Commit Graph

179 Commits (d1a87553bb9f3ed88e351acbf4cea1199a05f995)
 

Author SHA1 Message Date
Dmitry Belyavskiy d1a87553bb Release the DRBG in global default libctx early
1 year ago
Dmitry Belyavskiy df4dd7dd7f Fix possible DoS translating ASN.1 object identifiers
1 year ago
Daiki Ueno 103d3109dc ci.fmf: Enable golang tests as reverse dependency
1 year ago
Peter Leitmann 34e7dd5be4 Add interop rpm-tmt-tests
1 year ago
Clemens Lang b1d3f019d4 FIPS: Re-enable DHX, disable FIPS 186-4 groups
1 year ago
Dmitry Belyavskiy 57f6d8f4a4 Use OAEP padding and aes-128-cbc by default in cms command in FIPS mode
1 year ago
Dmitry Belyavskiy 032dc0839c Enforce using EMS in FIPS mode - better alerts
1 year ago
Sahana Prasad 05bbcc9920 - Upload new upstream sources without manually hobbling them.
1 year ago
Dmitry Belyavskiy 45cb3a6b4e Backport implicit rejection for RSA PKCS#1 v1.5 encryption
1 year ago
Dmitry Belyavskiy 7680abf05d Input buffer over-read in AES-XTS implementation on 64 bit ARM
1 year ago
Dmitry Belyavskiy 4999352324 OpenSSL rsa_verify_recover key length checks in FIPS mode
1 year ago
Dmitry Belyavskiy ba8edd5ea8 Certificate policy check not enabled
1 year ago
Dmitry Belyavskiy 70a27e0ae3 Fix invalid certificate policies in leaf certificates check
1 year ago
Dmitry Belyavskiy 90306b7fd8 Fix excessive resource usage in verifying X509 policy constraints
1 year ago
Dmitry Belyavskiy 35f22d134e Enforce using EMS in FIPS mode
1 year ago
Clemens Lang 0dea6db970 Change explicit FIPS indicator for RSA decryption to unapproved
2 years ago
Clemens Lang 1bd2a0cee3 Add missing patchfile, fix gettable params
2 years ago
Clemens Lang 1bd49c394a Add explicit FIPS indicator to RSA encryption and RSASVE
2 years ago
Clemens Lang 21d2b9fb47 Fix X942KDF indicator for short output key lengths
2 years ago
Clemens Lang e5f783d552 Fix Wpointer-sign compiler warning
2 years ago
Dmitry Belyavskiy 6eb72dd621 Increase RNG seeding buffer size to 32
2 years ago
Dmitry Belyavskiy fb4b72ff2f DH PCT should abort on failure
2 years ago
Dmitry Belyavskiy bfdbb139b4 Disable DHX keys completely in FIPS mode
2 years ago
Dmitry Belyavskiy 960e6deebf Abort on PCT failure
2 years ago
Dmitry Belyavskiy dd6f0d33c8 Remove previous low-level PCT
2 years ago
Dmitry Belyavskiy fa195e46a2 Pairwise consistency tests should use Digest+Sign/Verify
2 years ago
Dmitry Belyavskiy d2996a9b03 Limit RSA_NO_PADDING for encryption and signature in FIPS mode
2 years ago
Clemens Lang d60644ea6a Add explicit FIPS indicator for PBKDF2
2 years ago
Clemens Lang 50cb33e688 GCM: Implement explicit FIPS indicator for IV gen
2 years ago
Clemens Lang 58955140b6 Zeroize FIPS module integrity check MAC after check
2 years ago
Clemens Lang 6a9e17a8c1 KDF: Add FIPS indicators
2 years ago
Dmitry Belyavskiy 9ebabfa10a Stop everlasting RNG reseeding
2 years ago
Dmitry Belyavskiy 9d8f618208 Fixed NULL dereference during PKCS7 data verification
2 years ago
Dmitry Belyavskiy 8673fb7c22 Fixed X.400 address type confusion in X.509 GeneralName
2 years ago
Dmitry Belyavskiy 0f4062ead5 Fixed NULL dereference validating DSA public key
2 years ago
Dmitry Belyavskiy 5e4feef220 Fixed Invalid pointer dereference in d2i_PKCS7 functions
2 years ago
Dmitry Belyavskiy b889341096 Fixed Use-after-free following BIO_new_NDEF
2 years ago
Dmitry Belyavskiy 529db6cf12 Fixed Double free after calling PEM_read_bio_ex
2 years ago
Dmitry Belyavskiy c5b0dc92d3 Fixed Timing Oracle in RSA Decryption
2 years ago
Dmitry Belyavskiy 593a315f09 Fixed X.509 Name Constraints Read Buffer Overflow
2 years ago
Clemens Lang 770dcce08b Disallow SHAKE in OAEP decryption in FIPS mode
2 years ago
Dmitry Belyavskiy b19d91aec3 Refactor OpenSSL fips module MAC verification
2 years ago
Clemens Lang c0667361a5 Fix explicit indicator for PSS salt length
2 years ago
Dmitry Belyavskiy 657265459d Backport of ppc64le Montgomery multiply enhancement
2 years ago
Dmitry Belyavskiy c29e183891 Adjusting include for the FIPS_mode macro
2 years ago
Dmitry Belyavskiy d60bf2b343 Removed recommended package for openssl-libs
2 years ago
Dmitry Belyavskiy f2a49ef424 We should export 2 versions of OPENSSL_str[n]casecmp to be compatible with upstream
2 years ago
Dmitry Belyavskiy 0f139ead1a Various provider-related imrovements necessary for PKCS#11 provider correct operations
2 years ago
Dmitry Belyavskiy 07892fe646 Rebasing to OpenSSL 3.0.7 - removing redundant patches
2 years ago
Dmitry Belyavskiy 477d91adec Rebasing to OpenSSL 3.0.7
2 years ago