[Plants] An independent Rust implementation of the -07 formats, interop-tested against demo/

Angel <angeltoranzoportela@gmail.com> Wed, 30 September 2026 14:06 UTC

Received: by mx.ietf.org (Postfix) id 27A9A42 for <plants@ietf.org>; Wed, 30 Sep 2026 14:06:04 +0000 (UTC)
Received: by mail-oo2-x2a.google.com with SMTP id 46e09a7af769-81bea216172so2292018a34.0 for <plants@ietf.org>; Wed, 30 Sep 2026 07:03:08 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1790776981; cv=none; d=google.com; s=arc-20260327; b=dN3NcjJjNVHAxj3WEhKDpN/WJsdtzKq2eduOVtgqdHPwSXebE6OMqfK6wrB/mBTAzU DQfz36nguI8S+qnjjc3Z3MiDXOrenjb3OYNHc/lkzs/pgadZZ31IsTxwDMyZhFHUyS7T rnNdQqNi7RinaiozmjY9pSs6rtpVj7VjCj/6nharyT/+DCt9I1XLRanFyfMswdtSdCnQ PkTLLXWdN3IEhqzY335udXE03U8HCUpskMAT2ps3WFqIkORfRM2PK2JN8GqM35lCqRdm /fBI8gRImqge38zkb8m//4EeGvxBXwRQ+e9qqKcgULBIbYCmpXKJhTctyY1NpMwfIbjF 50RQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=content-transfer-encoding:to:subject:message-id:date:from :mime-version:dkim-signature; bh=IfpUS5BsVIJ9140+T9Okn1MAF/6m4ReZL0AOKlEJXcs=; fh=sBcTFEJY+T6D2ut3P6DYkXFMfKEvdIpHeUYz5bx6baE=; b=JQ1mu5BIClGgwCCL6kcvMjsRFTmT8wZ6fqb95X+OcS6WkWRAkI9nRQI0I0seAVEjeQ ONqSCnf+2XMpQe8iC4hUm/Hd2sl5So30TN0F4ZLuMQtdbIQRuKIJiMU0jOZwUIKF9YYB URHF3o+Ak7hPKi1+hw+CCOArO30pw4Wtmhz9CTBjA+Bz7hcw3iGmgGnpIkSDvU6Fm89M 9TGRPX9GBIIg12gqXFNahoWue7IAWxFBOSUzIn1+AHonIEpGgs60sLegp/lRRtD8R2s3 fduWynCb7BVmLXuf6+7mJek/saLPkz/1HjMQjfvAP5pqtsAQ4ryAvCiXhjAEWQyMUfgw 3+LA==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790776981; x=1791381781; darn=ietf.org; h=content-transfer-encoding:content-type:to:subject:message-id:date :from:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=IfpUS5BsVIJ9140+T9Okn1MAF/6m4ReZL0AOKlEJXcs=; b=G5NUjORl/2M7iacUtZcDIVMIXVx8Xdnxr9ZwUrX+MW5CtiaBRXKsKMTyUgcGJo+kUw BW+Oblc6/25cQfD/a2GRIr3ti8+Qmp4e6D+L9KsQcSVFuw6E33V4XE0oGW20/QZ5j41z RJs11jGnyMrQChTGBPO5nAE56VOfhzaFtgZkkYYeACaYKGiNdSxrgjpDbtKweDOxtc97 GUKK1t/9zrBZ/6ijm6FJPfixnle+Y+pdu45Tlqr6mN0Y5lp+FV6ayKfxVauPV0VuIsir JVsGT/vLxIAluMHmGz4A1YCn/arNE4JSczDYXE8T0ALlOQ37Qq7gIqN9mLoWxXV0RUq0 UUIg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790776981; x=1791381781; h=content-transfer-encoding:content-type:to:subject:message-id:date :from:mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=IfpUS5BsVIJ9140+T9Okn1MAF/6m4ReZL0AOKlEJXcs=; b=osrPq5SBCwNSen6QwyOuRAkjJSXdY+lLKwrGlai7hTivymMJzXEM1d44ekRIwOS6Pz Idpa7sqJREbeGFsAM6v1eBvZvmyoL6MWadeokFpq7koARKHKkrgxOmtPMTP0RTPoTr1T s/LKoo/O2bnOMBUhFcvfggrKTCMoHkOEBh4i99kZWmjpbW0AdMNIxmrFPQgkZOT3YX0P RMIKR+Cuu9Lp4IMmVrqzRxwwWHPOeNclyDu8OOA3XHyibHwoqW964wqO4UkWNF73Ovoz lUjNbwVbqD6GYTKG58pbkStqA988PFB6Q2SiZu++nwUEFfdMoGdNOow3Li2Oi6Eewmzm uBiA==
X-Gm-Message-State: AFuF++l9REb+fRttj0NuaPvi4cnDS/HNDEDklkvZUh1PGEMvwup9wR1B n4XnGQYEhJTbJR1cUy9cRaEzFTwMHq+Hg6Nhw3FGGlRrxKQSRXVRJPjrdL0HQ3Z35bjBYRktDiX Zm60wseG2a1Gn4qIiQrdihS9HjIhrZiL/o/il
X-Gm-Gg: AYBFou3JyvFrKCpovn7V4sxbvg6y5E482AQYr3cWFbpDg7B4OLzpv3x01cD7UjfvHF2 d+SkXu/mljz0T44TAkx02KEywmIXJjZhLwEwUJ/z+EShKHE+bye16aCHFvMRxdHBJue0IiBhJ0J NyiVehpNUVkff683suSHo6kaKtM561DT/kxHEivUY3yYoFnXNczmYQAbE0RqwBqBjxOpaBse94B 5GZrA5QTnm99QZNaJtuSG5M4Pp+taISsYZAlHU2A5tCIMRHxGzJ0G08ssTnG6ySjRRxe154Kf2U OLw3B73SKdJIPRNP0S5qehmao8J/1MoKucOVE06kQeG10BMWVh8Pk5ADjFSGWbyVllCeDFIeaKO AZMbHYZSK
X-Received: by 2002:a05:6820:290b:b0:6d8:59ed:bbd6 with SMTP id 006d021491bc7-6dcf74ff811mr1315113eaf.88.1790776981213; Wed, 30 Sep 2026 07:03:01 -0700 (PDT)
MIME-Version: 1.0
From: Angel <angeltoranzoportela@gmail.com>
Date: Wed, 30 Sep 2026 16:02:50 +0200
X-Gm-Features: AclHuK9Qke5qgKx0jF0uDUeR5-A55TSrC2cqrBiqIqXU7uzkgjftTbytXrqmOLA
Message-ID: <CANetTsm3iVV7L7A57iJiEknAJBV37E8e=_cvo+N4K8=FS7JW+g@mail.gmail.com>
To: plants@ietf.org
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Message-ID-Hash: LCF63JSRYTO3UI5PO7HLWY64MA3FB6ZD
X-Message-ID-Hash: LCF63JSRYTO3UI5PO7HLWY64MA3FB6ZD
X-MailFrom: angeltoranzoportela@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.10
Precedence: list
Subject: [Plants] An independent Rust implementation of the -07 formats, interop-tested against demo/
List-Id: "PKI, Logs, And Tree Signatures" <plants.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/plants/Tp4GXZGJRoZaUjhPlvJady2nB3Y>
List-Archive: <https://mailarchive.ietf.org/arch/browse/plants>
List-Help: <mailto:plants-request@ietf.org?subject=help>
List-Owner: <mailto:plants-owner@ietf.org>
List-Post: <mailto:plants@ietf.org>
List-Subscribe: <mailto:plants-join@ietf.org>
List-Unsubscribe: <mailto:plants-leave@ietf.org>

