Commit Graph

  • 991bdc19a6
    Merge 89bbe44efd into a1f4cfac71 Chris Conlon 2026-09-17 23:21:21 +0000
  • 89bbe44efd F-12960: guard AES-CCM JNI array releases on the acquired pointers Chris Conlon 2026-09-17 16:51:32 -0600
  • c3814fee11 F-12959: guard AES-GCM JNI array releases on the acquired pointers Chris Conlon 2026-09-17 16:47:37 -0600
  • b06cfd31d7 F-12953: include buffered bytes in the Cipher update() output size pre-check Chris Conlon 2026-09-17 16:43:08 -0600
  • d190e8995b F-13680: remove the environment dump from the rpm packaging target Chris Conlon 2026-09-17 16:37:05 -0600
  • cabc1c08a5 F-12958: gate PKCS12 PBKDF on HAVE_PKCS12 to match wolfSSL and FeatureDetect Chris Conlon 2026-09-17 16:34:25 -0600
  • e879c7d5ef
    Merge 5d63c39340 into a1f4cfac71 Chris Conlon 2026-09-17 16:25:17 -0600
  • 5d63c39340 Android: define HAVE_GMTIME_R so wolfSSL date checks are thread safe Chris Conlon 2026-09-16 16:37:34 -0600
  • 328b9cefe3 JNI/JCE: add SHAKE-128 and SHAKE-256 (FIPS 202 XOF) MessageDigest support Chris Conlon 2026-09-01 12:54:21 -0600
  • 36eb96797a
    Merge 246996f163 into a1f4cfac71 Chris Conlon 2026-09-17 15:55:48 -0600
  • 246996f163 JNI/JCE: generate the AES-GCM IV inside wolfCrypt for encrypt init without parameters Chris Conlon 2026-09-17 14:06:29 -0600
  • d2b76e8fdc
    Merge 8326214a18 into a1f4cfac71 Chris Conlon 2026-09-17 20:11:06 +0000
  • 8326214a18 JNI/JCE: add RSA/ECB/NoPadding Cipher for the raw RSA primitive Chris Conlon 2026-09-17 09:38:20 -0600
  • a1f4cfac71
    Merge pull request #264 from cconlon/fenrirAug20_2 master Ruby Martin 2026-09-17 13:53:34 -0500
  • 887e459e16
    Merge pull request #257 from cconlon/fenrirAug13_2 Ruby Martin 2026-09-17 12:18:49 -0500
  • 9b6f445f61
    Merge pull request #259 from cconlon/fenrirAug17 Ruby Martin 2026-09-17 11:05:40 -0500
  • 22baab9774
    Merge 935fc782ac into b8392ced50 Chris Conlon 2026-09-16 21:55:54 +0000
  • 935fc782ac JNI/JCE: add Ed25519/Ed448 support (Signature, KeyPairGenerator, KeyFactory) Chris Conlon 2026-09-10 12:30:12 -0600
  • fd48a30fc9
    Merge d9fb4aac46 into b8392ced50 Chris Conlon 2026-09-16 15:54:04 -0600
  • d9fb4aac46 F-3766: drop the retired JCenter repository from the Android IDE config Chris Conlon 2026-09-04 16:52:13 -0600
  • af4e685919 F-12196: add encryptedKeyPemToDer with a wipeable char array password Chris Conlon 2026-09-04 16:47:56 -0600
  • 404fcca4fe
    Merge 637c08b0c8 into b8392ced50 Chris Conlon 2026-09-16 21:41:55 +0000
  • 637c08b0c8 F-12193: validate PBKDF password and salt lengths against their arrays Chris Conlon 2026-09-04 15:23:46 -0600
  • 7bb0692834 F-12192: read fixed-size WKS bodies with readFully in engineLoad Chris Conlon 2026-09-04 15:19:49 -0600
  • 3024b2e364 F-11219: zeroize copied private outputs in the RSA CRT export wrapper Chris Conlon 2026-09-04 15:12:46 -0600
