summaryrefslogtreecommitdiff
Commit message (Expand)AuthorAgeFilesLines
* Convert legacy stack server to ssl_sigalg_for_peer().jsing2021-06-291-47/+29
* Convert legacy stack client to ssl_sigalg_for_peer().jsing2021-06-291-34/+12
* Provide a ssl_sigalg_for_peer() function and use in the TLSv1.3 code.jsing2021-06-294-15/+33
* Move the RSA-PSS check for TLSv1.3 to ssl_sigalg_pkey_ok().jsing2021-06-296-34/+29
* Factor out handling of legacy default signature algorithms.jsing2021-06-291-32/+27
* Mop up now unused variables.jsing2021-06-291-7/+2
* Require a ServerHello following a HelloRetryRequest to use the same cipher.jsing2021-06-291-2/+11
* Reject zero-length non-application data fragments in the legacy stack.jsing2021-06-291-1/+11
* Use the order action->sender == ctx->mode everywhere for consistency.tb2021-06-281-3/+3
* ctx->alert is not a boolean, so compare it explicitly against 0.tb2021-06-281-3/+3
* The state machine now takes care of setting the legacy state,tb2021-06-281-11/+1
* Expand info callback support for TLSv1.3tb2021-06-282-7/+187
* Track the sigalgs used by ourselves and our peer.jsing2021-06-273-9/+14
* Have ssl3_send_client_verify() pass *pkey to called functions.jsing2021-06-271-22/+11
* Change ssl_sigalgs_from_value() to perform sigalg list selection.jsing2021-06-276-32/+31
* Rename ssl_sigalg() to ssl_sigalg_from_value().jsing2021-06-276-17/+18
* Change ssl_sigalgs_build() to perform sigalg list selection.jsing2021-06-274-28/+29
* Tidy some comments and simplify some code.jsing2021-06-271-15/+7
* Keep sigalg initialiser order consistent - key type, then hash.jsing2021-06-272-20/+20
* Add test coverage for TLSv1.3 client hellos.jsing2021-06-271-13/+166
* Add test coverage for DTLSv1.2 client hellos.jsing2021-06-271-7/+102
* Improve test coverage for SSL_OP_NO_DTLSv1.jsing2021-06-271-1/+9
* Correct handling of SSL_OP_NO_DTLSv1.jsing2021-06-271-3/+3
* Teach hexdump() how to identify differing bytes.jsing2021-06-271-9/+13
* More appropriately set cipher_list_len when AES acceleration is available.jsing2021-06-271-5/+6
* Tweak some data types and sprinkle some const.jsing2021-06-271-15/+15
* Fix .Xr order. From mandoc -Tlint.tb2021-06-262-7/+7
* Garbage collect prototoype for ssl_parse_serverhello_tlsext() whichtb2021-06-231-3/+1
* zap wonky commas;jmc2021-06-221-5/+5
* Clarify tls_config_set_*_file() file I/O semanticskn2021-06-221-13/+11
* Add GnuTLS interoperability test in appstest.shinoguchi2021-06-211-1/+109
* zap trailing whitespacetb2021-06-191-4/+7
* Correctly handle epoch wrapping in dtls1_get_bitmap().jsing2021-06-192-4/+5
* Add DTLS test cases that use non-zero initial epochs.jsing2021-06-192-5/+44
* Provide the ability to set the initial DTLS epoch value.jsing2021-06-194-7/+29
* Initialise the epoch for the DTLS processed and unprocessed queues.jsing2021-06-191-1/+4
* Add more complex DTLS tests for delay/reordering.jsing2021-06-191-17/+160
* Expand comment that details why two DTLS tests currently fail.jsing2021-06-191-2/+5
* Provide the ability to delay/reorder DTLS packets.jsing2021-06-191-14/+147
* Remove SSL_CTX_set_read_ahead() calls - it is now the default for DTLS.jsing2021-06-181-3/+1
* Like ARM, RISC-V does not implement floating point exceptions.kettenis2021-06-173-6/+6
* Mop up part of dtls1_dispatch_alert().jsing2021-06-151-9/+2
* Simplify nonce handling in the TLSv1.2 record layer.jsing2021-06-141-13/+16
* Remove TLS1_AD_INTERNAL_ERROR from internal visibility againtb2021-06-141-3/+1
* Use SSL_AD_INTERNAL_ERRORtb2021-06-141-2/+2
* ugly hack around broken build until people wake up.deraadt2021-06-141-1/+3
* Add SSL_AD_MISSING_EXTENSION.jsing2021-06-132-2/+9
* Define SSL_AD_* as actual values.jsing2021-06-133-42/+49
* Remove tls1_alert_code().jsing2021-06-133-73/+3
* Place obsolete alerts under #ifndef LIBRESSL_INTERNAL.jsing2021-06-131-4/+7