| Author | Object | Transaction | Date |
|---|
| • gniibe | rCe235f38f9b9f: tests: Reproducer for short dklen in FIPS mode | | Fri, Jan 30, 10:43 AM |
| • gniibe | rCe7b1fbda6a9e: hmac,hkdf: Check the HMAC key length in FIPS mode. | | Fri, Jan 30, 10:43 AM |
| • gniibe | rC5191379da3ad: build: Prefer gpgrt-config when available. | | Fri, Jan 30, 10:43 AM |
| • gniibe | T5034: dev: Deprecate libassuan-config, libgcrypt-config, ksba-config, ntbtls-config, npth-config, and gpg-error-config | | Fri, Jan 30, 10:43 AM |
| • gniibe | T6039: FIPS: Allow salt=NULL (or shorter salt) for HKDF | | Fri, Jan 30, 10:43 AM |
| • gniibe | rC7f4fafb5564d: Revert "kdf:pkdf2: Require longer input when FIPS mode." | | Fri, Jan 30, 10:43 AM |
| • gniibe | rC47db7fe3a0c3: Revert "kdf:pkdf2: Require longer input when FIPS mode." | | Fri, Jan 30, 10:43 AM |
| • gniibe | rCd09d3d33c79d: kdf:pkdf2: Require longer input when FIPS mode. | | Fri, Jan 30, 10:43 AM |
| • gniibe | rC7f4fafb5564d: Revert "kdf:pkdf2: Require longer input when FIPS mode." | | Fri, Jan 30, 10:43 AM |
| • gniibe | rCe7b1fbda6a9e: hmac,hkdf: Check the HMAC key length in FIPS mode. | | Fri, Jan 30, 10:43 AM |
| • gniibe | rC5191379da3ad: build: Prefer gpgrt-config when available. | | Fri, Jan 30, 10:43 AM |
| • gniibe | rC0dcb7e05c9e1: build: Prefer gpgrt-config when available. | | Fri, Jan 30, 10:43 AM |
| • gniibe | rC58c92098d053: hmac,hkdf: Allow use of shorter salt for HKDF. | | Fri, Jan 30, 10:43 AM |
| • gniibe | rCb095ea755973: hmac,hkdf: Check the HMAC key length in FIPS mode. | | Fri, Jan 30, 10:43 AM |
| • gniibe | rC057844700ec2: pkdf2: Add checks for FIPS. | | Fri, Jan 30, 10:43 AM |
| • gniibe | T6039: FIPS: Allow salt=NULL (or shorter salt) for HKDF | | Fri, Jan 30, 10:43 AM |
| • gniibe | rC20ad5df60b03: fips: Mark AES key wrapping as approved. | | Fri, Jan 30, 10:43 AM |
| • gniibe | rC057844700ec2: pkdf2: Add checks for FIPS. | | Fri, Jan 30, 10:43 AM |
| • gniibe | rCf4a861f3e5ae: pkdf2: Add checks for FIPS. | | Fri, Jan 30, 10:43 AM |
| • gniibe | rCc34c9e70055e: fips: Mark AES key wrapping as approved. | | Fri, Jan 30, 10:43 AM |
| • gniibe | rC20ad5df60b03: fips: Mark AES key wrapping as approved. | | Fri, Jan 30, 10:43 AM |
| • gniibe | T5512: Implement service indicators | | Fri, Jan 30, 10:43 AM |
| • gniibe | rCbf1e62e59200: rsa: Prevent usage of long salt in FIPS mode | | Fri, Jan 30, 10:43 AM |
| • gniibe | rCfdd2a8b3329e: rsa: Prevent usage of long salt in FIPS mode | | Fri, Jan 30, 10:43 AM |
| • gniibe | rC06ea5b5332ff: fips,rsa: Prevent usage of X9.31 keygen in FIPS mode. | | Fri, Jan 30, 10:43 AM |
| • gniibe | rC392e0ccd25f3: fips,rsa: Prevent usage of X9.31 keygen in FIPS mode. | | Fri, Jan 30, 10:43 AM |
| • gniibe | rCbdeea2a53e9e: t-rsa-testparm: fix 'function declaration isn’t a prototype' warning | | Fri, Jan 30, 10:43 AM |
| • gniibe | rC896fe69757e0: doc: Minor fix up. | | Fri, Jan 30, 10:43 AM |
| • gniibe | rC7ddad4035d92: doc: Minor fix up. | | Fri, Jan 30, 10:43 AM |
| • gniibe | rC0909186b9e66: t-rsa-testparm: fix 'function declaration isn’t a prototype' warning | | Fri, Jan 30, 10:43 AM |
| • gniibe | rC693ffa145378: build: Fix configure.ac for strict C99. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rCb1a3424e7f80: build: Fix m4 macros for strict C compiler. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rC83ea195b61d5: build: Fix configure.ac for strict C99. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rC44a3f26539f7: ecc: Do not allow skipping tests in FIPS Mode. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rCe3b441214f93: build: Fix m4 macros for strict C compiler. | | Fri, Jan 30, 10:42 AM |
| • gniibe | T6394: FIPS requires running PCT tests unconditionally | | Fri, Jan 30, 10:42 AM |
