Ben Taylor
fbaf177f2d
Fix style issues
...
Signed-off-by: Ben Taylor <ben.taylor@linaro.org>
2026-06-18 13:04:13 +01:00
Ben Taylor
55536a07c9
Remove redundant function from pkcs7_parse_reuse
...
Signed-off-by: Ben Taylor <ben.taylor@linaro.org>
2026-06-18 13:04:13 +01:00
Ben Taylor
434d7114a8
Add ChangeLog
...
Signed-off-by: Ben Taylor <ben.taylor@linaro.org>
2026-06-18 13:04:13 +01:00
Ben Taylor
b1a4b07509
Add fix for stale pointer after mbedtls_pkcs7_free
...
Signed-off-by: Ben Taylor <ben.taylor@linaro.org>
2026-06-18 13:04:13 +01:00
Gilles Peskine
1f5b89077c
Merge pull request #1655 from bjwtaylor/ECDHE-PSK-integer-overflow-restricted-4.1
...
Backport Ecdhe psk integer overflow restricted fix to 4.1
2026-06-16 11:49:57 +02:00
Ronald Cron
5ea102945d
Merge pull request #1661 from minosgalanakis/public-sync/mbedtls-4.1-14062026
...
[Sync] Merge mbedtls-4.1 into Merge mbedtls-4.1-restricted
2026-06-16 09:02:13 +02:00
Ronald Cron
9d54126d0e
Merge pull request #1646 from bjwtaylor/oob-key-exchange-restricted-4.1
...
Add fix for OOB key exchange error 4.1
2026-06-15 22:42:15 +02:00
Ben Taylor
a98b95074a
Update ChangeLog to include CVE number
...
Co-authored-by: Gilles Peskine <gilles.peskine@arm.com>
Signed-off-by: Ben Taylor <32939606+bjwtaylor@users.noreply.github.com>
2026-06-15 09:20:59 +01:00
Minos Galanakis
e1896dbfd8
Merge remote-tracking branch 'public/mbedtls-4.1' into public-sync/mbedtls-4.1-14062026
...
Signed-off-by: Minos Galanakis <minos.galanakis@arm.com>
2026-06-14 19:36:52 +01:00
Ben Taylor
1a5e328377
Fix style issue
...
Signed-off-by: Ben Taylor <ben.taylor@linaro.org>
2026-06-12 09:13:45 +01:00
Ben Taylor
f5cb455b5c
Correct ChangeLog style
...
Signed-off-by: Ben Taylor <ben.taylor@linaro.org>
2026-06-12 09:13:45 +01:00
Ben Taylor
ff8de9cec9
Add CVE to ChangeLog
...
Co-authored-by: Ronald Cron <ronald.cron@arm.com>
Signed-off-by: Ben Taylor <32939606+bjwtaylor@users.noreply.github.com>
2026-06-12 09:13:45 +01:00
Ben Taylor
4cb3470f91
Improve the wording of the ChangeLog
...
Co-authored-by: Ronald Cron <ronald.cron@arm.com>
Signed-off-by: Ben Taylor <32939606+bjwtaylor@users.noreply.github.com>
2026-06-12 09:13:45 +01:00
Ben Taylor
cf37056714
Add improvements to ChangeLog
...
Signed-off-by: Ben Taylor <ben.taylor@linaro.org>
2026-06-12 09:13:45 +01:00
Ben Taylor
1e061ee95a
Add reported by and CVE placeholder
...
Signed-off-by: Ben Taylor <ben.taylor@linaro.org>
(cherry picked from commit ab2a7d5a3472f39190344f754e6cee5039fcba50)
2026-06-10 14:34:10 +01:00
Ben Taylor
afdbd67f21
Correct style of ChangeLog
...
Signed-off-by: Ben Taylor <ben.taylor@linaro.org>
(cherry picked from commit 0501e447cc19ed06b69daea5e17585e1294030cd)
2026-06-10 14:34:10 +01:00
Ben Taylor
2705873c5a
Improve ChangeLog
...
Signed-off-by: Ben Taylor <ben.taylor@linaro.org>
(cherry picked from commit c058818451833a748da112e3b8129fd299480ceb)
2026-06-10 14:34:10 +01:00
Ben Taylor
93b10471aa
Add ChangeLog
...
Signed-off-by: Ben Taylor <ben.taylor@linaro.org>
(cherry picked from commit e71e49e634ba49b2b630f268bc8f0dd392751ec3)
2026-06-10 14:34:10 +01:00
Ben Taylor
4afd1c1685
Add in tests for ECDHE-PSK integer overflow
...
Signed-off-by: Ben Taylor <ben.taylor@linaro.org>
(cherry picked from commit c567299ee6bade9547a97d3ad1dcd5f3bd98ea6f)
2026-06-10 14:34:10 +01:00
Ben Taylor
f63ca6e0af
Added fix for Integer overflow using a large ECDHE Identity
...
