Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | SSL_MAX_DIGEST is no longer needed. | jsing | 2018-09-08 | 2 | -17/+10 |
| | |||||
* | ASN1_OBJECTs should be freed with ASN1_OBJECT_free(3), not with free(3). | tb | 2018-09-08 | 1 | -2/+2 |
| | | | | ok inoguchi, jsing | ||||
* | Fix indent and adjust line fit to 80 columns. | inoguchi | 2018-09-08 | 1 | -930/+961 |
| | |||||
* | indent labels | tb | 2018-09-08 | 2 | -8/+8 |
| | |||||
* | missing word & a couple of typos | tb | 2018-09-08 | 1 | -3/+3 |
| | |||||
* | Split test blocks into a function. Test contents are not changed. | inoguchi | 2018-09-08 | 1 | -62/+86 |
| | |||||
* | Test more ciphers and randomize the order in regress appstest.sh | inoguchi | 2018-09-08 | 1 | -5/+9 |
| | | | | | | - change test target ciphers - randomize the test ciphers order - display test cipher count | ||||
* | tests all available TLSv1.2 ciphers | inoguchi | 2018-09-07 | 1 | -11/+14 |
| | |||||
* | Declare strings passed to local_listen() as const. This makes it | bluhm | 2018-09-07 | 1 | -3/+3 |
| | | | | | consistent to remote_connect() and getaddrinfo(3). from Nan Xiao | ||||
* | Drop SSL_CIPHER_ALGORITHM2_AEAD flag. | jsing | 2018-09-06 | 4 | -31/+25 |
| | | | | | | | All of our algorithm_mac == SSL_AEAD cipher suites use EVP_AEAD, so we can condition on that rather than having a separate redundant flag. ok tb@ | ||||
* | Do not close the socket twice in netcat. | bluhm | 2018-09-06 | 1 | -5/+6 |
| | | | | from Nan Xiao; OK tb@ | ||||
* | Use the newer/more sensible names for EVP_MD_CTX_* functions. | jsing | 2018-09-05 | 5 | -16/+16 |
| | | | | | | | | | | EVP_MD_CTX_create -> EVP_MD_CTX_new EVP_MD_CTX_destroy -> EVP_MD_CTX_free This should make the intent more obvious and reduce head scratching during code reviews. Raised by tb@ | ||||
* | Correctly clear the current cipher state, when changing cipher state. | jsing | 2018-09-05 | 3 | -41/+37 |
| | | | | | | | | | | | | | | | | | When a renegotiation results in a change of cipher suite, the renegotation would fail if it switched from AEAD to non-AEAD or vice versa. This is due to the fact that the previous EVP_AEAD or EVP_CIPHER state remained, resulting in incorrect logic that caused MAC failures. Rename ssl_clear_cipher_ctx() to ssl_clear_cipher_state() and split it into separate read/write components, then call these functions from the appropriate places when a ChangeCipherSpec message is being processed. Also, remove the separate ssl_clear_hash_ctx() calls and fold these into the ssl_clear_cipher_{read,write}_state() functions. Issue reported by Bernard Spil, who also tested this diff. ok tb@ | ||||
* | use timing-safe compares for checking results in signature verification | djm | 2018-09-05 | 4 | -9/+10 |
| | | | | | | (there are no known attacks, this is just inexpensive prudence) feedback and ok tb@ jsing@ | ||||
* | Stop using composite EVP_CIPHER AEADs. | jsing | 2018-09-03 | 1 | -25/+7 |
| | | | | | | | | | | | The composite AEADs are "stitched" mode ciphers, that are only supported on some architectures/CPUs and are designed to be faster than a separate EVP_CIPHER and EVP_MD implementation. The three AEADs are used for less than ideal cipher suites (if you have hardware support that these use there are better cipher suite options), plus continuing to support AEADs via EVP_CIPHER is creating additional code complexity. ok inoguchi@ tb@ | ||||
* | Stop handling AES-GCM via ssl_cipher_get_evp(). | jsing | 2018-09-03 | 1 | -20/+3 |
| | | | | | | | All of the AES-GCM ciphersuites use the EVP_AEAD interface, so there is no need to support them via EVP_CIPHER. ok inoguchi@ tb@ | ||||
* | Clean up SSL_DES and SSL_IDEA remnants. | jsing | 2018-09-03 | 1 | -41/+13 |
| | | | | | | | All ciphersuites that used these encryption algorithms were removed some time ago. ok bcook@ inoguchi@ tb@ | ||||
* | Remove a few unnecessary casts | tb | 2018-09-02 | 1 | -5/+5 |
| | |||||
* | Print SKIPPED if package wycheproof-testvectors is missing. This | bluhm | 2018-09-02 | 1 | -2/+2 |
| | | | | | is the magic string that is recognized by my test framework. OK tb@ | ||||
