]>
git.ipfire.org Git - thirdparty/nettle.git/log
Niels Möller [Wed, 26 Dec 2018 16:49:31 +0000 (17:49 +0100)]
In openssl benchmarks, use RSA_generate_key_ex.
Niels Möller [Wed, 26 Dec 2018 16:27:00 +0000 (17:27 +0100)]
eccdata: Check that table size is at least 2.
Intended to silence warning from the clang static analyzer.
Niels Möller [Wed, 26 Dec 2018 15:30:04 +0000 (16:30 +0100)]
Bump version number and sonames, for Nettle-3.5
Niels Möller [Wed, 26 Dec 2018 15:19:17 +0000 (16:19 +0100)]
Delete obsolete TODO file
Niels Möller [Wed, 26 Dec 2018 15:18:09 +0000 (16:18 +0100)]
New header file pkcs1-internal.h
Niels Möller [Wed, 26 Dec 2018 10:30:21 +0000 (11:30 +0100)]
Merge branch 'release-3.4-fixes' into master
Niels Möller [Wed, 26 Dec 2018 10:07:51 +0000 (11:07 +0100)]
Fix compilation with gcc -std=c89
Niels Möller [Wed, 26 Dec 2018 10:04:31 +0000 (11:04 +0100)]
Fix accidental use of C99 for loop.
* rsa-sign-tr.c (sec_equal): Fix accidental use of C99 for loop.
Reported by Andreas Gustafsson.
* testsuite/rsa-sec-decrypt-test.c (test_main): Likewise.
Niels Möller [Tue, 4 Dec 2018 20:55:48 +0000 (21:55 +0100)]
Note release of Nettle-3.4.1.
Niels Möller [Wed, 28 Nov 2018 21:42:56 +0000 (22:42 +0100)]
Update NEWS file for 3.4.1.
Mention dependency on GMP-6, and RSA performance regression.
Niels Möller [Wed, 28 Nov 2018 21:33:47 +0000 (22:33 +0100)]
Update configure check to require GMP-6.0.0 or later.
Niels Möller [Wed, 28 Nov 2018 21:01:29 +0000 (22:01 +0100)]
Rewrite pkcs1_decrypt as a wrapper around _pkcs1_sec_decrypt_variable.
* testsuite/rsa-encrypt-test.c (test_main): Fix allocation of
decrypted storage. Update test of rsa_decrypt, to allow clobbering
of all of the passed in message area.
Niels Möller [Wed, 28 Nov 2018 20:54:15 +0000 (21:54 +0100)]
Add rsa-internal.h to distributed headers.
Patch from Simo Sorce.
Niels Möller [Wed, 28 Nov 2018 20:52:30 +0000 (21:52 +0100)]
rsa-internal.h: Add include of rsa.h.
Niels Möller [Tue, 27 Nov 2018 07:56:27 +0000 (08:56 +0100)]
Describe RSA improvements in NEWS.
Niels Möller [Tue, 27 Nov 2018 07:21:02 +0000 (08:21 +0100)]
Rewrote _rsa_sec_compute_root, for clarity.
Use new local helper functions, with their own itch functions.
Niels Möller [Mon, 26 Nov 2018 06:32:28 +0000 (07:32 +0100)]
rsa-compute-root-test: Fix qsize. Try more keys.
Niels Möller [Sun, 25 Nov 2018 20:57:59 +0000 (21:57 +0100)]
Update mini-gmp version for _rsa_sec_compute_root_tr rename.
Niels Möller [Sun, 25 Nov 2018 19:29:07 +0000 (20:29 +0100)]
Renamed rsa-sec-compute-root-test --> rsa-compute-root-test.
Niels Möller [Sun, 25 Nov 2018 19:10:13 +0000 (20:10 +0100)]
cnd_mpn_zero: Use a volatile-declared mask variable.
Niels Möller [Sun, 25 Nov 2018 18:46:30 +0000 (19:46 +0100)]
Move decl. of rsa_sec_compute_root_tr to internal header.
Also renamed with leading underscore, and updated all callers.
