]>
git.ipfire.org Git - thirdparty/nettle.git/log
Niels Möller [Tue, 16 May 2023 19:11:04 +0000 (21:11 +0200)]
x86_64: Fix alignment bug in _nettle_ghash_update.
Niels Möller [Mon, 15 May 2023 18:01:14 +0000 (20:01 +0200)]
Fix mpz_init/mpz_clear usage in eccdata.c.
Niels Möller [Sun, 14 May 2023 15:03:00 +0000 (17:03 +0200)]
ChangeLog entry for 3.9 release.
Niels Möller [Fri, 12 May 2023 19:43:00 +0000 (21:43 +0200)]
Delete unused file texinfo.tex.
Niels Möller [Fri, 12 May 2023 19:36:50 +0000 (21:36 +0200)]
Update config.guess, config.sub and install-sh to latest gnulib versions.
Niels Möller [Fri, 12 May 2023 19:15:23 +0000 (21:15 +0200)]
Document Nettle-3.9 known issues.
Simon Josefsson [Thu, 11 May 2023 19:02:00 +0000 (21:02 +0200)]
Doc fix for version and date.
Simon Josefsson [Thu, 11 May 2023 18:42:00 +0000 (20:42 +0200)]
Improve ARCFOUR docs.
Niels Möller [Wed, 10 May 2023 14:59:28 +0000 (16:59 +0200)]
Fix compile error in --disable-public-key configuration.
Justus Winter [Tue, 9 May 2023 05:49:54 +0000 (07:49 +0200)]
Fixes to OCB documentation.
Niels Möller [Sun, 7 May 2023 14:32:39 +0000 (16:32 +0200)]
Update NEWS.
Niels Möller [Sun, 7 May 2023 14:26:45 +0000 (16:26 +0200)]
Update version numbers for Nettle-3.9.
Niels Möller [Sun, 7 May 2023 13:30:40 +0000 (15:30 +0200)]
NEWS entries for Nettle-3.9.
Niels Möller [Tue, 26 Jul 2022 18:35:55 +0000 (20:35 +0200)]
NEWS entries for Nettle-3.8.1
(cherry picked from commit
f441231f77687c00acf66971bcfbd1dd97776f97 )
Niels Möller [Tue, 25 Apr 2023 18:51:40 +0000 (20:51 +0200)]
Rework SIV tests.
Niels Möller [Mon, 24 Apr 2023 17:47:53 +0000 (19:47 +0200)]
Rework OCB tests.
Niels Möller [Sun, 23 Apr 2023 19:06:59 +0000 (21:06 +0200)]
ChangeLog update.
Niels Möller [Sun, 23 Apr 2023 19:05:44 +0000 (21:05 +0200)]
Delete an obsolete comment and an obsolete forward declaration.
Niels Möller [Sun, 23 Apr 2023 18:56:11 +0000 (20:56 +0200)]
Rename siv-test.c --> siv-cmac-test.c.
Niels Möller [Fri, 21 Apr 2023 12:53:33 +0000 (14:53 +0200)]
Document OCB support.
Niels Möller [Fri, 21 Apr 2023 12:52:19 +0000 (14:52 +0200)]
Minor whitespace fix.
Niels Möller [Thu, 13 Apr 2023 17:11:25 +0000 (19:11 +0200)]
Rewrite of table-based ghash code, for side-channel silence.
Niels Möller [Fri, 7 Apr 2023 08:57:46 +0000 (08:57 +0000)]
Merge branch 'x86_ghash' into 'master'
Use Test instruction instead of And to check remaining single block
See merge request nettle/nettle!59
Maamoun TK [Mon, 3 Apr 2023 05:54:39 +0000 (05:54 +0000)]
Use Test instruction instead of And to check remaining single block
Justus Winter [Thu, 23 Feb 2023 10:06:51 +0000 (11:06 +0100)]
Update reference to the Yarrow paper.
