1. 29d1655 Add MBEDTLS_ECDH_C guards to ECDH code-paths using legacy ECDH by Hanno Becker · 6 years ago
  2. 975b9ee Fix guards around use of legacy ECDH context by Hanno Becker · 6 years ago
  3. 621113f tinyCrypt: Write client's key share by Hanno Becker · 6 years ago
  4. a3c2c17 tinyCrypt: Share ECDH secret calculation code-path by Hanno Becker · 6 years ago
  5. 75f12d1 tinyCrypt: Add ServerKeyExchange parsing code by Hanno Becker · 6 years ago
  6. ef982d5 tinyCrypt: Bind RNG wrapper to tinyCrypt in mbedtls_ssl_setup() by Hanno Becker · 6 years ago
  7. e12aafb tinyCrypt: Initial commit towards ECDHE support by Jarno Lamsa · 6 years ago
  8. 3328b18 Move ssl_process_in_server_key_exchange to avoid func use-before-def by Hanno Becker · 6 years ago
  9. 4e46709 Document precoditions on some HS parsing/writing functions by Hanno Becker · 6 years ago
  10. 7d552fa Avoid collision of ssl_xxx_key_exchange_yyy() func names in cli/srv by Hanno Becker · 6 years ago
  11. 48e526b Document parameter precondition for ssl_rsa_generate_partial_pms() by Hanno Becker · 6 years ago
  12. aa49620 Minor documentation improvement to ssl_rsa_encrypt_partial_pms() by Hanno Becker · 6 years ago
  13. 084694d Fix copy-pasta in documentation for outgoing CliKeyExchange by Hanno Becker · 6 years ago
  14. 44a29f4 Remove redundant use of local variable in CliKeyExch writing by Hanno Becker · 6 years ago
  15. ae22dd3 Simplify logic of restartable ECDHE in CliKeyExch writing by Hanno Becker · 6 years ago
  16. 91cf769 Remove restartable ECP return code check from ECDH suite handling by Hanno Becker · 6 years ago
  17. 8793fab Fix two typos in comments by Manuel Pégourié-Gonnard · 6 years ago
  18. 587c1ae Make IAR happy by dummy-initializing an unused variable by Hanno Becker · 6 years ago
  19. a855cb6 Avoid unused variable warning in ServerKeyExchange parsing by Hanno Becker · 6 years ago
  20. 868cb58 Rename SSL_PROC_CHK -> MBEDTLS_SSL_CHK by Hanno Becker · 6 years ago
  21. 9a12243 Introduce getter function for RNG context by Hanno Becker · 6 years ago
  22. 4ec73cb Restructure SrvKeyExchange: Move parsing code by Hanno Becker · 6 years ago
  23. 8b7b879 Restructure SrvKeyExchange: Move msg skipping for PSK and RSA-PSK by Hanno Becker · 7 years ago
  24. eb76c20 Restructure SrvKeyExchange: Move code for skipping SrvKeyExchange by Hanno Becker · 7 years ago
  25. fca604d Restructure SrvKeyExchange: Move static DH parameter extraction by Hanno Becker · 7 years ago
  26. 04769dd Restructure SrvKeyExchange: Add frame for structure by Hanno Becker · 7 years ago
  27. 09d2364 Share code between In-CliKeyExch and Out-CliKeyExch by Hanno Becker · 6 years ago
  28. 4f68b04 Restructure outgoing CliKeyExch: Remove old code by Hanno Becker · 6 years ago
  29. 87e3c9a Restructure outgoing CliKeyExch: Move writing code by Hanno Becker · 7 years ago
  30. 01290c7 Restructure outgoing CliKeyExch: Move RSA/RSA-PSK PMS generation by Hanno Becker · 7 years ago
  31. 6fb638b Restructure outgoing CliKeyExch: Move PMS assembly code by Hanno Becker · 7 years ago
  32. 5d39768 Restructure outgoing CliKeyExch: Add frame for new structure by Hanno Becker · 7 years ago
  33. de62da9 Use separate functions to pend fatal and non-fatal alerts by Hanno Becker · 6 years ago
