mirror of
https://github.com/yuzu-emu/mbedtls.git
synced 2024-11-29 08:24:28 +01:00
Fix section order in the ChangeLog
This commit is contained in:
parent
f5bb78183a
commit
8c661b90c7
20
ChangeLog
20
ChangeLog
@ -2,6 +2,16 @@ mbed TLS ChangeLog (Sorted per branch, date)
|
|||||||
|
|
||||||
= mbed TLS x.x.x branch released xxxx-xx-xx
|
= mbed TLS x.x.x branch released xxxx-xx-xx
|
||||||
|
|
||||||
|
Default behavior changes
|
||||||
|
* The truncated HMAC extension now conforms to RFC 6066. This means
|
||||||
|
that when both sides of a TLS connection negotiate the truncated
|
||||||
|
HMAC extension, Mbed TLS can now interoperate with other
|
||||||
|
compliant implementations, but this breaks interoperability with
|
||||||
|
prior versions of Mbed TLS. To restore the old behavior, enable
|
||||||
|
the (deprecated) option MBEDTLS_SSL_TRUNCATED_HMAC_COMPAT in
|
||||||
|
config.h. Found by Andreas Walz (ivESK, Offenburg University of
|
||||||
|
Applied Sciences).
|
||||||
|
|
||||||
Security
|
Security
|
||||||
* Fix implementation of the truncated HMAC extension. The previous
|
* Fix implementation of the truncated HMAC extension. The previous
|
||||||
implementation allowed an offline 2^80 brute force attack on the
|
implementation allowed an offline 2^80 brute force attack on the
|
||||||
@ -40,16 +50,6 @@ Changes
|
|||||||
* MD functions deprecated in 2.7.0 are no longer inline, to provide
|
* MD functions deprecated in 2.7.0 are no longer inline, to provide
|
||||||
a migration path for those depending on the library's ABI.
|
a migration path for those depending on the library's ABI.
|
||||||
|
|
||||||
Default behavior changes
|
|
||||||
* The truncated HMAC extension now conforms to RFC 6066. This means
|
|
||||||
that when both sides of a TLS connection negotiate the truncated
|
|
||||||
HMAC extension, Mbed TLS can now interoperate with other
|
|
||||||
compliant implementations, but this breaks interoperability with
|
|
||||||
prior versions of Mbed TLS. To restore the old behavior, enable
|
|
||||||
the (deprecated) option MBEDTLS_SSL_TRUNCATED_HMAC_COMPAT in
|
|
||||||
config.h. Found by Andreas Walz (ivESK, Offenburg University of
|
|
||||||
Applied Sciences).
|
|
||||||
|
|
||||||
= mbed TLS 2.7.0 branch released 2018-02-03
|
= mbed TLS 2.7.0 branch released 2018-02-03
|
||||||
|
|
||||||
Security
|
Security
|
||||||
|
Loading…
Reference in New Issue
Block a user