summaryrefslogtreecommitdiff
path: root/src/lib/libc/stdlib/div.c (unfollow)
Commit message (Collapse)AuthorFilesLines
2016-11-06Split ssl3_get_client_key_exchange() into separate per algorithm functions.jsing1-320/+388
ok beck@
2016-11-06Remove pointless check - without fixed ECDH, there is only one way to reachjsing1-8/+1
this code path. ok beck@ bcook@
2016-11-06tweak previous;jmc1-3/+3
2016-11-06simplify error handling in c2i_ASN1_OBJECTbcook1-10/+12
ok beck@, miod@
2016-11-06Split out the DHE and ECDHE code paths fromjsing1-203/+221
ssl3_send_server_key_exchange(). ok beck@ bcook@
2016-11-06rename tlslegacy to tlsall, and better describe what it does.beck2-8/+8
ok jsing@
2016-11-06Adjust cipher suite strengths - move MD5 to LOW, RC4 to LOW and 3DES tojsing1-13/+13
MEDIUM. ok beck@ bcook@
2016-11-06Update regress for IDEA cipher suite removal.jsing1-83/+83
2016-11-06Remove the single IDEA cipher suite. There is no good reason to supportjsing3-29/+3
this. ok beck@ bcook@
2016-11-06unifdef -m -UOPENSSL_NO_CHACHA -UOPENSSL_NO_POLY1305jsing2-6/+2
ok beck@
2016-11-06Add regress test script for openssl command.inoguchi3-2/+966
ok beck@
2016-11-06Avoid compiling in an unused function.jsing1-0/+2
Spotted by guenther@
2016-11-06adjust guards to elide unused Bi arraybcook1-2/+0
ok jsing@
2016-11-06Rework X509_verify_cert to support alt chains on certificate verification,beck1-117/+265
via boringssl. ok jsing@ miod@
2016-11-06The upcoming x509 alt chains diff tightens the trust requirementsbeck1-1/+17
for certificates. This (from OpenSSL) ensures that the current "default" behaviour remains the same. We should revisit this later ok jsing@
2016-11-06Commit a reminder that the default is not the default. This needs tobeck1-1/+2
be revisited. ok jsing@
2016-11-06remove unused variablebcook1-6/+3
2016-11-06use the correct function for freebcook1-2/+2
ok beck@
2016-11-06add an .Xr that was missingschwarze1-1/+2
2016-11-05document BN_set_negative() and BN_is_negative();schwarze6-516/+69
feedback and OK bcook@, OK jsing@
2016-11-05Part one of the alt chains changes, bring in newer modifications tobeck3-73/+411
VERIFY_PARAMS - based on boringssl. ok jsing@ miod@
2016-11-05Add objects for X25519, X448, Ed25519 and Ed448.jsing2-0/+15
ok miod@
2016-11-05One of the error paths would attempt to access not-yet-initialized locals.miod1-2/+2
Simply return since there is nothing more to do. Spotted by coverity. ok jsing@ beck@
2016-11-05Do a partial CBB conversion of ssl3_send_server_key_exchange(), which willjsing1-52/+67
make it easier to do further clean up. ok beck@ miod@
2016-11-05fix misplaced quote by tls_peer_ocsp_this_updatebcook1-2/+2
2016-11-05zap trailing whitespace, and add -o to usage() and help (-h);jmc2-6/+9
2016-11-05tweak previous;jmc1-6/+6
2016-11-05move manual pages from doc/ to man/ for consistency with otherschwarze85-169/+169
libraries, in particular considering that there are unrelated files in doc/; requested by jsing@ and beck@
2016-11-05Check BIO_new*() for failure.miod2-4/+9
ok beck@ jsing@
2016-11-05More X509_STORE_CTX_set_*() return value checks.miod3-12/+16
ok beck@ jsing@
2016-11-05bump minors for symbol addition for ocsp and x25519 symbol additionsbeck3-3/+3
2016-11-05Add support for server side OCSP stapling to libtls.beck9-16/+98
Add support for server side OCSP stapling to netcat.
2016-11-05Add regress for X25519, converted from BoringSSL.jsing3-1/+150
2016-11-05after getting rid of the pod files, clean up the Makefiles; ok bcook@schwarze4-41/+23
2016-11-05Add support for X25519.jsing5-1/+5136
This brings in code from BoringSSL, which is mostly taken from SUPERCOP. ok beck@ bcook@
2016-11-05rename ocsp_ctx to ocspbeck3-68/+68
ok jsing@
2016-11-05minor mandoc -Tlint nitsschwarze3-9/+8
2016-11-05add the missing content, sorry for committing an empty fileschwarze1-0/+69
2016-11-05Stricter validation of inputs of OPENSSL_asc2uni() and OPENSSL_uni2asc().miod1-17/+34
While there, try to make these slightly less obfuscated. ok beck@ jsing@
2016-11-05convert the remaining manual pages from pod to mdocschwarze25-1650/+3615
2016-11-05X509_STORE_CTX_set_*() may fail, so check for errors.miod1-4/+14
ok beck@
2016-11-05Do not leak the ressources possibly allocated by EVP_MD_CTX_init() in themiod1-2/+3
trivial error path of PKCS12_key_gen_uni(). ok beck@ jsing@
2016-11-05Set PROG so that the binary correctly gets recompiled when the librariesmiod1-11/+5
it is linked against change. ok beck@ jsing@
2016-11-05Make sure PEM_SealInit() will correctly destroy the PEM_ENCODE_SEAL_CTXmiod1-8/+22
upon error, as there is no way to do this outside of PEM_SealFinal(), which can only work if PEM_SealInit() succeeded... ok beck@ jsing@
2016-11-05No need to duplicate definitions from evp.h locally.miod2-14/+2
ok bock@ jsing@
2016-11-05Stop abusing the ternary operator to decide which function to call in amiod1-3/+6
return statement. ok beck@ jsing@
2016-11-05further tweakage, with an improvement from joel;jmc1-5/+5
ok jsing schwarze
2016-11-05Convert ssl3_get_server_kex_ecdhe() to CBS, simplifying tls1_check_curve()jsing3-62/+41
in the process. This also fixes a long standing bug where tls1_ec_curve_id2nid() is called with only one byte of the curve ID. ok beck@ miod@
2016-11-05Remove generated Symbols.map on make clean.jsing2-3/+5
ok guenther@
2016-11-04tweak previousschwarze1-34/+39