Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | rename tlslegacy to tlsall, and better describe what it does. | beck | 2016-11-06 | 2 | -8/+8 | |
| | | | | ok jsing@ | |||||
* | Adjust cipher suite strengths - move MD5 to LOW, RC4 to LOW and 3DES to | jsing | 2016-11-06 | 1 | -13/+13 | |
| | | | | | | MEDIUM. ok beck@ bcook@ | |||||
* | Update regress for IDEA cipher suite removal. | jsing | 2016-11-06 | 1 | -83/+83 | |
| | ||||||
* | Remove the single IDEA cipher suite. There is no good reason to support | jsing | 2016-11-06 | 3 | -29/+3 | |
| | | | | | | this. ok beck@ bcook@ | |||||
* | unifdef -m -UOPENSSL_NO_CHACHA -UOPENSSL_NO_POLY1305 | jsing | 2016-11-06 | 2 | -6/+2 | |
| | | | | ok beck@ | |||||
* | Add regress test script for openssl command. | inoguchi | 2016-11-06 | 3 | -2/+966 | |
| | | | | ok beck@ | |||||
* | Avoid compiling in an unused function. | jsing | 2016-11-06 | 1 | -0/+2 | |
| | | | | Spotted by guenther@ | |||||
* | adjust guards to elide unused Bi array | bcook | 2016-11-06 | 1 | -2/+0 | |
| | | | | ok jsing@ | |||||
* | Rework X509_verify_cert to support alt chains on certificate verification, | beck | 2016-11-06 | 1 | -117/+265 | |
| | | | | | via boringssl. ok jsing@ miod@ | |||||
* | The upcoming x509 alt chains diff tightens the trust requirements | beck | 2016-11-06 | 1 | -1/+17 | |
| | | | | | | | for certificates. This (from OpenSSL) ensures that the current "default" behaviour remains the same. We should revisit this later ok jsing@ | |||||
* | Commit a reminder that the default is not the default. This needs to | beck | 2016-11-06 | 1 | -1/+2 | |
| | | | | | be revisited. ok jsing@ | |||||
* | remove unused variable | bcook | 2016-11-06 | 1 | -6/+3 | |
| | ||||||
* | use the correct function for free | bcook | 2016-11-06 | 1 | -2/+2 | |
| | | | | ok beck@ | |||||
* | add an .Xr that was missing | schwarze | 2016-11-06 | 1 | -1/+2 | |
| | ||||||
* | document BN_set_negative() and BN_is_negative(); | schwarze | 2016-11-05 | 6 | -516/+69 | |
| | | | | feedback and OK bcook@, OK jsing@ | |||||
* | Part one of the alt chains changes, bring in newer modifications to | beck | 2016-11-05 | 3 | -73/+411 | |
| | | | | | VERIFY_PARAMS - based on boringssl. ok jsing@ miod@ | |||||
* | Add objects for X25519, X448, Ed25519 and Ed448. | jsing | 2016-11-05 | 2 | -0/+15 | |
| | | | | ok miod@ | |||||
* | One of the error paths would attempt to access not-yet-initialized locals. | miod | 2016-11-05 | 1 | -2/+2 | |
| | | | | | | Simply return since there is nothing more to do. Spotted by coverity. ok jsing@ beck@ | |||||
* | Do a partial CBB conversion of ssl3_send_server_key_exchange(), which will | jsing | 2016-11-05 | 1 | -52/+67 | |
| | | | | | | make it easier to do further clean up. ok beck@ miod@ | |||||
* | fix misplaced quote by tls_peer_ocsp_this_update | bcook | 2016-11-05 | 1 | -2/+2 | |
| | ||||||
* | zap trailing whitespace, and add -o to usage() and help (-h); | jmc | 2016-11-05 | 2 | -6/+9 | |
| | ||||||
* | tweak previous; | jmc | 2016-11-05 | 1 | -6/+6 | |
| | ||||||
* | move manual pages from doc/ to man/ for consistency with other | schwarze | 2016-11-05 | 85 | -169/+169 | |
| | | | | | libraries, in particular considering that there are unrelated files in doc/; requested by jsing@ and beck@ | |||||
* | Check BIO_new*() for failure. | miod | 2016-11-05 | 2 | -4/+9 | |
| | | | | ok beck@ jsing@ | |||||
* | More X509_STORE_CTX_set_*() return value checks. | miod | 2016-11-05 | 3 | -12/+16 | |
| | | | | ok beck@ jsing@ | |||||
* | bump minors for symbol addition for ocsp and x25519 symbol additions | beck | 2016-11-05 | 3 | -3/+3 | |
| | ||||||
* | Add support for server side OCSP stapling to libtls. | beck | 2016-11-05 | 9 | -16/+98 | |
| | | | | Add support for server side OCSP stapling to netcat. | |||||
* | Add regress for X25519, converted from BoringSSL. | jsing | 2016-11-05 | 3 | -1/+150 | |
| | ||||||
* | after getting rid of the pod files, clean up the Makefiles; ok bcook@ | schwarze | 2016-11-05 | 4 | -41/+23 | |
| | ||||||
* | Add support for X25519. | jsing | 2016-11-05 | 5 | -1/+5136 | |
| | | | | | | This brings in code from BoringSSL, which is mostly taken from SUPERCOP. ok beck@ bcook@ | |||||
* | rename ocsp_ctx to ocsp | beck | 2016-11-05 | 3 | -68/+68 | |
| | | | | ok jsing@ | |||||
* | minor mandoc -Tlint nits | schwarze | 2016-11-05 | 3 | -9/+8 | |
| | ||||||
* | add the missing content, sorry for committing an empty file | schwarze | 2016-11-05 | 1 | -0/+69 | |
| | ||||||
* | Stricter validation of inputs of OPENSSL_asc2uni() and OPENSSL_uni2asc(). | miod | 2016-11-05 | 1 | -17/+34 | |
| | | | | | | While there, try to make these slightly less obfuscated. ok beck@ jsing@ | |||||
* | convert the remaining manual pages from pod to mdoc | schwarze | 2016-11-05 | 25 | -1650/+3615 | |
| | ||||||
* | X509_STORE_CTX_set_*() may fail, so check for errors. | miod | 2016-11-05 | 1 | -4/+14 | |
| | | | | ok beck@ | |||||
* | Do not leak the ressources possibly allocated by EVP_MD_CTX_init() in the | miod | 2016-11-05 | 1 | -2/+3 | |
| | | | | | | trivial error path of PKCS12_key_gen_uni(). ok beck@ jsing@ | |||||
* | Set PROG so that the binary correctly gets recompiled when the libraries | miod | 2016-11-05 | 1 | -11/+5 | |
| | | | | | | it is linked against change. ok beck@ jsing@ | |||||
* | Make sure PEM_SealInit() will correctly destroy the PEM_ENCODE_SEAL_CTX | miod | 2016-11-05 | 1 | -8/+22 | |
| | | | | | | | upon error, as there is no way to do this outside of PEM_SealFinal(), which can only work if PEM_SealInit() succeeded... ok beck@ jsing@ | |||||
* | No need to duplicate definitions from evp.h locally. | miod | 2016-11-05 | 2 | -14/+2 | |
| | | | | ok bock@ jsing@ | |||||
* | Stop abusing the ternary operator to decide which function to call in a | miod | 2016-11-05 | 1 | -3/+6 | |
| | | | | | return statement. ok beck@ jsing@ | |||||
* | further tweakage, with an improvement from joel; | jmc | 2016-11-05 | 1 | -5/+5 | |
| | | | | ok jsing schwarze | |||||
* | Convert ssl3_get_server_kex_ecdhe() to CBS, simplifying tls1_check_curve() | jsing | 2016-11-05 | 3 | -62/+41 | |
| | | | | | | | in the process. This also fixes a long standing bug where tls1_ec_curve_id2nid() is called with only one byte of the curve ID. ok beck@ miod@ | |||||
* | Remove generated Symbols.map on make clean. | jsing | 2016-11-05 | 2 | -3/+5 | |
| | | | | ok guenther@ | |||||
* | tweak previous | schwarze | 2016-11-04 | 1 | -34/+39 | |
| | ||||||
* | Move pqueue regress from libcrypto to libssl, since that's where the pqueue | jsing | 2016-11-04 | 5 | -5/+5 | |
| | | | | | code now lives. Also unbreak the regress following the symbol hiding changes in libssl. | |||||
* | Rename ssl3_get_key_exchange() to ssl3_get_server_key_exchange(), since | jsing | 2016-11-04 | 3 | -7/+7 | |
| | | | | | | that's what it really is. ok miod@ | |||||
* | Build with WARNINGS=Yes. | jsing | 2016-11-04 | 1 | -1/+3 | |
| | ||||||
* | Avoid shadowing the socket global. | jsing | 2016-11-04 | 1 | -3/+3 | |
| | | | | ok miod@ | |||||
* | Make the tls_keypair_new() function a valid prototype. | jsing | 2016-11-04 | 1 | -2/+2 | |
| |