- b0bb3c8 Bump version to 2.16.12 by Manuel Pégourié-Gonnard · 3 years, 8 months ago
- fef64d5 Merge branch 'mbedtls-2.16-restricted' into mbedtls-2.16.12rc0-pr by Manuel Pégourié-Gonnard · 3 years, 8 months ago
- 7b9cd91 Merge pull request #5328 from gilles-peskine-arm/zeroize-tag-2.16 by Gilles Peskine · 3 years, 8 months ago
- b3f2273 mbedtls_cipher_check_tag: jump on error for more robustness to refactoring by Gilles Peskine · 3 years, 8 months ago
- e72ab77 Merge pull request #5311 from paul-elliott-arm/pkcs12_fix_2.16 by Gilles Peskine · 3 years, 8 months ago
- 7cab499 Initialize hash_len before using it by Gilles Peskine · 3 years, 8 months ago
- 6f8d7f1 PKCS#1v1.5 signature: better cleanup of temporary values by Gilles Peskine · 3 years, 8 months ago
- cd9e751 mbedtls_ssl_parse_finished: zeroize expected finished value on error by Gilles Peskine · 3 years, 8 months ago
- 75b596f mbedtls_ssl_cookie_check: zeroize expected cookie on cookie mismatch by Gilles Peskine · 3 years, 8 months ago
- 8dc7b24 mbedtls_cipher_check_tag: zeroize expected tag on tag mismatch by Gilles Peskine · 3 years, 8 months ago
- a89bdf0 Catch failures of md_hmac operations by Gilles Peskine · 3 years, 8 months ago
- 957e383 Zeroize local MAC variables by Gilles Peskine · 3 years, 8 months ago
- 987bb38 Remove incorrect hashing by Paul Elliott · 3 years, 8 months ago
- b4bfcbb Add explanation for safety in function by Paul Elliott · 3 years, 8 months ago
- 6b5707c Better fix for empty password / salt by Paul Elliott · 3 years, 9 months ago
- 4d44341 Fix for pkcs12 with NULL or zero length password by Paul Elliott · 3 years, 9 months ago
- eb490aa [session] fix a session copy bug by 吴敬辉 · 3 years, 8 months ago
- 7b420a8 Fix builds when config.h only defines MBEDTLS_BIGNUM_C by Tom Cosgrove · 3 years, 9 months ago
- 1d2c74c Merge pull request #5135 from openluopworld/origin/mbedtls-2.16 by Gilles Peskine · 3 years, 9 months ago
- 0a81720 Serialise builds of the .a files on Windows by Tom Cosgrove · 3 years, 9 months ago
- ed798a9 An initialization vector IV can have any number of bits between 1 and by openluopworld · 3 years, 9 months ago
- 70227d2 Merge pull request #4819 from gilles-peskine-arm/base64-no-table-2.16 by Manuel Pégourié-Gonnard · 3 years, 9 months ago
- cda1281 Fix copypasta in comment by Gilles Peskine · 3 years, 9 months ago
- 90b10c3 Merge pull request #4847 from mstarzyk-mobica/ecb-alt-ret-2.16 by Gilles Peskine · 3 years, 10 months ago
- 806ac52 Backport 2.16: Remove compiler warning if only MBEDTLS_PK_PARSE_C is defined by Kenneth Soerensen · 7 years ago
- f1b0c70 Merge pull request #4044 from darrenkrahn/mbedtls-2.16 by Janos Follath · 4 years ago
- 621333f Catch failures of AES or DES operations by Gilles Peskine · 4 years, 1 month ago
- bbf97cd mask_of_range: simplify high comparison by Gilles Peskine · 4 years ago
- 231b67a Base64 decode: simplify local variables (n) by Gilles Peskine · 4 years ago
- b44517e Base64 encoding: use ranges instead of tables by Gilles Peskine · 4 years ago
- ea96b3a Base64 decode: simplify local variables by Gilles Peskine · 4 years ago
- f4a0a27 Base64 decoding: use ranges instead of tables by Gilles Peskine · 4 years ago
- a47fdcf Base64 decoding: don't use the table for '=' by Gilles Peskine · 4 years ago
