Wade Simmons
|
90c7630270
|
extract the internal FIPS GCM implementation
We do this because the TLS wrapper is not thread safe on Open. instead of locking around it we
can grab the internal implementation that is thread safe. This is the FIPS
module implementation: `crypto/internal/fips140/aes/gcm.GCMWithXORCounterNonce`
- https://github.com/golang/go/blob/go1.26.4/src/crypto/internal/fips140/aes/gcm/gcm_nonces.go#L212-L287
The wrapper is struct `crypto/tls.xorNonceAEAD`, with field `aead`:
- https://github.com/golang/go/blob/go1.26.4/src/crypto/tls/cipher_suites.go#L482-L487
This can be cleaned up once these FIPS implementations are exposed directly:
- https://github.com/golang/go/issues/73110
|
2026-07-08 10:19:48 -04:00 |
|
Wade Simmons
|
3b30526379
|
boringcrypto cleanup
|
2026-06-09 13:24:59 -04:00 |
|
Wade Simmons
|
9709893009
|
use testing log
|
2026-06-09 12:26:04 -04:00 |
|
Wade Simmons
|
f437c7d372
|
more cleanup
|
2026-06-09 10:55:57 -04:00 |
|
Wade Simmons
|
06fb503fc3
|
WIP
|
2026-06-09 10:31:49 -04:00 |
|
Wade Simmons
|
7cd3875934
|
fix expected for fips140
We actually set the nonce wrong before this branch, fixing now.
|
2026-06-08 12:22:25 -04:00 |
|
Wade Simmons
|
90ea6346e9
|
WIP
|
2026-06-08 11:41:07 -04:00 |
|
Wade Simmons
|
37b752bb23
|
WIP
|
2026-06-08 09:43:28 -04:00 |
|
Wade Simmons
|
5dd566e220
|
also support fips140v1.26
This will be inprocess soon
|
2026-04-30 15:21:58 -04:00 |
|
Wade Simmons
|
6da314aa6b
|
WIP
|
2025-07-24 13:56:42 -04:00 |
|
Wade Simmons
|
4485c47641
|
WIP support new Go fips140 module
This will replace boring crypto at some point.
We should modify our protocol a bit and instead change to
NewGCMWithRandomNonce.
|
2025-03-31 12:08:58 -04:00 |
|