Signed-off-by: Ben Taylor <ben.taylor@linaro.org>
(cherry picked from commit baf449db7e31f031ed5def0fecf417122f72d3ee)
2026-06-10 14:34:10 +01:00
Ronald Cron
b9af3cd809
Merge pull request #1608 from minosgalanakis/security/mlfbyt4c_tls13_policy_bypass_4.1
...
Backport 4.1: TLS1.3 client HRR policy bypass[ARM-MLFBYT4C]
2026-06-10 13:04:01 +02:00
Ronald Cron
6b175d2404
Merge pull request #10771 from mpg/security-link-4.1
...
[4.1] Update broken link in SECURITY.md
2026-06-05 16:49:28 +00:00
Manuel Pégourié-Gonnard
a982231904
Update broken link
...
I believe the existing link was to the TF wiki which has been retired
for some time now.
Signed-off-by: Manuel Pégourié-Gonnard <manuel.pegourie-gonnard@arm.com>
2026-06-05 12:28:01 +02:00
Ben Taylor
0cc307762a
Add ChangeLog
...
Signed-off-by: Ben Taylor <ben.taylor@linaro.org>
2026-06-05 10:21:36 +01:00
Ben Taylor
1ac3989db6
Add fix for OOB key exchange error
...
Signed-off-by: Ben Taylor <ben.taylor@linaro.org>
2026-06-05 09:49:35 +01:00
Ronald Cron
a73dce874b
Merge pull request #1588 from gilles-peskine-arm/ssl_tls13_prepare_new_session_ticket-psa_get_random-4.1
...
Backport 4.1: Fix ssl_tls13_prepare_new_session_ticket returning 1 on an RNG failure
2026-05-29 16:20:07 +02:00
Ronald Cron
a9e971b1b0
Merge pull request #1634 from valeriosetti/issue1569-backport-4.1
...
[backport 4.1] TLS 1.3 certificate chain signature algorithm policy gap
2026-05-29 13:35:08 +02:00
Gilles Peskine
b05434c1b1
Improve changelog wording
...
Signed-off-by: Gilles Peskine <Gilles.Peskine@arm.com>
2026-05-28 16:32:35 +02:00
Valerio Setti
bd57fb5e8a
changelog: fix typos
...
Signed-off-by: Valerio Setti <vsetti@baylibre.com>
2026-05-28 13:07:51 +02:00
Valerio Setti
f0ed933ca8
changelog: add note about issue 1569 resolution
...
Signed-off-by: Valerio Setti <vsetti@baylibre.com>
2026-05-28 13:07:51 +02:00
Valerio Setti
271bf18193
ssl: improve documentation of mbedtls_ssl_conf_sig_algs()
...
Clarify that the 'sig_algs' set through this function are only enforced
during the key exchange and that 'mbedtls_ssl_conf_cert_profile()' should
instead be used to enforce the same algorithms when verifying certificates.
Signed-off-by: Valerio Setti <vsetti@baylibre.com>
2026-05-28 13:07:51 +02:00
Minos Galanakis
e16f0e0b01
ssl_write_supported_groups_ext: Updated documentation
...
Signed-off-by: Minos Galanakis <minos.galanakis@arm.com>
2026-05-26 10:31:03 +01:00
Janos Follath
a4f79350ac
Merge pull request #10742 from valeriosetti/backport-pr10741
...
[backport 4.1] mbedtls_config.c missing mbedtls_platform_requirements.h
2026-05-26 09:24:50 +00:00
Minos Galanakis
2e2087d246
test_suite_ssl: Added MBEDTLS_DEBUG_C guards to logs
...
Signed-off-by: Minos Galanakis <minos.galanakis@arm.com>
2026-05-20 15:01:43 +01:00
Minos Galanakis
c4461967af
test_suite_ssl: Restructured reject_hrr_selecting_unoffered_group
...
Signed-off-by: Minos Galanakis <minos.galanakis@arm.com>
2026-05-20 15:01:21 +01:00
Minos Galanakis
d3931632fa
test_suite_ssl: Renamed hrr_reject_selecting_unoffered_group
...
Signed-off-by: Minos Galanakis <minos.galanakis@arm.com>
2026-05-20 15:01:00 +01:00
Minos Galanakis
f8adf74988
sll_client: align TLS 1.3 supported_groups filtering with PSA curve support
...
Signed-off-by: Minos Galanakis <minos.galanakis@arm.com>
2026-05-20 15:00:52 +01:00
minosgalanakis
e862725edd
Merge pull request #10709 from yiwu0b11/remove_unused_ffdh_code-4.1
...
