Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | Add the following certs: | dhill | 2011-03-25 | 1 | -0/+665 | |
| | | | | | | | | | | | | | | DigiCert High Assurance CA-3 Go Daddy Secure Certification Authority COMODO High-Assurance Secure Server CA Equifax Secure Certificate Authority VeriSign Class 3 Public Primary Certification Authority - G5 Entrust Certification Authority - L1C Entrust.net Secure Server Certification Authority cross checked with mozilla ok beck@ | |||||
* | This script doesn't need write access to $curdir. Just check existence. | matthieu | 2011-03-24 | 1 | -3/+3 | |
| | | | | Fixes build on NFS src with no root access. ok jasper@ | |||||
* | tweak for clarity, ok millert@, jmc@ | espie | 2011-03-21 | 1 | -4/+4 | |
| | ||||||
* | add a regress test for the vis and unvis functions. after finding one | deraadt | 2011-03-13 | 1 | -4/+90 | |
| | | | | | bug, this then found a 2nd bug.. worked on with guenther | |||||
* | wrong type for variable; spotted by christian.siebert@cs.tu-chemnitz.de | deraadt | 2011-03-06 | 1 | -3/+3 | |
| | | | | ok guenther | |||||
* | Fix PR 6267: recheck POSIXLY_CORRECT each time getopt_long() starts a new | guenther | 2011-03-05 | 3 | -44/+16 | |
| | | | | | | | | argv and don't suppress the handling of leading '-' in optstring when POSIXLY_CORRECT is set. Based on patch from Eric Blake. ok and manpage update from millert@, manpage ok jmc@ | |||||
* | Remove expired certs. | dhill | 2011-03-03 | 1 | -174/+0 | |
| | | | | ok beck@ fgsch@ | |||||
* | Fix __cxa_finalize() so that calling __cxa_finalize(NULL) properly | matthew | 2011-03-02 | 1 | -2/+2 | |
| | | | | | | invokes handlers registered with __cxa_atexit(). "seems right" deraadt@ | |||||
* | fix from pr 6207. a bit more of an explanation: we write the correct | okan | 2011-02-12 | 1 | -4/+18 | |
| | | | | | | | | | | number of bits when connecting via a SOCKS 5 proxy over ipv6, but we also need to read the same number depending on the received address type. this issue is not noticeable with ssh's SOCKS 5 support since it always set the address type as ipv4. this fixes connections via SOCKS 5 proxies which set their address type as ipv6 when using ipv6. after review with, and ok, nicm@ | |||||
* | fix for CVE-2011-0014 "OCSP stapling vulnerability"; | djm | 2011-02-10 | 2 | -2/+14 | |
| | | | | | | ok markus@ jasper@ miod@ AFAIK nothing in base uses this, though apache2 from ports may be affected. | |||||
* | Put -I${includedir} back into Cflags so configure script tests like | naddy | 2011-01-25 | 1 | -4/+8 | |
| | | | | | | | test -n "`pkg-config --cflags openssl`" don't assume that OpenSSL isn't available. ok miod@, sthen@, ajacoutot@, djm@ | |||||
* | Correctly escape a literal colon in an enclosure; | schwarze | 2011-01-24 | 1 | -3/+3 | |
| | | | | the \: roff escape is an optional line break. | |||||
* | - simplify, krb5 handling is not needed. | jasper | 2011-01-21 | 2 | -27/+8 | |
| | | | | prompted by brad | |||||
* | a a -> a | lum | 2011-01-20 | 1 | -3/+3 | |
| | | | | ok jmc@ | |||||
* | superceded -> superseded; | jmc | 2011-01-14 | 1 | -3/+3 | |
| | ||||||
* | Minor tweaks to nc(1) man page and usage. | jeremy | 2011-01-09 | 2 | -16/+23 | |
| | | | | OK jmc@, nicm@, tedu@ | |||||
* | Enable unix datagram support by treating ENOBUFS like EAGAIN. | jeremy | 2011-01-08 | 1 | -2/+2 | |
| | | | | | | Separate commit requested by deraadt@. OK nicm@ | |||||
* | Support unix domain sockets in nc(1) with -Uu. | jeremy | 2011-01-08 | 2 | -25/+83 | |
| | | | | | | | | | | | | | | | | | | | | | Previously, using -U with -u was an error that was not documented in the man page. Now it will use a unix socket in datagram mode. Bidirectional unix datagram communication requires a socket at both ends, so in client mode (without -l), a temporary socket is created so that responses from the server can be received. If -s is specified with -U and -u, it specifies the location of the temporary socket to create. This was mostly written way back in 2007. Since then, various improvements implemented based on suggestions from guenther@, tedu@, and nicm@. Man page help from nicm@ and jmc@. Unix datagram support requires a small change to atomicio.c in order to function correctly, this will be committed separately shortly. OK nicm@ | |||||