Simo Sorce [Sun, 25 Nov 2018 18:23:38 +0000 (19:23 +0100)]
Switch rsa_compute_root to use side-channel safe variant
Niels Möller [Sun, 25 Nov 2018 17:53:55 +0000 (18:53 +0100)]
ChangeLog for previous change.
Simo Sorce [Fri, 9 Nov 2018 22:32:04 +0000 (17:32 -0500)]
Randomzed testing of rsa-sec-compute-root
Signed-off-by: Simo Sorce <simo@redhat.com>
Niels Möller [Sun, 25 Nov 2018 16:11:39 +0000 (17:11 +0100)]
testutils.c: Fix high bits of the mpz_urandomb used with mini-gmp.
Niels Möller [Sun, 25 Nov 2018 16:06:21 +0000 (17:06 +0100)]
ChangeLog for previous change.
Simo Sorce [Thu, 8 Nov 2018 16:27:05 +0000 (11:27 -0500)]
Catch bad private keys early on.
Niels Möller [Sun, 25 Nov 2018 15:58:38 +0000 (16:58 +0100)]
Use NETTLE_OCTET_SIZE_TO_LIMB_SIZE.
Niels Möller [Sun, 25 Nov 2018 15:57:27 +0000 (16:57 +0100)]
ChangeLog for previous change.
Simo Sorce [Mon, 12 Nov 2018 22:06:31 +0000 (17:06 -0500)]
Use side-channel silent pkcs1 in rsa_decrypt_tr
Signed-off-by: Simo Sorce <simo@redhat.com>
Niels Möller [Sun, 25 Nov 2018 15:47:23 +0000 (16:47 +0100)]
ChangeLog entry, and minor comment fixes
Simo Sorce [Mon, 12 Nov 2018 18:54:47 +0000 (13:54 -0500)]
Add variable len pkcs1-sec decoding function
add a side-channel silent pkcs1 decoding function for use in older
APIs.
Signed-off-by: Simo Sorce <simo@redhat.com>
Niels Möller [Sun, 25 Nov 2018 15:23:06 +0000 (16:23 +0100)]
Tweak valgrind marking is rsa_sec_decrypt tests.
* testsuite/rsa-sec-decrypt-test.c (rsa_decrypt_for_test): Tweak
valgrind marking, and document potential leakage of lowest and
highest bits of p and q.
Niels Möller [Sun, 25 Nov 2018 15:10:11 +0000 (16:10 +0100)]
Avoid calls to mpz_sizeinbase on RSA private key.
* rsa-sec-compute-root.c (_rsa_sec_compute_root): Avoid calls to
mpz_sizeinbase, since that potentially leaks most significant bits
of private key parameters a and b.
Niels Möller [Sun, 25 Nov 2018 15:05:40 +0000 (16:05 +0100)]
ChangeLog for previous change.
Simo Sorce [Mon, 15 Oct 2018 20:01:52 +0000 (16:01 -0400)]
Unit test for rsa_sec_decyrpt
Signed-off-by: Simo Sorce <simo@redhat.com>
Niels Möller [Sun, 25 Nov 2018 10:14:26 +0000 (11:14 +0100)]
ChangeLog for previous change.
Simo Sorce [Wed, 10 Oct 2018 20:15:49 +0000 (16:15 -0400)]
Add rsa_sec_decrypt as side-channel silent variant
Use side-channel silent RSA root function as well as PKCS1 padding
functions.
This variant accepts only a fixed length message, and returns error
if the pkcs1 padding returns a different length message.
The buffer is always left unchanged on error so that a TLS
implementation can pre-initialize it with a random key to use on
decoding error.
Signed-off-by: Simo Sorce <simo@redhat.com>
Niels Möller [Sun, 25 Nov 2018 09:38:23 +0000 (10:38 +0100)]
pkcs1-sec-decrypt-test.c: Fix valgrind marking of return value.
Niels Möller [Sun, 25 Nov 2018 09:37:22 +0000 (10:37 +0100)]
ChangeLog for previous change.
Simo Sorce [Tue, 23 Oct 2018 22:14:30 +0000 (18:14 -0400)]
Unit test for pkcs1-sec-decrypt
Signed-off-by: Simo Sorce <simo@redhat.com>
Niels Möller [Sun, 25 Nov 2018 09:29:02 +0000 (10:29 +0100)]
ChangeLog for previous change.