Hi all,

I'd like to report an independent implementation of the current
draft-ietf-plants-merkle-tree-certs formats and the results of testing it
against the reference implementation in the working group's repository.

What it is: mtc-core, <https://github.com/atoranzo/mtc-core>, MIT OR
Apache-2.0. It implements the issuance log (RFC 9162 MTH over SHA-256,
subtrees, inclusion and consistency proofs), MTCLogEntry /
TBSCertificateLogEntry, the CosignedMessage and subtree signatures with
ML-DSA (44/65/87), MTCProof and the certificate, the landmark sequence, the
CA flow (log, checkpoint, covering subtrees, cosignatures, standalone and
landmark-relative certificates), the CA certificate with the
MTCCertificationAuthority extension (unsigned, RFC 9925), and the relying
party's verification procedure including the single-pass entry hash. It
targets the working repository as of 2026-09-29, i.e. the OIDs
draft_oids.md assigns to plants-07 (id-alg-mtcProof = ...47.5).

What was tested:

- The four accumulated test vectors (65,058 cases, trees up to 130 leaves)
  and the large subtree vectors (2^48-1, 2^63-1, 2^64-1 leaves).
- Against demo/ at commit 99097c9e (Go 1.27.1), in both directions, with
  negatives: the 26 certificates demo generates from its own mtc.json
  (plants-07) get the same 26 verdicts from my verifier as from
  `demo verify` (21 OK, 5 FAIL, each negative failing for the reason it was
  built for); 9 certificates from my CA (4 deliberately broken) get the
  expected verdicts from `demo verify`, with my CA certificate and with
  demo's own (both CAs use demo's ML-DSA-44 test seed for 32473.1, so key
  generation and signatures were compared byte for byte); and demo's log of
  2122 entries rebuilt from its entry tiles reproduces its checkpoint root.
  The procedure and script are in the repository (interop/), and the run
  is recorded in AUDIT.md.

If a documented run between two independent codebases is useful for the
working group's interoperability milestone, everything above is
reproducible from the repository with the commands in interop/README.md.

Two things I noticed in demo/, filed as issues #341 and #342: the
checkpoint's signature lines carry a bare subtree signature with timestamp
zero rather than a tlog-cosignature timestamped_signature, which mtc-tlog
seems to require; and the sample policy.txt's trusted-subtree hashes do not
match the output of the shipped mtc.json, so the demo rejects its own
landmark-relative certificates with the sample policy.

What it is not: it is not audited; cosigners with ECDSA or Ed25519 keys are
not verified (their cosignatures are ignored); the relying-party policy is
the minimal "the CA plus a fixed set of cosigners", with no groups; the log
is not persisted and there is no ACME, CSR parsing or witness client; it is
not measured at scale. Interoperability is measured against one
implementation only.

Provenance: the code and prose were written with AI assistance; GENAI.md
in the repository says how it was used and AUDIT.md records each verified
change with its counters. I am the only author and accountable for it.

I'm aware of the Note Well. Corrections and questions very welcome,
especially on the two issues above.

Ángel Toranzo Portela