- e8a2fc8 Enforce dhm_min_bitlen exactly, not just the byte size by Gilles Peskine · 4 years, 7 months ago
- d48d5c6 Fix size_t and longlong specifiers for MinGW by Paul Elliott · 4 years, 6 months ago
- 3891caf Misc review requested fixes by Paul Elliott · 4 years, 7 months ago
- 9f35211 Fixes for invalid printf format specifiers by Paul Elliott · 4 years, 7 months ago
- cf56a0a psa: Move from key handle to key identifier by Ronald Cron · 5 years ago
- c26f8d4 Introduce psa_key_handle_is_null inline function by Ronald Cron · 4 years, 11 months ago
- 91e9515 Introduce PSA_KEY_HANDLE_INIT macro by Ronald Cron · 5 years ago
- c3ccd98 Check transport in the extension parser/writer by Johan Pascal · 4 years, 9 months ago
- 5ef72d2 Style and typos by Johan Pascal · 4 years, 9 months ago
- 275874b Fix previous commit by Johan Pascal · 4 years, 9 months ago
- 20c7db3 API modified so server side can get mki value by Johan Pascal · 4 years, 9 months ago
- adbd944 More minor fix by Johan Pascal · 4 years, 9 months ago
- 76fdf1d Minor fix and improvements by Johan Pascal · 4 years, 9 months ago
- d387aa0 style + missing cast by Johan Pascal · 4 years, 10 months ago
- 77696ee Add bound check in the client ssl_write_use_srtp_ext by Johan Pascal · 4 years, 10 months ago
- aae4d22 Improve code readability +micro optimization +style by Johan Pascal · 4 years, 10 months ago
- e79c1e8 style by Johan Pascal · 4 years, 10 months ago
- f6417ec mki length feats in a uint16_t by Johan Pascal · 4 years, 10 months ago
- 43f9490 SRTP profiles definition use macros only by Johan Pascal · 4 years, 10 months ago
- 9bc97ca SRTP-DTLS protection profile configuration list not copied into ssl_config by Johan Pascal · 4 years, 10 months ago
- a89ca86 The client shall not enforce the use of client certificate with use_srtp extension by Johan Pascal · 4 years, 11 months ago
- 313d7b5 Add variable validation by Ron Eldor · 7 years ago
- 75870ec Change byte copy to memcpy by Ron Eldor · 7 years ago
- 089c9fe Improve readability by Ron Eldor · 7 years ago
- a978804 Style fixes by Ron Eldor · 7 years ago
- ef72faf Style fixes by Ron Eldor · 7 years ago
- b465539 Add tests and code to support by Ron Eldor · 7 years ago
- 12c6ead Fix mki issues by Ron Eldor · 7 years ago
- 9d36d31 Fix failure in ssl-opts.sh by Ron Eldor · 7 years ago
- 57cc70e Enforce SRTP mandatory HS messages by Ron Eldor · 7 years ago
- 591f162 support mki value by Ron Eldor · 7 years ago
- 3adb992 Add mki value and some review comments by Ron Eldor · 8 years ago
- 701984d Comply with mbedtls naming rules by Johan Pascal · 8 years ago
- bbc057a Move available dtls srtp profile list to ssl_config by Johan Pascal · 9 years ago
- b62bb51 Add RFC5764 - SRTP key generation during DTLS handshake by Johan Pascal · 10 years ago
- 6edfe60 Merge pull request #2182 from hanno-arm/key_pwd by Manuel Pégourié-Gonnard · 5 years ago
- 1e14827 Update copyright notices to use Linux Foundation guidance by Bence Szépkúti · 5 years ago
- 3c88c65 Fix debug format specifier in ClientHello ciphersuite log by Hanno Becker · 7 years ago
- ecea07d Unify ciphersuite related debug output on client and server by Hanno Becker · 7 years ago
- db09ef6 Include common.h instead of config.h in library source files by Gilles Peskine · 5 years ago
- 5ee5707 ssl_client: Align line breaking with MBEDTLS_SSL_DEBUG_* by Ronald Cron · 5 years ago
- e131bfe Return error in case of bad user configurations by Hanno Becker · 8 years ago
- 261602c Uniformize bounds checks using new macro by Hanno Becker · 8 years ago
- 4c7bbe2 Remove unnecessary MBEDTLS_ECP_C preprocessor condition by Ronald Cron · 5 years ago
- b2fff6d Shorten lines in library/ssl_cli.c to at most 80 characters by Hanno Becker · 8 years ago
- 2848239 Merge branch 'development-restricted' into prepare-rc-2.22.0-updated by Manuel Pégourié-Gonnard · 5 years ago
- 215d2e1 Merge remote-tracking branch 'restricted/pr/662' into development-restricted by Manuel Pégourié-Gonnard · 5 years ago
- 15f30dc Merge remote-tracking branch 'public/pr/2856' into development by Manuel Pégourié-Gonnard · 5 years ago
- eccd888 Rename identifiers containing double-underscore by Gilles Peskine · 5 years ago
- 4245980 USE_PSA_CRYPTO: don't rely on the curve encoding by Gilles Peskine · 6 years ago
- 73c616b Put includes in alphabetical order by Janos Follath · 6 years ago
- 865b3eb Initialize return values to an error by Janos Follath · 6 years ago
