Skip to content

Conversation

@kojo1
Copy link
Collaborator

@kojo1 kojo1 commented Nov 1, 2020

TSL1.3 client requires cert_vfy before finished. CVE-2020-24613, PR3171
TLS 1.3, don't allow multiple ChangeCipherSpecs. CVE-2020-12457, PR2927
ECC timing resistance CVE-2020-11713, PR2894

return sp_ecc_mulmod_256(k, G, R, map, heap);
}
#endif
#ifdef WOLFSSL_SP_384

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Don't include the SP_384 code as it is not implemented in 4.1.0.

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Eliminated it.

Copy link

@SparkiDev SparkiDev left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The parts I was asked to review are all good.

@wolfssl-jp wolfssl-jp merged commit e88cb22 into wolfssl-jp:4.1.0 Nov 4, 2020
kojo1 added a commit that referenced this pull request Jan 3, 2024
ecc_mulmod: Joye double-add ladder
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants