Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | Clear K after new PRK is generated. | lloyd | 2008-10-28 | 1 | -4/+7 |
| | |||||
* | Set the default XTS (ASCII value of "Botan HMAC_RNG XTS") only once, in | lloyd | 2008-10-28 | 1 | -86/+92 |
| | | | | | | | the constructor. This avoids repeatedly resetting it for each reseed, if HMAC_RNG is used without entropy sources and using only application-provided entropy. Very slightly more efficient and also the code for reseed becomes a bit clearer. | ||||
* | Wrap lines to 80 columns | lloyd | 2008-10-28 | 10 | -30/+54 |
| | |||||
* | Modify AutoSeeded_RNG to use HMAC_RNG instead of Randpool, if HMAC_RNG is | lloyd | 2008-10-28 | 2 | -5/+20 |
| | | | | | | | | available in the build. If neither is avilable, the constructor will throw an exception. As before, the underlying RNG will be wrapped in an X9.31 PRNG using AES-256 as the block cipher (if X9.31 is enabled in the build). | ||||
* | Add HMAC_RNG, which is an RNG design based on Hugo Krawczyk's paper | lloyd | 2008-10-28 | 3 | -0/+403 |
| | | | | | | | | "On Extract-then-Expand Key Derivation Functions and an HMAC-based KDF". While it has much smaller state than Randpool (256-512 bits, typically, versus 4096 bits commonly used in Randpool), the more formal design analysis seems attractive (and realistically if the RNG can manage to contain 256 bits of conditional entropy, that is more than sufficient). | ||||
* | In ANSI_X931_RNG::reseed, only attempt to reseed the X9.31 state if | lloyd | 2008-10-28 | 1 | -7/+10 |
| | | | | the underlying PRNG's reseed was a success. | ||||
* | Substantially change Randpool's reseed logic. Now when a reseed | lloyd | 2008-10-27 | 19 | -34/+107 |
| | | | | | | | | | | | | | | | | | | | | | | | | | | is requested, Randpool will first do a fast poll on each entropy source that has been registered. It will count these poll results towards the collected entropy count, with a maximum of 96 contributed bits of entropy per poll (only /dev/random reaches this, others measure at 50-60 bits typically), and a maximum of 256 for sum contribution of the fast polls. Then it will attempt slow polls of all devices until it thinks enough entropy has been collected (using the rather naive entropy_estimate function). It will count any slow poll for no more than 256 bits (100 or so is typical for every poll but /dev/random), and will attempt to collect at least 512 bits of (estimated/guessed) entropy. This tends to cause Randpool to use significantly more sources. Previously it was common, especially on systems with a /dev/random, for only one or a few sources to be used. This change helps assure that even if /dev/random and company are broken or compromised the RNG output remains secure (assuming at least some amount of entropy unguessable by the attacker can be collected via other sources). Also change AutoSeeded_RNG do an automatic poll/seed when it is created. | ||||
* | TLS_PRF also depends on MD5 and SHA1, was not so marked | lloyd | 2008-10-26 | 1 | -0/+2 |
| | |||||
* | In KDF instead of lookup, instantiate fixed hashes (MD5, SHA-1) directly | lloyd | 2008-10-26 | 4 | -21/+24 |
| | |||||
* | Remove lookup.h use from OpenPGP S2K | lloyd | 2008-10-26 | 3 | -23/+14 |
| | |||||
* | Make S2K base class non-copyable and non-assignable by default (use clone ↵ | lloyd | 2008-10-26 | 1 | -0/+3 |
| | | | | instead) | ||||
* | Move EntropySource base class to new entropy_src.h (which allows the ↵ | lloyd | 2008-10-26 | 15 | -28/+76 |
| | | | | | | implementations to decouple from knowing about RandomNumberGenerator). | ||||
* | Remove prohibition against generating DSA parameter set with a 224 bit q, | lloyd | 2008-10-26 | 1 | -4/+0 |
| | | | | since SHA-224 is now implemented. | ||||
* | Move rng.h from core to rng | lloyd | 2008-10-26 | 1 | -0/+0 |
| | |||||
* | Move rng.{cpp,h} from core to rng/ topdir | lloyd | 2008-10-26 | 15 | -56/+158 |
