<feed xmlns='http://www.w3.org/2005/Atom'>
<title>openbsd/src/regress/lib/libssl/ssl/testssl, branch OPENBSD_7_6_BASE</title>
<subtitle>A mirror of https://github.com/libressl/openbsd.git
</subtitle>
<id>https://git.lua4.win/openbsd/atom?h=OPENBSD_7_6_BASE</id>
<link rel='self' href='https://git.lua4.win/openbsd/atom?h=OPENBSD_7_6_BASE'/>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/'/>
<updated>2023-07-02T17:21:33+00:00</updated>
<entry>
<title>Disable TLS 1.0 and TLS 1.1 in libssl</title>
<updated>2023-07-02T17:21:33+00:00</updated>
<author>
<name>beck</name>
<email></email>
</author>
<published>2023-07-02T17:21:33+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=4edd92a57f3a74829fe519f35b5c7c79e03ce0b0'/>
<id>urn:sha1:4edd92a57f3a74829fe519f35b5c7c79e03ce0b0</id>
<content type='text'>
Their time has long since past, and they should not be used.
This change restricts ssl to versions 1.2 and 1.3, and changes
the regression tests to understand we no longer speak the legacy
protocols.

For the moment the magical "golden" byte for byte comparison
tests of raw handshake values are disabled util jsing fixes them.

ok jsing@ tb@
</content>
</entry>
<entry>
<title>Use the security level knob in the test script.</title>
<updated>2022-07-07T13:20:12+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2022-07-07T13:20:12+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=c3dac70428be14a5592957954b6648a3301f6331'/>
<id>urn:sha1:c3dac70428be14a5592957954b6648a3301f6331</id>
<content type='text'>
from beck
</content>
</entry>
<entry>
<title>Force TLSv1.2 when testing SSLv3/TLSv1.2 cipher suites.</title>
<updated>2020-07-14T18:13:22+00:00</updated>
<author>
<name>jsing</name>
<email></email>
</author>
<published>2020-07-14T18:13:22+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=433ca5556ec97043c86247c7a189970e68a998b3'/>
<id>urn:sha1:433ca5556ec97043c86247c7a189970e68a998b3</id>
<content type='text'>
Otherwise we end up switching to TLSv1.3 and using a TLSv1.3 cipher suite.
</content>
</entry>
<entry>
<title>Test TLSv1.3 ciphersuites now that TLS_method() supports TLSv1.3.</title>
<updated>2020-07-07T19:41:31+00:00</updated>
<author>
<name>jsing</name>
<email></email>
</author>
<published>2020-07-07T19:41:31+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=f45a55fc46ffe1493df9e49ec2d3febaf23c557b'/>
<id>urn:sha1:f45a55fc46ffe1493df9e49ec2d3febaf23c557b</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Revise test to handle the fact that TLSv1.3 cipher suites are now being</title>
<updated>2020-04-09T17:55:45+00:00</updated>
<author>
<name>jsing</name>
<email></email>
</author>
<published>2020-04-09T17:55:45+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=02f91bf85c93ea810a5debf412591a16e609bd61'/>
<id>urn:sha1:02f91bf85c93ea810a5debf412591a16e609bd61</id>
<content type='text'>
included in the output from `openssl ciphers`.
</content>
</entry>
<entry>
<title>Test both SSLv3 (aka pre-TLSv1.2) and TLSv1.2 cipher suites with TLS.</title>
<updated>2020-04-09T17:27:11+00:00</updated>
<author>
<name>jsing</name>
<email></email>
</author>
<published>2020-04-09T17:27:11+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=5e806785eb03c3eea79c60e13b7eb743e022b13b'/>
<id>urn:sha1:5e806785eb03c3eea79c60e13b7eb743e022b13b</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Remove NPN test coverage.</title>
<updated>2017-08-12T21:05:06+00:00</updated>
<author>
<name>jsing</name>
<email></email>
</author>
<published>2017-08-12T21:05:06+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=aa07f6851bbcb6c8ad4d78c02d2b5814864eaac1'/>
<id>urn:sha1:aa07f6851bbcb6c8ad4d78c02d2b5814864eaac1</id>
<content type='text'>
</content>
</entry>
<entry>
<title>check if openssl(1) actually works before proceeding</title>
<updated>2015-09-27T18:20:18+00:00</updated>
<author>
<name>bcook</name>
<email></email>
</author>
<published>2015-09-27T18:20:18+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=517edd4aef01b023f59cf9b4ca4b8d1c7f226426'/>
<id>urn:sha1:517edd4aef01b023f59cf9b4ca4b8d1c7f226426</id>
<content type='text'>
It was possible for this test to pass even if the openssl command itself was
missing.
</content>
</entry>
<entry>
<title>Remove SSLv3 support from LibreSSL regression tests.</title>
<updated>2015-08-27T07:19:17+00:00</updated>
<author>
<name>doug</name>
<email></email>
</author>
<published>2015-08-27T07:19:17+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=46987ee4e7313e879bf949893a6f9d47b91bc72a'/>
<id>urn:sha1:46987ee4e7313e879bf949893a6f9d47b91bc72a</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Increase cipher suite test coverage by including all cipher suites that</title>
<updated>2014-12-12T12:23:35+00:00</updated>
<author>
<name>jsing</name>
<email></email>
</author>
<published>2014-12-12T12:23:35+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=a45d08be405ad0b8778ff090376a760138c5751c'/>
<id>urn:sha1:a45d08be405ad0b8778ff090376a760138c5751c</id>
<content type='text'>
use RSA authentication, rather than only those that use RSA key exchange.
</content>
</entry>
</feed>
