<feed xmlns='http://www.w3.org/2005/Atom'>
<title>openbsd/src/lib/libcrypto/man/BN_set_flags.3, branch OPENBSD_6_8_BASE</title>
<subtitle>A mirror of https://github.com/libressl/openbsd.git
</subtitle>
<id>https://git.lua4.win/openbsd/atom?h=OPENBSD_6_8_BASE</id>
<link rel='self' href='https://git.lua4.win/openbsd/atom?h=OPENBSD_6_8_BASE'/>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/'/>
<updated>2018-04-29T15:58:21+00:00</updated>
<entry>
<title>In view of the recent BN_FLG_CONSTTIME vulnerabilities in OpenSSL,</title>
<updated>2018-04-29T15:58:21+00:00</updated>
<author>
<name>schwarze</name>
<email></email>
</author>
<published>2018-04-29T15:58:21+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=0cafa356a8c4c7fcd0ceea551f687c5d7fbef24e'/>
<id>urn:sha1:0cafa356a8c4c7fcd0ceea551f687c5d7fbef24e</id>
<content type='text'>
carefully document constant time vs. non-constant time operation
of BN_div(3), BN_mod_exp(3), and BN_mod_inverse(3).

Until the work that is required on the ill-designed BN_exp(3) and
BN_gcd(3) interfaces can be undertaken, also document the imperfections
in their behaviour, for now.  Finally, mention BN_mod_exp(3) behaviour
for even moduli.

Delete the vague statement about some functions automatically
setting BN_FLG_CONSTTIME.  It created a false sense of security.
Do not rely on it: not all relevant functions do that.

Topic brought up by beck@, significant feedback and OK jsing@.
</content>
</entry>
<entry>
<title>crypto HISTORY up to SSLeay 0.9.1; researched from OpenSSL git</title>
<updated>2018-03-21T09:03:49+00:00</updated>
<author>
<name>schwarze</name>
<email></email>
</author>
<published>2018-03-21T09:03:49+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=9c6b7656d1237ca414073bcf0955561c2e9e90cc'/>
<id>urn:sha1:9c6b7656d1237ca414073bcf0955561c2e9e90cc</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Document BN_set_flags(3) and BN_get_flags(3).</title>
<updated>2017-01-30T01:29:31+00:00</updated>
<author>
<name>schwarze</name>
<email></email>
</author>
<published>2017-01-30T01:29:31+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=19dcc2c9146afbb7e7ee92dd56ef7f469c46c87e'/>
<id>urn:sha1:19dcc2c9146afbb7e7ee92dd56ef7f469c46c87e</id>
<content type='text'>
jsing@ confirmed that these macros are public and worth documenting.
</content>
</entry>
</feed>