Simo Sorce [Mon, 12 Nov 2018 18:59:06 +0000 (13:59 -0500)]
Add mpn_get_base256
Converts limbs to uint8_t buffer without conditional jumps.
Signed-off-by: Simo Sorce <simo@redhat.com>
Niels Möller [Sun, 25 Nov 2018 09:22:38 +0000 (10:22 +0100)]
ChangeLog for previous change.
Simo Sorce [Thu, 8 Nov 2018 19:38:12 +0000 (14:38 -0500)]
Add side-channel silent pkcs1 decoding function
Signed-off-by: Simo Sorce <simo@redhat.com>
Niels Möller [Sat, 24 Nov 2018 10:44:01 +0000 (11:44 +0100)]
ChangeLog for previous change.
Simo Sorce [Mon, 15 Oct 2018 19:02:50 +0000 (15:02 -0400)]
Add a side-channel silent conditional memcpy
Originally from Niels, with minor changes to avoid compiler warnings.
Niels Möller [Sat, 24 Nov 2018 10:27:39 +0000 (11:27 +0100)]
ChangeLog entries, minor comment and spacing fixes
Simo Sorce [Thu, 8 Nov 2018 16:59:48 +0000 (11:59 -0500)]
Use side-channel silent root for rsa signatures
Signed-off-by: Simo Sorce <simo@redhat.com>
Niels Möller [Sat, 24 Nov 2018 09:43:35 +0000 (10:43 +0100)]
ChangeLog entry and comment fixes.
Simo Sorce [Thu, 8 Nov 2018 16:15:59 +0000 (11:15 -0500)]
Add side-channel silent RSA root function
Signed-off-by: Simo Sorce <simo@redhat.com>
Niels Möller [Sat, 24 Nov 2018 09:28:42 +0000 (10:28 +0100)]
ChangeLog for previous change.
Simo Sorce [Thu, 8 Nov 2018 19:47:13 +0000 (14:47 -0500)]
Add convenience macro for size calculation
Returns number of limbs needed to contain N bytes long number.
Signed-off-by: Simo Sorce <simo@redhat.com>
Niels Möller [Sat, 24 Nov 2018 09:11:39 +0000 (10:11 +0100)]
Initial NEWS entries for nettle-3.4.1.
Niels Möller [Sat, 24 Nov 2018 09:09:31 +0000 (10:09 +0100)]
Bump version numbers for nettle-3.4.1.
* configure.ac: Bump package version to 3.4.1.
(LIBNETTLE_MINOR): Bump library version to 6.5.
(LIBHOGWEED_MINOR): Bump library version to 4.5.
Niels Möller [Tue, 16 Jan 2018 21:50:28 +0000 (22:50 +0100)]
Add "fall through" comment.
(cherry picked from commit
c4a814d77d475c474182e3e7051e4ac304e3c9e8 )
Niels Möller [Mon, 19 Nov 2018 20:24:29 +0000 (21:24 +0100)]
Copy .gitlab-ci.yml from master branch
Dmitry Eremin-Solenikov [Wed, 13 Jun 2018 09:41:40 +0000 (12:41 +0300)]
Fix quoting in autoconf ifunc test
* aclocal.m4 (NETTLE_CHECK_IFUNC): fix quoting so that
AC_LINK_IFELSE/AC_TRY_LINK is defined outside of this test.
Signed-off-by: Dmitry Eremin-Solenikov <dbaryshkov@gmail.com>
(cherry picked from commit
e07e5605b3da65e07c7fe5fcf1ce3b050595d1b5 )
Dominyk Tiller [Sun, 17 Jun 2018 17:20:09 +0000 (19:20 +0200)]
testsuite/symbols-test: Exclude ____chkstk_darwin symbols.
These are produced by Apple's Xcode 10 compiler.
(cherry picked from commit
f3e2607fce0c6da41eb1d9ee89b9535d4abec7be )
Niels Möller [Sun, 18 Feb 2018 09:18:00 +0000 (10:18 +0100)]
Fix link failure for pss-mgf1-test, in non-hogweed builds.