- ae466e7 Merge pull request #4787 from gilles-peskine-arm/fix-clang12-Wstring-concatenation-2.16 by Ronald Cron · 4 years ago
- 70bdf8d Use single-line string literals. by Guido Vranken · 5 years ago
- 4a78d58 Prevent triggering Clang 12 -Wstring-concatenation warning by Guido Vranken · 5 years ago
- 1cded87 Replace `_RR` with `prec_RR` to prevent reserved identifier clashes by Yuto Takano · 4 years, 1 month ago
- d7cd60f Replace `_B` with `B` to prevent reserved identifier clashes by Yuto Takano · 4 years, 1 month ago
- 124a87e Bump library version numbers by Bence Szépkúti · 4 years, 1 month ago
- 726a8cc Merge branch 'mbedtls-2.16-restricted' into mbedtls-2.16.11rc0-pr by Bence Szépkúti · 4 years, 1 month ago
- 4c20c77 Merge pull request #4735 from daverodgman/alert_bugfixes_2.16 by Dave Rodgman · 4 years, 1 month ago
- ffbbeee TLS UNSUPPORTED_EXTENSION error code changes by Dave Rodgman · 4 years, 1 month ago
- c15e31d pk.c: Ensure min hash_len in pk_hashlen_helper by Nick Child · 4 years, 2 months ago
- 459a461 Fix TLS alert codes by Dave Rodgman · 4 years, 1 month ago
- 1001d2c Fix unused parameter warning by Janos Follath · 4 years, 1 month ago
- 9a64d3e Add prefix to BYTES_TO_T_UINT_* by Janos Follath · 4 years, 1 month ago
- 5f9b667 Reject low-order points on Curve448 early by Janos Follath · 4 years, 1 month ago
- b741e8d Use mbedtls_mpi_lset() more by Janos Follath · 4 years, 1 month ago
- 7d34e2e Move mpi constant macros to bn_mul.h by Janos Follath · 4 years, 1 month ago
- c16ec6b Prevent memory leak in ecp_check_pubkey_x25519() by Janos Follath · 4 years, 1 month ago
- 9f12b11 Avoid complaints about undeclared non-static symbols by Manuel Pégourié-Gonnard · 4 years, 1 month ago
- 89ce7d2 Use more compact encoding of Montgomery curve constants by Manuel Pégourié-Gonnard · 4 years, 1 month ago
- 6ec1535 Use a more compact encoding of bad points by Manuel Pégourié-Gonnard · 4 years, 1 month ago
- 4d0b9da Reject low-order points on Curve25519 early by Manuel Pégourié-Gonnard · 4 years, 1 month ago
- 18efd1c Correct some statements about the ordering of A and B by Gilles Peskine · 4 years, 1 month ago
- f95d433 Clarification in a comment by Gilles Peskine · 4 years, 1 month ago
- 1d6b1dc Simplify is-zero check by Gilles Peskine · 4 years, 2 months ago
- afbf191 Write a proof of correctness for mbedtls_mpi_gcd by Gilles Peskine · 4 years, 2 months ago
- 2949d3a Explain how the code relates to the description in HAC by Gilles Peskine · 4 years, 2 months ago
- 44e6bb6 Fix multiplication with negative result and a low-order 0 limb by Gilles Peskine · 4 years, 2 months ago
- ab6ab6a Fix multiplication producing a negative zero by Gilles Peskine · 4 years, 2 months ago
- 5504d17 mbedtls_mpi_gcd: fix the case B==0 by Gilles Peskine · 4 years, 2 months ago
- c559eac Fix null pointer dereference in mbedtls_mpi_exp_mod by Gilles Peskine · 4 years, 2 months ago
- 07941f4 Merge pull request #4690 from gilles-peskine-arm/debug-print-mpi-null-2.16 by Manuel Pégourié-Gonnard · 4 years, 1 month ago
- c9807ea Merge pull request #4622 from gilles-peskine-arm/default-hashes-curves-2.16 by Manuel Pégourié-Gonnard · 4 years, 1 month ago
- fa719f7 Merge branch 'mbedtls-2.16' into mbedtls-2.16-restricted by Manuel Pégourié-Gonnard · 4 years, 1 month ago
- 3db875e Add missing parentheses by Gilles Peskine · 4 years, 2 months ago