Niels Möller [Mon, 3 Apr 2023 05:27:29 +0000 (07:27 +0200)]
ChangeLog and copyright update.
Niels Möller [Sun, 2 Apr 2023 12:52:45 +0000 (14:52 +0200)]
Merge branch 'nettle-x86_ghash' into master
See https://git.lysator.liu.se/nettle/nettle/-/merge_requests/57
Niels Möller [Sat, 25 Mar 2023 16:24:43 +0000 (17:24 +0100)]
New constant OCB_MAX_NONCE_SIZE.
Maamoun TK [Thu, 23 Mar 2023 22:23:09 +0000 (00:23 +0200)]
[x86_64] Use 2-way GHASH pclmul update
Niels Möller [Tue, 21 Feb 2023 06:53:18 +0000 (07:53 +0100)]
Add link to puthon bindings.
red@foxi.me [Wed, 15 Feb 2023 12:10:33 +0000 (12:10 +0000)]
midipix platform support
Signed-off-by: Ørjan Malde <red@foxi.me>
Niels Möller [Thu, 16 Feb 2023 19:18:59 +0000 (20:18 +0100)]
x86_64: Fix incorrect w64 setup in sha256_compress_n.asm.
Report and fix from Gisle Vanem.
Niels Möller [Thu, 16 Feb 2023 19:14:08 +0000 (20:14 +0100)]
x86_64: Comment fixes.
Niels Möller [Wed, 8 Feb 2023 07:35:09 +0000 (08:35 +0100)]
Add benchmarking of ocb_aes128.
Niels Möller [Tue, 7 Feb 2023 19:37:40 +0000 (20:37 +0100)]
Add tests of ocb message functions.
Niels Möller [Tue, 7 Feb 2023 19:04:03 +0000 (20:04 +0100)]
Implement OCB mode, RFC 7253.
Niels Möller [Mon, 6 Feb 2023 19:15:10 +0000 (20:15 +0100)]
Extend aead tests.
* testsuite/testutils.c (test_aead): Always use set_nonce function
pointer if non-NULL, test varying alignment, output the unexpected
data when test fails.
Niels Möller [Mon, 5 Dec 2022 14:20:02 +0000 (15:20 +0100)]
const-declare the xts_key argument to xts aes encrypt/decrypt message functions.
Niels Möller [Mon, 5 Dec 2022 14:15:22 +0000 (15:15 +0100)]
Add FIXME comment on ccm_aes128_encrypt_message, API could be improved.
Niels Möller [Thu, 10 Nov 2022 19:04:43 +0000 (20:04 +0100)]
Merge branch 'delete-arcfour-asm' into master
Niels Möller [Wed, 9 Nov 2022 19:55:46 +0000 (20:55 +0100)]
ChangeLog update.
Niels Möller [Wed, 9 Nov 2022 10:26:54 +0000 (11:26 +0100)]
Merge branch 'nettle-ppc-poly1305-multi' into master
See merge request nettle/nettle!56
Niels Möller [Wed, 9 Nov 2022 10:26:18 +0000 (11:26 +0100)]
Whitespace fixes.
Maamoun TK [Tue, 8 Nov 2022 06:19:33 +0000 (08:19 +0200)]
[PowerPC] Use INC_GPR/INC_VR marcos and define HAVE_NATIVE_poly1305_blocks in fat build
Niels Möller [Mon, 7 Nov 2022 19:18:20 +0000 (20:18 +0100)]
Add ASM_FLAGS variable to configure.