(cherry picked from commit
c5fc9131b13d53b07b7aa371f30df8621cf2abb8 )
Niels Möller [Tue, 16 Jan 2018 21:49:37 +0000 (22:49 +0100)]
tools/pkcs1-conv.c: Add missing break statements.
(cherry picked from commit
20c7ba59e2cb54f1bec7d679dbdbe00c42bdd190 )
Niels Möller [Thu, 9 Aug 2018 18:54:18 +0000 (20:54 +0200)]
Avoid cast between incompatible function types.
(cherry picked from commit
71f68cc45a269b206fc996309ef026f39d5af3df )
Niels Möller [Wed, 10 Oct 2018 17:16:40 +0000 (19:16 +0200)]
Add missing includes of stdlib.h.
(cherry picked from commit
7b4d6de8044e73849c2f24ce0322ae3fc48765a6 )
Niels Möller [Thu, 9 Aug 2018 18:27:57 +0000 (20:27 +0200)]
des-compat.c: Change length argument type from uint32_t to size_t.
(cherry picked from commit
f3bbc422efed4149b5661e064360ee678b23113a )
Niels Möller [Sat, 17 Nov 2018 13:23:06 +0000 (14:23 +0100)]
Add benchmarking of RSA signatures with blinding
Dmitry Eremin-Solenikov [Wed, 10 Oct 2018 17:26:25 +0000 (19:26 +0200)]
ctr16: fix encryption if src == dst
Niels Möller [Wed, 10 Oct 2018 17:16:40 +0000 (19:16 +0200)]
Add missing includes of stdlib.h.
Niels Möller [Thu, 13 Sep 2018 06:18:16 +0000 (08:18 +0200)]
rsa_generate_keypair: Delete unlikely and redundant check for p == q.
Niels Möller [Thu, 13 Sep 2018 06:14:09 +0000 (08:14 +0200)]
Merge branch 'attribute-deprecated'
Niels Möller [Fri, 7 Sep 2018 07:09:37 +0000 (09:09 +0200)]
Fix mis-spelling spotted by Torbjörn Granlund.
Niels Möller [Thu, 9 Aug 2018 20:00:03 +0000 (22:00 +0200)]
Mark obsolete helpers _rsa_blind and _rsa_unblind as deprecated.
Niels Möller [Thu, 9 Aug 2018 19:53:55 +0000 (21:53 +0200)]
Deprecate old AES interface.
Use new macro _NETTLE_ATTTRIBUTE_DEPRECATED.
Niels Möller [Thu, 9 Aug 2018 19:09:11 +0000 (21:09 +0200)]
New macro _NETTLE_ATTRIBUTE_PURE.
Niels Möller [Thu, 9 Aug 2018 18:54:18 +0000 (20:54 +0200)]
Avoid cast between incompatible function types.
Niels Möller [Thu, 9 Aug 2018 18:27:57 +0000 (20:27 +0200)]
des-compat.c: Change length argument type from uint32_t to size_t.
Niels Möller [Wed, 8 Aug 2018 20:31:01 +0000 (22:31 +0200)]
nettle.texinfo: New section on ABI and API compatibility.
Niels Möller [Mon, 30 Jul 2018 16:36:14 +0000 (18:36 +0200)]
ChangeLog entry for previous change.
Dmitry Eremin-Solenikov [Wed, 25 Jul 2018 11:53:21 +0000 (14:53 +0300)]
Add benchmarking for HMAC functions
In preparation of changing internal HMAC interface add benchmarking for
HMAC functions.
Signed-off-by: Dmitry Eremin-Solenikov <dbaryshkov@gmail.com>
Niels Möller [Fri, 13 Jul 2018 18:18:46 +0000 (20:18 +0200)]
Additional analogous assert in eratosthenese program.
Niels Möller [Fri, 13 Jul 2018 17:38:59 +0000 (19:38 +0200)]
Check for allocation overflow in eratosthenes program.
Niels Möller [Thu, 12 Jul 2018 20:39:00 +0000 (22:39 +0200)]
Fix handling of eratosthenes -q.
