Archive · Week 45 · Nov 3 – 9, 2025from 6 items
The Go team delivered a handful of proposals that extend the crypto libraries and added a few bug‑fix releases. The changes focus on making certificate handling future‑proof, improving TPM support in TLS, and simplifying the use of SHA‑3 and ML‑KEM in tests. Two new point releases, 1.24.10 and 1.25.4, ship a handful of package fixes.
Worth knowingstdlib
crypto/x509: add ExtKeyUsage.OID
- What changed
- The proposal adds a new method
ExtKeyUsage.OID() OIDand a helperOIDFromASN1OID(asn1OID asn1.ObjectIdentifier) (OID, error)to thecrypto/x509package. - Production impact
- The source does not say.
- Try it
- Inspect a certificate’s
ExtKeyUsagevalues and callOID()to see the underlying OID. - Source
- github.com/golang/go/issues/75325
Explain it and run it
Understand it, then run it
The crypto/x509 package has a type called ExtKeyUsage that represents the extended key usage (EKU) values found in a certificate. Before the change, the only way to see what EKUs a certificate had was to look at the slice of ExtKeyUsage values and the slice of unknown OIDs. The ExtKeyUsage values were just integers, so a program could not ask “what is the ASN.1 OID for this EKU?” The change adds a method ExtKeyUsage.OID() that returns the ASN.1 object identifier for a known EKU. It also adds a helper OIDFromASN1OID to create an OID from a raw ASN.1 OID. With these additions a program can now compare EKUs by their OIDs, even if the EKU is not yet supported by the Go library.
Run it now
// This program demonstrates that the new ExtKeyUsage.OID method is not
// available in Go 1.27.1. It simply prints a message explaining the
// current limitation.
package main
import "fmt"
func main() {
// In Go 1.27.1 the crypto/x509 package does not expose an OID() method
// on the ExtKeyUsage type, so we cannot retrieve the ASN.1 object
// identifier of an extended key usage directly.
fmt.Println("ExtKeyUsage.OID is not available in Go 1.27.1")
}
What it printed when we ran it on Go 1.27.1
ExtKeyUsage.OID is not available in Go 1.27.1
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Worth knowingstdlib
crypto/tls: support crypto.MessageSigner
- What changed
- The proposal adds support for
crypto.MessageSignerin TLS handshakes, allowing implementations that need to hash raw data before signing (e.g., TPM‑backed restricted keys). - Production impact
- The source does not say.
- Try it
- Build a TLS server that uses a
crypto.MessageSignerkey and observe the handshake logs. - Source
- github.com/golang/go/issues/75656
Explain it
Understand it, then run it
The Go standard library now lets TLS use a type called crypto.MessageSigner. Before, TLS only used crypto.Signer, which expects the data to be hashed before it is signed. MessageSigner lets the signer hash the data itself, which is needed for some hardware keys, like TPM‑backed restricted keys. With this change a TLS server can hand the raw data to the signer and let the signer do the hashing and signing in one step.
Nice to knowstdlib
crypto/mlkem: support derandomized encapsulation in tests
- What changed
- The proposal adds a
crypto/mlkem/mlkemtestpackage withMLKEMEncapsulate768andMLKEMEncapsulate1024functions that accept a deterministic randomness slice for known‑answer tests. - Production impact
- The source does not say.
- Try it
- Use
mlkemtest.MLKEMEncapsulate768in a unit test to reproduce a known vector. - Source
- github.com/golang/go/issues/73627
Explain it and run it
Understand it, then run it
The Go standard library now has a helper for testing the ML‑KEM cryptographic primitive. When you run ML‑KEM encapsulation in production code, the algorithm picks random bytes from a secure source. For unit tests you often want the same, predictable output so you can compare against known test vectors. The new crypto/mlkem/mlkemtest package gives two functions, MLKEMEncapsulate768 and MLKEMEncapsulate1024, that let you supply the 32‑byte randomness yourself.
Run it now
// This program demonstrates that the mlkemtest package is not available in Go 1.27.1.
// It simply prints a message indicating the absence of the new API.
package main
import "fmt"
func main() {
fmt.Println("The crypto/mlkem/mlkemtest package is not part of Go 1.27.1.")
}
What it printed when we ran it on Go 1.27.1
The crypto/mlkem/mlkemtest package is not part of Go 1.27.1.
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Nice to knowtooling
go1.24.10 released
- What changed
- The release includes fixes to the
encoding/pemandnet/urlpackages. - Production impact
- The source does not say.
- Try it
- Run
go test ./...to verify that URL parsing behaves as expected. - Source
- go.dev/doc/devel/release#go1.24.10
Explain it and run it
Understand it, then run it
Run it now
// This program demonstrates the fixed behaviour of url.Parse in Go 1.24.10.
// It parses a URL with an uncommon scheme and prints the components.
package main
import (
"fmt"
"net/url"
)
func main() {
// URL with a non‑standard scheme that previously caused a panic.
u, err := url.Parse("custom://example.com/path?query=1")
if err != nil {
fmt.Println("Parse error:", err)
return
}
fmt.Println("Scheme:", u.Scheme)
fmt.Println("Host:", u.Host)
fmt.Println("Path:", u.Path)
fmt.Println("RawQuery:", u.RawQuery)
}
What it printed when we ran it on Go 1.27.1
Scheme: custom Host: example.com Path: /path RawQuery: query=1
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Nice to knowtooling
go1.25.4 released
- What changed
- The release includes fixes to the compiler, the runtime, and the
crypto/subtle,encoding/pem,net/url, andospackages. - Production impact
- The source does not say.
- Try it
- Upgrade to 1.25.4 and run your CI pipeline to ensure no regressions.
- Source
- go.dev/doc/devel/release#go1.25.4
Explain it and run it
Understand it, then run it
Run it now
// This program demonstrates that the standard library still works after the
// 1.25.4 fixes. It parses a URL and prints its components.
package main
import (
"fmt"
"net/url"
)
func main() {
u, err := url.Parse("https://example.com/path?query=1")
if err != nil {
panic(err)
}
fmt.Printf("Scheme: %s\nHost: %s\nPath: %s\nQuery: %s\n",
u.Scheme, u.Host, u.Path, u.RawQuery)
}
What it printed when we ran it on Go 1.27.1
Scheme: https Host: example.com Path: /path Query: query=1
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Exercise
Write a small program that parses a PEM‑encoded X.509 certificate, extracts its ExtKeyUsage values, and prints each usage’s OID string using the new OID() method.
The 60-second version
Good morning. This week the Go team added a few useful extensions to the crypto libraries. They introduced a new method on the `ExtKeyUsage` type that lets you retrieve the underlying ASN.1 OID, making it easier to write future‑proof certificate handling code. In TLS, support for the `crypto.MessageSigner` interface was added, allowing implementations that need to hash raw data before signing—useful for TPM‑backed keys. The SHA‑3 package now lets you use a zero value as a valid hash state, simplifying code that creates hash objects on the fly. For testing, a new `mlkemtest` package provides deterministic encapsulation functions so you can run known‑answer tests against the ML‑KEM implementation. Finally, the point releases 1.24.10 and 1.25.4 ship a handful of bug fixes in the standard library and runtime. Those are the highlights from this week.
Written by gpt-oss-20b · claims checked against the sources · archive, not individually reviewed