cosmopolitan/third_party/mbedtls
Justine Tunney ea83cc0ad0 Make stronger crypto nearly as fast
One of the disadvantages of x25519 and ℘256 is it only provides 126 bits
of security, so that seems like a weak link in the chain, if we're using
ECDHE-ECDSA-AES256-GCM-SHA384. The U.S. government wants classified data
to be encrypted using a curve at least as strong as ℘384, which provides
192 bits of security, but if you read the consensus of stack exchange it
would give you the impression that ℘384 is three times slower.

This change (as well as the previous one) makes ℘384 three times as fast
by tuning its modulus and multiplication subroutines with new tests that
should convincingly show: the optimized code behaves the same way as the
old code. Some of the diff noise from the previous change is now removed
too, so that our vendored fork can be more easily compared with upstream
sources. So you can now have stronger cryptography without compromises.

℘384 modulus Justine                        l:         28𝑐          9𝑛𝑠
℘384 modulus MbedTLS NIST                   l:        127𝑐         41𝑛𝑠
℘384 modulus MbedTLS MPI                    l:      1,850𝑐        597𝑛𝑠

The benchmarks above show the improvements made by secp384r1() which is
an important function since it needs to be called 13,000 times whenever
someone establishes a connection to your web server. The same's true of
Mul6x6Adx() which is able to multiply 384-bit numbers in 73 cycles, but
only if your CPU was purchased after 2014 when Broadwell was introduced
2021-07-26 16:19:45 -07:00
..
test Make stronger crypto nearly as fast 2021-07-26 16:19:45 -07:00
aes.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
aes.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
aesni.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
aesni.h Make GCM AES faster 2021-07-06 08:27:16 -07:00
asn1.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
asn1parse.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
asn1write.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
asn1write.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
base64.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
base64.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
bigmul.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
bigmul4.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
bignum.c Make stronger crypto nearly as fast 2021-07-26 16:19:45 -07:00
bignum.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
bignum_internal.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
bigshift.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
ccm.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
ccm.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
certs.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
certs.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
chacha20.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
chacha20.h Make chacha20 go faster 2021-07-05 14:03:50 -07:00
chachapoly.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
chachapoly.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
check.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
chk.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
cipher.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
cipher.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
cipher_internal.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
cipher_wrap.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
common.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
config.h Make stronger crypto nearly as fast 2021-07-26 16:19:45 -07:00
ctr_drbg.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
ctr_drbg.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
debug.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
debug.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
des.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
des.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
dhm.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
dhm.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
ecdh.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
ecdh.h Make stronger crypto nearly as fast 2021-07-26 16:19:45 -07:00
ecdh_everest.c Make stronger crypto nearly as fast 2021-07-26 16:19:45 -07:00
ecdh_everest.h Make stronger crypto nearly as fast 2021-07-26 16:19:45 -07:00
ecdsa.c Make stronger crypto nearly as fast 2021-07-26 16:19:45 -07:00
ecdsa.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
ecp.c Make stronger crypto nearly as fast 2021-07-26 16:19:45 -07:00
ecp.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
ecp256.c Make stronger crypto nearly as fast 2021-07-26 16:19:45 -07:00
ecp384.c Make stronger crypto nearly as fast 2021-07-26 16:19:45 -07:00
ecp_curves.c Make stronger crypto nearly as fast 2021-07-26 16:19:45 -07:00
ecp_internal.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
ecpshl.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
endian.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
entropy.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
entropy.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
entropy_poll.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
entropy_poll.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
error.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
error.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
everest.c Make stronger crypto nearly as fast 2021-07-26 16:19:45 -07:00
everest.h Make stronger crypto nearly as fast 2021-07-26 16:19:45 -07:00
fastdiv.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
gcm.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
gcm.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
getalertdescription.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
getciphersuite.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
getciphersuitename.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
getsslstatename.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
hkdf.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
hkdf.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
hmac_drbg.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
hmac_drbg.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
iana.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
isciphersuitegood.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
karatsuba.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
LICENSE Import Mbed TLS v2.26.0 2021-06-24 11:12:45 -07:00
math.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
mbedtls.mk Make stronger crypto nearly as fast 2021-07-26 16:19:45 -07:00
md.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
md.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
md5.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
md5.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
mdtype.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
memory_buffer_alloc.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
memory_buffer_alloc.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
net_sockets.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
net_sockets.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
nist_kw.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
nist_kw.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
oid.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
oid.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
param.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
pem.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
pem.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
pk.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
pk.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
pk_internal.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
pk_wrap.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
pkcs5.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
pkcs5.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
pkparse.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
pktype.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
pkwrite.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
platform.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
platform.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
poly1305.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
poly1305.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
profile.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
rando.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
README.cosmo Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
rsa.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
rsa.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
rsa_internal.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
rsa_internal.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
san.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
san.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
secp256r1.c Make stronger crypto nearly as fast 2021-07-26 16:19:45 -07:00
secp384r1.c Make stronger crypto nearly as fast 2021-07-26 16:19:45 -07:00
select.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
sha1.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
sha1.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
sha256.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
sha256.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
sha512.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
sha512.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
shiftright-avx.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
shiftright-pure.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
shiftright.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
sigalg.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
speed.sh Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
srtp.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
ssl.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
ssl_cache.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
ssl_cache.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
ssl_ciphersuites.c Make stronger crypto nearly as fast 2021-07-26 16:19:45 -07:00
ssl_ciphersuites.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
ssl_cli.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
ssl_cookie.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
ssl_cookie.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
ssl_internal.h Make SSL handshakes much faster 2021-07-11 23:17:47 -07:00
ssl_invasive.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
ssl_msg.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
ssl_srv.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
ssl_ticket.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
ssl_ticket.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
ssl_tls.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
ssl_tls13_keys.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
ssl_tls13_keys.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
traceme.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
traceme.h Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
version.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
x509.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
x509.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
x509_create.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
x509_crl.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
x509_crl.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
x509_crt.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
x509_crt.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
x509_csr.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
x509_csr.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
x509write_crt.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
x509write_csr.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00
zeroize.c Add SNI support to redbean and improve SSL perf 2021-07-23 13:56:13 -07:00

