Commit message (Collapse) | Author | Files | Lines | ||
---|---|---|---|---|---|
2015-06-15 | Remove ancient SSL_OP_NETSCAPE_CA_DN_BUG from SSLeay days. | doug | 8 | -106/+40 | |
This commit matches the OpenSSL removal in commit 3c33c6f6b10864355553961e638514a6d1bb00f6. ok deraadt@ | |||||
2015-06-15 | Remove ancient compat hack SSL_OP_NETSCAPE_DEMO_CIPHER_CHANGE_BUG. | doug | 5 | -81/+11 | |
This was imported into OpenSSL from SSLeay. It was recently deleted in OpenSSL commit 7a4dadc3a6a487db92619622b820eb4f7be512c9 | |||||
2015-06-15 | Remove 1997's compat hack SSL_OP_SSLEAY_080_CLIENT_DH_BUG. | doug | 4 | -22/+16 | |
This is a hack for an old version of SSLeay which predates OpenSSL. | |||||
2015-06-15 | Update SSL_OP_* to remove ancient hacks that are no longer enabled. | doug | 2 | -26/+22 | |
2015-06-13 | Split up the logic in CBB_flush to separately handle the lengths. | doug | 2 | -42/+64 | |
Also, add comments about assuming short-form. ok miod@, tweak + ok jsing@ | |||||
2015-06-13 | Explain the ASN.1 restriction that requires extra logic for encoding. | doug | 2 | -4/+36 | |
ok miod@ jsing@ | |||||
2015-06-13 | When initial capacity is 0, always use NULL buffer. | doug | 2 | -14/+16 | |
malloc(0) is implementation defined and there's no reason to introduce that ambiguity here. Added a few cosmetic changes in sizeof and free. ok miod@ jsing@ | |||||
2015-06-13 | Add comments about how the CBS constants are constructed. | doug | 2 | -24/+86 | |
Also, introduce a few more #defines to make it obvious. ok miod@ jsing@ | |||||
2015-06-13 | Reject long-form tags in CBS_peek_asn1_tag. | doug | 2 | -2/+16 | |
Currently, CBS only handles short-form tags. ok miod@ jsing@ | |||||
2015-06-13 | Fix bad indenting in LibreSSL. | doug | 10 | -24/+24 | |
jsg@ noticed that some of the lines in libssl and libcrypto are not indented properly. At a quick glance, it looks like it has a different control flow than it really does. I checked the history in our tree and in OpenSSL to make sure these were simple mistakes. ok miod@ jsing@ | |||||
2015-06-13 | Remove unneeded sys/sysctl.h on linux. | bcook | 2 | -4/+2 | |
This only provides the sysctl wrapper in glibc, which we do not use and is not available in other libc implementations for Linux. Thanks to ncopa from github. | |||||
2015-06-11 | Avoid an infinite loop that can occur when verifying a message with anlibressl-v2.2.0 | jsing | 2 | -4/+4 | |
unknown hash function OID. Diff based on OpenSSL. Fixes CVE-2015-1792 (however, this code is not enabled/built in LibreSSL). ok doug@ miod@ | |||||
2015-06-11 | Avoid a potential out-of-bounds read in X509_cmp_time(), due to missing | jsing | 2 | -8/+54 | |
length checks. Diff based on changes in OpenSSL. Fixes CVE-2015-1789. ok doug@ | |||||
2015-06-11 | Avoid an infinite loop that can be triggered by parsing an ASN.1 | jsing | 2 | -6/+16 | |
ECParameters structure that has a specially malformed binary polynomial field. Issue reported by Joseph Barr-Pixton and fix based on OpenSSL. Fixes CVE-2015-1788. ok doug@ miod@ | |||||
2015-06-05 | Link ssl and crypto via BSDOBJDIR, works with native and cross builds | tobiasu | 1 | -3/+3 | |
ok mpi@ | |||||
2015-06-05 | Fix library search path so we link against the freshly built libcrypto.so | tobiasu | 1 | -2/+2 | |
instead of a stale one. ok miod@ mpi@ | |||||
2015-06-04 | force reseeding if pid has changed. | eric | 1 | -2/+7 | |
ok deraadt@ | |||||
2015-05-29 | Need to operate of CXXFLAGS now. | miod | 1 | -3/+3 | |
2015-05-26 | Use a relative path against BSDOBJDIR to pick libcrypto; makes cross-lib | miod | 1 | -2/+2 | |
work again. | |||||
2015-05-26 | Add OPENSSL_NO_EGD to opensslfeatures.h. | bcook | 2 | -0/+2 | |
Since RAND_egd has been removed from LibreSSL, simplify porting software that relies on it. See https://github.com/libressl-portable/openbsd/pull/34 from Bernard Spil, ok deraadt@ | |||||
2015-05-25 | Make SSL_CIPHER_get_bits() report ChaCha20-Poly1305 ciphers as using | guenther | 2 | -8/+8 | |
256bit keys problem noted by Tim Kuijsten (info (at) netsend.nl) ok deraadt@ miod@ bcook@ | |||||
2015-05-24 | Maximilian dot Fillinger at uni-duesseldorf dot de | schwarze | 3 | -74/+109 | |
starts helping with the pod2mdoc(1)-based conversion of LibreSSL crypto manuals from perlpod(1) to mdoc(7). Here comes the first file, slightly tweaked by me. | |||||
2015-05-23 | bump to version 2.2 | bcook | 2 | -4/+4 | |