Niels Möller [Thu, 12 Jul 2018 20:37:36 +0000 (22:37 +0200)]
Fix at-exit leak in eratosthenes program.
Niels Möller [Thu, 12 Jul 2018 20:34:01 +0000 (22:34 +0200)]
Make eccdata deallocate storage before exit.
Niels Möller [Thu, 12 Jul 2018 20:32:59 +0000 (22:32 +0200)]
Fix memory leak in eccdata.
Nikos Mavrogiannopoulos [Tue, 10 Jul 2018 18:58:36 +0000 (20:58 +0200)]
.gitlab-ci.yml: added cross compilation and tests on mips/aarch64/arm
This utilizes the qemu-user system used by gnutls. This also
deprecates the previous aarch64 build.
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
Niels Möller [Thu, 12 Jul 2018 08:24:00 +0000 (10:24 +0200)]
Fix arm fat setup for nettle_sha1_compress.
Nikos Mavrogiannopoulos [Mon, 9 Jul 2018 06:44:09 +0000 (08:44 +0200)]
.gitlab-ci.yml: updated build images to latest used by gnutls
Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
Niels Möller [Sun, 8 Jul 2018 07:57:04 +0000 (09:57 +0200)]
Fix x86_64 fat setup for nettle_sha1_compress.
Nikos Mavrogiannopoulos [Tue, 12 Jun 2018 11:26:00 +0000 (13:26 +0200)]
.gitlab-ci.yml: link with shared library on x86-64 build
This allows testing whether exported symbols are sufficient for the
included test suite.
Niels Möller [Sat, 7 Jul 2018 20:10:41 +0000 (22:10 +0200)]
Add two missing includes of the new internal headers.
Niels Möller [Sat, 7 Jul 2018 20:10:03 +0000 (22:10 +0200)]
ChangeLog for previous change.
Nikos Mavrogiannopoulos [Wed, 6 Jun 2018 13:17:00 +0000 (15:17 +0200)]
abi: explicitly export intended symbols and hide others
This adds all exported symbols in the map files explicitly under
the following rules:
- Symbols mentioned in internal headers go in a section which is
valid only for testing, and linking with these symbols will break
in library updates.
- Symbols mentioned in installed headers go in the exported sections
and are considered part of the ABI.
- All internal symbols move to internal headers.
- The _nettle_md5_compress and _nettle_sha1_compress become exported
without the _nettle prefix, due to existing usage.
Niels Möller [Sat, 7 Jul 2018 19:24:26 +0000 (21:24 +0200)]
Comment fix.
Niels Möller [Sun, 17 Jun 2018 17:29:12 +0000 (19:29 +0200)]
ChangeLog entry for previous change.
Dmitry Eremin-Solenikov [Wed, 13 Jun 2018 09:41:40 +0000 (12:41 +0300)]
Fix quoting in autoconf ifunc test
* aclocal.m4 (NETTLE_CHECK_IFUNC): fix quoting so that
AC_LINK_IFELSE/AC_TRY_LINK is defined outside of this test.
Signed-off-by: Dmitry Eremin-Solenikov <dbaryshkov@gmail.com>
Dominyk Tiller [Sun, 17 Jun 2018 17:20:09 +0000 (19:20 +0200)]
testsuite/symbols-test: Exclude ____chkstk_darwin symbols.
These are produced by Apple's Xcode 10 compiler.
Niels Möller [Tue, 27 Mar 2018 21:07:50 +0000 (23:07 +0200)]
Merge branch 'rename-data-symbols' into master-updates
Niels Möller [Sun, 25 Mar 2018 20:29:25 +0000 (22:29 +0200)]
Update NEWS file.
Niels Möller [Sun, 25 Mar 2018 09:42:48 +0000 (11:42 +0200)]
ChangeLog entries for ARM big-endian changes.
Michael Weiser [Tue, 13 Feb 2018 21:13:14 +0000 (22:13 +0100)]
Document arm endianness considerations
Extend arm/README to provide some background on considerations to be taken into
account when writing assembly routines supposed to work in big and little memory
endianness.