| • gniibe | rC2ddeec574bc1: ecc: Do not allow skipping tests in FIPS Mode. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rC44a3f26539f7: ecc: Do not allow skipping tests in FIPS Mode. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rCc41d4f502f1b: ecc: Make the PCT recoverable in FIPS mode and consistent with RSA. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rCfc19b27b5439: visibility: Check FIPS operational status for MD+Sign operation. | | Fri, Jan 30, 10:42 AM |
| • gniibe | T6397: PCT failures inconsistency in regards to the FIPS error state | | Fri, Jan 30, 10:42 AM |
| • gniibe | T6396: the gcry_pk_hash_sign/verify operates in FIPS non-operational mode | | Fri, Jan 30, 10:42 AM |
| • gniibe | rCc41d4f502f1b: ecc: Make the PCT recoverable in FIPS mode and consistent with RSA. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rC23a2d1285e35: ecc: Make the PCT recoverable in FIPS mode and consistent with RSA. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rCfc19b27b5439: visibility: Check FIPS operational status for MD+Sign operation. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rC654d0dfa0499: visibility: Check FIPS operational status for MD+Sign operation. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rC397ff085749e: kdf: Update tests in regards to the allowed parameters in FIPS mode. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rCa51f0e66842a: fips: Add explicit indicators for md and mac algorithms. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rC4cff7e739829: random: Remove unused SHA384 DRBGs. | | Fri, Jan 30, 10:42 AM |
| • gniibe | T6376: FIPS 140-3: add explicit indicators for md and mac to unblock MD5 in apt | | Fri, Jan 30, 10:42 AM |
| • gniibe | T6393: DRBG with SHA384 is no longer allowed in FIPS mode (and looks like impossible to enable anyway) | | Fri, Jan 30, 10:42 AM |
| • gniibe | T5512: Implement service indicators | | Fri, Jan 30, 10:42 AM |
| • gniibe | rC45b80678109e: random: Remove unused SHA384 DRBGs. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rC4cff7e739829: random: Remove unused SHA384 DRBGs. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rCa51f0e66842a: fips: Add explicit indicators for md and mac algorithms. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rC397ff085749e: kdf: Update tests in regards to the allowed parameters in FIPS mode. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rC076dd2ffcd95: fips: Check return value from ftell | | Fri, Jan 30, 10:42 AM |
| • gniibe | rCc88672a327f6: fips: Add explicit indicators for md and mac algorithms. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rC3fd3bb31597f: fips: Check return value from ftell | | Fri, Jan 30, 10:42 AM |
| • gniibe | rC535a4d345872: fips: Recover test cases for selftest, add skipping in FIPS mode. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rCf5fe94810f30: kdf: Update tests in regards to the allowed parameters in FIPS mode. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rC0024db5afee8: fips: Unblock MD5 in fips mode but mark non-approved in indicator. | | Fri, Jan 30, 10:42 AM |
| • gniibe | T6376: FIPS 140-3: add explicit indicators for md and mac to unblock MD5 in apt | | Fri, Jan 30, 10:42 AM |
