{"id":13338007,"url":"https://github.com/Rohde-Schwarz/botan","last_synced_at":"2025-03-11T08:32:30.036Z","repository":{"id":45736352,"uuid":"52816996","full_name":"Rohde-Schwarz/botan","owner":"Rohde-Schwarz","description":"Crypto and TLS for C++11","archived":false,"fork":true,"pushed_at":"2024-10-29T09:46:33.000Z","size":139040,"stargazers_count":34,"open_issues_count":1,"forks_count":4,"subscribers_count":13,"default_branch":"master","last_synced_at":"2024-10-29T09:55:36.632Z","etag":null,"topics":["c-plus-plus","crypto","cryptography","security","tls","x509"],"latest_commit_sha":null,"homepage":"http://botan.randombit.net","language":"C++","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":"randombit/botan","license":"bsd-2-clause","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/Rohde-Schwarz.png","metadata":{"files":{"readme":"readme.rst","changelog":null,"contributing":null,"funding":null,"license":"license.txt","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null}},"created_at":"2016-02-29T19:22:51.000Z","updated_at":"2024-10-07T09:15:41.000Z","dependencies_parsed_at":"2023-09-26T10:52:02.781Z","dependency_job_id":null,"html_url":"https://github.com/Rohde-Schwarz/botan","commit_stats":null,"previous_names":[],"tags_count":1,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Rohde-Schwarz%2Fbotan","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Rohde-Schwarz%2Fbotan/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Rohde-Schwarz%2Fbotan/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Rohde-Schwarz%2Fbotan/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/Rohde-Schwarz","download_url":"https://codeload.github.com/Rohde-Schwarz/botan/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":243000938,"owners_count":20219775,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["c-plus-plus","crypto","cryptography","security","tls","x509"],"created_at":"2024-07-29T19:15:16.925Z","updated_at":"2025-03-11T08:32:27.561Z","avatar_url":"https://github.com/Rohde-Schwarz.png","language":"C++","funding_links":[],"categories":[],"sub_categories":[],"readme":"Botan: Crypto and TLS for C++11\n========================================\n\nThe `German Federal Office for Information Security (BSI) \u003chttps://www.bsi.bund.de/EN/\u003e`_\ncarried out a project \"Secure Implementation of a Universal Crypto Library\"\nin which it analyzed open source cryptographic libraries and developed a secure\ncryptographic library based on the `Botan \u003chttps://botan.randombit.net\u003e`_ cryptographic library.\nBotan 2.0 satisfies the basic requirements of the BSI and\nits use is recommended in security products. The library includes all algorithms \nrecommended by BSI technical guidelines `02102-1 \u003chttps://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Technische-Richtlinien/TR-nach-Thema-sortiert/tr02102/tr02102_node.html\u003e`_,\n`02102-2 \u003chttps://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Technische-Richtlinien/TR-nach-Thema-sortiert/tr02102/tr02102_node.html\u003e`_ and `03111 \u003chttps://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Technische-Richtlinien/TR-nach-Thema-sortiert/tr03111/TR-03111_node.html\u003e`_.\nBotan is licensed under the Simplified BSD license and can therefore be freely \nused in open source as well as commercial software.\n\nThis repository contains versions of Botan that are approved by the BSI. All changes made\nto Botan during the project were contributed to the original project. Our goal is to keep \nthis fork in sync with the official repository, but we cannot assure this. In case an approved\nversion differs from an official Botan version, the changes are listed in the `release notes \u003cnews.rst\u003e`_.\n\nVersioning\n----------------------------------------\n\nThe versioning scheme used here is based on that of the\n`original project \u003chttps://botan.randombit.net/news.html\u003e`_. In case\nthere are differences between an official release version and an approved version,\nthe approved version number will contain the original version it is based on followed by\na `RSCSN` suffix. For example, the version 2.4.0-RSCS1 is based on the official\nBotan version 2.4.0, but contains additional changes that are not part of 2.4.0\n(but may be part of a future Botan version).\nNew Botan releases will be audited on a regular basis and cryptographically relevant\nchanges will be checked and documented. These releases will eventually be\nreleased here when approved by the BSI.\n\nRelease Downloads\n----------------------------------------\n\nThe latest version is `2.4.0-RSCS1 \u003chttps://cdn.rohde-schwarz.com/pws/dl_downloads/dl_software/zip/Cybersecurity-software-Botan-2.4.0-RSCS1.zip\u003e`_ (`sig \u003chttps://cdn.rohde-schwarz.com/pws/dl_downloads/dl_software/sig/Cybersecurity-software-Botan-2.4.0-RSCS1.zip.sig\u003e`_) released on 2018-09-28.\n\n`SHA-256 \u003chttps://cdn.rohde-schwarz.com/pws/dl_downloads/dl_software/sha256/Cybersecurity-software-Botan-2.4.0-RSCS1.zip.sha256\u003e`_: EADC9A20FBE6AF4725CBA26B0636C1244083BAF4F936A129AF498D056EACBF75\n\nAll approved releases are signed with the following key::\n  \n  -----BEGIN PUBLIC KEY-----\n  MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAyGKrzmfZhGuIaMXGZ56x\n  yKtzTuvDrK50edCd1/EccVtS1V/52bmM/mfWaTCvUKUd+BlKw544L+hEaMdoGMvj\n  rkJL70DxU+fqV3NHBJKDqV+fJi4X8iWPIq3B/Tu08jFYjeHoRDN3BcaGFSQnR9lC\n  1p3PXbga8Mpk5Qe93ca3tGawr2AKt0ImdVwWvcPlL2JHr63jB0YARYzf1M8DtDzk\n  RQewoyrxbyQbup4Qgd2IbJsfTbNxgeWFMSeiBEZVnqVosKvzLybXZpmbmZSxQr64\n  qT8JRzlJbIh3RrJlfGPu2YFojg9x+uL0KqGGPhqDFIR/UQdW1Ve+kjh7MaSQJsnZ\n  u/+HoGJVSDfkiW1ZLPfYHDye85e4c5z4JCxbOMn2IVSlFWxfrNjaIU6jEjxyS09E\n  6W9Yr2r5iC/ef5BFc38JgVuvfMa3RJHSqY4AfIl+GnozwtKzYsedfKAZkZUx+kiu\n  65FdQqHR1iMrM4kxmRIeYxttdF7h0NzU7CGGXoVV14qRMQ9ZMTHPyasqmt5JihK6\n  cyn9e8DPzgndm2HhBJeQdSMCWraZoZqO8GjzuTuSVtt4a3C/G++rpLA9RXHRwK1P\n  UjeWn1B9Pd6fX4oZ1/eQF+Y5oZnl80IsILOE2CdxEKN2TNQftESdKNNWe+nCEY1c\n  sSPNDnqFuHxJaS2oS5A3BBUCAwEAAQ==\n  -----END PUBLIC KEY-----\n\nThe SHA-256 public key fingerprint is B1B688ED5FD24ACD53E73BE74A5279916471B2A9C80BC33AA9A7EDC58A715CF0.\n\nVerify the release signature using Botan (where the public key listed above is referred to as *Botan-Signing-Key.pem*)::\n\n  $ botan verify --hash=SHA-512 --emsa=EMSA4 Botan-Signing-Key.pem Cybersecurity-software-Botan-2.4.0-RSCS1.zip Cybersecurity-software-Botan-2.4.0-RSCS1.zip.sig\n  Signature is valid\n\nVerify the release signature using OpenSSL (you need to base64 decode the signature first)::\n\n  $ type Cybersecurity-software-Botan-2.4.0-RSCS1.zip.sig | openssl base64 -d -out Cybersecurity-software-Botan-2.4.0-RSCS1.zip.sig.dec\n\nor alternatively using python::\n\n  $ python -m base64 -d Cybersecurity-software-Botan-2.4.0-RSCS1.zip.sig \u003e Cybersecurity-software-Botan-2.4.0-RSCS1.zip.sig.dec\n\n  $ openssl dgst -sha512 -sigopt rsa_padding_mode:pss -sigopt rsa_pss_saltlen:64 -verify Botan-Signing-Key.pem -signature Cybersecurity-software-Botan-2.4.0-RSCS1.zip.sig.dec Cybersecurity-software-Botan-2.4.0-RSCS1.zip\n  Verified OK\n\nDocumentation\n----------------------------------------\n\nBotan provides a comprehensive `API documentation \u003chttps://botan.randombit.net/doxygen/\u003e`_ as well as\na users `handbook \u003chttps://botan.randombit.net/handbook/\u003e`_.