| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
docs: clarify stateful signing key handling Document the security requirements for XMSS and XMSSMT public APIs: - require a single active owner for each private-key state - prohibit signing with contexts inherited across fork - persist updated state after every signing attempt - prevent reuse or rollback of exported state snapshots - clarify that duplicated contexts contain public-key material only - add missing XMSSMT API documentation - propagate the requirements to certificate, CSR, and CRL signing APIs Cherry-picked from: https://gitcode.com/openHiTLS/openhitls/merge_requests/1703 | 1 个月前 | |
Fix some code issues 1、Fix the abnormal branch return value error of SAL_CERT_CheckCertKeyUsage function 2、Add valueLen size judgment to the macro function "PROCESS_STRING_PARAM" 3、Fix parameter passing error when calling 'CheckCertSecuritylevel' to parse CA list 4、Add length judgment to HITLS_CFG_SetAlpnProtos interface 5、Adjust the member data types of the internal structure 'HkdfLabel' 6、CcmPrepare/AdeDecrypt determines inLen>tagLen 7、Cleaning up some sensitive information Cherry-picked from: https://gitcode.com/openHiTLS/openhitls/merge_requests/1762 | 15 天前 | |
fix:bug fix of pki 、cms and cpdecskey 1:The value of unusedBits may not be zero. 2: Side-channel issues 3: Inconsistency between version field and standard 4: CMS streaming signature performs the signature operation twice 5: Annotation issues Cherry-picked from: https://gitcode.com/openHiTLS/openhitls/merge_requests/1769 | 12 天前 | |
docs: clarify stateful signing key handling Document the security requirements for XMSS and XMSSMT public APIs: - require a single active owner for each private-key state - prohibit signing with contexts inherited across fork - persist updated state after every signing attempt - prevent reuse or rollback of exported state snapshots - clarify that duplicated contexts contain public-key material only - add missing XMSSMT API documentation - propagate the requirements to certificate, CSR, and CRL signing APIs Cherry-picked from: https://gitcode.com/openHiTLS/openhitls/merge_requests/1703 | 1 个月前 | |
fix(pki): harden X509 verification for certificate version, SAN parsing, and security level integration - Reject v1/v2 certificates carrying extensions with HITLS_X509_ERR_VFY_EXTENSIONS_REQUIRE_V3 - Require v3 certificates for intermediate CAs; allow v1/v2 trust anchors without extensions - Fix SAN parsing to properly handle zero-length entries instead of silently skipping them - Fix self-assignment and memory safety in HITLS_X509_SetNameList - Propagate TLS security level to X509 verification secbits check via SetAuthLevel Cherry-picked from: https://gitcode.com/openHiTLS/openhitls/merge_requests/1399 | 3 个月前 | |
Improve the documentation comment structure | 5 个月前 | |
fix:Clean up sensitive data and fix some code issues Cherry-picked from: https://gitcode.com/openHiTLS/openhitls/merge_requests/1500 | 2 个月前 | |
fix:Fix some bugs of pki Cherry-picked from: https://gitcode.com/openHiTLS/openhitls/merge_requests/1453 | 3 个月前 | |
New command line added Cherry-picked from: https://gitcode.com/openHiTLS/openhitls/merge_requests/415 | 1 年前 | |
refactor: make list traversal stateless and harden x509 verification add node-based BSL list helpers and migrate shared-list readers off curr-mutating macros precompute DN UTF-8 during parse and reuse cached values in X.509 compare/verify clean up app UIO ownership handling and expand PKI/TLS regression coverage Cherry-picked from: https://gitcode.com/openHiTLS/openhitls/merge_requests/1233 Cherry-picked from: https://gitcode.com/openHiTLS/openhitls/merge_requests/1244 | 4 个月前 |
| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
| 1 个月前 | ||
| 15 天前 | ||
| 12 天前 | ||
| 1 个月前 | ||
| 3 个月前 | ||
| 5 个月前 | ||
| 2 个月前 | ||
| 3 个月前 | ||
| 1 年前 | ||
| 4 个月前 |