Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | | | | unused files, not part of OpenSSL 0.9.7 | markus | 2002-09-03 | 38 | -9120/+0 | |
| | | | | ||||||
* | | | | do not modify input files, allows ro source builds; tested by fries@ | markus | 2002-08-30 | 1 | -6/+7 | |
| | | | | ||||||
* | | | | remove generated files and generated symlinks (in make clean) | markus | 2002-08-30 | 1 | -203/+0 | |
| | | | | ||||||
* | | | | Better fixes from openssl cvs; from markus@ | miod | 2002-08-05 | 1 | -3/+4 | |
| | | | | ||||||
* | | | | typo; from openssl cvs | markus | 2002-08-02 | 1 | -1/+1 | |
| | | | | ||||||
* | | | | sync with http://www.openssl.org/news/patch_20020730_0_9_7.txt | markus | 2002-07-30 | 2 | -9/+9 | |
| | | | | | | | | | | | | | | | | | | | | (adds fix for unused kerberos and engine code, and some more assertions, as well as a 64bit integer string fix for conf_mod.c) | |||||
* | | | | apply patches from OpenSSL Security Advisory [30 July 2002], | markus | 2002-07-30 | 4 | -6/+12 | |
| | | | | | | | | | | | | | | | | http://marc.theaimsgroup.com/?l=openssl-dev&m=102802395104110&w=2 | |||||
* | | | | remove #define crypt DES_crypt; ok deraadt@ | markus | 2002-07-19 | 1 | -4/+0 | |
| | | | | ||||||
* | | | | correct memset arguments; from Moritz Jodeit <moritz@jodeit.org> via PR/2822. | fgsch | 2002-07-16 | 1 | -2/+2 | |
| | | | | ||||||
* | | | | enviroment -> environment | jufi | 2002-07-07 | 1 | -2/+2 | |
| | | | | ||||||
* | | | | remove support for RC4 via /dev/crypto, suggested by Niels; ok provos@ | markus | 2002-06-20 | 1 | -18/+0 | |
| | | | | ||||||
* | | | | do not syslog from libraries! | deraadt | 2002-06-19 | 1 | -10/+1 | |
| | | | | ||||||
* | | | | KNF, -Wall, and other cleanups. still does not failover 100% correctly | deraadt | 2002-06-19 | 1 | -22/+52 | |
| | | | | | | | | | | | | | | | | for operations when /dev/crypto is missing, for instance in chroot | |||||
* | | | | stupid stupid bug ja ja ja ja | deraadt | 2002-06-19 | 1 | -1/+1 | |
| | | | | ||||||
* | | | | unbreak sshd with privsep: open /dev/crypto, keep fd, and call | markus | 2002-06-18 | 1 | -5/+20 | |
| | | | | | | | | | | | | | | | | CRIOGET per EVP_Init(); ok niklas@, miod@ | |||||
* | | | | per-evp state is now sizeof(struct dev_crypto_state) instead sizeof(struct ↵ | markus | 2002-06-18 | 1 | -6/+6 | |
| | | | | | | | | | | | | | | | | session_op) | |||||
* | | | | keep a FD per EVP_init, use a global FD for all asym operations; | markus | 2002-06-13 | 1 | -83/+85 | |
| | | | | | | | | | | | | | | | | ok beck@ | |||||
* | | | | KNF | deraadt | 2002-06-11 | 1 | -19/+16 | |
| | | | | ||||||
* | | | | add "dsa_dsa_mod_exp" - This mimics the software dsa_mod_exp funtion | beck | 2002-06-11 | 1 | -3/+37 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | using two mod_exp operations - otherwise we use BN_mod_exp2 entirely in software, which makes dsa verifications glacially slow while signatures, (which use mod_exp) are fast. This lets cards that can only do bn_mod_exp decently offload most of dsa. | |||||
* | | | | Make DSA work now... at least for things that can do bn_mod_exp. | beck | 2002-06-11 | 1 | -7/+4 | |
| | | | | ||||||
* | | | | Make asymmetric crypto work in userland | beck | 2002-06-11 | 1 | -36/+114 | |
| | | | | | | | | | | | | | | | | | | | | this will only be used if you both have a card that supports it with a working driver and you set sysctl kern.userasymcrypto=1 | |||||
* | | | | Pass the right arguments for RSA, DSA, and modexp operations. Fix the | angelos | 2002-06-09 | 1 | -30/+37 | |
| | | | | | | | | | | | | | | | | translation between the crypto framework's format and the BN structure. | |||||
* | | | | After much horrible and painful slogging through asn1 code, | beck | 2002-06-08 | 1 | -0/+1 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | this fixes the source of connection problems with ssl/tls connections between sparc64 and other things. The punchline, we just found a bug in floating point emulation on sparc64 when this script produces off-by-one output on sparc64. This fix is annoyingly easy for the effort expended. | |||||