| • gniibe | rCdc4a60e2d70b: fips: Unblock MD5 in fips mode but mark non-approved in indicator. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rC0024db5afee8: fips: Unblock MD5 in fips mode but mark non-approved in indicator. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rC6805d76b7ed4: fips: Fix fips indicator function. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rCc5de9e77fb33: fips: Fix fips indicator function. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rC0b7ad923978f: doc: Document the new FIPS indicators. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rCfcb9ec67a117: doc: Document the new FIPS indicators. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rC05a9c9d1ba1d: fips: Add function-name based FIPS indicator. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rC0b2b30c0c42f: fips: Explicitly allow only some PK flags. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rC4c1c8a707f96: fips: Explicitly allow only some PK flags. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rC251f1749900e: fips: Explicitly disable overriding random in FIPS mode. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rC051bbe84d889: fips: Mark gcry_pk_encrypt/decrypt function non-approved. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rCe0a5a9eb8301: fips: Explicitly disable overriding random in FIPS mode. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rC05cb8355d3e6: fips: Mark gcry_pk_encrypt/decrypt function non-approved. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rCf6f345fe89b0: fips: More elaborate way of getting FIPS pk flags indicators. | | Fri, Jan 30, 10:42 AM |
| • gniibe | T6417: FIPS service indicator regarding the public key algorithm flags and objects | | Fri, Jan 30, 10:42 AM |
| • werner | rC14835c5d7662: doc: Add remark that leading zeroes are stripped from printed MPIs. | | Fri, Jan 30, 10:42 AM |
| • werner | T6435: libgcrypt | gcry_mpi_ec_mul return a truncated point coordinate | | Fri, Jan 30, 10:42 AM |
| • gniibe | rCf2ab06bc3ccc: build: Allow build with -Oz. | | Fri, Jan 30, 10:42 AM |
| • gniibe | T6432: libgcrypt - flag munging does not account for -Oz | | Fri, Jan 30, 10:42 AM |
| • gniibe | rC7edf1abb9a0d: build: Allow build with -Oz. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rCf2ab06bc3ccc: build: Allow build with -Oz. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rC4128f73d3a83: cipher: Enable the fast path to ChaCha20 only when supported. | | Fri, Jan 30, 10:42 AM |
| • gniibe | T6384: libgcrypt link error if cipher chacha20 is not included | | Fri, Jan 30, 10:42 AM |
| • gniibe | rC137f1fd82bc9: cipher: Enable the fast path to ChaCha20 only when supported. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rC4128f73d3a83: cipher: Enable the fast path to ChaCha20 only when supported. | | Fri, Jan 30, 10:42 AM |
| • werner | rCb75a58df84a5: cipher: Fix edge case for SET_ALLOW_WEAK_KEY. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rCd41177937cea: random: Use getrandom only when it's appropriate. | | Fri, Jan 30, 10:42 AM |
| jukivili | rC9b1ee0574ed9: Revert "cipher: Fix edge case for SET_ALLOW_WEAK_KEY." | | Fri, Jan 30, 10:42 AM |
| • gniibe | T6442: libgcrypt-1.10.2: getrandom() is not available everywhere | | Fri, Jan 30, 10:42 AM |
| • werner | T6451: libgcrypt | gcry_cipher_setkey: 3DES-CBC key returns GPG_ERR_WEAK even with GCRYCTL_SET_ALLOW_WEAK_KEY | | Fri, Jan 30, 10:42 AM |
| jukivili | T6451: libgcrypt | gcry_cipher_setkey: 3DES-CBC key returns GPG_ERR_WEAK even with GCRYCTL_SET_ALLOW_WEAK_KEY | | Fri, Jan 30, 10:42 AM |
| jukivili | rCb75a58df84a5: cipher: Fix edge case for SET_ALLOW_WEAK_KEY. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rCfa21ddc158b5: random: Use getrandom only when it's appropriate. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rCd41177937cea: random: Use getrandom only when it's appropriate. | | Fri, Jan 30, 10:42 AM |
| • gniibe | rCaab1d63e4def: random: Use getrandom (GRND_RANDOM) in FIPS mode. | | Fri, Jan 30, 10:42 AM |
| jukivili | rC9b1ee0574ed9: Revert "cipher: Fix edge case for SET_ALLOW_WEAK_KEY." | | Fri, Jan 30, 10:42 AM |
| jukivili | rC7cdfc869b7af: doc: add documentation for GCRYCTL_SET_ALLOW_WEAK_KEY | | Fri, Jan 30, 10:42 AM |