  • 0a01e7db42 F-11218: zeroize the copied output array in the RNG byte-array wrapper Chris Conlon 2026-09-04 15:08:27 -0600
  • 9b12d43b6d F-11217: zeroize copied sensitive arrays in FIPS byte-array wrappers Chris Conlon 2026-09-04 15:04:59 -0600
  • e088ed482c F-11216: zeroize copied key arrays in AES mode setters before release Chris Conlon 2026-09-04 14:50:20 -0600
  • 47af88cf3b F-11214: normalize NULL SPKI parameters in ML-DSA cert and key matching Chris Conlon 2026-09-04 14:45:34 -0600
  • afbe80aea2 F-10002: detach native threads attached by the FIPS error callback Chris Conlon 2026-09-04 14:35:13 -0600
  • 1a03cafc4f
    Merge f774a8cec5 into b8392ced50 Chris Conlon 2026-09-16 14:22:55 -0600
  • f774a8cec5 JNI/JCE: add AES-CFB (CFB1/CFB8/CFB128) support Chris Conlon 2026-08-31 16:28:25 -0600
  • 546c6495c9
    Merge 5e1a2ec903 into b8392ced50 Chris Conlon 2026-09-16 13:53:18 -0600
  • 5e1a2ec903 JNI/JCE: add AES key wrap Chris Conlon 2026-08-27 17:12:35 -0600
  • e08efa4846
    Merge 2ad669d89e into b8392ced50 Chris Conlon 2026-09-16 11:56:38 -0600
  • 2ad669d89e JNI/JCE: add AES-XTS support Chris Conlon 2026-08-27 11:44:30 -0600
  • 2da8699db2 F-12195: zeroize the copied PKCS8 array in the algorithm ID parser Chris Conlon 2026-09-04 16:36:00 -0600
  • ece6631823 F-12194: zeroize the copied private key PEM before JNI release Chris Conlon 2026-09-04 16:33:10 -0600
  • 75020aefbc F-10001: reject undersized hash arrays in MD5 byte-array native final Chris Conlon 2026-09-04 14:16:41 -0600
  • 7e90cad1de F-10007: regenerate Android Gradle wrapper jar with Gradle 8.4 Chris Conlon 2026-09-04 14:06:14 -0600
  • ad8f284c7d
    Merge 00a57804bd into b8392ced50 Chris Conlon 2026-09-11 23:26:26 +0000
  • 00a57804bd F-9999: validate backing buffer sizes in FIPS JNI wrappers Chris Conlon 2026-09-02 10:25:08 -0600
  • fc90b31e40 F-12191: bound PBKDF2 iteration count when loading untrusted WKS streams Chris Conlon 2026-09-01 14:39:16 -0600
  • cd8c0ce919 F-12190: reject negative WKS certificate chain count before allocation Chris Conlon 2026-09-01 14:25:55 -0600
  • 4d4532cc62 F-12170: correct public-DER size-query comment in RsaKeyToPublicDer Chris Conlon 2026-09-01 14:17:32 -0600
  • 7be0a58c95 F-12169: correct Rng.generateBlock ByteBuffer size doc Chris Conlon 2026-09-01 14:16:03 -0600
  • 419eeb9beb
    Merge f9fd5cb656 into b8392ced50 Chris Conlon 2026-09-11 23:24:16 +0000
  • f9fd5cb656 F-12167: return false for invalid RSA-PSS signatures instead of throwing Chris Conlon 2026-09-01 10:44:18 -0600
  • 18490e7326 F-12166: preserve JNI exceptions and avoid unresolved field ID in getNativeStruct Chris Conlon 2026-09-01 10:25:38 -0600
  • c8cd44719c F-12165: validate AES-GMAC tag length in WolfCryptMac init Chris Conlon 2026-09-01 10:19:53 -0600
  • 0b1dec74ae F-12189: stop logging FIPS key material, secrets, and plaintext in debug builds Chris Conlon 2026-09-01 10:12:30 -0600