- 6527bd6 Fix issue #2718 (condition always false) by irwir · 6 years ago
- b64bf06 Parse HelloVerifyRequest: avoid buffer overread at the start by Gilles Peskine · 6 years ago
- b51130d Parse HelloVerifyRequest: avoid buffer overread on the cookie by Gilles Peskine · 6 years ago
- de718b9 Make calc_verify() return the length as well by Manuel Pégourié-Gonnard · 6 years ago
- df3b089 Use psa_raw_key_agreement by Janos Follath · 6 years ago
- 1239d70 Remove calls to psa_allocate_key by Janos Follath · 6 years ago
- 53b8ec2 Make variable naming consistent by Janos Follath · 6 years ago
- 7bb5e6b Update psa_create_key to PSA 1.0 by Janos Follath · 6 years ago
- bd09610 Update psa_generator_abort to PSA 1.0 by Janos Follath · 6 years ago
- 6de99db Update psa_generator_read to PSA 1.0 by Janos Follath · 6 years ago
- 7d7ded8 Update psa_key_agreement to PSA 1.0 by Janos Follath · 6 years ago
- 7374ee6 Update GENERATOR_INIT macro to PSA 1.0 by Janos Follath · 6 years ago
- 3d158eb Update KEYPAIR macros to PSA 1.0 by Janos Follath · 6 years ago
- a0e20d0 Rename MBEDTLS_SSL_CID to MBEDTLS_SSL_DTLS_CONNECTION_ID by Hanno Becker · 6 years ago
- ebcc913 Consistently reference CID draft through name + URL by Hanno Becker · 6 years ago
- 4cac442 Update references to CID draft to version 5 by Hanno Becker · 6 years ago
- 79594fd Set pointer to start of plaintext at record decryption time by Hanno Becker · 6 years ago
- 5a29990 Improve structure of client-side CID extension parsing by Hanno Becker · 6 years ago
- 2262648 Improve debugging output of client-side CID extension parsing by Hanno Becker · 6 years ago
- a8373a1 Implement parsing of CID extension in ServerHello by Hanno Becker · 6 years ago
- 49770ff Implement writing of CID extension in ClientHello by Hanno Becker · 6 years ago
- ade9e28 ssl_cli.c : add explicit casting to unsigned char by Andrzej Kurek · 6 years ago
- e694c3e Remove ciphersuite_info from ssl_transform by Hanno Becker · 8 years ago
- bd5580a Add further debug statements on assertion failures by Hanno Becker · 6 years ago
- 62d58ed Add debug output in case of assertion failure by Hanno Becker · 6 years ago
- ae553dd Free peer's public key as soon as it's no longer needed by Hanno Becker · 6 years ago
- a6899bb Adapt client-side signature verification to use raw public key by Hanno Becker · 6 years ago
- be7f508 Adapt ssl_get_ecdh_params_from_cert() to use raw public key by Hanno Becker · 6 years ago
- c7d7e29 Adapt ssl_write_encrypted_pms() to use raw public key by Hanno Becker · 6 years ago
- 8273df8 Re-classify errors on missing peer CRT by Hanno Becker · 6 years ago
- 77adddc Make use of macro and helper detecting whether CertRequest allowed by Hanno Becker · 6 years ago
- 86016a0 Merge remote-tracking branch 'origin/pr/2338' into development by Jaeden Amero · 6 years ago
- 9f47f82 Merge remote-tracking branch 'origin/pr/2391' into development by Jaeden Amero · 6 years ago
- 0a94a64 Add debugging output to confirm that PSA was used for ECDHE by Hanno Becker · 7 years ago
- c14a3bb Make variable in ssl_write_client_key_exchange() more descriptive by Hanno Becker · 7 years ago
- 4a63ed4 Implement ClientKeyExchange writing in PSA-based ECDHE suites by Hanno Becker · 7 years ago
- bb89e27 Implement ServerKeyExchange parsing for PSA-based ECDHE suites by Hanno Becker · 7 years ago
- b2964cb SSL/TLS client: Remove old session ticket on renegotiation by Hanno Becker · 6 years ago
- c470b6b Merge development commit 8e76332 into development-psa by Andrzej Kurek · 6 years ago
- 3fbdada SSL: Make use of the new ECDH interface by Janos Follath · 7 years ago
- 520224e Rename ssl_conf_has_[raw_]_psk to ssl_conf_has_static_[raw_]psk by Hanno Becker · 7 years ago
- afd311e Skip PMS generation on client if opaque PSK is used by Hanno Becker · 7 years ago
- dfab8e2 Allow opaque PSKs in pure-PSK ciphersuites only by Hanno Becker · 7 years ago
- 2e4f616 Don't suggest the use of a PSK suite if no PSK configured on client by Hanno Becker · 7 years ago
- de13963 Merge remote-tracking branch 'restricted/pr/520' into development-restricted-proposed by Simon Butcher · 7 years ago
- c37423f Fix misleading sub-state name and comments by Manuel Pégourié-Gonnard · 7 years ago
- 8df1023 Add explicit unsigned-to-signed integer conversion by Hanno Becker · 7 years ago
- 0c161d1 Fix bounds check in ssl_parse_server_psk_hint() by Hanno Becker · 7 years ago