Commit Graph

  • 9df64ad39f Fix license header in pre-commit hook Bence Szépkúti 2020-08-19 17:17:56 +02:00
  • ef9874d11a Update terminology Gilles Peskine 2020-08-19 21:55:27 +02:00
  • 5298f684bd Fix hyperlinks Gilles Peskine 2020-08-19 21:53:59 +02:00
  • 2e843aeb3e Update some open questions Gilles Peskine 2020-08-19 21:43:59 +02:00
  • 0dfd10d2a2 Copyediting Gilles Peskine 2020-08-19 21:41:27 +02:00
  • 2645bcc709 Fix license header in pre-commit hook Bence Szépkúti 2020-08-19 17:17:56 +02:00
  • 47ad15d9ec Merge pull request #3581 from bensze01/copyright-2.7 danh-arm 2020-08-19 16:41:44 +01:00
  • 2823efabc8 Merge pull request #3580 from bensze01/copyright-2.16 danh-arm 2020-08-19 16:31:50 +01:00
  • e8582ba0f3 Merge pull request #3546 from bensze01/copyright danh-arm 2020-08-19 15:59:42 +01:00
  • 44bfbe3b95 Update copyright notices to use Linux Foundation guidance Bence Szépkúti 2020-08-19 16:54:51 +02:00
  • a2947ac7bb Update copyright notices to use Linux Foundation guidance Bence Szépkúti 2020-08-19 16:37:36 +02:00
  • d15c740df6 Fix memory leak in mbedtls_md_setup with HMAC Gilles Peskine 2020-08-19 12:03:11 +02:00
  • 7fe2c5f086 Add mbedtls_ssl_cf_memcpy_offset() with tests Manuel Pégourié-Gonnard 2020-08-18 12:02:54 +02:00
  • 3c31afaca6 Use temporary buffer to hold the peer's HMAC Manuel Pégourié-Gonnard 2020-08-13 12:08:54 +02:00
  • 1e14827beb Update copyright notices to use Linux Foundation guidance Bence Szépkúti 2020-08-07 13:07:28 +02:00
  • e5595501ce Fix e2k support changelog snippet makise-homura 2020-08-19 01:33:15 +03:00
  • d0107b96af Replace spec language by Mbed TLS documentation: lifetimes Gilles Peskine 2020-08-18 23:05:06 +02:00
  • 08bde36e73 Clarify that the location is where the key material is accessible Gilles Peskine 2020-08-18 23:04:08 +02:00
  • e74f372330 Get back -Wsigned-one-bit-field and fix sources according to it makise-homura 2020-08-18 23:57:48 +03:00
  • 0be6aa9957 Get back -Wsign-compare and fix sources according to it makise-homura 2020-08-18 23:52:53 +03:00
  • ac2fd6524a Support building on e2k (Elbrus) architecture makise-homura 2020-08-18 21:59:46 +03:00
  • 918b5f15d1 Merge pull request #3556 from mpg/x509-verify-non-dns-san-2.7 Manuel Pégourié-Gonnard 2020-08-18 10:02:16 +02:00
  • daba4f67cc Merge pull request #3555 from mpg/x509-verify-non-dns-san-2.16 Manuel Pégourié-Gonnard 2020-08-18 10:02:08 +02:00
  • 30c1df3f84 Merge pull request #3570 from gufe44/net-sockets-fixes-2.7 Manuel Pégourié-Gonnard 2020-08-18 09:13:52 +02:00
  • b9c64e4538 Merge pull request #3558 from gufe44/net-sockets-fixes-2.16 Manuel Pégourié-Gonnard 2020-08-18 09:13:30 +02:00
  • 721f7c1e64 Add minimal client authentication test to ssl-opt.sh Hanno Becker 2020-08-17 12:17:32 +01:00
  • 2f54a3c2e4 Add tests to ssl-opt.sh exercising new key_pwd[2] parameters Hanno Becker 2020-08-17 12:14:06 +01:00
  • 226eedb5f3 Add password protected version of key for data_files/server{2,5}.key Hanno Becker 2020-08-17 12:14:00 +01:00
  • 5bfa623e9b Merge pull request #3565 from mpg/improve-ssl-opt-logs-2.16 Manuel Pégourié-Gonnard 2020-08-17 12:05:16 +02:00
  • 52df1cc4f0 Merge pull request #3566 from mpg/improve-ssl-opt-logs-2.7 Manuel Pégourié-Gonnard 2020-08-17 12:04:48 +02:00
  • 98944cd756 Merge pull request #3404 from mpg/improve-ssl-opt-logs Manuel Pégourié-Gonnard 2020-08-17 12:04:36 +02:00
  • 2d3ac68336 Parse key-file and -password parameters in same place in ssl_client2 Hanno Becker 2020-08-17 09:42:37 +01:00
  • bffa54f4eb Add usage string for key_pwd argument in ssl_client2 program Hanno Becker 2020-08-17 09:42:19 +01:00