  34. 1facd55 Replace xxx_send_alert by xxx_pend_alert to save code by Hanno Becker · 6 years ago
  35. 3b014fc Merge remote-tracking branch 'origin/pr/604' into baremetal by Simon Butcher · 6 years ago
  36. 981f81d Add missing uses of mbedtls_ssl_get_minor() by Hanno Becker · 6 years ago
  37. f1bc9e1 Introduce helper functions to traverse signature hashes by Hanno Becker · 6 years ago
  38. feb1cee Merge remote-tracking branch 'origin/pr/602' into baremetal by Simon Butcher · 6 years ago
  39. 7decea9 Simplify supported EC extension writing code by Hanno Becker · 6 years ago
  40. a4a9c69 Introduce helper macro for traversal of supported EC TLS IDs by Hanno Becker · 6 years ago
  41. 8085588 Remove unnecessary guards in client-side EC curve extension writing by Hanno Becker · 6 years ago
  42. 381eaa5 Remove min/maj version from SSL context if only one version enabled by Hanno Becker · 6 years ago
  43. 2881d80 Introduce getter function for max/min SSL version by Hanno Becker · 6 years ago
  44. 3fa1ee5 Set SSL minor version only after validation by Hanno Becker · 6 years ago
  45. e965bd3 Allow hardcoding of min/max minor/major SSL version at compile-time by Hanno Becker · 6 years ago
  46. f4d6b49 Allow use of continue in single-ciphersuite 'loops' by Hanno Becker · 6 years ago
  47. 73f4cb1 Rename XXX_SINGLE_CIPHERSUITE -> XXX_CONF_SINGLE_CIPHERSUITE by Hanno Becker · 6 years ago
  48. e02758c Remove ciphersuite from SSL session if single suite hardcoded by Hanno Becker · 6 years ago
  49. df64596 Remove ciphersuite from handshake params if single suite hardcoded by Hanno Becker · 6 years ago
  50. 1499027 Adapt ClientHello writing to case of single hardcoded ciphersuite by Hanno Becker · 6 years ago
  51. 473f98f Introduce ciphersuite handle type by Hanno Becker · 6 years ago
  52. ece325c Allow compile-time configuration of PRNG in SSL module by Hanno Becker · 6 years ago
  53. 44ba6b0 Merge remote-tracking branch 'restricted/pr/594' into baremetal-proposed by Manuel Pégourié-Gonnard · 6 years ago
  54. 37261e6 Merge remote-tracking branch 'restricted/pr/601' into baremetal-proposed by Manuel Pégourié-Gonnard · 6 years ago
  55. 417d2ce Merge remote-tracking branch 'restricted/pr/584' into baremetal-proposed by Manuel Pégourié-Gonnard · 6 years ago
  56. b0b2b67 Allow compile-time configuration of legacy renegotiation by Hanno Becker · 6 years ago
  57. 93c8262 Clarify conditions related to resumption in client by Manuel Pégourié-Gonnard · 6 years ago
  58. 754b9f3 Introduce getter function for renego_status by Manuel Pégourié-Gonnard · 6 years ago
  59. 3652e99 Add getter function for handshake->resume by Manuel Pégourié-Gonnard · 6 years ago
  60. 44b1076 Remove now-redundant code by Manuel Pégourié-Gonnard · 6 years ago
  61. 594a1bb Fix a few style issues by Manuel Pégourié-Gonnard · 6 years ago
  62. 29f2dd0 Address review comments by Jarno Lamsa · 6 years ago
  63. dbf6073 Fix ssl_cli resumption guards by Jarno Lamsa · 6 years ago
  64. 5165169 Fix test issues by Jarno Lamsa · 6 years ago
  65. 59bd12b Add new config MBEDTLS_SSL_SESSION_RESUMPTION by Jarno Lamsa · 6 years ago
  66. 2224ccf Don't use assertion for failures of mbedtls_x509_crt_x_acquire() by Hanno Becker · 6 years ago
  67. c6d1c3e Remove frame/pk parameter from mbedtls_x509_crt_xxx_release() by Hanno Becker · 6 years ago
