replaced byAsn1Value.tag, which holds BoringSSL'sCBS_ASN1_TAG. UsetagClass,isConstructed, andtagNumberinstead of decoding it by hand. - Breaking: the
Asn1Valueconstructor is now private; values are produced byAsn1Reader. - The DER reader is now backed by BoringSSL's
CBSparser:- Tag/length parsing uses
CBS_get_any_asn1_element. asObjectIdentifier()usesCBS_asn1_oid_to_text.asInteger()usesCBS_is_valid_asn1_integerwithBN_bin2bn/BN_bn2dec.asBoolean()usesCBS_get_asn1_bool.asString()usesASN1_STRING_to_UTF8, which correctly transcodes every ASN.1 string type BoringSSL supports.Asn1TagandAsn1Classnow re-export BoringSSL'sCBS_ASN1_*constants.- As a result, DER encoding rules are enforced by BoringSSL: non-minimal
long-form lengths and non-minimal
INTEGERencodings are now rejected.
- Tag/length parsing uses
Asn1Value.asString()accepts an optionalstringTypefor IMPLICIT context-specific tags, where the tag number identifies theCHOICEalternative rather than the underlying string type.- Certificate validity times are parsed with
ASN1_TIME_to_posixinstead of slicing theGeneralizedTimestring in Dart. - Fixed
X509Extension.stringValuemangling non-ASCII values in the raw (non-DER) fallback path, which decoded UTF-8 bytes as UTF-16 code units. - Internal: the repeated FFI marshalling patterns are now shared combinators
(
withResource,withOutputBuffer,withSizedOutput,takeOwnedString,withMemBioString,withMemBufBio), removing every hand-writtentry/finallyaround a BoringSSLX_new/X_freepair and the duplicated BIO-to-string reader. This also fixes a latent bug in that reader, which decoded UTF-8 in fixed 1 KiB chunks and could split a multi-byte sequence across a chunk boundary.
0.2.0 #
- Added a minimal ASN.1 DER reader (
package:boring/asn1.dart) for decoding the application-specific payloads of X.509 extensions:Asn1Reader,Asn1Value,Asn1Class,Asn1Tag, andAsn1Exception.- Decodes strings, integers, booleans, object identifiers, and nested constructed elements, including long-form lengths and context-specific tags.
- Added X.509 v3 extension support to
X509Certificate:extensionsenumerates every extension with its OID, short name, criticality, and raw DER payload.getExtension(oid)andgetExtensionString(oid)look up an extension by dotted-decimal OID, transparently unwrapping DER-encoded ASN.1 strings and falling back to raw UTF-8 payloads.subjectAlternativeNamesandissuerAlternativeNamesdecodeGeneralNameentries, withemailAddresses,dnsNames, andurisconvenience getters.keyUsage,extendedKeyUsage,isCertificateAuthority, andsubjectKeyIdentifier.
- Added
X509Oidconstants for standard X.509 extensions, Certificate Transparency SCTs, and all Sigstore Fulcio OIDC extensions (1.3.6.1.4.1.57264.1.*), plusKeyUsagebit constants. - Added a Project Wycheproof conformance test suite (
tool/run_conformance_tests.sh) covering AEAD, Ed25519, ECDSA, RSA, HKDF, and HMAC. - Added GitHub Actions CI running formatting, analysis, unit tests, and the conformance suite.
0.1.0 #
- Initial release of
package:boring. - High-performance cryptography and PKI powered by BoringSSL with Dart Native Assets.
- Isolated symbols with
bssl_dartprefix to guarantee 100% collision-free execution alongside Flutter and Dart VM internal BoringSSL. - Cryptographic primitives:
- CSPRNG (
BoringRand.secureRandom) - Digests (
BoringDigest: SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, streamingDigestContext) - HMAC (
BoringHmac: SHA-256, SHA-384, SHA-512, streamingHmacContext) - HKDF (
BoringHkdf: extract, expand, deriveBits) - AEAD (
BoringAead: AES-128-GCM, AES-256-GCM, ChaCha20-Poly1305, XChaCha20-Poly1305) - Ed25519 (
BoringEd25519: keypair generation, sign, verify) - Asymmetric Keys (
BoringPrivateKey,BoringPublicKey: RSA, ECDSA P-256/P-384/P-521, PKCS#8 & SPKI DER/PEM)
- CSPRNG (
- PKI & X.509:
- Certificate parsing (
X509Certificate: DER and PEM, metadata getters, public key extraction) - Chain verification (
X509Verifier: trust store management, intermediate chain resolution, time-based verification)
- Certificate parsing (