<feed xmlns='http://www.w3.org/2005/Atom'>
<title>openbsd/src/lib/libssl, branch libressl-v2.5.4</title>
<subtitle>A mirror of https://github.com/libressl/openbsd.git
</subtitle>
<id>https://git.lua4.win/openbsd/atom?h=libressl-v2.5.4</id>
<link rel='self' href='https://git.lua4.win/openbsd/atom?h=libressl-v2.5.4'/>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/'/>
<updated>2017-04-29T23:41:32+00:00</updated>
<entry>
<title>MFC.</title>
<updated>2017-04-29T23:41:32+00:00</updated>
<author>
<name>jsing</name>
<email></email>
</author>
<published>2017-04-29T23:41:32+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=2e2c612066aa993717528a0249c15c51128d61cb'/>
<id>urn:sha1:2e2c612066aa993717528a0249c15c51128d61cb</id>
<content type='text'>
Fix a bug caused by the return value being set early to signal successful
DTLS cookie validation. This can mask a later failure and result in a
positive return value being returned from ssl3_get_client_hello(), when
it should return a negative value to propagate the error.

ok beck@
</content>
</entry>
<entry>
<title>tweak previous;</title>
<updated>2017-03-29T00:24:42+00:00</updated>
<author>
<name>jmc</name>
<email></email>
</author>
<published>2017-03-29T00:24:42+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=566b15588d1c49bbd944fea3da94fcf285215959'/>
<id>urn:sha1:566b15588d1c49bbd944fea3da94fcf285215959</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Fix typo in function name;</title>
<updated>2017-03-28T18:21:55+00:00</updated>
<author>
<name>schwarze</name>
<email></email>
</author>
<published>2017-03-28T18:21:55+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=d1f04b7864cd35fb243022229472db0685723c6e'/>
<id>urn:sha1:d1f04b7864cd35fb243022229472db0685723c6e</id>
<content type='text'>
from Markus Triska &lt;triska at metalevel dot at&gt;
via OpenSSL commit 1f164c6f.
</content>
</entry>
<entry>
<title>After i wrote SSL_renegotiate(3) from scratch, OpenSSL also</title>
<updated>2017-03-28T18:19:53+00:00</updated>
<author>
<name>schwarze</name>
<email></email>
</author>
<published>2017-03-28T18:19:53+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=042281ef2d25ebf7aad0cf50cc01a03e363f5604'/>
<id>urn:sha1:042281ef2d25ebf7aad0cf50cc01a03e363f5604</id>
<content type='text'>
documented the function.  Merge the more detailed descriptions
and the additional documentation of SSL_renegotiate_abbreviated(3)
and SSL_renegotiate_pending(3).
From Matt Caswell, OpenSSL commit 39820637.
</content>
</entry>
<entry>
<title>Update RFC reference for TLSEXT_TYPE_padding.</title>
<updated>2017-03-25T14:15:11+00:00</updated>
<author>
<name>jsing</name>
<email></email>
</author>
<published>2017-03-25T14:15:11+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=d0b1250ee44d9aa30fca043cb7e60ad9ae230bd6'/>
<id>urn:sha1:d0b1250ee44d9aa30fca043cb7e60ad9ae230bd6</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Check tls1_PRF() return value in tls1_generate_master_secret().</title>
<updated>2017-03-25T13:42:29+00:00</updated>
<author>
<name>jsing</name>
<email></email>
</author>
<published>2017-03-25T13:42:29+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=575422e50be96435269d5ec45262963a5aa50a97'/>
<id>urn:sha1:575422e50be96435269d5ec45262963a5aa50a97</id>
<content type='text'>
</content>
</entry>
<entry>
<title>More cleanup for tls1_PRF()/tls1_P_hash() - change the argument order of</title>
<updated>2017-03-25T13:36:56+00:00</updated>
<author>
<name>jsing</name>
<email></email>
</author>
<published>2017-03-25T13:36:56+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=6046430e35e488ca3bd1c18f3189c27c070527cc'/>
<id>urn:sha1:6046430e35e488ca3bd1c18f3189c27c070527cc</id>
<content type='text'>
tls1_PRF() so that it matches tls1_P_hash(), use more explicit argument
names and change lengths to size_t.

ok inoguchi@
</content>
</entry>
<entry>
<title>Fewer magic numbers.</title>
<updated>2017-03-18T13:04:30+00:00</updated>
<author>
<name>jsing</name>
<email></email>
</author>
<published>2017-03-18T13:04:30+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=515da2cdc879182cffc5d378d1112ca0807d5df2'/>
<id>urn:sha1:515da2cdc879182cffc5d378d1112ca0807d5df2</id>
<content type='text'>
</content>
</entry>
<entry>
<title>t1_enc.c</title>
<updated>2017-03-18T13:01:55+00:00</updated>
<author>
<name>jsing</name>
<email></email>
</author>
<published>2017-03-18T13:01:55+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=c437861be75788bd6eb34d4950224fc1d6e986f7'/>
<id>urn:sha1:c437861be75788bd6eb34d4950224fc1d6e986f7</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Currently tls1_PRF() requires that a temporary buffer be provided, that</title>
<updated>2017-03-18T12:58:18+00:00</updated>
<author>
<name>jsing</name>
<email></email>
</author>
<published>2017-03-18T12:58:18+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=def63193c2b83eaf0fcd62a1c4d85970ea9f15ed'/>
<id>urn:sha1:def63193c2b83eaf0fcd62a1c4d85970ea9f15ed</id>
<content type='text'>
matches the size of the output buffer. This is used in the case where
there are multiple hashes - tls_P_hash() is called with the temporary
buffer and the result is then xored into the output buffer.

Avoid this by simply using a local buffer in tls_P_hash() and then xoring
the result into the output buffer. Overall this makes the code cleaner
and simplifies all of the tls_PRF() callers.

Similar to BoringSSL.

ok inoguchi@
</content>
</entry>
</feed>
