Skip to content

Added support for EC keys - #38

Open
deltadecay wants to merge 5 commits into
JuliaWeb:mainfrom
deltadecay:main
Open

deltadecay wants to merge 5 commits into
JuliaWeb:mainfrom
deltadecay:main

Conversation

@deltadecay

Copy link
Copy Markdown

Hello,
I've added support for EC key pairs and method to generate one from builtin curve id or name.

Example:

using OpenSSL
#curves = ec_builtin_curves()

eckey = EvpPKey(ec_generate_key("secp256k1"))

@codecov

codecov Bot commented Dec 1, 2025 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 92.72727% with 4 lines in your changes missing coverage. Please review.
✅ Project coverage is 75.57%. Comparing base (10f7b7b) to head (f7a7465).
⚠️ Report is 27 commits behind head on main.

Files with missing lines Patch % Lines
src/OpenSSL.jl 92.72% 4 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main      #38      +/-   ##
==========================================
- Coverage   77.56%   75.57%   -1.99%     
==========================================
  Files           2        2              
  Lines        1083     1175      +92     
==========================================
+ Hits          840      888      +48     
- Misses        243      287      +44     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@aviks

aviks commented Dec 2, 2025

Copy link
Copy Markdown
Member

So this fails for our integration tests with OpenSSL v1.x -- can you address those somehow?

@deltadecay

Copy link
Copy Markdown
Author

The integration tests pass now, but not codecov. Any recommendations how to write tests that check failure of the ccalls?

@aviks

aviks commented Dec 10, 2025

Copy link
Copy Markdown
Member

Eh, if the patch coverage is better than project coverage, I think it can be merged. I'll take a closer look tonight.

EC_KEY_new_by_curve_name only sets the curve; without EC_KEY_generate_key
the key had no private or public key and could not sign anything.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@quinnj

quinnj commented Sep 30, 2026

Copy link
Copy Markdown
Member

Thanks @deltadecay, and sorry for the long wait. I pushed one fix and one change on top:

  • Key generation: EC_KEY_new_by_curve_name only sets the curve. Without EC_KEY_generate_key, ec_generate_key returned a key with no private or public part (EC_KEY_check_key returned 0), so it couldn't sign anything. It now generates the pair, and the test checks that the key is valid and can sign a self-signed certificate.
  • Exports: the new names (EC, ECBuiltinCurve, ec_generate_key, ec_builtin_curves) are no longer exported. We're keeping the export list from growing, so use them as OpenSSL.ec_generate_key(...).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants