cosmopolitan/third_party/mbedtls
Justine Tunney f3e28aa192 Make SSL handshakes much faster
This change boosts SSL handshake performance from 2,627 to ~10,000 per
second which is the same level of performance as NGINX at establishing
secure connections. That's impressive if we consider that redbean is a
forking frontend application server. This was accomplished by:

  1. Enabling either SSL session caching or SSL tickets. We choose to
     use tickets since they reduce network round trips too and that's
     a more important metric than wrk'ing localhost.

  2. Fixing mbedtls_mpi_sub_abs() which is the most frequently called
     function. It's called about 12,000 times during an SSL handshake
     since it's the basis of most arithmetic operations like addition
     and for some strange reason it was designed to make two needless
     copies in addition to calling malloc and free. That's now fixed.

  3. Improving TLS output buffering during the SSL handshake only, so
     that only a single is write and read system call is needed until
     blocking on the ping pong.

redbean will now do a better job wiping sensitive memory from a child
process as soon as it's not needed. The nice thing about fork is it's
much faster than reverse proxying so the goal is to use the different
address spaces along with setuid() to minimize the risk that a server
key will be compromised in the event that application code is hacked.
2021-07-11 23:17:47 -07:00
..
test Make sha1 / sha256 / sha512 go faster 2021-06-26 00:11:12 -07:00
aes.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
aes.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
aesni.c Make GCM AES faster 2021-07-06 08:27:16 -07:00
aesni.h Make GCM AES faster 2021-07-06 08:27:16 -07:00
asn1.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
asn1parse.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
asn1write.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
asn1write.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
base64.c Make GCM AES faster 2021-07-06 08:27:16 -07:00
base64.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
bignum.c Make SSL handshakes much faster 2021-07-11 23:17:47 -07:00
bignum.h Make SSL handshakes much faster 2021-07-11 23:17:47 -07:00
bn_mul.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
ccm.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
ccm.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
certs.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
certs.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
chacha20.c Make chacha20 go faster 2021-07-05 14:03:50 -07:00
chacha20.h Make chacha20 go faster 2021-07-05 14:03:50 -07:00
chachapoly.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
chachapoly.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
check.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
cipher.c Make GCM AES faster 2021-07-06 08:27:16 -07:00
cipher.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
cipher_internal.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
cipher_wrap.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
common.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
config.h Make SSL handshakes much faster 2021-07-11 23:17:47 -07:00
ctr_drbg.c Add HTTP/HTTPS Fetch() API to redbean 2021-07-07 21:44:27 -07:00
ctr_drbg.h Add HTTP/HTTPS Fetch() API to redbean 2021-07-07 21:44:27 -07:00
debug.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
debug.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
des.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
des.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
dhm.c Make chacha20 go faster 2021-07-05 14:03:50 -07:00
dhm.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
ecdh.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
ecdh.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
ecdsa.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
ecdsa.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
ecp.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
ecp.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
ecp_curves.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
ecp_internal.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
endian.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
entropy.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
entropy.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
entropy_poll.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
entropy_poll.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
error.c Make GCM AES faster 2021-07-06 08:27:16 -07:00
error.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
everest.c Make redbean ssl handshake go a little faster 2021-07-03 05:51:04 -07:00
everest.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
gcm.c Make GCM AES faster 2021-07-06 08:27:16 -07:00
gcm.h Make GCM AES faster 2021-07-06 08:27:16 -07:00
getalertdescription.c Add test for ioctl(SIOCGIFCONF) and polyfill on BSDs 2021-06-25 18:44:04 -07:00
getciphersuitename.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
hkdf.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
hkdf.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
hmac_drbg.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
hmac_drbg.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
iana.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
isciphersuitegood.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
LICENSE Import Mbed TLS v2.26.0 2021-06-24 11:12:45 -07:00
mbedtls.mk Make SSL handshakes much faster 2021-07-11 23:17:47 -07:00
md.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
md.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
md5.c Add more hashing apis to redbean 2021-07-05 01:05:10 -07:00
md5.h Add more hashing apis to redbean 2021-07-05 01:05:10 -07:00
md_internal.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
mdtype.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
memory_buffer_alloc.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
memory_buffer_alloc.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
nist_kw.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
nist_kw.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
oid.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
oid.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
param.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
pem.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
pem.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
pk.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
pk.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
pk_internal.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
pk_wrap.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
pkcs5.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
pkcs5.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
pkparse.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
pktype.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
pkwrite.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
platform.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
platform.h Make GCM AES faster 2021-07-06 08:27:16 -07:00
poly1305.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
poly1305.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
rando.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
README.cosmo Make SSL handshakes much faster 2021-07-11 23:17:47 -07:00
rsa.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
rsa.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
rsa_internal.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
rsa_internal.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
san.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
san.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
sha1.c Make GCM AES faster 2021-07-06 08:27:16 -07:00
sha1.h Add more hashing apis to redbean 2021-07-05 01:05:10 -07:00
sha256.c Add more hashing apis to redbean 2021-07-05 01:05:10 -07:00
sha256.h Add more hashing apis to redbean 2021-07-05 01:05:10 -07:00
sha512.c Add more hashing apis to redbean 2021-07-05 01:05:10 -07:00
sha512.h Add more hashing apis to redbean 2021-07-05 01:05:10 -07:00
sigalg.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
srtp.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
ssl.h Make SSL handshakes much faster 2021-07-11 23:17:47 -07:00
ssl_cache.c Make SSL handshakes much faster 2021-07-11 23:17:47 -07:00
ssl_cache.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
ssl_ciphersuites.c Make SSL handshakes much faster 2021-07-11 23:17:47 -07:00
ssl_ciphersuites.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
ssl_cli.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
ssl_cookie.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
ssl_cookie.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
ssl_internal.h Make SSL handshakes much faster 2021-07-11 23:17:47 -07:00
ssl_invasive.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
ssl_msg.c Add HTTP/HTTPS Fetch() API to redbean 2021-07-07 21:44:27 -07:00
ssl_srv.c Make SSL handshakes much faster 2021-07-11 23:17:47 -07:00
ssl_ticket.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
ssl_ticket.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
ssl_tls.c Make SSL handshakes much faster 2021-07-11 23:17:47 -07:00
ssl_tls13_keys.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
ssl_tls13_keys.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
version.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
x509.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
x509.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
x509_create.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
x509_crl.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
x509_crl.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
x509_crt.c Add HTTP/HTTPS Fetch() API to redbean 2021-07-07 21:44:27 -07:00
x509_crt.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
x509_csr.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
x509_csr.h Add SSL to redbean 2021-06-24 13:20:50 -07:00
x509write_crt.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
x509write_csr.c Add SSL to redbean 2021-06-24 13:20:50 -07:00
zeroize.c Make SSL handshakes much faster 2021-07-11 23:17:47 -07:00

DESCRIPTION

  Mbed TLS is a crypto library built by ARM that's been released
  under a more permissive license than alternatives like OpenSSL
  and is useful for interoperating with systems that require TLS

SOURCE

  https://github.com/ARMmbed/mbedtls/archive/refs/tags/v2.26.0.tar.gz

LICENSE

  Apache 2.o

LOCAL CHANGES

  - Reduce build+test latency from 15 seconds to 5 seconds.

  - Features have been added that enable this library to produce SSL
    certificates that can be used by Google Chrome. This required we
    add featurces for editing Subject Alternative Names and Extended
    Key Usage X.509 extension fields since upstream mbedtls can only
    do that currently for Netscape Navigator.

  - Local changes needed to be made to test_suite_ssl.datax due to it
    not taking into consideration disabled features like DTLS.

  - Local changes needed to be made to test_suite_x509parse.datax due
    to the features we added for subject alternative name parsing.

  - We've slimmed things down to meet our own specific local needs.
    For example, we don't need the PSA code since we don't target ARM
    hardware. We also don't need algorithms like camellia, blowfish,
    ripemd, arc4, ecjpake, etc. We want security code that's simple,
    readable, and easy to maintain. For example, the formally verified
    eliptic curve diffie-helman code was 38 files and most of it was
    dead code which could be consolidated into one < 1 kLOC file.

  - The only breaking API change that's been made is to redefine int
    arrays of things like long lists of ciphersuites to be uint8_t or
    uint16_t instead when appropriate.

  - Exported test code so it (a) doesn't have python as a build time
    dependency, (b) doesn't print to stdout on success, (c) bundles
    its dependencies inside a zip container so the tests are able to
    run hermetically if the binary is scp'd to some machine, and (d)
    doesn't have large amounts of duplicated generated code.

  - Fix mbedtls_mpi_sub_abs() to not call malloc/free/memcpy since
    it's called 11,124 times during as SSL handshake.

  - Make chacha20 26% faster.

  - Make base64 100x faster.

  - Make gcm faster.