index
:
openbsd
OPENBSD_2_0
OPENBSD_2_1
OPENBSD_2_2
OPENBSD_2_3
OPENBSD_2_4
OPENBSD_2_5
OPENBSD_2_6
OPENBSD_2_7
OPENBSD_2_8
OPENBSD_2_9
OPENBSD_3_0
OPENBSD_3_1
OPENBSD_3_2
OPENBSD_3_3
OPENBSD_3_4
OPENBSD_3_5
OPENBSD_3_6
OPENBSD_3_7
OPENBSD_3_8
OPENBSD_3_9
OPENBSD_4_0
OPENBSD_4_1
OPENBSD_4_2
OPENBSD_4_3
OPENBSD_4_4
OPENBSD_4_5
OPENBSD_4_6
OPENBSD_4_7
OPENBSD_4_8
OPENBSD_4_9
OPENBSD_5_0
OPENBSD_5_1
OPENBSD_5_2
OPENBSD_5_3
OPENBSD_5_4
OPENBSD_5_5
OPENBSD_5_6
OPENBSD_5_7
OPENBSD_5_8
OPENBSD_5_9
OPENBSD_6_0
OPENBSD_6_1
OPENBSD_6_2
OPENBSD_6_3
OPENBSD_6_4
OPENBSD_6_5
OPENBSD_6_6
OPENBSD_6_7
OPENBSD_6_8
OPENBSD_6_9
OPENBSD_7_0
OPENBSD_7_1
OPENBSD_7_2
OPENBSD_7_3
OPENBSD_7_4
OPENBSD_7_5
OPENBSD_7_6
master
A mirror of https://github.com/libressl/openbsd.git
summary
refs
log
tree
commit
diff
log msg
author
committer
range
path:
root
/
src
/
lib
/
libcrypto
/
x509
(
follow
)
Commit message (
Expand
)
Author
Age
Files
Lines
*
Enable X509_V_FLAG_TRUSTED_FIRST by default in the legacy verifier.
deraadt
2021-09-30
1
-1
/
+2
*
Avoid a potential overread in x509_constraints_parse_mailbox()
deraadt
2021-09-26
1
-5
/
+9
*
This is errata/6.8/013_libressl.patch.sig
libressl-v3.2.4
tb
2021-02-03
3
-5
/
+10
*
Fix a NULL dereference in GENERAL_NAME_cmp()
libressl-v3.2.3
tb
2020-12-08
1
-6
/
+46
*
Ensure leaf is set up on X509_STORE_CTX before verification.
jsing
2020-09-26
1
-9
/
+7
*
jumping into the x509 fray with a bunch of whitespace repair
deraadt
2020-09-26
1
-6
/
+6
*
Ensure chain is set on the X509_STORE_CTX before triggering callback.
jsing
2020-09-23
1
-12
/
+39
*
Fix some line wrapping and other whitespace issues.
tb
2020-09-21
1
-45
/
+34
*
Move freeing and zeroing up to right after the while loop.
tb
2020-09-21
1
-5
/
+5
*
Avoid memleak caused by shadowing
tb
2020-09-20
1
-2
/
+5
*
KNF/whitespace nits
tb
2020-09-20
2
-6
/
+7
*
Correct a 1 byte read overflow in x509_contraints_uri and add
beck
2020-09-20
1
-4
/
+9
*
Fix a memory leak in x509_constraints_extract_names
tb
2020-09-20
1
-6
/
+6
*
remove superfluous NULL check
beck
2020-09-19
1
-2
/
+2
*
Fix potential overflow in CN subject line parsing, thanks to
beck
2020-09-18
1
-4
/
+5
*
revert my putting this on a diet. sadly the NAME_CONSTRAINTS_check
beck
2020-09-16
1
-7
/
+1
*
noop NAME_CONSTRAINTS_check stub
inoguchi
2020-09-16
1
-4
/
+5
*
Make check in x509_verify_ctx_set_max_signatures() consistent with others.
jsing
2020-09-16
1
-4
/
+2
*
Dedup code in x509_verify_ctx_new_from_xsc().
jsing
2020-09-16
1
-14
/
+7
*
set error_depth and current_cert to make more legacy callbacks that don't check
beck
2020-09-15
1
-1
/
+3
*
Deduplicate the time validation code between the legacy and new
beck
2020-09-15
3
-27
/
+8
*
ifdef out code that is no longer used in here. once we are certain
beck
2020-09-15
1
-2
/
+5
*
Set error if we are given an NULL ctx in x509_verify, and set error
beck
2020-09-14
1
-5
/
+3
*
nuke a stray space
tb
2020-09-14
1
-2
/
+2
*
Fix potential leak when tmpext fails to be added to
beck
2020-09-14
1
-2
/
+6
*
remove unneeded variable "type".
beck
2020-09-14
1
-6
/
+5
*
Don't leak names on success
beck
2020-09-14
1
-1
/
+2
*
remove unneded variable "time1"
beck
2020-09-14
1
-6
/
+6
*
remove unneded variable "time"
beck
2020-09-14
1
-3
/
+2
*
fix bug introduced on review where refactor made it possible to
beck
2020-09-14
1
-2
/
+2
*
re-enable new x509 chain verifier as the default
beck
2020-09-14
1
-3
/
+1
*
Correctly fix double free introduced on review.
beck
2020-09-14
2
-3
/
+3
*
Fix double free - review moved the pop_free of roots to x509_verify_ctx_free
beck
2020-09-14
1
-2
/
+1
*
revert previous, need to fix a problem
beck
2020-09-14
1
-1
/
+3
*
Enable the use of the new x509 chain validator by default.
beck
2020-09-14
1
-3
/
+1
*
Add new x509 certificate chain validator in x509_verify.c
beck
2020-09-13
9
-57
/
+1188
*
Change over to use the new x509 name constraints verification.
beck
2020-09-12
1
-28
/
+7
*
Add x509_constraints.c - a new implementation of x509 name constraints, with
beck
2020-09-11
2
-0
/
+1270
*
Add issuer cache, to be used by upcoming changes to validation code.
beck
2020-09-11
2
-0
/
+214
*
Remove remaining error *_str_functs[]
jsing
2020-06-05
1
-66
/
+2
*
One error file per directory is plenty.
jsing
2020-06-05
2
-227
/
+155
*
Collapse the x509v3 directory into x509.
jsing
2020-06-04
37
-0
/
+13636
*
When building a chain look for non-expired certificates first.
jsing
2020-05-31
1
-8
/
+29
*
add stdlib.h for reallocarray
bcook
2019-05-23
1
-1
/
+2
*
Fix a number of ASN1_INTEGER vs ASN1_STRING mixups coming from the
tb
2019-03-13
1
-2
/
+2
*
Typo in comment.
tb
2019-03-06
1
-2
/
+2
*
Add const to EVP_PKCS82PKEY().
tb
2018-08-24
1
-2
/
+2
*
After removing support for broken PKCS#8 formats (it was high time),
tb
2018-08-24
1
-8
/
+5
*
Remove EVP_PKEY2PKCS8_broken() and PKCS8_set_broken()
tb
2018-08-24
1
-13
/
+8
*
Provide X509_get0_serialNumber()
tb
2018-08-24
2
-2
/
+9
[next]