From e32c84394839ae608bc32095a57559cceb6706d6 Mon Sep 17 00:00:00 2001 From: Max Inden Date: Tue, 22 Sep 2026 10:54:57 +0000 Subject: [PATCH 1/2] Adapt to nss-rs 0.16 API changes nss-rs 0.16 changes the public key key_data() accessor to return &[u8] instead of Vec, and drops the p11 re-export of AES_BLOCK_SIZE. Call .to_vec() at the two key_data() sites and use a literal AES block size (as the openssl backend already does). This builds against both older and newer nss-rs. --- src/crypto/nss.rs | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/src/crypto/nss.rs b/src/crypto/nss.rs index 394e305e..3e269ea0 100644 --- a/src/crypto/nss.rs +++ b/src/crypto/nss.rs @@ -8,7 +8,7 @@ use nss_rs::p11::{ }; // nss-rs exposes these as raw bindgen u32 constants; shadow as usize for ergonomic use. -const AES_BLOCK_SIZE: usize = nss_rs::p11::AES_BLOCK_SIZE as usize; +const AES_BLOCK_SIZE: usize = 16; const SHA256_LENGTH: usize = nss_rs::p11::SHA256_LENGTH as usize; use nss_rs::nss_prelude::PRBool; use nss_rs::{IntoResult, SECItem, SECItemBorrowed, ScopedSECItem}; @@ -109,7 +109,7 @@ pub fn gen_p256() -> Result<(Vec, Vec)> { pkcs8_priv_item.into_vec() }; - let sec1_pub = client_public.key_data()?; + let sec1_pub = client_public.key_data()?.to_vec(); Ok((pkcs8_priv, sec1_pub)) } @@ -165,7 +165,7 @@ pub fn ecdhe_p256_raw(peer: &super::COSEEC2Key) -> Result<(Vec, Vec)> { let shared_point = ecdh_nss_raw(client_private, peer_public)?; - Ok((shared_point, client_public.key_data()?)) + Ok((shared_point, client_public.key_data()?.to_vec())) } /// AES-256-CBC encryption for data that is a multiple of the AES block size (16 bytes) in length. From 14bbffe0fe90e6623ecadc865daa59060b2a431b Mon Sep 17 00:00:00 2001 From: Max Inden Date: Tue, 22 Sep 2026 10:54:57 +0000 Subject: [PATCH 2/2] Release 0.6.1 --- Cargo.toml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Cargo.toml b/Cargo.toml index 72c43010..33601a3c 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "authenticator" -version = "0.6.0" +version = "0.6.1" authors = [ "Dana Keeler ", "J.C. Jones ", "John Schanck ", "Kyle Machulis ", "Martin Sirringhaus " ] keywords = ["ctap2", "u2f", "fido", "webauthn"] categories = ["cryptography", "hardware-support", "os"]