Niels Möller [Mon, 7 Nov 2022 19:13:30 +0000 (20:13 +0100)]
Comment fix
Maamoun TK [Sun, 6 Nov 2022 06:11:18 +0000 (06:11 +0000)]
Update BLOCK_R64 macro description
Maamoun TK [Sun, 6 Nov 2022 06:00:38 +0000 (08:00 +0200)]
[PowerPC] Move register allocation from poly1305.m4
Maamoun TK [Tue, 1 Nov 2022 06:09:44 +0000 (08:09 +0200)]
[PowerPC] Implement _nettle_poly1305_blocks based on radix 2^44
Niels Möller [Mon, 31 Oct 2022 18:18:24 +0000 (19:18 +0100)]
x86_64: Implement _nettle_poly1305_blocks.
Niels Möller [Mon, 31 Oct 2022 18:04:23 +0000 (19:04 +0100)]
New function _nettle_poly1305_update.
Niels Möller [Mon, 31 Oct 2022 17:48:52 +0000 (18:48 +0100)]
Minor comment fix.
Niels Möller [Thu, 20 Oct 2022 19:07:51 +0000 (19:07 +0000)]
Merge branch 'power7-chacha-fix' into 'master'
Fix illegal instruction in chacha-2core.asm on POWER7
See merge request nettle/nettle!54
Maamoun TK [Thu, 20 Oct 2022 12:54:19 +0000 (14:54 +0200)]
Fix illegal instruction in chacha-2core.asm on POWER7
Zoltan Fridrich [Sun, 16 Oct 2022 13:00:36 +0000 (15:00 +0200)]
Documentation of Balloon hash.
Maamoun TK [Thu, 13 Oct 2022 09:47:08 +0000 (11:47 +0200)]
Use updated version of qemu that emulates vmsumudm properly on ppc
Maamoun TK [Thu, 13 Oct 2022 09:46:50 +0000 (11:46 +0200)]
Undo workaround for unsupported vmsumudm on ppc
Maamoun TK [Thu, 13 Oct 2022 09:44:41 +0000 (11:44 +0200)]
Fix bug in poly1305-internal.asm affecting big-endian mode
Niels Möller [Thu, 13 Oct 2022 17:16:36 +0000 (19:16 +0200)]
Add back implementation of mpn_sec_tabselect, for mini-gmp builds.
Niels Möller [Tue, 11 Oct 2022 18:27:39 +0000 (20:27 +0200)]
Delete sec_tabselect, use gmp's mpn_sec_tabselect instead.
Niels Möller [Sun, 2 Oct 2022 15:56:16 +0000 (17:56 +0200)]
Add benchmarking of modulo q inversion.
Niels Möller [Thu, 29 Sep 2022 19:23:22 +0000 (21:23 +0200)]
Fix compiler warnings in the eccdata program.
Niels Möller [Thu, 29 Sep 2022 19:19:50 +0000 (21:19 +0200)]
ChangeLog update.
Niels Möller [Wed, 28 Sep 2022 17:29:15 +0000 (19:29 +0200)]
Delete ecc->mul_g and ecc->h_to_a indirection for ecdsa/gostdsa sign.
Niels Möller [Wed, 28 Sep 2022 17:21:50 +0000 (19:21 +0200)]
Delete ecc->mul and ecc->mul_g indirection for ecdsa/gostdsa verify.
Niels Möller [Wed, 28 Sep 2022 15:50:16 +0000 (17:50 +0200)]
Merge branch 'ecdsa-duplication-fix'
Niels Möller [Wed, 28 Sep 2022 15:46:27 +0000 (17:46 +0200)]
Comment update
Niels Möller [Wed, 28 Sep 2022 09:49:54 +0000 (11:49 +0200)]
Stricter validation of nettle_cipher and nettle_hash in tests.
Increase NETTLE_MAX_HASH_BLOCK_SIZE to 144, to accommodate sha3_224.
Niels Möller [Wed, 28 Sep 2022 08:59:36 +0000 (10:59 +0200)]
ChangeLog and AUTHORS update for SIV-GCM.
Niels Möller [Wed, 28 Sep 2022 08:46:41 +0000 (10:46 +0200)]
ChangeLog and AUTHORS update for Balloon.