- 5eace4c Indicate that the truncation from size_t to int is deliberate by Gilles Peskine · 4 years, 2 months ago
- e1a3128 Simplify mbedtls_debug_print_mpi and fix the case of empty bignums by Gilles Peskine · 4 years, 2 months ago
- 8297657 Fix fd range for select on Windows by Gilles Peskine · 4 years, 2 months ago
- 9065d78 Refactor file descriptor checks into a common function by Gilles Peskine · 4 years, 2 months ago
- e9eca7f Homogenize coding patterns by Manuel Pégourié-Gonnard · 4 years, 2 months ago
- 56efc52 Merge pull request #4628 from ronald-cron-arm/dhm-key-generation-bias by Manuel Pégourié-Gonnard · 4 years, 2 months ago
- 6aba8fc No C99 loops in this branch by Manuel Pégourié-Gonnard · 4 years, 2 months ago
- de2ab2a Fix GCC warning by Manuel Pégourié-Gonnard · 4 years, 2 months ago
- 4fc96df Silence MSVC type conversion warnings by Manuel Pégourié-Gonnard · 4 years, 2 months ago
- 12f0238 Simplify sign selection by Manuel Pégourié-Gonnard · 4 years, 2 months ago
- dc6a5f2 Avoid UB caused by conversion to int by Manuel Pégourié-Gonnard · 4 years, 2 months ago
- a1283cc Use bit operations for mpi_safe_cond_swap() by Manuel Pégourié-Gonnard · 4 years, 2 months ago
- 245a806 Use bit operations for mpi_safe_cond_assign() by Manuel Pégourié-Gonnard · 4 years, 2 months ago
- 432ebba Avoid using == for sensitive comparisons by Manuel Pégourié-Gonnard · 4 years, 2 months ago
- 87bd444 Use constant-time look-up for modular exponentiation by Manuel Pégourié-Gonnard · 4 years, 5 months ago
- 1283ed9 Merge branch 'mbedtls-2.16' into mbedtls-2.16-restricted by Manuel Pégourié-Gonnard · 4 years, 2 months ago
- 2e0969a ecp: Fix bias in the generation of blinding values by Ronald Cron · 4 years, 2 months ago
- 39b1a51 DHM: add notes about leading zeros by Gilles Peskine · 4 years, 4 months ago
- b4367a3 dhm: Fix bias in private key generation and blinding by Ronald Cron · 4 years, 2 months ago
- 260be63 dhm_check_range: microoptimization by Gilles Peskine · 4 years, 4 months ago
- c53560e DHM refactoring: use dhm_random_below in dhm_make_common by Gilles Peskine · 4 years, 4 months ago
- b2fbda3 DHM blinding: don't accept P-1 as a blinding value by Gilles Peskine · 4 years, 4 months ago
- e75bb63 DHM refactoring: unify mbedtls_dhm_make_{params,public} by Gilles Peskine · 4 years, 4 months ago
- 347ada7 Document more precisely what goes into the default profile by Gilles Peskine · 4 years, 2 months ago
- 6db34e6 Merge pull request #4542 from mpg/fix-ssl-cf-hmac-alt-2.16 by Gilles Peskine · 4 years, 2 months ago
- 995d89c Fix null pointer arithmetic in error case by Gilles Peskine · 4 years, 2 months ago
- ac12767 Fix non-constant-time comparison in mbedtls_ecp_gen_privkey by Manuel Pégourié-Gonnard · 4 years, 2 months ago
- 39f5dae CAMELLIA: add missing context init/free by Gilles Peskine · 4 years, 2 months ago
- ba93f59 ARIA: add missing context init/free by Gilles Peskine · 4 years, 2 months ago
- 85060d2 Merge pull request #4498 from netfoundry/gcc11.fixes_2.16 by Gilles Peskine · 4 years, 3 months ago
- 1012b7c Merge pull request #4504 from gilles-peskine-arm/ciphersuite-sha384-guard-2.16 by Gilles Peskine · 4 years, 3 months ago
- f26d12c Fix dependency for TLS-RSA-WITH-CAMELLIA-256-GCM-SHA384 by Gilles Peskine · 4 years, 3 months ago
- 7f0d193 Fix misuse of MD API in SSL constant-flow HMAC by Manuel Pégourié-Gonnard · 4 years, 3 months ago