* | Remove an extraneous return statement with the wrong return value. | millert | 2011-01-07 | 1 | -8/+6 | |
| | | | | Fix some gcc warnings. | |||||
* | - adjust krb5 directories | jasper | 2011-01-03 | 1 | -8/+5 | |
| | | | | - zap a trailing tab | |||||
* | - ensure ${DESTDIR}/usr/lib/pkgconfig/ as running make distrib-dirs is not | jasper | 2010-12-28 | 1 | -2/+3 | |
| | | | | common/encouraged practice | |||||
* | - generate and install pkg-config files for openssl, which more and more | jasper | 2010-12-28 | 2 | -1/+122 | |
| | | | | | | | | projects depend on being present (e.g. various ports). as discussed with various porters in a hungarian spa help/feedback from ingo@ and also OK halex@ no objections from djm@ | |||||
* | remove comment that hasn't been true for quite a while now; | otto | 2010-12-22 | 1 | -6/+1 | |
| | | | | ok deraadt@ djm@ | |||||
* | avoid pointer arithmetic on void * | dhill | 2010-12-16 | 1 | -5/+5 | |
| | | | | | | tested for a while by me. ok otto@ | |||||
* | move CRYPTO_VIAC3_MAX out of cryptodev.h and into the only | jsg | 2010-12-16 | 2 | -0/+4 | |
| | | | | | | file it will be used from. requested by/ok mikeb@ | |||||
* | The VIA ciphers are added to an array of CRYPTO_ALGORITHM_MAX length | jsg | 2010-12-16 | 2 | -4/+4 | |
| | | | | | | | which should have been declared as CRYPTO_ALGORITHM_MAX + 1, fix this and reserve enough space for the VIA additions as well. ok/comments from mikeb & deraadt | |||||
* | Security fix for CVE-2010-4180 as mentioned in ↵ | jasper | 2010-12-15 | 4 | -0/+16 | |
| | | | | | | | | | | | http://www.openssl.org/news/secadv_20101202.txt. where clients could modify the stored session cache ciphersuite and in some cases even downgrade the suite to weaker ones. This code is not enabled by default. ok djm@ | |||||
* | overriden -> overridden; | jmc | 2010-12-12 | 1 | -4/+4 | |
| | ||||||
* | involes -> involves; from Carlos Alberto Pereira Gomes | jmc | 2010-11-30 | 1 | -1/+1 | |
| | ||||||
* | - Apply security fix for CVE-2010-3864 (+commit 19998 which fixes the fix). | jasper | 2010-11-17 | 2 | -36/+84 | |
| | | | | ok djm@ deraadt@ | |||||
* | remove skipjack and cast from the libc; ok deraadt | mikeb | 2010-10-28 | 3 | -1053/+2 | |
| | ||||||
* | print the pointer value that caused the error (if available); ok | otto | 2010-10-21 | 1 | -47/+54 | |
| | | | | deraadt@ nicm@ (on an earlier version) | |||||
* | Disable use of dladdr() on a.out arches, they do not provide it (yet); ok djm@ | miod | 2010-10-18 | 2 | -2/+2 | |
| | ||||||
* | various tweaks for consistency; | jmc | 2010-10-17 | 1 | -92/+62 | |
| | ||||||
* | use standard list width; | jmc | 2010-10-15 | 1 | -29/+29 | |
| | ||||||
* | nicer formatting for the various synopses; | jmc | 2010-10-15 | 1 | -276/+344 | |
| | ||||||
* | document "openssl ts"; | jmc | 2010-10-15 | 1 | -4/+629 | |
| | ||||||
* | probabalistic -> probabilistic; from naddy | jmc | 2010-10-14 | 1 | -2/+2 | |
| | ||||||
* | for openssl prime, note that results are probabalistic; from djm | jmc | 2010-10-14 | 1 | -2/+5 | |
| | ||||||
* | document "openssl prime"; | jmc | 2010-10-13 | 1 | -1/+47 | |
| | ||||||
* | document "openssl pkeyparam"; | jmc | 2010-10-13 | 1 | -6/+54 | |
| | ||||||
* | document "openssl pkeyutl"; | jmc | 2010-10-12 | 1 | -2/+212 | |
| | ||||||
* | document "openssl pkey"; | jmc | 2010-10-09 | 1 | -1/+127 | |
| | ||||||
* | document "openssl genpkey"; | jmc | 2010-10-09 | 1 | -2/+176 | |
| | ||||||
* | document "openssl engine"; | jmc | 2010-10-08 | 1 | -1/+51 | |
| | ||||||
* | document "openssl ecparam"; | jmc | 2010-10-08 | 1 | -1/+182 | |
| | ||||||
* | supply the correct value of ciphers DEFAULT; from djm | jmc | 2010-10-08 | 1 | -3/+3 | |
| | ||||||
* | document "openssl ec"; | jmc | 2010-10-08 | 1 | -3/+209 | |
| | ||||||
* | OpenSSL grows another undocumented header, apparently needed on armish | djm | 2010-10-07 | 1 | -1/+2 | |
| | ||||||
* | More OpenSSL fixes: | djm | 2010-10-06 | 7 | -26/+30 | |
| | | | | | | | | | - Update local engines for the EVP API change (len u_int => size_t) - Use hw_cryptodev.c instead of eng_cryptodev.c - Make x86_64-xlate.pl always write to the output file and not stdout, fixing "make -j" builds (spotted by naddy@) ok naddy@ |