Page MenuHomeVyOS Platform

Support ED25519 and ED448 signatures on public keys in VyOS PKI
Closed, ResolvedPublicFEATURE REQUEST

Description

Letsencrypt started signing their CA certificates (current Root YE and intermediates YE1 and YE1) with ED25519 and ED448, neither of which are supported in VyOS PKI, so importing those new LE CA's into the VyOS PKI is impossible, which makes impossible using LE-issued certificates on the HAPROXY loadbalancer.

This impacts production, currently we have patched pki.py on our routers, but I reckon it needs a more permanent fix.

The fix is simple and goes into pki.py:

def verify_certificate(cert, ca_cert):
    # Verify certificate was signed by specified CA
    if ca_cert.subject != cert.issuer:
        return False

    ca_public_key = ca_cert.public_key()
    try:
        if isinstance(ca_public_key, rsa.RSAPublicKeyWithSerialization):
            ca_public_key.verify(
                cert.signature,
                cert.tbs_certificate_bytes,
                padding=padding.PKCS1v15(),
                algorithm=cert.signature_hash_algorithm)
        elif isinstance(ca_public_key, dsa.DSAPublicKeyWithSerialization):
            ca_public_key.verify(
                cert.signature,
                cert.tbs_certificate_bytes,
                algorithm=cert.signature_hash_algorithm)
        elif isinstance(ca_public_key, ec.EllipticCurvePublicKeyWithSerialization):
            ca_public_key.verify(
                cert.signature,
                cert.tbs_certificate_bytes,
                signature_algorithm=ec.ECDSA(cert.signature_hash_algorithm))
        elif isinstance(ca_public_key, ed25519.Ed25519PublicKey):
            ca_public_key.verify(
                cert.signature,
                cert.tbs_certificate_bytes)
        elif isinstance(ca_public_key, ed448.Ed448PublicKey):
            ca_public_key.verify(
                cert.signature,
                cert.tbs_certificate_bytes)
        else:
            return False # We cannot verify it
        return True
    except InvalidSignature:
        return False

def verify_crl(crl, ca_cert):
    # Verify CRL was signed by specified CA
    if ca_cert.subject != crl.issuer:
        return False

    ca_public_key = ca_cert.public_key()
    try:
        if isinstance(ca_public_key, rsa.RSAPublicKeyWithSerialization):
            ca_public_key.verify(
                crl.signature,
                crl.tbs_certlist_bytes,
                padding=padding.PKCS1v15(),
                algorithm=crl.signature_hash_algorithm)
        elif isinstance(ca_public_key, dsa.DSAPublicKeyWithSerialization):
            ca_public_key.verify(
                crl.signature,
                crl.tbs_certlist_bytes,
                algorithm=crl.signature_hash_algorithm)
        elif isinstance(ca_public_key, ec.EllipticCurvePublicKeyWithSerialization):
            ca_public_key.verify(
                crl.signature,
                crl.tbs_certlist_bytes,
                signature_algorithm=ec.ECDSA(crl.signature_hash_algorithm))
        elif isinstance(ca_public_key, ed25519.Ed25519PublicKey):
            ca_public_key.verify(
                crl.signature,
                crl.tbs_certlist_bytes)
        elif isinstance(ca_public_key, ed448.Ed448PublicKey):
            ca_public_key.verify(
                crl.signature,
                crl.tbs_certlist_bytes)
        else:
            return False # We cannot verify it
        return True
    except InvalidSignature:
        return False

Details

Version
-
Is it a breaking change?
Perfectly compatible
Issue type
Bug (incorrect behavior)

Event Timeline

ebowsky triaged this task as High priority.
ebowsky created this object in space S1 VyOS Public.
Viacheslav changed the subtype of this task from "Task" to "Feature Request".Aug 18 2026, 11:14 AM
Viacheslav subscribed.

@ebowsky would you like to claim the task and add a PR?

Hey @Viacheslav, sure, why not, give me a couple of days.

Viacheslav changed the task status from Open to In progress.Aug 19 2026, 1:04 PM
Viacheslav assigned this task to ebowsky.
Viacheslav moved this task from Need Triage to Completed on the VyOS Rolling board.