TrustedFirmware Git Browser
Code Review
Sign In
review.trustedfirmware.org
/
mirror
/
mbed-tls
/
af5ab918d92313c938a5628aa6e24fd3a288353c
af5ab91
Detect mismatching compile-time and cmd line config in ssl-opt.sh
by Hanno Becker
· 6 years ago
aa9fc6d
Update query_config.c
by Hanno Becker
· 6 years ago
ab1ce76
Mention possibility of hardcoding SSL config in ssl.h
by Hanno Becker
· 6 years ago
f765ce6
Remove ExtendedMS configuration API if hardcoded at compile-time
by Hanno Becker
· 6 years ago
57e72c7
Move getter functions for SSL configuration to ssl_internal.h
by Hanno Becker
· 6 years ago
4c4a2e1
Don't break func'def after linkage type, fixing check-names.sh
by Hanno Becker
· 6 years ago
1ab322b
Remove extended_ms field from HS param if ExtendedMS enforced
by Hanno Becker
· 6 years ago
a49ec56
Introduce getter function for `extended_ms` field in HS struct
by Hanno Becker
· 6 years ago
3010d55
Introduce helper macro indicating if use of ExtendedMS is enforced
by Hanno Becker
· 6 years ago
03b64fa
Rearrange ExtendedMasterSecret parsing logic
by Hanno Becker
· 6 years ago
aabbb58
Exemplify harcoding SSL config at compile-time in example of ExtMS
by Hanno Becker
· 6 years ago
393338c
Merge pull request #586 from ARMmbed/remove_peer_crt_after_handshake_no_digest-baremetal
by Manuel Pégourié-Gonnard
· 6 years ago
79cf74a
Merge pull request #583 from ARMmbed/remove_peer_crt_after_handshake-baremetal
by Manuel Pégourié-Gonnard
· 6 years ago
8dcd80e
Merge pull request #578 from ARMmbed/x509_parse_bf-baremetal
by Manuel Pégourié-Gonnard
· 6 years ago
cc3b7cc
Merge pull request #579 from Patater/bm-dont-use-non-existent-encrypt-then-mac
by Manuel Pégourié-Gonnard
· 6 years ago
e256f7c
Add test for !KEEP_PEER_CERTIFICATE + !RENEGOTIAITON to all.sh
by Hanno Becker
· 6 years ago
5882dd0
Remove CRT digest from SSL session if !RENEGO + !KEEP_PEER_CERT
by Hanno Becker
· 6 years ago
0528f82
Clarify documentation of serialized session format
by Hanno Becker
· 6 years ago
d972f00
Use consistent error messages in check_config.h
by Hanno Becker
· 6 years ago
17daaa5
Move return statement in ssl_srv_check_client_no_crt_notification
by Hanno Becker
· 6 years ago
2326d20
Validate consistency of certificate hash type and length in session
by Hanno Becker
· 6 years ago
fd5dc8a
Fix unused variable warning in ssl_parse_certificate_coordinate()
by Hanno Becker
· 6 years ago
488c8de
Add missing compile time guard in ssl_client2
by Hanno Becker
· 6 years ago
b6f7241
Update programs/ssl/query_config.c
by Hanno Becker
· 6 years ago
b7fab76
ssl_client2: Reset peer CRT info string on reconnect
by Hanno Becker
· 6 years ago
c39e23e
Add further debug statements on assertion failures
by Hanno Becker
· 6 years ago
42de8f8
Fix typo in documentation of ssl_parse_certificate_chain()
by Hanno Becker
· 6 years ago
e9839c0
Add debug output in case of assertion failure
by Hanno Becker
· 6 years ago
2984bd2
Add config sanity check for !MBEDTLS_SSL_KEEP_PEER_CERTIFICATE
by Hanno Becker
· 6 years ago
f9ca30d
ssl_client2: Zeroize peer CRT info buffer when reconnecting
by Hanno Becker
· 6 years ago
890d7ee
Reintroduce numerous ssl-opt.sh tests if !MBEDTLS_SSL_KEEP_PEER_CERT
by Hanno Becker
· 6 years ago
975c463
