[API Proposal]: Export Keying Material for TLS sessions
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 38/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- csharp
- Domain
- api, networking, security
Research direction
Start with the SslStream entry point and RFC 5705, then review the Windows Schannel and Linux OpenSSL references named in the issue. Determine how the proposed overloads map to the listed platform support, including Secure Transport on macOS. Done means the API behavior and platform availability are implemented and validated consistently.
Written by the indexing model from the issue text.
Description
Background and motivation
Add an API that exposes the functionality outlined in RFC 5705: Keying Material Exporters.
This is useful as it will allow my company to drop an external library to use this functionality.
API Proposal
updated by @rzikm
namespace System.Net.Security;
public partial class SslStream {
public void ExportKeyingMaterial(string label, Span<byte>output);
public void ExportKeyingMaterial(string label, ReadOnlySpan<byte> context, Span<byte> output);
}
API Usage
await using var sslStream = new SslStream(someStream, true);
// Initialize and finish SSL handshake
await sslStream.AuthenticateAsServerAsync(...);
// or as client
// await sslStream.AuthenticateAsClientAsync(...);
// Use the export keying material API
byte[] keyingMaterial = new byte[128];
sslStream.ExportKeyingMaterial("showcase key", keyingMaterial);
Console.WriteLine(Convert.ToHexString(keyingMaterial));
Alternative proposal
Unless I am mistaken, the label string is supposed to be an ASCII string, so we can accept it as ROS
namespace System.Net.Security;
public partial class SslStream {
public void ExportKeyingMaterial(ReadOnlySpan<byte> label, Span<byte>output);
public void ExportKeyingMaterial(ReadOnlySpan<byte> label, ReadOnlySpan<byte> context, Span<byte> output);
}
API Usage
since labels are usually literal constants in code, UTF-8 string literals can be used
byte[] keyingMaterial = new byte[128];
sslStream.ExportKeyingMaterial("showcase key"u8, keyingMaterial);
Console.WriteLine(Convert.ToHexString(keyingMaterial));
Risks
Platform support:
- Windows - needs verification (should be implementable as per
https://learn.microsoft.com/en-us/windows/win32/api/schannel/ns-schannel-secpkgcontext_keyingmaterialinfo, https://learn.microsoft.com/en-us/windows/win32/secauthn/querycontextattributes--schannel, see SECPKG_ATTR_KEYING_MATERIAL) - Linux - implementable (https://docs.openssl.org/master/man3/SSL_export_keying_material/)
- OSX - Not implemented for Secure Transport (package used to back SslStream implementaion)
- Dominant language
- C#
- Stars
- 18.3k
- Forks
- 5.6k
- PR merge metrics
- PR metrics pending
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from dotnet/runtime
-
agentic-workflows untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
-
area-System.Reflection blocking-clean-ci-optional Known Build Error os-mac-os-x untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
-
area-CodeGen-coreclr untriaged
Difficulty 1/5 Under an hour Newbie friendliness 92/100
-
agentic-workflows untriaged
Difficulty 1/5 Under an hour Newbie friendliness 78/100
-
area-VM-meta-mono untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
-
:watch: Not Triaged 11.0 fundamentals/subsvc
Difficulty 2/5 1-3 hours Newbie friendliness 92/100
dotnet/AspNetCore.Docs#37699 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
SubtitleEdit/subtitleedit#15108 · 1 comment ·
-
area/docs-content Bug pulumi/docs
Difficulty 1/5 1-3 hours Newbie friendliness 94/100
-
Create parent directories only after the containment check in InstallHelper.TryExtractToDirectory Open
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
PowerShell/PSResourceGet#2056 ·