Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | Allow setting the validation time during PKIX path validation | Jack Lloyd | 2016-10-21 | 2 | -18/+29 |
| | | | | | | | Previously validation asked the system clock which is not always the correct thing (for example when using Roughtime protocol). Had been on the todo list forever, forced into it by some of the test certs expiring today. | ||||
* | Add create_private_key, expose key loading functions in pk_algs.h | Jack Lloyd | 2016-10-20 | 7 | -69/+225 |
| | |||||
* | Tighten up TLS server handshake logic. | Jack Lloyd | 2016-10-20 | 1 | -20/+15 |
| | | | | | | | | | Previously client was allowed to omit the Certificate message, a leftover from supporting SSLv3. In all versions of TLS, an empty message must be sent if the client does not want to use a cert. No known security impact, but nothing we need to allow anymore. Clean up the handshake switch a bit by using return statements. | ||||
* | Merge GH #669 Add SHA-3, SHAKE-128, and BoringSSL-mode NewHope | Jack Lloyd | 2016-10-20 | 15 | -209/+554 |
|\ | |||||
| * | Add SHAKE-128 as stream cipher | Jack Lloyd | 2016-10-19 | 8 | -106/+240 |
| | | | | | | | | | | Updates NewHope to use that instead of the hard-coded SHAKE-128, and adds toggle for BoringSSL compat mode using AES-128/CTR + SHA-256. | ||||
| * | Add proper SHA-3 | Jack Lloyd | 2016-10-19 | 10 | -115/+326 |
| | | | | | | | | | | | | | | | | | | | | Kind of a copy and paste of Keccak, but only a single copy of the permutation at least. Keccak depends on SHA-3 instead of the reverse, so that SHA-3 can be enabled without also bringing in an unapproved hash function. Updates newhope code and removes API function newhope_hash which was an unofficial SHA-3-256. | ||||
* | | Reorganize anon namespace code to fix last doxygen warn [ci skip] | René Korthaus | 2016-10-20 | 1 | -8/+8 |
| | | |||||
* | | Fix doxygen warnings [ci skip] | René Korthaus | 2016-10-19 | 39 | -58/+101 |
| | | |||||
* | | Minor doxygen fixes [ci skip] | René Korthaus | 2016-10-19 | 10 | -10/+10 |
| | | |||||
* | | Improve pubkey doxygen [ci skip] | René Korthaus | 2016-10-19 | 15 | -17/+251 |
| | | |||||
* | | Improve tls doxygen [ci skip] | René Korthaus | 2016-10-19 | 9 | -0/+99 |
| | | |||||
* | | Improve stream doxygen [ci skip] | René Korthaus | 2016-10-19 | 4 | -7/+26 |
| | | |||||
* | | Improve rng doxygen [ci skip] | René Korthaus | 2016-10-19 | 6 | -11/+82 |
| | | |||||
* | | Improve pkcs11 doxygen [ci skip] | René Korthaus | 2016-10-19 | 3 | -13/+49 |
| | | |||||
* | | Improve pk_pad doxygen [ci skip] | René Korthaus | 2016-10-19 | 6 | -5/+13 |
| | | |||||
* | | Improve pbkdf doxygen [ci skip] | René Korthaus | 2016-10-19 | 1 | -4/+54 |
| | | |||||
* | | Improve modes doxygen [ci skip] | René Korthaus | 2016-10-19 | 9 | -8/+104 |
| | | |||||
* | | Improve misc doxygen [ci skip] | René Korthaus | 2016-10-19 | 2 | -0/+18 |
| | | |||||
* | | Improve mac doxygen [ci skip] | René Korthaus | 2016-10-19 | 1 | -4/+6 |
| | | |||||
* | | Improve kdf doxygen [ci skip] | René Korthaus | 2016-10-19 | 8 | -8/+54 |
| | | |||||
* | | Improve hash doxygen [ci skip] | René Korthaus | 2016-10-19 | 2 | -4/+13 |
| | | |||||
* | | Improve block doxygen [ci skip] | René Korthaus | 2016-10-19 | 1 | -3/+6 |
|/ | |||||
* | Maintainer mode fixes | Jack Lloyd | 2016-10-17 | 3 | -14/+12 |
| | |||||
* | In TLS::Session_Keys return values by reference | Jack Lloyd | 2016-10-17 | 1 | -6/+6 |
| | |||||
* | Update SRP6 version | Jack Lloyd | 2016-10-17 | 1 | -1/+1 |
| | | | | API changed in 227d59d88 but did not bump the version. | ||||