ok deraadt@ | |||||
2015-05-20 | No need to check the return value of memcpy() if you actually checked this | miod | 2 | -6/+4 | |
pointer for NULL the line above; ok doug@ | |||||
2015-05-17 | Record inter-library dependencies between libcrypto, libssl and libtls | kettenis | 6 | -2/+11 | |
2015-05-15 | Make index/rindex weak aliases of strchr/strrchr since they are not | millert | 4 | -90/+6 | |
part of the ISO C standard and have also been dropped from POSIX. OK guenther@ kettenis@ | |||||
2015-05-15 | Fix return paths with missing EVP_CIPHER_CTX_cleanup() calls. | jsg | 10 | -30/+32 | |
ok doug@ | |||||
2015-05-14 | rev 1.3 introduced a check to an if statement without adding braces. | jsg | 1 | -3/+1 | |
Claudio points out the size is checked by an earlier test so just remove it to restore the original handling of the partial octet case. Discussed with claudio and gilles. | |||||
2015-05-13 | If crypt(3) is called with an unknown setting, return NULL instead | bluhm | 1 | -1/+3 | |
of some undefined value. OK tedu@ | |||||
2015-05-12 | Add dlclose(3) to SEE ALSO | guenther | 1 | -2/+3 | |
ok millert@ jmc@ schwarze@ | |||||
2015-05-11 | When checking flags that will be passed to open(), test the O_ACCMODE portion | guenther | 1 | -2/+3 | |
separately to avoid false negatives. ok miod@ millert@ | |||||
2015-05-08 | Make this run on strict alignment architectures. | miod | 1 | -6/+9 | |
2015-05-04 | Add SwissSign CA root certificates. Requested by robert@, ok dcoppa@ aja@ miod@ | sthen | 1 | -0/+381 | |
2015-04-30 | use strdup() to init string | deraadt | 2 | -6/+4 | |
ok doug millert | |||||
2015-04-29 | Add whitespace and replace OPENSSL_free with free in documentation. | doug | 6 | -22/+22 | |
ok jsing@ | |||||
2015-04-29 | Call CBB_add_space() rather than reimplementing it. | doug | 2 | -4/+4 | |
ok jsing@ | |||||
2015-04-29 | Rename cbb_buffer_add_u to cbb_add_u and remove redundant code. | doug | 2 | -30/+12 | |
All of cbb_buffer_add_u's callers first call CBB_flush and send cbb->base. cbb_add_u() now has that common code in one place. ok jsing@ | |||||
2015-04-29 | Added len_len error checking for internal cbb_buffer_add_u(). | doug | 2 | -2/+8 | |
ok jsing@ | |||||
2015-04-29 | Call CBS_mem_equal() rather than reimplementing it. | doug | 2 | -6/+4 | |
ok jsing@ | |||||
2015-04-29 | Avoid NULL deref in CBS_get_any_asn1_element(). | doug | 2 | -4/+6 | |
This function is documented as allowing NULL for out_header_len. ok jsing@ | |||||
2015-04-29 | Added error checking for len argument in cbs_get_u(). | doug | 2 | -2/+8 | |
tweak + ok jsing@ | |||||
2015-04-29 | free() can handle NULL. | doug | 2 | -16/+8 | |
ok jsing@ | |||||
2015-04-29 | Reject dNSName of " " for subjectAltName extension. | doug | 1 | -1/+20 | |
RFC 5280 says " " must not be used as a dNSName. ok jsing@ jca@ | |||||
2015-04-29 | Add missing BN_CTX_end() calls. | doug | 8 | -36/+36 | |
After calling BN_CTX_start(), there must be a BN_CTX_end() before returning. There were missing BN_CTX_end() calls in error paths. One diff chunk was simply removing redundant code related to this. ok deraadt@ | |||||
2015-04-27 | Not all Linux libc's include linux/sysctl.h in sys/sysctl.h. | bcook | 2 | -4/+6 | |
Include it if we have the sysctl syscall. | |||||
2015-04-27 | Support AIX versions without WPAR support. | bcook | 2 | -2/+10 | |
From Michael Felt. | |||||
2015-04-25 | Don't ignore the reference count in X509_STORE_free. | doug | 2 | -2/+10 | |
Based on this upstream commit: bff9ce4db38b297c72a6d84617d71ae2934450f7 which didn't make it into a release until 1.0.2. Thanks to william at 25thandclement dot com for reporting this! ok deraadt@ jsing@ beck@ | |||||
2015-04-25 | Check for invalid leading zeros in CBS_get_asn1_uint64. | doug | 3 | -8/+20 | |
ASN.1 integers cannot have all zeros or all ones for the first 9 bits. This rule ensures the numbers are encoded with the smallest number of content octets (see ITU-T Rec X.690 section 8.3.2). Based on BoringSSL commit 5933723b7b592e9914f703d630b596e140c93e16 ok deraadt@ jsing@ | |||||
2015-04-23 | Do not need to buf[0] = 0 before strlcpy(buf, ... | deraadt | 2 | -4/+2 | |
2015-04-15 | Only set the cipher list if one was specified and actually check the return | jsing | 1 | -7/+12 | |
value from SSL_CTX_set_cipher_list(). Also remove pointless getenv() handling. ok bcook@ doug@ |