  • c6c4fdac0e F-12168: correct OCSP response success sentinel in doc comment Chris Conlon 2026-09-01 10:02:09 -0600
  • d2ba4641c7
    Merge 34245fd083 into b8392ced50 Chris Conlon 2026-09-11 23:21:24 +0000
  • 34245fd083 F-12188: require wolfSSL 5.9.2+ for native X509 CertPathBuilder verifier Chris Conlon 2026-08-31 16:15:31 -0600
  • f87dd1faac F-12164: reject mismatched PRF algorithm in PBKDF2 translateKey Chris Conlon 2026-08-31 16:06:04 -0600
  • 1cbc268b18 F-12163: preserve DH privateValueLength in DER parameter encoding Chris Conlon 2026-08-31 15:57:49 -0600
  • ab922d9a1d F-12162: enforce native AES-CCM nonce length limits at init time Chris Conlon 2026-08-31 15:47:51 -0600
  • 5677a6c915 F-12161: account for AES-CCM auth tag in Cipher engineGetOutputSize Chris Conlon 2026-08-31 15:37:15 -0600
  • c4b440967a
    Merge da92b80bd3 into b8392ced50 Chris Conlon 2026-09-11 23:20:15 +0000
  • da92b80bd3 F-10000: reject undersized hash arrays in SHA byte-array native finals Chris Conlon 2026-08-28 17:31:06 -0600
  • 0380b95346 F-8213: zeroize prior AesCmac key clone before storing new key Chris Conlon 2026-08-28 16:28:17 -0600
  • e1e97fe400 F-8212: bound bufSz to buffer capacity in FIPS RNG GenerateBlock wrappers Chris Conlon 2026-08-28 16:13:11 -0600
  • 1c64843fa0
    Merge 1e0c9212ed into b8392ced50 Chris Conlon 2026-09-11 23:16:34 +0000
  • 1e0c9212ed JNI: guard cipher and MAC debug logging against NULL caller buffers Chris Conlon 2026-08-27 16:11:07 -0600
  • 4f5131953c F-3563: zeroize Hmac and ChaCha native structs on release Chris Conlon 2026-08-27 14:35:28 -0600
  • 114338bb0c F-9328: fix stale testConvertWksToWks comment claiming stream identity Chris Conlon 2026-08-27 13:20:13 -0600
  • eb33338cae F-9327: correct wcSHA3_224 class javadoc label to SHA3-224 Chris Conlon 2026-08-27 13:14:13 -0600
  • 998f8f91a4 F-11209: log the generated region in RNG debug output Chris Conlon 2026-08-27 13:12:36 -0600
  • f712411289 F-11208: log the processed region in SHA ByteBuffer update/final debug output Chris Conlon 2026-08-27 13:10:56 -0600
  • fa2e99a46b F-11207: log the processed region in MD5 ByteBuffer update/final debug output Chris Conlon 2026-08-27 13:04:32 -0600
  • efe1cf855e F-9997: add explicit non-blinding arm to wc_RsaSetRNG JNI wrapper Chris Conlon 2026-08-27 12:59:14 -0600
  • a89f7877e6 F-6156: avoid XMALLOC(0) on AAD-only AES-GCM/CCM paths Chris Conlon 2026-08-27 12:52:54 -0600
  • 5a0be9de59 F-3996: reject IV shorter than one AES block in AesCts key setup Chris Conlon 2026-08-27 12:33:40 -0600
  • 3ca22fba6b F-3769: log the written output region in AesCtr ByteBuffer update debug output Chris Conlon 2026-08-27 10:10:43 -0600
  • 3be2d9378a
    Merge e0da7509e9 into b8392ced50 Chris Conlon 2026-09-11 23:15:13 +0000
  • e0da7509e9 F-4001: quote CERT_LOCATION and cp paths in update-certs.sh, validate certs dir Chris Conlon 2026-08-26 17:15:43 -0600