| | | | | | | | | | | | | | | Add a new class AutoSeeded_RNG that is a RandomNumberGenerator that wraps up the logic formerly in RandomNumberGenerator::make_rng. make_rng in fact now just returns a new AutoSeeded_RNG object. AutoSeeded_RNG is a bit more convenient because - No need to use auto_ptr - No need to dereference (same syntax everywhere - it's an underestimated advantage imo) Also move the code from timer/timer_base to timer/ | ||||
* | Move kdf/kdf_base to kdf | lloyd | 2008-10-26 | 10 | -7/+6 |
| | |||||
* | Move pbe/pbe_base to pbe/ | lloyd | 2008-10-26 | 6 | -3/+3 |
| | |||||
* | Move s2k.{h,cpp} and S2K algos from core and kdf to new s2k/ dir | lloyd | 2008-10-26 | 13 | -2/+1 |
| | |||||
* | Put pk_pad.{h,cpp} from core into pk_pad/ dir (cleaner I think) | lloyd | 2008-10-26 | 6 | -2/+15 |
| | |||||
* | Move libstate and selftest out of core/ dir to toplevel | lloyd | 2008-10-26 | 26 | -5/+5 |
| | |||||
* | Add alias for Intel T2250. Based on /proc/cpuinfo sent by Benjamin Lau | lloyd | 2008-10-24 | 1 | -0/+1 |
| | |||||
* | Added prescott submodel to ia32 architecture, including aliases for | markus | 2008-10-24 | 1 | -0/+7 |
| | | | | most Intel Core Duo (32 bit, as opposed to Core 2 Duo being 64 bit). | ||||
* | Use -O2 instead of -O3 with Intel C++ | lloyd | 2008-10-22 | 1 | -1/+1 |
| | |||||
* | Install pkg-config file to /lib/pkgconfig | lloyd | 2008-10-22 | 2 | -5/+13 |
| | |||||
* | Update ICC flags for 10.1 | lloyd | 2008-10-22 | 1 | -3/+3 |
| | |||||
* | Delete generated botan.pc on make distclean | lloyd | 2008-10-15 | 2 | -2/+2 |
| | |||||
* | Add pkg-config support (requested/suggested by Zack Weinberg on monotone-dev) | lloyd | 2008-10-15 | 1 | -0/+11 |
| | |||||
* | merge of '141433027ee455b8c8b2829f5233eb577039bd41' | lloyd | 2008-10-15 | 1 | -3/+3 |
|\ | | | | | | | and 'a70931899dfcc15fe8aa2ace40712717859afe50' | ||||
| * | Doxygen comment | lloyd | 2008-10-15 | 1 | -3/+3 |
| | | |||||
* | | Clean up VC++ ia32 asm a bit, use new defs of word3_muladd* from generic ↵ | lloyd | 2008-10-15 | 1 | -49/+28 |
| | | | | | | | | mp_asmi.h | ||||
* | | Fix include of mp_asm.h in mp_ia32_msvc/mp_asmi.h (used quotes instead of ↵ | lloyd | 2008-10-15 | 2 | -5/+5 |
|/ | | | | brackets) | ||||
* | Fixup Doxygen error | lloyd | 2008-10-14 | 1 | -3/+3 |
| | |||||
* | Enable sorting in Doxygen output | lloyd | 2008-10-14 | 1 | -1/+1 |
| | |||||
* | Remove two declared but not defined constructors of EAC_Signed_Object | lloyd | 2008-10-14 | 1 | -4/+1 |
| | |||||
* | Add an OID to policy.cpp needed by the CVC code | lloyd | 2008-10-14 | 1 | -0/+3 |
| | |||||
* | Add ECKAEG benchmark. Fix several problems found in ECKAEG key (had pure ↵ | lloyd | 2008-10-13 | 2 | -36/+59 |
| | | | | virtuals) | ||||
* | RNG::reseed comment | lloyd | 2008-10-13 | 1 | -1/+1 |
| | |||||
* | Add some Doxygen comments from InSiTo written for config.h (now gone/split up) | lloyd | 2008-10-13 | 2 | -13/+69 |
| | |||||
* | Remove spurious trailing ; after blocks | lloyd | 2008-10-13 | 5 | -8/+9 |
| | |||||
* | Add InSiTo Doxygen comments for freestore.h | lloyd | 2008-10-13 | 1 | -4/+40 |
| | |||||
* | Wrap lines | lloyd | 2008-10-13 | 1 | -5/+8 |
| | |||||
* | Doxygen comments for eac_asn_obj.h from latest InSiTo | lloyd | 2008-10-13 | 1 | -20/+132 |
| | |||||
* | Add trailing H__ to some header guards. Line wrap long comment. | lloyd | 2008-10-13 | 8 | -34/+37 |
| | |||||
* | Add Doxygen comments for secmem.h from InSiTo | lloyd | 2008-10-13 | 1 | -19/+237 |
| | |||||
* | Add Doxygen comments from InSiTo to x509self.h | lloyd | 2008-10-13 | 1 | -27/+148 |
| | |||||
* | Doxygen comments for X509_Certificate, from InSiTo | lloyd | 2008-10-13 | 1 | -12/+123 |
| | |||||
* | Doxygen comments for pkcs8.h from InSiTo | lloyd | 2008-10-13 | 1 | -31/+127 |
| | |||||
* | Doxygen comments for lookup.h from InSiTo | lloyd | 2008-10-13 | 1 | -35/+184 |
| | |||||
* | Another batch of InSiTo Doxygen comments | lloyd | 2008-10-13 | 4 | -39/+268 |
| | |||||
* | Kill stray char | lloyd | 2008-10-13 | 1 | -1/+1 |
| |