ssl_client2: Extract peer CRT info from verification callback
by Hanno Becker
· 6 years ago
24bc570
Improve documentation of mbedtls_ssl_get_peer_cert()
by Hanno Becker
· 6 years ago
3ed6457
Improve documentation of MBEDTLS_SSL_KEEP_PEER_CERTIFICATE
by Hanno Becker
· 6 years ago
dd68931
Fix indentation of Doxygen comment in ssl_internal.h
by Hanno Becker
· 6 years ago
9d64b78
Set peer CRT length only after successful allocation
by Hanno Becker
· 6 years ago
257ef65
Remove question in comment about verify flags on cli vs. server
by Hanno Becker
· 6 years ago
e669770
Remove misleading and redundant guard around restartable ECC field
by Hanno Becker
· 6 years ago
92820a1
Add test for !MBEDTLS_SSL_KEEP_PEER_CERTIFICATE to all.sh
by Hanno Becker
· 6 years ago
34106f6
Free peer CRT chain immediately after verifying it
by Hanno Becker
· 6 years ago
0cc7af5
Parse peer's CRT chain in-place from the input buffer
by Hanno Becker
· 6 years ago
6c83db7
Free peer's public key as soon as it's no longer needed
by Hanno Becker
· 6 years ago
1757247
Correct compile-time guards for ssl_clear_peer_cert()
by Hanno Becker
· 6 years ago
597ffe4
Adapt ChangeLog
by Hanno Becker
· 6 years ago
bfab9df
Guard mbedtls_ssl_get_peer_cert() by new compile-time option
by Hanno Becker
· 6 years ago
8b6d2cd
Add dependency to ssl-opt.sh tests which need peer CRT debug info
by Hanno Becker
· 6 years ago
81d11aa
Adapt mbedtls_ssl_parse_certificate() to removal of peer_cert field
by Hanno Becker
· 6 years ago
5062897
Adapt ssl_clear_peer_cert() to removal of `peer_cert` field
by Hanno Becker
· 6 years ago
d5258fa
Adapt mbedtls_ssl_session_copy() to removal of `peer_cert` field
by Hanno Becker
· 6 years ago
cd90126
Adapt client auth detection in ssl_parse_certificate_verify()
by Hanno Becker
· 6 years ago
b265f5f
Use mbedtls_ssl_get_peer_cert() to query peer cert in cert_app
by Hanno Becker
· 6 years ago
0833c10
Adapt server-side signature verification to use raw public key
by Hanno Becker
· 6 years ago
69fad13
Adapt client-side signature verification to use raw public key
by Hanno Becker
· 6 years ago
53b6b7e
Adapt ssl_get_ecdh_params_from_cert() to use raw public key
by Hanno Becker
· 6 years ago
374800a
Adapt ssl_write_encrypted_pms() to use raw public key
by Hanno Becker
· 6 years ago
cf291d6
Make a copy of peer's raw public key after verifying its CRT chain
by Hanno Becker
· 6 years ago
3bf8cdf
Add field for peer's raw public key to TLS handshake param structure
by Hanno Becker
· 6 years ago
32c530e
Add raw public key buffer bounds to mbedtls_x509_crt struct
by Hanno Becker
· 6 years ago
2e6d347
Remove peer CRT from mbedtls_ssl_session if !KEEP_PEER_CERT
by Hanno Becker
· 6 years ago
4a2f8e5
Add peer CRT digest to session tickets
by Hanno Becker
· 6 years ago
e4aeb76
Parse and verify peer CRT chain in local variable
by Hanno Becker
· 7 years ago
df75938
Mitigate triple handshake attack by comparing digests only
by Hanno Becker
· 7 years ago
3008d28
Compute digest of peer's end-CRT in mbedtls_ssl_parse_certificate()
by Hanno Becker
· 7 years ago
9fb6e2e
Extend mbedtls_ssl_session by buffer holding peer CRT digest
by Hanno Becker
· 7 years ago
c88289a
Update version_features.c
by Hanno Becker
· 6 years ago
b90f655
Add configuration option to remove peer CRT after handshake