Niels Möller [Wed, 28 Sep 2022 08:24:50 +0000 (08:24 +0000)]
Merge branch 'wip/dueno/aes-gcm-siv' into 'master'
Implement AES-GCM-SIV
See merge request nettle/nettle!52
Daiki Ueno [Tue, 16 Aug 2022 07:37:51 +0000 (16:37 +0900)]
Implement AES-GCM-SIV
This implements AES-GCM-SIV, described in RFC8452, on top of the
existing AES-GCM primitives. In particular, its hash algorithm
POLYVAL is implemented using the GHASH with additional byte order
conversion according to RFC8452 Appendix A.
Signed-off-by: Daiki Ueno <dueno@redhat.com>
Zoltan Fridrich [Sat, 24 Sep 2022 08:57:34 +0000 (10:57 +0200)]
Add Red Hat copyright lines.
Zoltan Fridrich [Sat, 24 Sep 2022 08:56:31 +0000 (10:56 +0200)]
Avoid calling hash update with NULL input (and zero length)
Zoltan Fridrich [Sat, 24 Sep 2022 08:54:38 +0000 (10:54 +0200)]
Delete fail variable in tests
Zoltan Fridrich [Wed, 14 Sep 2022 08:07:19 +0000 (10:07 +0200)]
Implement balloon password hashing
Niels Möller [Wed, 14 Sep 2022 14:17:52 +0000 (16:17 +0200)]
Fix ECDSA verify corner case
* ecc-ecdsa-verify.c (ecc_ecdsa_verify): Use ecc_nonsec_add_jjj,
to produce correct result in a corner case where point addition
needs to use point duplication. Also use ecc_j_to_a rather than
ecc->h_to_a, since ecdsa supports only weierstrass curves.
* ecc-gostdsa-verify.c (ecc_gostdsa_verify): Analogous change.
* testsuite/ecdsa-verify-test.c (test_main): Add corresponding test.
* testsuite/ecdsa-sign-test.c (test_main): And a test producing
the problematic signature.
Niels Möller [Wed, 14 Sep 2022 14:02:41 +0000 (16:02 +0200)]
New function ecc_nonsec_add_jjj
Niels Möller [Thu, 8 Sep 2022 18:24:16 +0000 (20:24 +0200)]
Cleanup of eccdata.
* eccdata.c (string_toupper): New utility function.
(output_modulo): Move more of the per-modulo output here.
(output_curve): Remove corresponding code.
Niels Möller [Wed, 31 Aug 2022 16:06:03 +0000 (18:06 +0200)]
Move bswap-related functions to bswap-internal.h.
Niels Möller [Fri, 19 Aug 2022 07:39:31 +0000 (09:39 +0200)]
Update AUTHORS file with SM4 contribution.
Niels Möller [Thu, 18 Aug 2022 14:51:48 +0000 (16:51 +0200)]
Add sm4.h to HEADERS.
Niels Möller [Thu, 18 Aug 2022 13:35:49 +0000 (15:35 +0200)]
ChangeLog entries for SM4.