  • 34ce81f896 Avoid overly long usage string literal in ssl_server2 program Hanno Becker 2020-08-17 09:40:54 +01:00
  • a4e86141f1 Always revoke certificate on CRL Raoul Strackx 2020-06-15 17:03:13 +02:00
  • 19735b69b8 Fix building on NetBSD 9.0 gufe44 2020-08-13 11:03:54 +02:00
  • 3ca3b9ea88 Fix building on NetBSD 9.0 gufe44 2020-08-17 07:14:16 +02:00
  • c60c30eb68 Merge pull request #3557 from Ouss4/assert Gilles Peskine 2020-08-14 23:24:04 +02:00
  • 71f4fa13bb Merge pull request #721 from gilles-peskine-arm/x509parse_crl-empty_entry-development Gilles Peskine 2020-08-14 23:22:31 +02:00
  • 4ca60502d8 Merge pull request #734 from gilles-peskine-arm/x509parse_crl-empty_entry-2.16 Gilles Peskine 2020-08-14 23:22:23 +02:00
  • 126b69aee5 Merge pull request #735 from gilles-peskine-arm/x509parse_crl-empty_entry-2.7 Gilles Peskine 2020-08-14 23:22:19 +02:00
  • 74e2534a10 Fix typo in mbedtls_ssl_set_bio description. Christopher Moynihan 2020-08-14 12:27:21 -07:00
  • fa452c4566 Fix guard in ECJPAKE tests in ssl-opt.sh Hanno Becker 2020-08-14 15:42:49 +01:00
  • ee63af6f8f Adapt ssl-opt.sh to modified ciphersuite log format Hanno Becker 2020-08-14 15:41:23 +01:00
  • 8ca03a7b68 Merge pull request #3554 from mpg/x509-verify-non-dns-san-dev Manuel Pégourié-Gonnard 2020-08-14 11:32:22 +02:00
  • 793c4367d7 Remove obsolete buildbot reference in compat.sh Manuel Pégourié-Gonnard 2020-07-27 09:46:53 +02:00
  • 33659700a3 Fix misuse of printf in shell script Manuel Pégourié-Gonnard 2020-07-27 09:45:32 +02:00
  • ed0aaf46a9 Fix added proxy command when IPv6 is used Manuel Pégourié-Gonnard 2020-07-16 10:19:32 +02:00
  • c5ae9c8532 Simplify test syntax Manuel Pégourié-Gonnard 2020-06-25 09:54:46 +02:00
  • 57e328e805 Fix logic error in setting client port Manuel Pégourié-Gonnard 2020-06-25 09:52:54 +02:00
  • e5201e479a ssl-opt.sh: include test name in log files Manuel Pégourié-Gonnard 2020-06-08 12:06:21 +02:00
  • bc079e263b ssl-opt.sh: remove old buildbot-specific condition Manuel Pégourié-Gonnard 2020-06-08 11:49:05 +02:00
  • 1fcb1a18c8 ssl-opt.sh: add proxy to all DTLS tests Manuel Pégourié-Gonnard 2020-06-08 11:40:06 +02:00
  • 063f3bba90 Add ChangeLog entry Hanno Becker 2020-08-14 10:02:36 +01:00
  • 62870c9a7e Remove obsolete buildbot reference in compat.sh Manuel Pégourié-Gonnard 2020-07-27 09:46:53 +02:00
  • a1919ad6e0 Fix misuse of printf in shell script Manuel Pégourié-Gonnard 2020-07-27 09:45:32 +02:00
  • 7442f843d5 Fix added proxy command when IPv6 is used Manuel Pégourié-Gonnard 2020-07-16 10:19:32 +02:00
  • 581af9f720 Simplify test syntax Manuel Pégourié-Gonnard 2020-06-25 09:54:46 +02:00
  • bedcb3eb24 Fix logic error in setting client port Manuel Pégourié-Gonnard 2020-06-25 09:52:54 +02:00
  • cbd5c03343 ssl-opt.sh: include test name in log files Manuel Pégourié-Gonnard 2020-06-08 12:06:21 +02:00
  • e63fc6d52b ssl-opt.sh: remove old buildbot-specific condition Manuel Pégourié-Gonnard 2020-06-08 11:49:05 +02:00
  • fcf6c16470 ssl-opt.sh: add proxy to all DTLS tests Manuel Pégourié-Gonnard 2020-06-08 11:40:06 +02:00
  • 5c5efdfcf9 Fix format specifier in ssl_ciphersuite_match() Hanno Becker 2019-01-28 14:59:35 +00:00
  • 3c88c65426 Fix debug format specifier in ClientHello ciphersuite log Hanno Becker 2019-01-02 11:17:25 +00:00
  • ecea07d6c3 Unify ciphersuite related debug output on client and server Hanno Becker 2018-11-07 16:24:35 +00:00
  • ca04fdc2cc Add support for password protected key file to ssl_client2 Hanno Becker 2018-11-07 16:22:14 +00:00
  • e58a630cb0 Add support for password protected key file to ssl_server2 Hanno Becker 2018-11-07 16:20:16 +00:00
  • c4af324a4b Merge branch 'development' into development-restricted Manuel Pégourié-Gonnard 2020-08-14 10:11:21 +02:00
  • 99d67823a2 Merge pull request #3559 from gufe44/netbsd-rand-arc4random_buf-2.7 Gilles Peskine 2020-08-13 15:27:57 +02:00
  • 9acf943b98 Merge pull request #3560 from gufe44/netbsd-rand-arc4random_buf-2.16 Gilles Peskine 2020-08-13 15:27:53 +02:00
  • 3890f7cd3d Merge pull request #3540 from gufe44/netbsd-rand-arc4random_buf Gilles Peskine 2020-08-13 15:27:45 +02:00
  • 7cf6ff76d5 Merge pull request #3549 from mpg/check-generated-files-2.7 Gilles Peskine 2020-08-13 11:24:30 +02:00
  • 1505e42de9 Merge pull request #3548 from mpg/check-generated-files-2.16 Gilles Peskine 2020-08-13 11:24:26 +02:00
  • 9ec3648ab3 Merge pull request #3495 from mpg/check-generated-files Gilles Peskine 2020-08-13 11:24:23 +02:00
  • ba5cba838c Log change as bugfix gufe44 2020-08-13 06:24:42 +02:00
  • d5f8c26e01 Add changelog entry gufe44 2020-08-06 12:52:04 +02:00
  • 3fa7c64edf Use arc4random_buf instead of rand on NetBSD gufe44 2020-08-03 17:56:50 +02:00
  • da0ea9e9df Log change as bugfix gufe44 2020-08-13 06:24:42 +02:00
  • 6f837332f0 Add changelog entry gufe44 2020-08-06 12:52:04 +02:00
  • 29fcac3263 Log change as bugfix gufe44 2020-08-13 06:24:42 +02:00
  • 206cb39116 Use arc4random_buf instead of rand on NetBSD gufe44 2020-08-03 17:56:50 +02:00
  • e0b2687a2d Undef ASSERT before defining it to ensure that no previous definition has sneaked in through included files. Ouss4 2020-08-11 16:07:09 +01:00
  • 691bed7cce Merge pull request #733 from gabor-mezei-arm/689_bp27_zeroising_of_plaintext_buffers Gilles Peskine 2020-08-12 18:51:47 +02:00
  • 0ca801af76 Merge pull request #732 from gabor-mezei-arm/689_bp216_zeroising_of_plaintext_buffers Gilles Peskine 2020-08-12 18:51:44 +02:00
  • e900b59703 Merge pull request #719 from gabor-mezei-arm/689_zeroising_of_plaintext_buffers Gilles Peskine 2020-08-12 18:51:42 +02:00
  • de7e03688d Merge pull request #3489 from CodeMonkeyLeet/mbedtls-2.16_backport_3464 Gilles Peskine 2020-08-12 18:22:22 +02:00
  • e447f47cc8 Add the decomposition of the base case as a comment Gilles Peskine 2020-08-06 16:05:35 +02:00
  • 78e54b9b1d x509_crl_parse: fix 1-byte buffer overflow and entry->raw.tag Gilles Peskine 2020-07-16 18:26:29 +02:00
  • 4ac28b8d1e x509parse_crl: more negative test cases Gilles Peskine 2020-07-16 18:18:22 +02:00
  • 4ddfdbf76a Add the decomposition of the base case as a comment Gilles Peskine 2020-08-06 16:05:35 +02:00
  • 6579235d9c x509_crl_parse: fix 1-byte buffer overflow and entry->raw.tag Gilles Peskine 2020-07-16 18:26:29 +02:00
  • d8dc8e29c1 x509parse_crl: more negative test cases Gilles Peskine 2020-07-16 18:18:22 +02:00
  • 58c8da2d7e Add test: DNS names should not match IP addresses Manuel Pégourié-Gonnard 2020-07-23 12:39:53 +02:00
  • 894c05df32 Add test: DNS names should not match IP addresses Manuel Pégourié-Gonnard 2020-07-23 12:39:53 +02:00
  • dfd517234d Merge pull request #3488 from CodeMonkeyLeet/mbedtls-2.16_backport_2632 Manuel Pégourié-Gonnard 2020-08-11 10:32:18 +02:00
  • 204e05404f Add ChangeLog entry for X.509 CN-type vulnerability Manuel Pégourié-Gonnard 2020-07-24 10:33:39 +02:00
  • f58e5cc4f4 Improve documentation of cn in x509_crt_verify() Manuel Pégourié-Gonnard 2020-07-24 10:31:37 +02:00
  • f3e4bd8632 Fix comparison between different name types Manuel Pégourié-Gonnard 2020-07-21 13:22:41 +02:00
  • 7d2a4d873f Add test: DNS names should not match IP addresses Manuel Pégourié-Gonnard 2020-07-23 12:39:53 +02:00
  • 9539f831b2 Swap out CRC calculation in AES in favour of a simple hash Andrzej Kurek 2020-08-10 15:58:13 -04:00