Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							e7e89844d6 
							
						 
					 
					
						
						
							
							Fix and document corner-cases of time checking  
						
						 
						
						
						
						
					 
					
						2015-06-22 23:41:24 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							cdc26ae099 
							
						 
					 
					
						
						
							
							Add mbedtls_ssl_set_hs_authmode  
						
						 
						
						... 
						
						
						
						While at it, fix the following:
- on server with RSA_PSK, we don't want to set flags (client auth happens via
  the PSK, no cert is expected).
- use safer tests (eg == OPTIONAL vs != REQUIRED) 
						
						
					 
					
						2015-06-22 14:52:40 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							1685368408 
							
						 
					 
					
						
						
							
							Rationalize snprintf() usage in X.509 modules  
						
						 
						
						
						
						
					 
					
						2015-06-22 14:42:04 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							6c0c8e0d3d 
							
						 
					 
					
						
						
							
							Include fixed snprintf for Windows in platform.c  
						
						 
						
						... 
						
						
						
						Use _WIN32 to detect it rather that _MSC_VER as it turns out MSYS2 uses the
broken MS version by default too. 
						
						
					 
					
						2015-06-22 14:42:04 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							8ba88f0460 
							
						 
					 
					
						
						
							
							Fix stupid typo in documentation  
						
						 
						
						
						
						
					 
					
						2015-06-22 14:40:56 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							7580ba475d 
							
						 
					 
					
						
						
							
							Add a concept of entropy source strength.  
						
						 
						
						... 
						
						
						
						The main goal is, we want and error if cycle counter is the only source. 
						
						
					 
					
						2015-06-22 14:40:56 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							3f77dfbd52 
							
						 
					 
					
						
						
							
							Add MBEDTLS_ENTROPY_HARDWARE_ALT  
						
						 
						
						... 
						
						
						
						Makes it easier for an external module to plug its hardware entropy collector. 
						
						
					 
					
						2015-06-22 14:40:56 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							bf82ff0209 
							
						 
					 
					
						
						
							
							Fix entropy thresholds  
						
						 
						
						
						
						
					 
					
						2015-06-22 14:40:56 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							60c793bdc9 
							
						 
					 
					
						
						
							
							Split HAVE_TIME into HAVE_TIME + HAVE_TIME_DATE  
						
						 
						
						... 
						
						
						
						First one means we have time() but it may not return the actual wall clock
time, second means it does. 
						
						
					 
					
						2015-06-22 14:40:56 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							c0696c216b 
							
						 
					 
					
						
						
							
							Rename mbedtls_mpi_msb to mbedtls_mpi_bitlen  
						
						 
						
						
						
						
					 
					
						2015-06-18 16:49:37 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							097c7bb05b 
							
						 
					 
					
						
						
							
							Rename relevant global symbols from size to bitlen  
						
						 
						
						... 
						
						
						
						Just applying rename.pl with this file:
mbedtls_cipher_get_key_size mbedtls_cipher_get_key_bitlen
mbedtls_pk_get_size mbedtls_pk_get_bitlen
MBEDTLS_BLOWFISH_MIN_KEY MBEDTLS_BLOWFISH_MIN_KEY_BITS
MBEDTLS_BLOWFISH_MAX_KEY MBEDTLS_BLOWFISH_MAX_KEY_BITS 
						
						
					 
					
						2015-06-18 16:43:38 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							fb317c5221 
							
						 
					 
					
						
						
							
							Rename parameter in a x509 helper  
						
						 
						
						
						
						
					 
					
						2015-06-18 16:41:13 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							39a48f4934 
							
						 
					 
					
						
						
							
							Internal renamings in PK  
						
						 
						
						... 
						
						
						
						+ an unrelated comment in SSL 
						
						
					 
					
						2015-06-18 16:06:55 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							12ad798c87 
							
						 
					 
					
						
						
							
							Rename ssl_session.length to id_len  
						
						 
						
						
						
						
					 
					
						2015-06-18 15:50:37 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							797f48ace6 
							
						 
					 
					
						
						
							
							Rename ecp_curve_info.size to bit_size  
						
						 
						
						
						
						
					 
					
						2015-06-18 15:45:05 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							898e0aa210 
							
						 
					 
					
						
						
							
							Rename key_length in cipher_info  
						
						 
						
						
						
						
					 
					
						2015-06-18 15:31:10 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							b8186a5e54 
							
						 
					 
					
						
						
							
							Rename len to bitlen in function parameters  
						
						 
						
						... 
						
