Commit Graph

319 Commits

Author SHA1 Message Date
Zhi Guan
0bcffd3734 Update TLS 1.3 2026-04-13 11:34:16 +08:00
Zhi Guan
2e550edc35 Update TLS 1.3 2026-04-12 11:48:15 +08:00
Zhi Guan
3d29d5066d Update TLS 1.3 PSK-only mode 2026-03-28 11:09:26 +08:00
Zhi Guan
e996e72537 Update TLS 1.3 0-RTT 2026-03-23 20:50:55 +08:00
Zhi Guan
5efe2005d4 Update TLS 1.3 PSK 1-RTT 2026-03-23 10:32:16 +08:00
Zhi Guan
0d1acec6df Update TLS 1.3 handshake
Working on HelloRetryRequest, NewSessionTicket
2026-03-21 18:41:46 +08:00
Zhi Guan
ead4caecb7 Update TLS 1.3 state machine 2026-03-17 16:51:12 +08:00
Zhi Guan
3322a5fc7b Update TLS 1.3 2026-02-27 11:02:22 +08:00
Zhi Guan
ee2fa409f2 Update TLCP to state machine 2026-02-27 09:11:49 +08:00
Zhi Guan
cac8f394a0 Update X509_KEY API to support SM9 2026-02-24 10:45:33 +08:00
Zhi Guan
8eb0d3b572 x509_key all tests passed 2026-02-05 20:26:40 +08:00
Zhi Guan
9c58806408 Rewrite TLS 1.2 as a state machine 2026-02-01 20:38:13 +08:00
Zhi Guan
a15e0f34c7 Add ECDSA with curve P-256
for TLS testing
2026-01-24 12:27:12 +08:00
Zhi Guan
05ba2f8e54 Support HSS/XMSS/XMSSMT certificate, CSR, and CRL
LMS and SPHINCS+ do not have official OID, so officially supported by X.509
2026-01-18 21:13:58 +08:00
Zhi Guan
e8eb873c47 Add x509_private_key_from_file 2026-01-18 17:31:00 +08:00
Zhi Guan
9db11c6d06 Update XMSS
Add key_update callback and private_key_from_file
2026-01-18 17:09:27 +08:00
Zhi Guan
2e8d3abbc9 Update LMS 2026-01-18 17:08:16 +08:00
Zhi Guan
9488128154 Add LMS key_update callback 2026-01-18 12:12:45 +08:00
Zhi Guan
47639a9e23 Add X509_KEY to support different public key algos 2026-01-16 17:25:17 +08:00
Zhi Guan
d7f93bf379 Update SPHINCS+ 2026-01-15 18:37:22 +08:00
Zhi Guan
a212b17099 Update LMS/HSS
Set SHA-256/SM3 independently.
2026-01-15 18:27:20 +08:00
Zhi Guan
02d3d0224e Update XMSS
Functions and types with prefix `xmss`
Set SM3 or SHA256 independently.
2026-01-15 18:22:11 +08:00
Zhi Guan
3afd4a047b Update Kyber 2026-01-12 20:41:44 +08:00
Zhi Guan
1f64cb7389 Add SPHINCS+ commands to gmssl
Add `sphincskeygen`, `sphincssign`, `sphincsverify`
2026-01-11 21:30:05 +08:00
Zhi Guan
58a51a8474 Add SHA256 HMAC
SPHINCS+ need HMAC
2026-01-11 15:19:42 +08:00
Zhi Guan
4df06e7196 Update SPHINCS+ 2026-01-10 23:30:00 +08:00
Zhi Guan
242365bef1 Update SPHINCS+ 2026-01-08 22:23:32 +08:00
Zhi Guan
aa28fc5252 Update SPHINCS+ 2026-01-07 22:18:26 +08:00
Zhi Guan
22a9340576 Add SPHINCS+ 2026-01-06 21:59:21 +08:00
Zhi Guan
38451da6a8 Update XMSS 2026-01-05 21:19:23 +08:00
Zhi Guan
e919690d6a Update XMSS 2026-01-05 12:02:24 +08:00
Zhi Guan
83ef4e88bf Update XMSS 2026-01-04 22:37:38 +08:00
Zhi Guan
14e4edede7 Update XMSS 2026-01-04 10:04:53 +08:00
Zhi Guan
f5f3b6a5b2 Update lms.h 2026-01-04 09:59:45 +08:00
Zhi Guan
b58eb671d5 Update Kyber 2026-01-04 09:59:29 +08:00
Zhi Guan
8239b4099f Add ENABLE_KYBER to CMake 2025-12-27 10:52:07 +08:00
Zhi Guan
a03f5132cd Add XMSS-SM3 signature 2025-12-18 18:35:15 +08:00
Zhi Guan
4791a30466 Add XMSS/XMSS^MT OID 2025-12-10 08:56:27 +08:00
Zhi Guan
fce32d149e Update socket.h 2025-12-09 08:46:21 +08:00
Zhi Guan
4ef98b0833 Merge pull request #1839 from mikecovlee/master
[bugfix] fix win32 incompatible pointer type error and cmake warnings
2025-12-08 20:42:24 +08:00
Zhi Guan
2b67dca44a Update ASN.1 2025-12-08 16:50:56 +08:00
Zhi Guan
d41c8b1287 Merge pull request #1786 from droe/droe/fix-ssl2
Fix SSL 2 version constant to 0x0002
2025-12-08 11:03:13 +08:00
Zhi Guan
bae8f54667 Update XMSS-SM3
XMSS is in developing, not fully tested
2025-12-08 10:24:00 +08:00
Zhi Guan
833150f297 Reomve sm3 from lms/hss names 2025-12-07 22:08:17 +08:00
Zhi Guan
49f4e1f28a Update SM3 LMS/HSS 2025-12-07 21:35:10 +08:00
Zhi Guan
a6d69ede57 Update sm2.h 2025-12-07 21:32:21 +08:00
Zhi Guan
3cec02d288 Add LMS/HSS public key DER encoding 2025-12-04 16:06:10 +08:00
Zhi Guan
6a51ca01dc Add SM3 LMS/HSS hash-based post-quantum signatures 2025-12-04 11:46:16 +08:00
Michael Lee
236590835a Fix error that can not override DEBUG 2025-12-02 16:46:01 +08:00
Daniel Roethlisberger
061045f206 Fix SSL 2 version constant to 0x0002
SSL 2 uses a version field of 0x0002, not 0x0200.  This is confirmed not
only in the original Netscape spec [1] and RFC draft of the time [2],
but also in major implementations such as OpenSSL [3] and Wireshark [4].

[1] https://www-archive.mozilla.org/projects/security/pki/nss/ssl/draft02.html
[2] https://datatracker.ietf.org/doc/html/draft-hickman-netscape-ssl-00
[3] https://github.com/openssl/openssl/blob/OpenSSL_0_9_6m/ssl/ssl2.h#L66-L71
[4] https://github.com/wireshark/wireshark/blob/release-4.4/epan/dissectors/packet-tls-utils.h#L266-L277
2025-01-19 22:31:12 +01:00