  68. 2fefa48 Make use of acquire/release in ssl_parse_server_key_exchange() by Hanno Becker · 6 years ago
  69. 39ae65c Make use of acquire/release in ssl_get_ecdh_params_from_cert() by Hanno Becker · 6 years ago
  70. 0c16816 Make use of acquire/release in client-side ssl_write_encrypted_pms() by Hanno Becker · 6 years ago
  71. 1ab322b Remove extended_ms field from HS param if ExtendedMS enforced by Hanno Becker · 6 years ago
  72. 03b64fa Rearrange ExtendedMasterSecret parsing logic by Hanno Becker · 6 years ago
  73. aabbb58 Exemplify harcoding SSL config at compile-time in example of ExtMS by Hanno Becker · 6 years ago
  74. 5882dd0 Remove CRT digest from SSL session if !RENEGO + !KEEP_PEER_CERT by Hanno Becker · 6 years ago
  75. c39e23e Add further debug statements on assertion failures by Hanno Becker · 6 years ago
  76. e9839c0 Add debug output in case of assertion failure by Hanno Becker · 6 years ago
  77. 6c83db7 Free peer's public key as soon as it's no longer needed by Hanno Becker · 6 years ago
  78. 69fad13 Adapt client-side signature verification to use raw public key by Hanno Becker · 6 years ago
  79. 53b6b7e Adapt ssl_get_ecdh_params_from_cert() to use raw public key by Hanno Becker · 6 years ago
  80. 374800a Adapt ssl_write_encrypted_pms() to use raw public key by Hanno Becker · 6 years ago
  81. f02d550 Re-classify errors on missing peer CRT by Hanno Becker · 6 years ago
  82. ae39b9e Make use of macro and helper detecting whether CertRequest allowed by Hanno Becker · 6 years ago
  83. c725e4b Merge remote-tracking branch 'origin/pr/590' into baremetal by Simon Butcher · 6 years ago
  84. 01a8eb2 Merge remote-tracking branch 'origin/pr/585' into baremetal by Simon Butcher · 6 years ago
  85. 20095af Changes according to review comments by Jarno Lamsa · 6 years ago
  86. 842be16 Check for the enforcing and fail handshake if the peer doesn't support by Jarno Lamsa · 6 years ago
  87. 64c1681 Use new macros for all TLS/DTLS tests by Manuel Pégourié-Gonnard · 6 years ago
  88. ff4bd9f Use new tools for all cases with TLS-specific code by Manuel Pégourié-Gonnard · 6 years ago
  89. 3d699e4 SSL/TLS client: Remove old session ticket on renegotiation by Hanno Becker · 7 years ago
  90. 0d1d76f Merge remote-tracking branch 'origin/pr/561' into baremetal by Simon Butcher · 6 years ago
  91. 5a790f9 Merge remote-tracking branch 'origin/pr/563' into baremetal by Simon Butcher · 6 years ago
  92. a5a2b08 Rename MBEDTLS_SSL_CID to MBEDTLS_SSL_DTLS_CONNECTION_ID by Hanno Becker · 6 years ago
  93. 3cdf8fe Consistently reference CID draft through name + URL by Hanno Becker · 6 years ago
  94. 75b334f Update references to CID draft to version 5 by Hanno Becker · 6 years ago
  95. f5970a0 Set pointer to start of plaintext at record decryption time by Hanno Becker · 6 years ago
  96. f885d3b Improve structure of client-side CID extension parsing by Hanno Becker · 6 years ago
  97. 8f68f87 Improve debugging output of client-side CID extension parsing by Hanno Becker · 6 years ago
  98. 1ba81f6 Implement parsing of CID extension in ServerHello by Hanno Becker · 6 years ago
  99. 39ec525 Implement writing of CID extension in ClientHello by Hanno Becker · 6 years ago
  100. a575975 Make calc_verify() return the length as well by Manuel Pégourié-Gonnard · 6 years ago