\n\nAPI documentation and the handbook for the latest version approved by the BSI can be found here:\n\n* `API documentation \u003cdoc/bsi/doxygen.zip\u003e`_\n* `Handbook \u003cdoc/bsi/handbook.pdf\u003e`_\n\nIn addition to the official documentation, we provide the following documents,\nwhich were created during the BSI project:\n\n* `Software architecture \u003cdoc/bsi/architecture.pdf\u003e`_\n* `Implementation of cryptographic algorithms and protocols \u003cdoc/bsi/crypto.pdf\u003e`_\n* `Specification of tests \u003cdoc/bsi/testspecification.pdf\u003e`_\n* `Test report \u003cdoc/bsi/testreport.pdf\u003e`_\n\nSupport \u0026 Maintenance\n----------------------------------------\n\nIf you need help with a problem, please `open an issue \u003chttps://github.com/randombit/botan/issues/new\u003e`_\nat the offical GitHub repository. In case you want to contribute some changes, please also\n`contribute \u003chttps://github.com/randombit/botan/compare\u003e`_ them to the official Botan repository.\n\nBSI Compliant Usage of Botan\n----------------------------------------\n\nBotan contains a `BSI module policy \u003csrc/build-data/policy/bsi.txt\u003e`_ which includes all algorithms recommended by BSI\ntechnical guidelines and prohibits alternative algorithms.\nTo configure Botan with the BSI policy::\n\n  $ ./configure.py --module-policy=bsi\n\nAdditional modules which are not automatically enabled by the BSI policy\ncan be enabled manually using `--enable-modules`, for example::\n\n  $ ./configure.py --module-policy=bsi --enable-modules=tls,ffi,x509,xts\n\nTLS\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n\nBotan contains a TLS Policy class `BSI_TR_02102_2 \u003csrc/lib/tls/tls_policy.h\u003e`_ that only allows the algorithms recommended in\nBSI technical guideline `02102-2 \u003chttps://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Technische-Richtlinien/TR-nach-Thema-sortiert/tr02102/tr02102_node.html\u003e`_.\nThis policy can be passed whereever a ``TLS_Policy`` reference is accepted by the API.\nFor more information, see the `handbook \u003chttps://botan.randombit.net/handbook/api_ref/tls.html\u003e`_.\n\n\nRandom Number Generation\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n\nBotan contains an implementation of `NIST SP 800-90A \u003chttps://csrc.nist.gov/publications/detail/sp/800-90a/rev-1/final\u003e`_'s `HMAC_DRBG \u003csrc/lib/rng/hmac_drbg/hmac_drbg.h\u003e`_.\nThe parameters reseed interval, maximum number of bytes per request and the entropy source(s) for\nseeding and reseeding can be configured per ``HMAC_DRBG`` instance. For example,\na ``PKCS11_RNG`` can be used as an entropy source::\n\n  Botan::PKCS11::PKCS11_RNG p11_rng(session);\n  Botan::HMAC_DRBG drbg(Botan::MessageAuthenticationCode::create(\"HMAC(SHA-512)\"), p11_rng);\n\n``HMAC_DRBG`` will automatically reseed whenever the reseed interval or maximum number\nof bytes per request are exceeded. On platforms which support ``fork()``, it will also\nautomatically reseed after a fork. For more information, see the `handbook \u003chttps://botan.randombit.net/handbook/api_ref/rng.html\u003e`_.\n\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FRohde-Schwarz%2Fbotan","html_url":"https://awesome.ecosyste.ms/projects/github.com%2FRohde-Schwarz%2Fbotan","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FRohde-Schwarz%2Fbotan/lists"}