Appendix C. Parameter Reference

Requirement F8 obliges every algorithm to report its parameters, and §5.5 stated the rule that everything the protocol must know crosses the boundary as a parameter. This appendix collects, per component, what must be answered and what consumes it. A parameter that is not answered does not produce an error at the provider; it produces a failure at the consumer, often far away (§8.3, §15.3).

C.1 Digest

ParameterTypeAnswered byConsumed byIf wrong
sizesize_tAlgorithmKey schedule; secret, Finished and transcript widthsTruncated or over-read secrets (15.3)
blocksizesize_tAlgorithmHMAC inside HKDFEvery HKDF step wrong, immediately

C.2 AEAD cipher

ParameterTypeAnswered byConsumed byIf wrong
keylensize_tAlgorithmTraffic key derivationWrong key length; handshake fails after keys are installed
ivlensize_tAlgorithmStatic IV derivation; nonce constructionNonce misconstruction — catastrophic (8.4)
taglensize_tAlgorithmRecord sizingRecord-length errors (8.3)
blocksizesize_tAlgorithmBuffer arithmeticBuffer sizing errors
modeuintAlgorithmConsumer's mode dispatchTreated as non-AEAD
aeadintAlgorithmAEAD capability checkRejected for TLS 1.3 use
tagoctetsContextRetrieved after encrypt; supplied before decryptIntegrity failure or false accept (8.6)
ivlen (ctx)size_tContextPer-operation IV widthAs above
AADoctetsContextRecord header bindingHeader not authenticated

C.3 Key management and key exchange

ItemDirectionConsumed byNote
Public key export encodingProvider to corekey_share constructionThis encoding is the wire encoding (10.2)
Public key importCore to providerPeer share reconstructionValidation happens here (10.4)
Derive output lengthProvider to coreShared secret bufferMust be the fixed field size, not the computed length (10.3)
Group name / internal name / algorithmCapabilityNegotiationWire name decoupled from implementation name (4.3.1)
Group idCapabilitysupported_groupsFrom a registry or private-use range (10.6)
Security bitsCapabilitySecurity-level filteringUnderstated filters it out; overstated defeats a control (11.3)
Min / max TLSCapabilityVersion gatingConfine to TLS 1.3 (16.3)

C.4 Signature

ItemDirectionConsumed byNote
IANA nameCapabilityConfiguration and protocol identityTwo-layer naming (11.3)
Algorithm nameCapabilityFetch
OIDCapabilityCertificate matchingBrings encoders/decoders into scope (11.4)
Code pointCapabilitysignature_algorithmsAs for groups
Security bitsCapabilityPolicy rankingAs above
Signature max lengthTwo-call conventionCaller allocationMust be the maximum, not the typical

C.5 Checklist

A component is parameter-complete when, for every row above that applies to it, the parameter appears in the gettable list and is answered by the get function. The two are separate obligations: a parameter advertised but not answered, or answered but not advertised, is a defect that some consumers tolerate and others do not, which produces the worst kind of bug — one that depends on the consumer.