Tianjia Zhang [Mon, 21 Feb 2022 08:37:16 +0000 (16:37 +0800)]
doc: documentation for GCM using SM4 cipher
Signed-off-by: Tianjia Zhang <tianjia.zhang@linux.alibaba.com>
Tianjia Zhang [Mon, 21 Feb 2022 08:37:15 +0000 (16:37 +0800)]
gcm: Add SM4 as the GCM underlying cipher
Signed-off-by: Tianjia Zhang <tianjia.zhang@linux.alibaba.com>
Niels Möller [Thu, 18 Aug 2022 09:31:47 +0000 (11:31 +0200)]
doc: Add menu items for SM4
Tianjia Zhang [Mon, 21 Feb 2022 08:37:14 +0000 (16:37 +0800)]
doc: documentation for SM4 cipher algorithm
Signed-off-by: Tianjia Zhang <tianjia.zhang@linux.alibaba.com>
Tianjia Zhang [Mon, 21 Feb 2022 08:37:13 +0000 (16:37 +0800)]
nettle-benchmark: bench SM4 symmetric algorithm
Signed-off-by: Tianjia Zhang <tianjia.zhang@linux.alibaba.com>
Tianjia Zhang [Mon, 21 Feb 2022 08:37:12 +0000 (16:37 +0800)]
testsuite: add test for SM4 symmetric algorithm
Add a testuite for SM4 symmetric algorithm. Test vectors are based
on: https://tools.ietf.org/id/draft-ribose-cfrg-sm4-10.html
Signed-off-by: Tianjia Zhang <tianjia.zhang@linux.alibaba.com>
Tianjia Zhang [Mon, 21 Feb 2022 08:37:11 +0000 (16:37 +0800)]
Introduce SM4 symmetric cipher algorithm
Introduce the SM4 cipher algorithms (OSCCA GB/T 32907-2016).
SM4 (GBT.32907-2016) is a cryptographic standard issued by the
Organization of State Commercial Administration of China (OSCCA)
as an authorized cryptographic algorithms for the use within China.
SMS4 was originally created for use in protecting wireless
networks, and is mandated in the Chinese National Standard for
Wireless LAN WAPI (Wired Authentication and Privacy Infrastructure)
(GB.15629.11-2003).
Signed-off-by: Tianjia Zhang <tianjia.zhang@linux.alibaba.com>
Niels Möller [Thu, 18 Aug 2022 07:54:42 +0000 (09:54 +0200)]
Change mips abi check to apply only to mips64.
Niels Möller [Wed, 17 Aug 2022 14:53:11 +0000 (16:53 +0200)]
tests: Define mpz_urandomm when building with mini-gmp.
Niels Möller [Tue, 16 Aug 2022 19:31:41 +0000 (21:31 +0200)]
Fix memory leak in new test.
Niels Möller [Tue, 16 Aug 2022 17:47:20 +0000 (19:47 +0200)]
Reduce output range of ecc_mod_sub.
* ecc-mod-arith.c (ecc_mod_sub): Ensure that if inputs are in the
range 0 <= a, b < 2m, then output is in the same range.
* eccdata.c (output_curve): New outputs ecc_Bm2p and ecc_Bm2q.
* ecc-internal.h (struct ecc_modulo): New member Bm2m (B^size -
2m), needed by ecc_mod_sub. Update all curves.
* testsuite/ecc-mod-arith-test.c: New tests for ecc_mod_add and
ecc_mod_sub.
Niels Möller [Tue, 16 Aug 2022 15:03:03 +0000 (17:03 +0200)]
Minor cleanup to eccdata program
Niels Möller [Mon, 15 Aug 2022 07:27:36 +0000 (09:27 +0200)]
Merge branch 'sha256-compress-n' into master-updates
Niels Möller [Sun, 14 Aug 2022 18:53:10 +0000 (20:53 +0200)]
Workaround for qemu bug affecting the ppc intruction vmsumudm
Introduce overriding environment variable NETTLE_FAT_DISABLE_POWER9
that disables use of power9 code. This makes poly1305 tests under qemu
pass. See https://gitlab.com/qemu-project/qemu/-/issues/1156.
Niels Möller [Sun, 7 Aug 2022 19:03:56 +0000 (21:03 +0200)]
Document hash compress functions, based on patch from Corentin Labbe.
Niels Möller [Sun, 7 Aug 2022 18:40:59 +0000 (20:40 +0200)]
Tweak to AC_CONFIG_SRCDIR.
* configure.ac: Refer to nettle-types.h, rather than arcfour.c,
for AC_CONFIG_SRCDIR.
Niels Möller [Sun, 7 Aug 2022 18:34:12 +0000 (20:34 +0200)]
Delete all arcfour assembly code