wolfCOSE Adds COSE Countersignatures

wolfSSL is adding RFC 9338 COSE Countersignature support to wolfCOSE, letting a second party sign over an already-signed, encrypted, or MAC’d COSE message. Countersignatures matter for notarization, timestamping, and multi-party workflows, proving that a message existed and was endorsed by an additional authority after the fact, and making wolfCOSE a fit for supply-chain and attestation use cases that need layered, independently verifiable signatures.

The feature set includes:

  • Countersignature and Countersignature0 creation and verification
  • Countersigning of COSE_Sign1, COSE_Sign, COSE_Encrypt0, COSE_Encrypt, COSE_Mac0, and COSE_Mac
  • Current header labels 11 and 12, plus verification of legacy labels 7 and 9
  • In-place countersigning with explicit overlap protection and a measured maximum stack path of 1,912 bytes
  • Command-line support and RFC 9338 Appendix A plus legacy RFC 8152 interop vectors

Validation covers text and integer header labels, duplicate labels, protected-header placement, and nested COSE structures.


For additional information regarding this feature, interested parties may contact wolfSSL at facts@wolfssl.com or call +1 425 245 8247. See the PR #74.

Download wolfSSL Now