Skip to content

feat: add numbered cnsa2 interop policies#5905

Open
CarolYeh910 wants to merge 2 commits into
aws:mainfrom
CarolYeh910:interop_policies
Open

feat: add numbered cnsa2 interop policies#5905
CarolYeh910 wants to merge 2 commits into
aws:mainfrom
CarolYeh910:interop_policies

Conversation

@CarolYeh910

@CarolYeh910 CarolYeh910 commented Jun 4, 2026

Copy link
Copy Markdown
Contributor

Goal

Add numbered CNSA 2.0 interop policies to support the CNSA 1.0→2.0 transition.

Why

How

  • Add policy 20260513: TLS 1.3 only with ML-KEM-1024 + ML-DSA-87, based on 20250414 with broad signature support.
  • Add signature preferences 20260513 and certificate signature preferences 20260514.
  • Register 20260219, 20260220, 20260513 by their numbered names in the policy selection table.
  • Upload policy snapshots for all three.

Callouts

Testing

Added compatibility tests: 20250414 → 20260513 with P-256 and P-384 certs; 20260513 → 20260513 with ML-DSA-87 certs.

Related

#5760

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

@github-actions github-actions Bot added the s2n-core team label Jun 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant