d8a268261d
Rather than Barrett reduction, we can just sample rotate_offset at the point where we save the first byte of the MAC. Thanks to Andy Polyakov for the idea in https://github.com/openssl/openssl/pull/1027#issuecomment-263218179 Change-Id: If3a7c2d176406fc332ac512648e6f5ef4dc8b7e5 Reviewed-on: https://boringssl-review.googlesource.com/12475 Commit-Queue: David Benjamin <davidben@google.com> Reviewed-by: Adam Langley <agl@google.com> |
||
---|---|---|
.. | ||
test | ||
aead_test.cc | ||
aead.c | ||
cipher_test.cc | ||
cipher.c | ||
CMakeLists.txt | ||
derive_key.c | ||
e_aes.c | ||
e_chacha20poly1305.c | ||
e_des.c | ||
e_null.c | ||
e_rc2.c | ||
e_rc4.c | ||
e_ssl3.c | ||
e_tls.c | ||
internal.h | ||
tls_cbc.c |