Release of Cryptographic Library Botan 3.0.0

The release of the Cryptographic Library Botan 3.0.0 is now available, used in the NeoPG project, a fork of GnuPG 2. The library provides a large collection of ready-to-use primitives employed in the TLS protocol, X.509 certificates, AEAD ciphers, TPM modules, PKCS#11, password hashing, and post-quantum cryptography (hash-based signatures and key agreement based on McEliece). The library is written in C++ and is distributed under the BSD license.

Among the changes in the new release:

  • The codebase permits the use of the C++20 standard (previously C++11 was used), consequently raising the requirements for compilers—now at least GCC 11, Clang 14, or MSVC 2022 are needed for building. Support for HP and Pathscale compilers, as well as Google NaCL and IncludeOS projects has been discontinued.
  • A substantial number of changes breaking backward compatibility have been introduced. Many deprecated header files, such as those specific to certain algorithms (aes.h, etc.), have been removed. Implementations of functions and algorithms previously marked as obsolete (CAST-256, MISTY1, Kasumi, DESX, XTEA, PBKDF1, MCEIES, CBC-MAC, Tiger, NEWHOPE, CECPQ1) have been deleted. The use of /proc and /dev/random for entropy generation for the pseudorandom number generator has been discontinued. Some classes (e.g., Data_Store), structures, and enumerations have been removed from the API. The return and use of raw pointers has been minimized where possible.
  • Support for TLS 1.3 has been added. Support for TLS 1.0, TLS 1.1, and DTLS 1.0 has been discontinued. The TLS implementation has removed support for cipher suites DSA, SRP, SEED, AES-128 OCB, CECPQ1, DHE_PSK, and Camellia CBC, anonymous ciphers, and SHA-1 hashes.
  • Support for the post-quantum cryptographic algorithm Kyber, resistant to attacks from quantum computers, has been added.
  • Support for the post-quantum cryptographic algorithm Dilithium for digital signatures has been added.
  • Support for hashing in the form of a point on an elliptic curve using the SSWU technique (draft-irtf-cfrg-hash-to-curve) has been added.
  • Support for the cryptographic hash function BLAKE2b has been added.
  • A new interface T::new_object has been proposed, returning unique_ptr instead of a raw pointer 'T*'.
  • New functions and APIs have been added: X509_DN::DER_encode, Public_Key::get_int_field, ideal_granularity, requires_entire_message, SymmetricAlgorithm::has_keying_material. A large number of new functions for use in C (C89) code have been introduced.
  • The Argon2 algorithm implementation utilizes AVX2 instructions.
  • Reduced the size of tables in the implementations of the Camellia, ARIA, SEED, DES, and Whirlpool algorithms.
  • A new implementation of DES/3DES has been proposed, which is protected against most classes of side-channel attacks evaluating cache state.
  • The SHACAL2 implementation is optimized for systems based on ARMv8 and POWER architectures.
  • The code for calculating parity bits, converting bcrypt/base64, and determining ASN.1 string type has been eliminated from table lookups and is now independent of the processed data (executed in constant time).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster