<feed xmlns='http://www.w3.org/2005/Atom'>
<title>openbsd/src/lib/libcrypto/dh/dh_key.c, branch OPENBSD_6_8_BASE</title>
<subtitle>A mirror of https://github.com/libressl/openbsd.git
</subtitle>
<id>https://git.lua4.win/openbsd/atom?h=OPENBSD_6_8_BASE</id>
<link rel='self' href='https://git.lua4.win/openbsd/atom?h=OPENBSD_6_8_BASE'/>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/'/>
<updated>2018-11-12T17:39:17+00:00</updated>
<entry>
<title>Missing initialization for pub_key. CID 184303.</title>
<updated>2018-11-12T17:39:17+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2018-11-12T17:39:17+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=7d635d52fecd4640ce8a3679055f747c8f7e42b9'/>
<id>urn:sha1:7d635d52fecd4640ce8a3679055f747c8f7e42b9</id>
<content type='text'>
ok bcook
</content>
</entry>
<entry>
<title>Initialize priv_key and pub_key on first use instead of at the top.</title>
<updated>2018-11-09T23:49:18+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2018-11-09T23:49:18+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=3a1709b1032136da69943b85f89bd08db5f23a9b'/>
<id>urn:sha1:3a1709b1032136da69943b85f89bd08db5f23a9b</id>
<content type='text'>
While there, eliminate a flag that was only used once.

ok beck jsing mestre
</content>
</entry>
<entry>
<title>unrevert the use of bn_rand_interval().</title>
<updated>2018-11-06T07:02:33+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2018-11-06T07:02:33+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=b1f2fa8da88f8be2fe7d6d9d2b8308537fcfb408'/>
<id>urn:sha1:b1f2fa8da88f8be2fe7d6d9d2b8308537fcfb408</id>
<content type='text'>
ok beck jsing
</content>
</entry>
<entry>
<title>revert use of bn_rand_interval due to failures with ECDHE and TLS</title>
<updated>2018-11-06T02:14:39+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2018-11-06T02:14:39+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=2040275bab908960f255a8c01f793ac41a51b26b'/>
<id>urn:sha1:2040275bab908960f255a8c01f793ac41a51b26b</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Make use of bn_rand_interval() where appropriate.</title>
<updated>2018-11-05T23:54:27+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2018-11-05T23:54:27+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=eaddac22ab3166ef515cb4c286c0c3ed322fbe40'/>
<id>urn:sha1:eaddac22ab3166ef515cb4c286c0c3ed322fbe40</id>
<content type='text'>
ok beck jsing
</content>
</entry>
<entry>
<title>Eliminate a few "} else" branches, a few unneeded NULL checks before</title>
<updated>2018-11-05T23:50:05+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2018-11-05T23:50:05+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=8e9f1d9b90e9437962a4af66f58e24dd9fa2c0c7'/>
<id>urn:sha1:8e9f1d9b90e9437962a4af66f58e24dd9fa2c0c7</id>
<content type='text'>
freeing and indent nearby labels.

ok beck jsing
</content>
</entry>
<entry>
<title>Remove two unnecessary BN_FLG_CONSTTIME dances: BN_mod_exp_ct() already</title>
<updated>2018-11-05T23:46:16+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2018-11-05T23:46:16+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=d84e997e985b21f7846260ada232d4d74b349e3e'/>
<id>urn:sha1:d84e997e985b21f7846260ada232d4d74b349e3e</id>
<content type='text'>
takes care of this internally.

ok beck jsing
</content>
</entry>
<entry>
<title>zap stray tab</title>
<updated>2018-06-12T15:33:18+00:00</updated>
<author>
<name>sthen</name>
<email></email>
</author>
<published>2018-06-12T15:33:18+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=60f21d03f2d8bf7428ce8a6df3877e2f33b2409b'/>
<id>urn:sha1:60f21d03f2d8bf7428ce8a6df3877e2f33b2409b</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Reject excessively large primes in DH key generation. Problem reported</title>
<updated>2018-06-12T15:32:54+00:00</updated>
<author>
<name>sthen</name>
<email></email>
</author>
<published>2018-06-12T15:32:54+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=944885610663d79b2787c4d04d9ae3b283754f55'/>
<id>urn:sha1:944885610663d79b2787c4d04d9ae3b283754f55</id>
<content type='text'>
by Guido Vranken to OpenSSL (https://github.com/openssl/openssl/pull/6457)
and based on his diff.  suggestions from tb@, ok tb@ jsing@

"During key agreement in a TLS handshake using a DH(E) based ciphersuite a
malicious server can send a very large prime value to the client. This will
cause the client to spend an unreasonably long period of time generating a key
for this prime resulting in a hang until the client has finished. This could be
exploited in a Denial Of Service attack."
</content>
</entry>
<entry>
<title>Send the function codes from the error functions to the bit bucket,</title>
<updated>2017-01-29T17:49:23+00:00</updated>
<author>
<name>beck</name>
<email></email>
</author>
<published>2017-01-29T17:49:23+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=d1f47bd292f36094480caa49ada36b99a69c59b0'/>
<id>urn:sha1:d1f47bd292f36094480caa49ada36b99a69c59b0</id>
<content type='text'>
as was done earlier in libssl. Thanks inoguchi@ for noticing
libssl had more reacharounds into this.
ok jsing@ inoguchi@
</content>
</entry>
</feed>