* | Indent include so amalgamation works correctly | Jack Lloyd | 2016-10-17 | 1 | -2/+1 |
| | | | | | Otherwise <future> is thrown into the top of botan_all.h which causes problems on IncludeOS | ||||
* | Merge GH #665 Add IncludeOS target, make filesystem/threads optional | Jack Lloyd | 2016-10-17 | 59 | -85/+281 |
|\ | |||||
| * | Add ISA annotations to functions using SIMD, AES, etc | Jack Lloyd | 2016-10-14 | 9 | -0/+44 |
| | | | | | | | | | | | | | | | | Also emit `#pragma GCC target` in the ISA specific amalgamation files. This allows compiling without any special compiler flags, at least with GCC 6.2 and Clang 3.8. The ISA annotations are ignored in MSVC, which just emits whatever instruction the intrinsic requires. | ||||
| * | More no-filesystem fixes | Jack Lloyd | 2016-10-12 | 5 | -0/+12 |
| | | |||||
| * | Fix mutex in oids.cpp | Jack Lloyd | 2016-10-12 | 1 | -7/+7 |
| | | | | | | | | Remove bogus includes for TLS tests | ||||
| * | Abstract out mutex type. Make threads optional. | Jack Lloyd | 2016-10-12 | 30 | -62/+162 |
| | | |||||
| * | Add IncludeOS target. Make filesystem support optional. | Jack Lloyd | 2016-10-10 | 16 | -17/+57 |
| | | |||||
* | | Remove constexpr use introduced in 20f7e4ec | Jack Lloyd | 2016-10-16 | 2 | -7/+7 |
| | | | | | | | | Turns out MSVC 2013 doesn't have constexpr at all (!!) | ||||
* | | util: Some simple constexpr uses | Jack Lloyd | 2016-10-13 | 3 | -31/+9 |
| | | | | | | | | Remove unused and empty get_byte.h | ||||
* | | Change Certificate_Store_in_SQL to take RNG as argument. | Jack Lloyd | 2016-10-13 | 4 | -14/+19 |
| | | | | | | | | | | Previously it created a new AutoSeeded_RNG in each function, sometimes without even using it. | ||||
* | | ffi: Avoid deprecated PK constructors. | Jack Lloyd | 2016-10-13 | 1 | -4/+4 |
| | | | | | | | | The system rng is already a hard requirement for FFI anyway. | ||||
* | | Merge GH #659 TLS CBC is optional | Jack Lloyd | 2016-10-13 | 6 | -2/+18 |
|\ \ | |||||
| * | | Make TLS CBC optional | Jack Lloyd | 2016-10-08 | 6 | -2/+18 |
| | | | |||||
* | | | Merge GH #646 Fix MSVC debug configurations. Add debug builds to AppVeyor | Jack Lloyd | 2016-10-13 | 1 | -0/+9 |
|\ \ \ | |||||
| * | | | Diable static_assert in secure_allocator in MSVC debug | Simon Warta | 2016-10-13 | 1 | -0/+9 |
| | | | | |||||
* | | | | Merge GH #663 Compression docs | Jack Lloyd | 2016-10-11 | 1 | -1/+38 |
|\ \ \ \ | |||||
| * | | | | Improve compression doc [ci skip] | René Korthaus | 2016-10-11 | 1 | -1/+38 |
| | | | | | |||||
* | | | | | Merge GH #662 Doxygen comments | Jack Lloyd | 2016-10-11 | 12 | -146/+395 |
|\ \ \ \ \ | |||||
| * | | | | | Improve cert doxygen [ci skip] | René Korthaus | 2016-10-11 | 12 | -146/+395 |
| |/ / / / | |||||
* / / / / | Improve base doxygen [ci skip] | René Korthaus | 2016-10-11 | 3 | -1/+22 |
|/ / / / | |||||
* | | / | Add doxygen mainpage | René Korthaus | 2016-10-10 | 1 | -0/+57 |
| |_|/ |/| | | | | | | | | Adds a Crypto++-like doxygen mainpage. Replaces the formerly empty mainpage. | ||||
* | | | Merge GH #655 Fix Win32 CryptoAPI source | Jack Lloyd | 2016-10-10 | 1 | -1/+1 |
|\ \ \ | |||||
| * | | | The implicit constructor does not specify a provider. | slaviber | 2016-10-07 | 1 | -1/+1 |
| | | | | | | | | | | | | | | | | | | | | | | | | With no provider specified, Win32_CAPI_EntropySource::poll does not call ::CryptGenRandom and returns 0, leading to subsequent PRNG_Unseeded exceptions. | ||||
* | | | | Fix Clang warnings | Jack Lloyd | 2016-10-09 | 2 | -4/+2 |
| | | | | |||||
* | | | | The other half of 55b8fb5 | Jack Lloyd | 2016-10-09 | 1 | -7/+9 |
| | | | | | | | | | | | | | | | | GH #656 |