Improve ChangeLog wording for key export

Signed-off-by: Hanno Becker <hanno.becker@arm.com>
This commit is contained in:
Hanno Becker 2021-06-11 15:40:16 +01:00 committed by Dave Rodgman
parent e0dad720ee
commit 1e1c23d768

View file

@ -1,13 +1,10 @@
API changes
* mbedtls_ssl_conf_export_keys_ext_cb() and
mbedtls_ssl_conf_export_keys_cb() have been removed
and replaced by a new API
mbedtls_ssl_set_export_keys_cb().
* The signature of key export callbacks configured via
mbedtls_ssl_set_export_keys_cb() is different from that
of the previous mbedtls_ssl_conf_export_keys_cb(): First,
raw keys and IVs are no longer exported. Further, callbacks
now receive an additional parameter indicating the type
of secret that's being exported, paving the way for the
larger number of secrets in TLS 1.3. Finally, the key export
callback and context are now connection-specific.
mbedtls_ssl_conf_export_keys_cb() have been removed and
replaced by a new API mbedtls_ssl_set_export_keys_cb().
Raw keys and IVs are no longer passed to the callback.
Further, callbacks now receive an additional parameter
indicating the type of secret that's being exported,
paving the way for the larger number of secrets
in TLS 1.3. Finally, the key export callback and
context are now connection-specific.