* | Remove ECDH from TODO list. Done! | tb | 2018-09-02 | 1 | -2/+1 |
| | |||||
* | Unify FAIL printfs. | tb | 2018-09-02 | 1 | -8/+8 |
| | |||||
* | After libcrypto/ecdh/ech_key.c -r1.8 fixed the failing test cases, remove | tb | 2018-09-02 | 1 | -13/+3 |
| | | | | two noisy INFO and reorder things a bit. | ||||
* | Elliptic curve arithmetic only makes sense between points that belong to | tb | 2018-09-02 | 1 | -1/+5 |
| | | | | | | | | | | | | the same curve. Some Wycheproof tests violate this assumption, making ECDH_compute_key() compute and return garbage. Check that pub_key lies on the curve of the private key so that the calculations make sense. Most paths that get here have this checked (in particular those from OpenSSH and libssl), but one might get here after using d2i_* or manual computation. discussed with & ok jsing; "good catch!" markus | ||||
* | Run Wycheproof ECDH tests against libcrypto. Some tests currently fail, | tb | 2018-09-02 | 1 | -1/+154 |
| | | | | will be fixed with the next commit to libcrypto. | ||||
* | Use a Boolean rather than repeated string comparison. | tb | 2018-09-02 | 1 | -3/+5 |
| | |||||
* | Tweak comment. | tb | 2018-09-01 | 1 | -5/+2 |
| | |||||
* | Remove RSA-PSS from todo-list | tb | 2018-09-01 | 1 | -2/+2 |
| | |||||
* | Run Wycheproof RSASSA-PSS testvectors against libcrypto. | tb | 2018-09-01 | 1 | -2/+144 |
| | |||||
* | Remove unused argument to tls1_change_cipher_state_cipher(). | jsing | 2018-08-31 | 1 | -7/+4 |
| | |||||
* | Instead of enumerating the files to clean by hand, set PROGS=${TESTS}. | tb | 2018-08-31 | 2 | -5/+7 |
| | | | | Suggested by jsing | ||||
* | Make sure to clean up the .d files with 'make clean' | tb | 2018-08-30 | 1 | -2/+2 |
| | |||||
* | Nuke ssl_pending/ssl_shutdown function pointers. | jsing | 2018-08-30 | 9 | -56/+14 |
| | | | | | | | ssl3_pending() is used for all protocols and dtls1_shutdown() just calls ssl3_shutdown(), so just call the appropriate function directly instead. ok beck@ inoguchi@ tb@ | ||||
* | AES is now done also. | tb | 2018-08-29 | 1 | -3/+3 |
| | |||||
* | Pass algorithm as a string to all *TestGroup functions for consistency. | tb | 2018-08-29 | 1 | -22/+22 |
| | |||||
* | Run Wycheproof AES-GCM testvectors against libcrypto. | tb | 2018-08-29 | 1 | -42/+83 |
| | |||||
* | Calculate and check tag during AES-CCM encryption test. | tb | 2018-08-29 | 1 | -1/+25 |
| | |||||
* | typo | tb | 2018-08-29 | 1 | -2/+2 |
| | |||||
* | Don't fatal on keys of invalid sice, just print an INFO. | tb | 2018-08-29 | 1 | -2/+3 |
| | |||||
* | Run Wycheproof AES-CMAC testvectors against libcrypto. | tb | 2018-08-28 | 1 | -2/+116 |
| | |||||
* | remove some extra parens and fix some other formatting issues | tb | 2018-08-28 | 1 | -17/+17 |
| | | | | pointed out by gofmt (thanks anton) | ||||
* | Remove extra "and" in "These functions and have been available" | tb | 2018-08-28 | 1 | -3/+3 |
| | |||||
* | zap trailing whitespace | tb | 2018-08-28 | 1 | -7/+7 |
| | |||||
* | Drop SSLv2, SSLv3 support. | cheloha | 2018-08-28 | 1 | -6/+2 |
| | | | | | | | No need to check for SSLv2/3 sessions when printing the tally mark. Also do SSLv23_client_method -> TLS_client_method. ok jsing@ | ||||
* | Check for SSL_write(3) error. | cheloha | 2018-08-28 | 1 | -3/+4 |
| | | | | | | | | | | jsing@ notes that this is not a complete solution, as we don't account for retries or partial writes, but that this is a step in a right direction. May want to revisit this later to provide a complete solution. ok jsing@ | ||||
* | tweak failure messages | tb | 2018-08-27 | 1 | -9/+9 |
| | |||||
* | dedup AES-CBC-PKCS5 encryption and decryption checks | tb | 2018-08-27 | 1 | -66/+24 |
| | |||||
* | 2x missing "..." | tb | 2018-08-27 | 1 | -3/+3 |
| | |||||
* | Run Wycheproof AES-CCM testvectors against libcrypto. | tb | 2018-08-27 | 1 | -2/+200 |
| | |||||
* | n2s and l2n3 finally bite the dust! | jsing | 2018-08-27 | 1 | -7/+1 |
| | |||||
* | Convert ssl3_get_cert_verify() to CBS and clean up somewhat. | jsing | 2018-08-27 | 1 | -74/+72 |
| | | | | ok inoguchi@ |