* | | | | Merge OpenSSL 0.9.7-stable-20020605, | beck | 2002-06-07 | 38 | -2450/+366 | |
| | | | | | | | | | | | | | | | | correctly autogenerate obj_mac.h | |||||
* | | | | sig_atomic_t type must also be volatile | deraadt | 2002-06-03 | 1 | -1/+1 | |
| | | | | ||||||
* | | | | do not assume scripts are executable | deraadt | 2002-05-25 | 6 | -6/+6 | |
| | | | | ||||||
* | | | | Merge openssl-0.9.7-stable-SNAP-20020519 | beck | 2002-05-21 | 11 | -36/+69 | |
| | | | | ||||||
* | | | | add aes/bf/cast; ok deraadt@ | markus | 2002-05-16 | 1 | -2/+50 | |
| | | | | ||||||
* | | | | use hw_cryptodev | deraadt | 2002-05-16 | 1 | -24/+24 | |
| | | | | ||||||
* | | | | Damn my rush to make it build again. | beck | 2002-05-15 | 1 | -2842/+0 | |
| | | | | ||||||
* | | | | OpenSSL 0.9.7 stable 2002 05 08 merge | beck | 2002-05-15 | 632 | -17104/+65035 | |
| | | | | ||||||
* | | | | fix to match documented behaviour. RAND_file_name must return a pointer to | beck | 2001-12-20 | 1 | -9/+13 | |
| | | | | | | | | | | | | | | | | buf, not something else. | |||||
* | | | | merge openssl 0.9.6b-engine | beck | 2001-08-01 | 19 | -256/+390 | |
| | | | | | | | | | | | | | | | | | | | | Note that this is a maintenence release, API's appear *not* to have changed. As such, I have only increased the minor number on these libraries | |||||
* | | | | http://www.openssl.org/news/secadv_prng.txt; ok beck@ | markus | 2001-08-01 | 1 | -8/+17 | |
| | | | | ||||||
* | | | | openssl-engine-0.9.6a merge | beck | 2001-06-22 | 121 | -443/+958 | |
| | | | | ||||||
* | | | | typo | deraadt | 2001-06-16 | 1 | -1/+0 | |
| | | | | ||||||
* | | | | import DSA changes from 0.9.6a (Bleichenbacher attack), ok provos@/deraadt@ | markus | 2001-04-23 | 3 | -21/+66 | |
| | | | | ||||||
* | | | | CRT and DH+SSL fix from 0.9.6a, ok provos@/deraadt@ | markus | 2001-04-22 | 1 | -1/+11 | |
| | | | | ||||||
* | | | | Use correct interpreters | niklas | 2001-01-26 | 1 | -2/+2 | |
| | | | | ||||||
* | | | | make sure s always has enough from for trailing \0. even though strlcpy will | beck | 2001-01-12 | 1 | -1/+1 | |
| | | | | | | | | | | | | | | | | truncate, thanks to itojun@ | |||||
* | | | | do not honour environment variables if issetugid, and even more strongly ↵ | deraadt | 2001-01-02 | 2 | -18/+19 | |
| | | | | | | | | | | | | | | | | support the random device | |||||
* | | | | fix util script runs to not assume they are executable. | beck | 2000-12-18 | 3 | -3/+3 | |
| | | | | ||||||
* | | | | openssl-engine0.9.6 merge | beck | 2000-12-15 | 89 | -0/+0 | |
| | | | | | | | | | | | | | | | | Again, be sure to whack an old /usr/obj/lib/libssl if you are doing builds | |||||
* | | | | openssl-engine-0.9.6 merge | beck | 2000-12-15 | 427 | -12838/+34187 | |
| | | | | ||||||
* | | | | Fix typo; claudio@core-sdi.com. | fgsch | 2000-10-10 | 1 | -1/+1 | |
| | | | | ||||||
* | | | | $HOME paranoia: never use getenv("HOME") w/o checking for NULL and non-zero | millert | 2000-08-02 | 1 | -1/+1 | |
| | | | | ||||||
* | | | | use %s with fprintf | deraadt | 2000-07-07 | 1 | -1/+1 | |
| | | | | ||||||
* | | | | RSA goes in tree for next our next release, as it will be after | beck | 2000-06-15 | 2 | -33/+322 | |
| | | | | | | | | | | | | | | | | | | | | | | | | Sept 21. Note: This means you shouldn't really be running -current for anything in the United States. Either wait for Sept 21, or for the next release, or move to the free world :) | |||||
* | | | | Fix strcpy/strcat abuse and fix stupid behaviour of the default | beck | 2000-04-16 | 1 | -7/+24 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | RAND_file_name - changed so that it stats the filename it returns before returing it. If the file won't stat, return DEVRANDOM (for us /dev/arandom) instead, thus making the default behaviour moderately intelligent. | |||||
* | | | | Fix randfile so it doesn't attempt to chmod and write entropy back to | beck | 2000-04-16 | 1 | -1/+14 | |
| | | | | | | | | | | | | | | | | | | | | | | | | devices. This caused people's /dev/arandom's to be permitted 600, which causes rsa to fail to get random data, which results in all kinds of fun with ssh :) |