						
						
						Clarify a few comments too. 
						
						
					 
					
						2015-06-18 14:58:58 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							b31c5f68b1 
							
						 
					 
					
						
						
							
							Add SSL presets.  
						
						 
						
						... 
						
						
						
						No need to use a separate profile as in X.509, everything we need is already
in ssl_config. Just load appropriate values. 
						
						
					 
					
						2015-06-17 14:59:27 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							7bfc122703 
							
						 
					 
					
						
						
							
							Implement sig_hashes  
						
						 
						
						
						
						
					 
					
						2015-06-17 14:34:48 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							36a8b575a9 
							
						 
					 
					
						
						
							
							Create API for mbedtls_ssl_conf_sig_hashes().  
						
						 
						
						... 
						
						
						
						Not implemented yet. 
						
						
					 
					
						2015-06-17 14:27:39 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							9d412d872c 
							
						 
					 
					
						
						
							
							Small internal changes in curve checking  
						
						 
						
						... 
						
						
						
						- switch from is_acceptable to the more usual check
- add NULL check just in case user screwed up config 
						
						
					 
					
						2015-06-17 14:27:39 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							27716cc1da 
							
						 
					 
					
						
						
							
							Clarify a point in the documentation  
						
						 
						
						
						
						
					 
					
						2015-06-17 14:27:38 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							b541da6ef3 
							
						 
					 
					
						
						
							
							Fix define for ssl_conf_curves()  
						
						 
						
						... 
						
						
						
						This is a security feature, it shouldn't be optional. 
						
						
					 
					
						2015-06-17 14:27:38 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							6e3ee3ad43 
							
						 
					 
					
						
						
							
							Add mbedtls_ssl_conf_cert_profile()  
						
						 
						
						
						
						
					 
					
						2015-06-17 14:27:38 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							f8ea856296 
							
						 
					 
					
						
						
							
							Change data structure of profiles to bitfields  
						
						 
						
						... 
						
						
						
						- allows to express 'none' or 'all' more easily than lists
- more compact and easier to declare statically
- easier to check too
Only drawback: if we ever have more than 32 curves, we'll need an ABI change to
make that field a uint64_t. 
						
						
					 
					
						2015-06-17 14:27:38 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							88db5da117 
							
						 
					 
					
						
						
							
							Add pre-defined profiles for cert verification  
						
						 
						
						
						
						
					 
					
						2015-06-17 14:27:38 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							9505164ef4 
							
						 
					 
					
						
						
							
							Create cert profile API (unimplemented yet)  
						
						 
						
						
						
						
					 
					
						2015-06-17 14:27:38 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							bd990d6629 
							
						 
					 
					
						
						
							
							Add ssl_conf_dhm_min_bitlen()  
						
						 
						
						
						
						
					 
					
						2015-06-17 11:37:04 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							1b1e65f541 
							
						 
					 
					
						
						
							
							Fix typos and other small issues in doc  
						
						 
						
						
						
						
					 
					
						2015-06-11 13:38:03 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							7ee5ddd798 
							
						 
					 
					
						
						
							
							Merge branch 'mbedtls-1.3' into development  
						
						 
						
						... 
						
						
						
						* mbedtls-1.3:
  Fix compile errors with NO_STD_FUNCTIONS
  Expand config.pl's notion of "full"
  Ack external bugfix in Changelog
  FIx misplaced Changelog entry (oops)
  Fix compile bug: incompatible declaration of polarssl_exit in platform.c
  Fix contributor's name in Changelog 
						
						
					 
					
						2015-06-03 10:33:55 +01:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							ba56136b5c 
							
						 
					 
					
						
						
							
							Avoid in-out length in base64  
						
						 
						
						
						
						
					 
					
						2015-06-02 16:30:35 +01:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							3335205a21 
							
						 
					 
					
						
						
							
							Avoid in-out length in dhm_calc_secret()  
						
						 
						
						
						