by Hanno Becker
· 7 years ago
869144b
Improve documentation of mbedtls_ssl_get_peer_cert()
by Hanno Becker
· 7 years ago
f02d550
Re-classify errors on missing peer CRT
by Hanno Becker
· 6 years ago
a177b38
Simplify session cache implementation via mbedtls_ssl_session_copy()
by Hanno Becker
· 6 years ago
58fccf2
Give ssl_session_copy() external linkage
by Hanno Becker
· 6 years ago
35e4177
Allow passing any X.509 CRT chain to ssl_parse_certificate_chain()
by Hanno Becker
· 7 years ago
3cf5061
Introduce helper function for peer CRT chain verification
by Hanno Becker
· 7 years ago
a7c1df6
Don't progress TLS state machine on peer CRT chain parsing error
by Hanno Becker
· 7 years ago
ae39b9e
Make use of macro and helper detecting whether CertRequest allowed
by Hanno Becker
· 6 years ago
6b9a6f3
Add helper function to check whether a CRT msg is expected
by Hanno Becker
· 6 years ago
5097cba
Introduce helper function to determine whether suite uses server CRT
by Hanno Becker
· 7 years ago
b71e90a
Use helper macro to detect whether some ciphersuite uses CRTs
by Hanno Becker
· 7 years ago
613d490
Unify state machine update in mbedtls_ssl_parse_certificate()
by Hanno Becker
· 7 years ago
a46c287
Clear peer's CRT chain outside before parsing new one
by Hanno Becker
· 7 years ago
b8a0857
Introduce helper to check for no-CRT notification from client
by Hanno Becker
· 7 years ago
8794fd9
Introduce CRT counter to CRT chain parsing function
by Hanno Becker
· 7 years ago
2214159
Introduce helper function to clear peer CRT from session structure
by Hanno Becker
· 7 years ago
933b9fc
Break overly long line in definition of mbedtls_ssl_get_session()
by Hanno Becker
· 7 years ago
1332f35
Don't reuse CRT from initial handshake during renegotiation
by Hanno Becker
· 7 years ago
e210b66
Merge remote-tracking branch 'origin/pr/595' into baremetal
by Simon Butcher
· 6 years ago
7400e8f
Merge remote-tracking branch 'origin/pr/591' into baremetal
by Simon Butcher
· 6 years ago
eddc78a
Fix documentation of X.509 parsing test
by Hanno Becker
· 6 years ago
5b4a619
Add X.509 CRT parsing test for mixed time-encodings
by Hanno Becker
· 6 years ago
615bda0
Improve X.509 CRT parsing test names
by Hanno Becker
· 6 years ago
b9df4bd
Add negative X.509 parsing tests for v3Ext in v1/v2 CRT
by Hanno Becker
· 6 years ago
576f355
Add negative X.509 parsing tests for IssuerID/SubjectID in v1 CRT
by Hanno Becker
· 6 years ago
22adeeb
Improve name of X.509 CRT parsing test
by Hanno Becker
· 6 years ago
36023dc
Always use the same X.509 alg structure inside and outside of TBS
by Hanno Becker
· 6 years ago
53634e3
Fix test dependencies in X.509 CRT parsing suite
by Hanno Becker
· 6 years ago
d061c3d
Fix test case name formatting in X.509 parsing suite
by Hanno Becker
· 6 years ago
57e0693
Use ASN.1 NULL TLVs when testing invalid tags
by Hanno Becker
· 6 years ago
98c6b6a
Shorten X.509 CRT parsing test names
by Hanno Becker
· 6 years ago
24d93a4
Extend negative testing for X.509 Signature parsing
by Hanno Becker
· 6 years ago
56eb0b4
Extend negative testing for X.509 SignatureAlgorithm parsing
by Hanno Becker
· 6 years ago
cb60e2c
Extend negative testing for X.509 v3 Extension parsing
by Hanno Becker
· 6 years ago
Next »