summaryrefslogtreecommitdiff
path: root/src/lib/libssl/s3_cbc.c (follow)
Commit message (Collapse)AuthorAgeFilesLines
* This commit was manufactured by cvs2git to create tag 'OPENBSD_5_8_BASE'.OPENBSD_5_8_BASEcvs2svn2015-08-021-686/+0
|
* Remove workaround for TLS padding bug from SSLeay days.doug2015-07-171-19/+1
| | | | | | | | | OpenSSL doesn't remember which clients were impacted and the functionality has been broken in their stable releases for 2 years. Based on OpenSSL commit a8e4ac6a2fe67c19672ecf0c6aeafa15801ce3a5. ok jsing@
* Add error handling for EVP_DigestInit_ex().doug2014-12-151-5/+11
| | | | | | | | | | | | | A few EVP_DigestInit_ex() calls were left alone since reporting an error would change the public API. Changed internal ssl3_cbc_digest_record() to return a value due to the above change. It will also now set md_out_size=0 on failure. This is based on part of BoringSSL's commit to fix malloc crashes: https://boringssl.googlesource.com/boringssl/+/69a01608f33ab6fe2c3485d94aef1fe9eacf5364 ok miod@
* decompress libssl. ok beck jsingtedu2014-07-101-2/+3
|
* tags as requested by miod and teduderaadt2014-06-121-1/+1
|
* Add a define for the SSLv3 sequence size and use it, rather than sprinklingjsing2014-06-081-2/+2
| | | | | | magic numbers around. ok deraadt@
* Make use of SSL_IS_DTLS, SSL_USE_EXPLICIT_IV, SSL_USE_SIGALGS andjsing2014-05-301-1/+2
| | | | | | SSL_USE_TLS1_2_CIPHERS. Largely based on OpenSSL head.
* quick pass at removing ability to disable sha256 and sha512. ok miodtedu2014-04-171-12/+0
|
* remove FIPS mode support. people who require FIPS can buy something thattedu2014-04-151-51/+0
| | | | | meets their needs, but dumping it in here only penalizes the rest of us. ok miod
* First pass at applying KNF to the OpenSSL code, which almost makes itjsing2014-04-141-238/+207
| | | | | readable. This pass is whitespace only and can readily be verified using tr and md5.
* cherry pick bugfixes for http://www.openssl.org/news/secadv_20130205.txtmarkus2013-02-141-0/+790
from the openssl git (changes between openssl 1.0.1c and 1.0.1d). ok djm@