Skip to content

[Security]: X3DHKeyManager.verifyBundle doesn't verify signed-prekey signature #1405

Description

In \packages/agent-mesh/sdks/typescript/src/encryption/x3dh.ts, \�erifyBundle()\ only checks field lengths — it does NOT perform Ed25519 signature verification on the signed prekey.

Additionally, \PreKeyBundle\ schema doesn't include the Ed25519 identity key needed for verification (only has X25519 key).

Fix needed:

  1. Add \identityKeyEd\ (Ed25519 public key) to PreKeyBundle schema
  2. Call \�d25519.verify(sig, signedPreKey, identityKeyEd)\ in verifyBundle()

This is a real crypto-binding regression vs the vendored SDK.

Ref: Azure/kars#27 review (blocker #6)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    securitySecurity-related issues

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions