Commit Graph

  • 9d22619a13 Change Arm Trademarks to the issue template Ron Eldor 2017-10-30 18:39:47 +02:00
  • 9f60bc57ce Address PR review comments Ron Eldor 2017-10-29 17:53:52 +02:00
  • 1f311ed587 Backport 1.3:Fix crash when calling mbedtls_ssl_cache_free twice Ron Eldor 2017-10-17 18:15:41 +03:00
  • be17ed59d6 Address PR review comments Ron Eldor 2017-10-29 17:53:52 +02:00
  • 5bd272627b Backport 2.1:Fix crash when calling mbedtls_ssl_cache_free twice Ron Eldor 2017-10-17 18:15:41 +03:00
  • c7acb913ce Change Arm Trademarks Ron Eldor 2017-10-30 17:03:57 +02:00
  • 22360825ae Address PR review comments Ron Eldor 2017-10-29 17:53:52 +02:00
  • df4180a235 Don't break debug messages Hanno Becker 2017-10-27 13:43:58 +01:00
  • 2412061a5a Correct typo and improve documentation Hanno Becker 2017-10-26 11:53:35 +01:00
  • 7bba968afc Adapt ChangeLog Hanno Becker 2017-10-26 11:53:26 +01:00
  • 3f81691d29 Revert to old behaviour of profile_check_key() Manuel Pégourié-Gonnard 2017-10-26 10:24:16 +02:00
  • 254eec8bb4 Document choice of script exit code Manuel Pégourié-Gonnard 2017-10-26 09:47:36 +02:00
  • 3319555b7c Improve documentation of mbedtls_rsa_import[_raw] Hanno Becker 2017-10-25 17:04:10 +01:00
  • 825c3db149 Adapt ChangeLog Hanno Becker 2017-10-25 16:10:07 +01:00
  • c2102893af Zeroize stack before returning from mpi_fill_random Hanno Becker 2017-10-25 16:09:08 +01:00
  • 754663f8c4 Fix information leak in ecp_gen_keypair_base Hanno Becker 2017-10-25 16:08:19 +01:00
  • 0727ca41b7 Make mpi_read_binary time constant Hanno Becker 2017-10-25 16:07:09 +01:00
  • 25e39d38bd Add ChangeLog message for EC private exponent information leak Hanno Becker 2017-10-19 10:10:18 +01:00
  • cf873f74d4 Adapt ChangeLog Hanno Becker 2017-10-19 09:13:35 +01:00
  • 0f49bbc1fc Zeroize stack before returning from mpi_fill_random Hanno Becker 2017-10-18 12:41:30 +01:00
  • b3088b4b37 Fix information leak in ecp_gen_keypair_base Hanno Becker 2017-10-17 15:19:38 +01:00
  • 7d80688e53 Make mpi_read_binary time constant Hanno Becker 2017-10-17 15:17:27 +01:00
  • cb2ba29c49 Mention that mpi_fill_random interprets PRNG output as big-endian Hanno Becker 2017-10-17 15:17:05 +01:00
  • 18710eb102 Adapt ChangeLog Hanno Becker 2017-10-25 09:50:22 +01:00
  • be812f68c5 Add build and ssl-opt.sh run for SSL_DISABLE_RENEGOTIATION to all.sh Hanno Becker 2017-10-25 09:49:13 +01:00
  • e8f3d933e9 Add dep'n on !DISABLE_RENEGOTIATION to renego tests in ssl-opt.sh Hanno Becker 2017-10-25 09:38:00 +01:00
  • bfd0991daa Fix handling of HS msgs in ssl_read if renegotiation unused Hanno Becker 2017-10-25 09:34:48 +01:00
  • 268191a305 Swap branches accepting/refusing renegotiation in in ssl_read Hanno Becker 2017-10-25 09:33:22 +01:00
  • 489f80cbf5 Adapt ChangeLog Hanno Becker 2017-10-24 11:56:58 +01:00
  • 4f9973efb9 Add build and ssl-opt.sh run for !SSL_RENEGOTIATION to all.sh Hanno Becker 2017-10-24 11:56:28 +01:00
  • 7889113075 Add dependency on SSL_RENEGOTIATION to renego tests in ssl-opt.sh Hanno Becker 2017-10-24 11:54:55 +01:00
  • 3cd07be889 Fix handling of HS msgs in mbedtls_ssl_read if renegotiation unused Hanno Becker 2017-10-24 11:49:19 +01:00
  • e454d73cc0 Swap branches accepting/refusing renegotiation in in ssl_read Hanno Becker 2017-10-24 11:47:37 +01:00
  • 8149321fed udp_proxy_wrapper.sh: fix cleanup not cleaning up Gilles Peskine 2017-10-24 12:22:40 +02:00
  • afc4f892d1 udp_proxy_wrapper.sh: more robust Gilles Peskine 2017-10-24 10:00:17 +02:00
  • 19773ff835 Avoid comparing size between RSA and EC keys Manuel Pégourié-Gonnard 2017-10-24 10:51:26 +02:00
  • a677cdd459 Detect IPv6 in udp_proxy_wrapper.sh grepping for server_addr=::1 Hanno Becker 2017-10-23 15:29:31 +01:00
  • 22829e9860 Don't use sed -r in udp_proxy_wrapper.sh Hanno Becker 2017-10-23 15:28:55 +01:00
  • 4ac73e7804 Use shell string processing instead of sed in ssl-opt.sh Hanno Becker 2017-10-23 15:27:37 +01:00
  • 9745cfd87d RSA PSS: remove redundant check; changelog Gilles Peskine 2017-10-19 17:46:14 +02:00
  • e41158ba10 Add comment on the meaning of ssl->in_offt == NULL Hanno Becker 2017-10-23 13:30:32 +01:00
  • e72489de11 Remove internal references and use milder wording for some comments Hanno Becker 2017-10-23 13:23:50 +01:00
  • a6fb089efc Don't split debug messages Hanno Becker 2017-10-23 13:17:48 +01:00
  • ffb1e1ab3d Documentation improvements Hanno Becker 2017-10-23 13:17:42 +01:00
  • c2f52b4b7b Wrong identifier used to check Encrypt-then-MAC flag Hanno Becker 2017-10-23 10:28:28 +01:00
  • 584ebe1bcb Wrong identifier used to check Encrypt-then-MAC flag Hanno Becker 2017-10-20 14:24:51 +01:00
  • 27b34d5bad Wrong identifier used to check Encrypt-then-MAC flag Hanno Becker 2017-10-20 14:24:51 +01:00
  • 28474f41a0 RSA PSS: remove redundant check; changelog Gilles Peskine 2017-10-19 17:46:14 +02:00
  • 91048a3aac RSA PSS: remove redundant check; changelog Gilles Peskine 2017-10-19 17:46:14 +02:00
  • 797c084394 Add tests for disabled MFL-extension to all.sh Hanno Becker 2017-10-19 15:49:21 +01:00
  • 6ed76f74d2 Use a conservative excess of the maximum fragment length in tests Hanno Becker 2017-10-18 14:42:01 +01:00
  • 64691dc3fc Let ssl-opt.sh gracefully fail is SSL_MAX_CONTENT_LEN is not 16384 Hanno Becker 2017-09-22 16:58:50 +01:00
  • b658ee63c2 Adapt ChangeLog Hanno Becker 2017-09-18 16:07:19 +01:00
  • a360411e4f Fixed SIGSEGV problem when writing with ssl_write_real a buffer that is over MBEDTLS_SSL_MAX_CONTENT_LEN bytes Florin 2017-07-22 09:01:44 +02:00
  • e298c8b46c Correct typo Hanno Becker 2017-09-18 14:58:11 +01:00
  • 0d885d3d8c Add expected number of fragments to 16384-byte packet tests Hanno Becker 2017-09-18 15:04:19 +01:00
  • 2fabe5fb70 Add tests for messages beyond 16384 bytes to ssl-opt.sh Hanno Becker 2017-09-18 15:01:50 +01:00
  • 0560778fb0 Add missing test-dependencies for MBEDTLS_SSL_MAX_FRAGMENT_LENGTH Hanno Becker 2017-09-18 15:00:34 +01:00
  • 1a662eb928 Allow requests of size larger than 16384 in ssl_client2 Hanno Becker 2017-09-18 15:05:46 +01:00
  • 5d9224e11c RSA PSS: fix first byte check for keys of size 8N+1 Gilles Peskine 2017-10-19 15:23:49 +02:00
  • 31a2d14b92 RSA PSS: fix first byte check for keys of size 8N+1 Gilles Peskine 2017-10-19 15:23:49 +02:00
  • b00b0da452 RSA PSS: fix first byte check for keys of size 8N+1 Gilles Peskine 2017-10-19 15:23:49 +02:00
  • 509fef7de3 Add ChangeLog message for EC private exponent information leak Hanno Becker 2017-10-19 10:10:18 +01:00
  • a21e2a015b Adapt ChangeLog Hanno Becker 2017-10-19 09:13:35 +01:00
  • 7addb7f0a0 RSA PSS: fix minimum length check for keys of size 8N+1 Gilles Peskine 2017-10-18 19:03:42 +02:00
  • 9e2058281d RSA PSS: fix minimum length check for keys of size 8N+1 Gilles Peskine 2017-10-18 19:03:42 +02:00
  • 139108af94 RSA PSS: fix minimum length check for keys of size 8N+1 Gilles Peskine 2017-10-18 19:03:42 +02:00
  • 9cfabe3597 Use a conservative excess of the maximum fragment length in tests Hanno Becker 2017-10-18 14:42:01 +01:00
  • 08c36635cb Avoid possible miscast of PK key Manuel Pégourié-Gonnard 2017-10-18 14:57:11 +02:00
  • 900fba616f Fix check_wildcard() calling convention Manuel Pégourié-Gonnard 2017-10-18 14:28:11 +02:00
  • 08eacecc62 Fix some style issues and comment typos Manuel Pégourié-Gonnard 2017-10-18 14:20:24 +02:00
  • 888071184c Zeroize stack before returning from mpi_fill_random Hanno Becker 2017-10-18 12:41:30 +01:00
  • 69944b1e67 Make matching more robbust in generate_errors.pl Andres Amaya Garcia 2017-10-17 21:24:56 +01:00
  • d2da622138 Ensure that only .h files are parsed in generate_errors.pl Andres Amaya Garcia 2017-10-17 21:23:15 +01:00
  • 511bb84c60 RSA: Fix another buffer overflow in PSS signature verification Gilles Peskine 2017-10-17 19:02:13 +02:00
  • 55db24ca50 RSA: Fix buffer overflow in PSS signature verification Gilles Peskine 2017-10-17 19:01:38 +02:00
  • d0cd855145 RSA: Fix another buffer overflow in PSS signature verification Gilles Peskine 2017-10-17 19:02:13 +02:00
  • 005939db98 update README file (#1144) RonEld 2017-10-17 20:19:48 +03:00
  • 5c3247120f RSA: Fix buffer overflow in PSS signature verification Gilles Peskine 2017-10-17 19:01:38 +02:00
  • 6a54b0240d RSA: Fix another buffer overflow in PSS signature verification Gilles Peskine 2017-10-17 19:02:13 +02:00
  • 28a0c72795 RSA: Fix buffer overflow in PSS signature verification Gilles Peskine 2017-10-17 19:01:38 +02:00
  • e1a9a4a826 Fix crash when calling mbedtls_ssl_cache_free twice Ron Eldor 2017-10-17 18:15:41 +03:00
  • 7c8cb9c28b Fix information leak in ecp_gen_keypair_base Hanno Becker 2017-10-17 15:19:38 +01:00
  • 073c199224 Make mpi_read_binary time constant Hanno Becker 2017-10-17 15:17:27 +01:00
  • 15f2b3e538 Mention that mpi_fill_random interprets PRNG output as big-endian Hanno Becker 2017-10-17 15:17:05 +01:00
  • 3f2da84bca Resolve PR review comments Ron Eldor 2017-10-17 15:50:30 +03:00
  • 479e8e24e6 Adapt ChangeLog Hanno Becker 2017-10-12 15:39:45 +01:00
  • 134c2ab891 Add build and ssl-opt.sh run for !SSL_RENEGOTIATION to all.sh Hanno Becker 2017-10-12 15:29:50 +01:00
  • 6a2436493f Add dependency on SSL_RENEGOTIATION to renego tests in ssl-opt.sh Hanno Becker 2017-10-12 15:18:45 +01:00
  • 40f8b51221 Add comments on the use of the renego SCSV and the renego ext Hanno Becker 2017-10-12 14:58:55 +01:00
  • 6851b10ec7 Note that disabling SSL_RENEGO doesn't open door for renego attack Hanno Becker 2017-10-12 14:57:48 +01:00
  • 21df7f90d2 Fix handling of HS msgs in mbedtls_ssl_read if renegotiation unused Hanno Becker 2017-10-17 11:03:26 +01:00
  • b4ff0aafd9 Swap branches accepting/refusing renegotiation in in ssl_read Hanno Becker 2017-10-17 11:03:04 +01:00
  • fc8fbfa059 Switch to gender neutral wording in rsa.h Hanno Becker 2017-10-17 10:31:15 +01:00
  • 580869dae8 Handle RSA_EXPORT_UNSUPPORTED error code in strerror Hanno Becker 2017-10-17 10:29:18 +01:00
  • e2a73c13cf Enhancement of ChangeLog entry Hanno Becker 2017-10-17 10:22:47 +01:00
  • 554c32dae6 Mention validate_params does primality tests only if GENPRIME def'd Hanno Becker 2017-10-17 10:21:53 +01:00
  • 68767a6e88 Improve documentation in mbedtls_rsa_check_privkey Hanno Becker 2017-10-17 10:13:31 +01:00
  • f8c028a2fb Minor corrections Hanno Becker 2017-10-17 09:20:57 +01:00
  • 4055a3a16f Shorten prime array in mbedtls_rsa_deduce_primes Hanno Becker 2017-10-17 09:15:26 +01:00