DESCRIPTION

  Mbed TLS is a crypto library built by ARM that's been released
  under a more permissive license than alternatives like OpenSSL
  and is useful for interoperating with systems that require TLS

SOURCE

  https://github.com/ARMmbed/mbedtls/archive/refs/tags/v2.26.0.tar.gz

LICENSE

  Apache 2.o

LOCAL CHANGES

  - Reduce build+test latency from 15 seconds to 5 seconds.

  - Features have been added that enable this library to produce SSL
    certificates that can be used by Google Chrome. This required we
    add featurces for editing Subject Alternative Names and Extended
    Key Usage X.509 extension fields since upstream mbedtls can only
    do that currently for Netscape Navigator.

  - Local changes needed to be made to test_suite_ssl.datax due to it
    not taking into consideration disabled features like DTLS.

  - Local changes needed to be made to test_suite_x509parse.datax due
    to the features we added for subject alternative name parsing.

  - We've slimmed things down to meet our own specific local needs.
    For example, we don't need the PSA code since we don't target ARM
    hardware. We also don't need algorithms like camellia, blowfish,
    ripemd, arc4, ecjpake, etc. We want security code that's simple,
    readable, and easy to maintain. For example, the formally verified
    eliptic curve diffie-helman code was 38 files and most of it was
    dead code which could be consolidated into one < 1 kLOC file.

  - The only breaking API change that's been made is to redefine int
    arrays of things like long lists of ciphersuites to be uint8_t or
    uint16_t instead when appropriate.

  - Exported test code so it (a) doesn't have python as a build time
    dependency, (b) doesn't print to stdout on success, (c) bundles
    its dependencies inside a zip container so the tests are able to
    run hermetically if the binary is scp'd to some machine, and (d)
    doesn't have large amounts of duplicated generated code.

  - Fix mbedtls_mpi_sub_abs() to not call malloc/free/memcpy since
    it's called 11,124 times during as SSL handshake.

  - Make P-256 and P-384 modulus goes 5x faster.

  - Make chacha20 26% faster.

  - Make base64 100x faster.

  - Make gcm faster.