						
					 
					
						2015-06-02 16:17:08 +01:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							f79b425226 
							
						 
					 
					
						
						
							
							Avoid in-out length parameter in bignum  
						
						 
						
						
						
						
					 
					
						2015-06-02 15:41:48 +01:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							77cfe177e1 
							
						 
					 
					
						
						
							
							Remove now-useless typedef in ssl.h  
						
						 
						
						
						
						
					 
					
						2015-06-02 11:18:35 +01:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							c730ed3f2d 
							
						 
					 
					
						
						
							
							Rename boolean functions to be clearer  
						
						 
						
						
						
						
					 
					
						2015-06-02 10:38:50 +01:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							3eb50fa591 
							
						 
					 
					
						
						
							
							Cosmetics in doxygen doc  
						
						 
						
						
						
						
					 
					
						2015-06-02 10:28:09 +01:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							81abefd46c 
							
						 
					 
					
						
						
							
							Fix typos/style in doxygen documentation  
						
						 
						
						
						
						
					 
					
						2015-05-29 12:53:47 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							d14acbc31a 
							
						 
					 
					
						
						
							
							Test assumptions we make about the platform  
						
						 
						
						... 
						
						
						
						Things that are not guaranteed by the standard but should be true of all
platforms of interest to us:
- 8-bit chars
- NULL pointers represented by all-bits-zero 
						
						
					 
					
						2015-05-29 12:25:40 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							f78e4de6f4 
							
						 
					 
					
						
						
							
							Fix warnings from -pedantic  
						
						 
						
						
						
						
					 
					
						2015-05-29 10:52:14 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							864108daab 
							
						 
					 
					
						
						
							
							Move from gmtime_r to gmtime + mutexes  
						
						 
						
						... 
						
						
						
						* gmtime_r is not standard so -std=c99 warns about it
* Anyway we need global mutexes in the threading layer, so better depend only
  on that, rather that global mutexes + some _r functions 
						
						
					 
					
						2015-05-29 10:18:09 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							ba19432d2e 
							
						 
					 
					
						
						
							
							Move from asm to __asm by default  
						
						 
						
						... 
						
						
						
						- GCC with -std=c99 warns about asm but likes __asm
_ armcc5 has __asm but not asm 
						
						
					 
					
						2015-05-29 10:18:09 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							2a84dfd747 
							
						 
					 
					
						
						
							
							Make ssl_cookie.c thread-safe  
						
						 
						
						
						
						
					 
					
						2015-05-28 17:28:39 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							b48ef9cce9 
							
						 
					 
					
						
						
							
							Improve documentation about HelloVerifyRequest  
						
						 
						
						
						
						
					 
					
						2015-05-28 17:28:39 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							398b206ff0 
							
						 
					 
					
						
						
							
							Update doc for ssl_conf_renegotiation  
						
						 
						
						
						
						
					 
					
						2015-05-28 17:28:38 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							41b9c2b418 
							
						 
					 
					
						
						
							
							Remove individual mdX_file() and shaX_file()  
						
						 
						
						
						
						
					 
					
						2015-05-28 17:28:38 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							bfffa908a6 
							
						 
					 
					
						
						
							
							Implement md_file in the MD layer  
						
						 
						
						
						
						
					 
					
						2015-05-28 17:28:38 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							eb0d8706ce 
							
						 
					 
					
						
						
							
							Add option for even smaller SHA-256  
						
						 
						
						
						
						
					 
					
						2015-05-28 16:45:23 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							6a8ca33fa5 
							
						 
					 
					
						
						
							
							Rename ERR_xxx_MALLOC_FAILED to ..._ALLOC_FAILED  
						
						 
						
						
						
						
					 
					
						2015-05-28 16:25:05 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							160e384360 
							
						 
					 
					
						
						
							
							Fix bad name choice  
						
						 
						
						
						
						
					 
					
						2015-05-27 20:27:06 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Manuel Pégourié-Gonnard 
							
						 
					 
					
						
						
						
						
							
						
						
							a7f8033fa4 
							
						 
					 
					
						
						
							
							Fix oversights in s/malloc/calloc/  
						
						 
						
						
						
						
					 
					
						2015-05-27 20:26:40 +02:00