Backport 4.1: tests: remove remaining FFDH code in compat.sh
2026-05-13 16:49:07 +00:00
Minos Galanakis
be84be5d9a
test_suite_ssl: doc fixes
...
Signed-off-by: Minos Galanakis <minos.galanakis@arm.com>
2026-05-13 11:45:44 +01:00
Minos Galanakis
45ca9e1e06
Added ChangeLog
...
Signed-off-by: Minos Galanakis <minos.galanakis@arm.com>
2026-05-12 15:02:05 +01:00
Minos Galanakis
2c164902ea
Adjusted dependecies for hrr_reject_unadvertised_group
...
Signed-off-by: Minos Galanakis <minos.galanakis@arm.com>
2026-05-12 15:02:05 +01:00
Minos Galanakis
bac133ffcb
test_suite_ssl: Introduced hrr_reject_unadvertised_group
...
Signed-off-by: Minos Galanakis <minos.galanakis@arm.com>
2026-05-12 15:02:05 +01:00
Minos Galanakis
cec2cef6b5
tls13_client: fix HRR selected_group validation
...
Reject HRR selected_group unless it matches the client’s original
supported_groups and is locally supported, so unadvertised groups are not
accepted in the second ClientHello.
Signed-off-by: Minos Galanakis <minos.galanakis@arm.com>
2026-05-12 15:02:05 +01:00
Ronald Cron
123216ea40
Merge pull request #10751 from gilles-peskine-arm/python-project-knowledge-directory-mbedtls-4.1
...
Backport 4.1: Create Python project knowledge directory
2026-05-12 13:38:11 +00:00
minosgalanakis
b2e36d7d7a
Merge pull request #1601 from mpg/mbedtls-4.1-restricted
...
Merge public 4.1 into -restricted
2026-05-12 09:46:03 +01:00
Manuel Pégourié-Gonnard
def1fe66ca
Merge branch 'mbedtls-4.1' into mbedtls-4.1-restricted
...
* mbedtls-4.1:
Update framework pointer to bring in fix for python imports
Update tf-psa-crypto to bring in python fix
2026-05-12 09:03:27 +02:00
Manuel Pégourié-Gonnard
10ff2fc1d9
Merge pull request #10750 from bjwtaylor/broken-build-1.1
...
Update framework pointer to bring in fix for python imports
2026-05-11 10:50:47 +00:00
Manuel Pégourié-Gonnard
e292284ddb
Merge branch 'mbedtls-4.1' into mbedtls-4.1-restricted
...
* mbedtls-4.1: (37 commits)
check_config: fix error message for missing TLS 1.2 key exchanges
check_config: add check for TLS 1.3 key exchanges
tests: depends.py: extend pkalgs including PSA_WANT_ALG_RSA_PKCS1V15_SIGN
tests: depends.py: fix reverse dependency for RSA
library: check_config: remove RSA encryption requirement from ECDHE-RSA
update ChangeLog
add ChangeLog
Fix build warning/error using llvm-mingw
test: improve symlink checks
test: versioned symlink order fix
test: reorder if-else structure
test: add debug output and fix for win config
ChangeLog fix
tests: fix DESTDIR install checks and add macOS compatibility
ChangeLog fixes
ChangeLog padding space fix
Test: add symlinks and dangling link check
ChangeLog fix
ChangeLog newline fix
Add changelog
...
2026-05-11 12:12:10 +02:00
Gilles Peskine
4f149ffc02
Update comment
...
Signed-off-by: Gilles Peskine <Gilles.Peskine@arm.com>
2026-05-08 18:00:45 +02:00
Gilles Peskine
c7b1c86e6b
Prefer to load tf_psa_crypto_test_case_info from project_knowledge
...
Try to load the list of tests that TF-PSA-Crypto wants us to ignore in three
ways, depending on the age of the tf-psa-crypto submodule:
* Modern: import `tf_psa_crypto_test_case_info` as an ordinary module,
expected to be found in `tf-psa-crypto/scripts/project_knowledge`.
* First location, quickly superseded: load
`tf-psa-crypto/tests/scripts/tf_psa_crypto_test_case_info.py`,
in a hackish way because we don't want to put that directory on the
load path.
* Oldest: there is no `tf_psa_crypto_test_case_info.py`. Use a hard-coded
list.
Once all the TF-PSA-Crypto branches we care about (e.g. pull requests
in progress) are updated with
`tf-psa-crypto/scripts/project_knowledge/tf_psa_crypto_test_case_info.py`,
we can drop the backward compatibilty hacks and simply
`import tf_psa_crypto_test_case_info` unconditionally and use
`tf_psa_crypto_test_case_info.INTERNAL_TEST_CASES` unconditionally.
Signed-off-by: Gilles Peskine <Gilles.Peskine@arm.com>
2026-05-08 18:00:45 +02:00