1
I Use This!
Very High Activity

Commits : Listings

Analyzed 1 day ago. based on code collected 1 day ago.
Sep 27, 2025 — Sep 27, 2026
Commit Message Contributor Files Modified Lines Added Lines Removed Code Location Date
Use raw agreement directly and cleanup More... 3 days ago
CryptoProWrapEngine now diversifies a copy of the KEK rather than the caller's KeyParameter array, and with no S-box uses the GOST 28147 default S-box instead of failing with a NullPointerException. More... 4 days ago
ParametersWithUKM now nests outside ParametersWithRandom: GOST28147WrapEngine, CryptoProWrapEngine and ECVKOAgreement accept it, the wrap engines still accept the earlier order, and the provider's GOST 28147 key wrap ciphers build it. More... 4 days ago
Merge branch 'main' of gitlab.cryptoworkshop.com:root/bc-java More... 4 days ago
conventions.md: CVE numbers stay out of release notes, commits and comments until the fixing version is released. More... 4 days ago
The PBES1 and PKCS#12 PBE providers now bound the iteration count they parse and derive with under org.bouncycastle.pbe.max_iteration_count, as PBKDF2 does. More... 4 days ago
Refactor CertPathValidatorUtilities.findTrustAnchor More... 4 days ago
CMS 1-Pass ECMQV now feeds the KDF the DER-encoded ECC-CMS-SharedInfo per RFC 5753, with the raw-ukm retry for earlier BC messages gated by org.bouncycastle.cms.allow_legacy_keyagree_kdf. More... 4 days ago
Corrected the SecurityExceptions factory list in conventions.md: the jdk1.3 overlay is no longer a factory behind. More... 4 days ago
ML-KEM KeyGenerator, Cipher, KEM and KeyFactory.translateKey now convert ML-KEM keys from other providers via their encodings, with TLS tests for keys supplied ahead of BC, relates to github #2466. More... 4 days ago
CMS: Better exception when no ukm for MQV, with test More... 4 days ago
Don't re-wrap CMSException in JceKeyAgreeRecipient More... 4 days ago
DefaultSecretKeySizeProvider uses registry OID for cast5CBC, and adds ideaCBC More... 4 days ago
Tidied the CMS key agreement recipient and generator: the agreement is now run once after the parameters are chosen, the mandatory-ukm check for static-static DH and GOST is made once up front, KeyMaterialGenerator is documented, and the jdk1.1 generator gains the GOST agreement and key wrap the jdk1.1 recipient already supported. More... 5 days ago
JceKeyAgreeRecipientInfoGenerator now generates a fresh 1-pass ECMQV ephemeral key pair for each KeyAgreeRecipientInfo rather than reusing one per generator, via a new KeyAgreeRecipientInfoGenerator.generationComplete() cleanup hook. More... 5 days ago
Merge branch 'main' of gitlab.cryptoworkshop.com:root/bc-java More... 5 days ago
DSTU 7624: KGCM re-init starts from a clean state and resets on failure, KCCM validates the MAC size against the block and takes the G1 length from processPacket's argument, over-long nonces are rejected, an IV-only init keeps the previous key, KXTS checks the output offset, DSTU7624Mac and the wrap engine check their lengths, and the mode-string CCM cipher generates a whole-block IV. More... 5 days ago
CertPathBuilder: count only non-self-issued intermediates against the maximum path length, and carry the caller's maximum path length and excluded certificates into the indirect CRL signer's path build. More... 5 days ago
DSTU 7624: KGCM/KGMac reject empty associated text with empty data, and DSTU7624Mac rejects an empty message, as DSTU 7624:2014 sec. 12.1 and sec. 9.1 require. More... 5 days ago
date validity fuzz report More... 5 days ago
Merge branch 'main' of gitlab.cryptoworkshop.com:root/bc-java More... 6 days ago
Synced the JKS keystore fixture into the jdk1.4 PKCS12StoreTest overlay, which the JKS and BCFKS store tests compile against. More... 6 days ago
Added the cast the jdk1.4 build's generic stripping requires on the signer iterator in CompositeMLDSASignedDataTest. More... 6 days ago
ASN.1: check the day of a UTCTime or GeneralizedTime against the length of the month it names, so a date the calendar would roll into the next month is rejected on read, with org.bouncycastle.asn1.allow_non_der_time admitting it. More... 6 days ago
CMS: derive the RFC 5990 RSA-KTS key to the length the data encapsulation mechanism's key-wrapping algorithm fixes, and refuse a keyLength which disagrees with it before deriving anything. More... 6 days ago
KeyAgreement: report an initialisation the unified and VKO agreements cannot carry out as the parameter error the JCA declares rather than as an unchecked exception, and apply the RFC 7836 default UKM of 1 when none is given. More... 6 days ago
BCJSSE: add the BCSSLContext interface, obtained from a BCJSSE SSLContext with ContextUtil.getBCSSLContext() by way of the new BCSSLSessionContext, giving access to the default and supported parameters for either mode as BCSSLParameters. More... 6 days ago
BCJSSE: add the BCSSLServerSocket extension interface, implemented by the provider's server sockets, allowing use of BCSSLParameters with server sockets from a BCJSSE SSLContext. More... 6 days ago
Fix failure messages More... 6 days ago
Uset setBit in blind calculation More... 6 days ago