  • 393557097f F-4000: quote JAVA_HOME and keystore paths in system-cacerts-to-wks.sh keytool call Chris Conlon 2026-08-26 17:07:14 -0600
  • 1909401fd9 F-3763: fail closed when no SHA-256 tool is available in CryptoBenchmark.sh Chris Conlon 2026-08-21 16:20:51 -0600
  • 399e3f4b6f F-6154: zeroize native ML-DSA seed and private key copies before JNI release Chris Conlon 2026-08-21 16:15:09 -0600
  • 3b1f9031fa F-6153: zeroize full RSA decrypt output buffer before free Chris Conlon 2026-08-21 15:58:45 -0600
  • 4382551949 F-5992: throw AEADBadTagException on AES-CCM tag failure Chris Conlon 2026-08-21 15:54:09 -0600
  • d3d9bdf218 F-5893: zeroize previous HMAC key on re-key in setKey Chris Conlon 2026-08-21 15:47:48 -0600
  • fae783ff7d F-5892: enforce minimum DH prime size on KeyFactory import Chris Conlon 2026-08-21 15:40:16 -0600
  • 67bad31ced F-5396: validate 3DES key and IV length in native setKey wrapper Chris Conlon 2026-08-21 14:59:49 -0600
  • 69d6555bda F-5395: validate AES IV length in native setKey wrappers Chris Conlon 2026-08-21 14:51:05 -0600
  • 36dd5f1664 F-5226: zeroize native ChaCha key copy before JNI release Chris Conlon 2026-08-21 14:28:12 -0600
  • 39974a4f62 F-5225: validate ChaCha IV length before native SetIV read Chris Conlon 2026-08-20 16:47:19 -0600
  • cb05f101c0 F-9989 / F-9990: correct copied import comments in Ed25519 wrappers Chris Conlon 2026-08-17 14:59:20 -0600
  • 1e0263ee43 F-9986 / F-9987 / F-9988: correct copied import comments in Curve25519 wrappers Chris Conlon 2026-08-17 14:45:50 -0600
  • 068f6b4938 F-9996: clean up partial initialization on JNI_OnLoad failure Chris Conlon 2026-08-17 14:40:05 -0600
  • f69f448e49 F-9995: detach natively attached threads in FIPS error callback Chris Conlon 2026-08-17 14:36:17 -0600
  • 786d92ca82 F-9994: log requested size in FIPS GCM decrypt wrappers Chris Conlon 2026-08-17 14:29:46 -0600
  • 8de26b2fe7 F-9993: free active CMAC context in native free and setKey reinit Chris Conlon 2026-08-17 14:25:10 -0600
  • 3970e39c1d F-9992: validate caller buffer sizes in RsaExportCrtKey wrapper Chris Conlon 2026-08-17 14:17:30 -0600
  • 8b6d7ccb3c F-9991: size BlockCipher update output from length instead of input.length Chris Conlon 2026-08-17 14:04:48 -0600
  • 65adee1049 F-3561: zeroize AES and 3DES key material in releaseNativeStruct Chris Conlon 2026-08-14 12:14:24 -0600
  • 3590c2af6d F-8206: check GetStringUTFChars result in ECC curve name paths Chris Conlon 2026-08-13 16:41:30 -0600
  • d52838c2d4 F-6903: bound direct buffer write position in SHA final wrappers Chris Conlon 2026-08-13 16:37:28 -0600
  • 8dedff93d4 F-6902: zeroize secret SLH-DSA input copies before JNI release Chris Conlon 2026-08-13 16:26:17 -0600
  • 5a75925fef F-6437: zeroize secret ML-KEM input copies before JNI release Chris Conlon 2026-08-13 16:20:09 -0600