summaryrefslogtreecommitdiff
path: root/src/lib/libssl/ssl_sigalgs.c (follow)
Commit message (Collapse)AuthorAgeFilesLines
* Unbreak legacy ciphers for prior to 1.1 by setting having a legacybeck2018-11-161-3/+12
| | | | | sigalg for MD5_SHA1 and using it as the non sigalgs default ok jsing@
* In TLS1.2 we use evp_sha1 if we fall back this far, not evp_md5_sha1 as in 1.1beck2018-11-141-2/+2
| | | | Makes connections to outlook.office365.com work
* Temporary workaround for breakage seen in www.videolan.org with curve mismatchbeck2018-11-131-3/+4
|
* Fix pkey_ok to be less strange, and add cuve checks required for the EC onesbeck2018-11-131-9/+26
| | | | ok tb@
* Add check function to verify that pkey is usable with a sigalg.beck2018-11-111-1/+17
| | | | | Include check for appropriate RSA key size when used with PSS. ok tb@
* Convert signatures and verifcation to use the EVP_DigestXXX apibeck2018-11-111-3/+1
| | | | | | to allow for adding PSS, Nuke the now unneejded guard around the PSS algorithms in the sigalgs table ok jsing@ tb@
* Remove dead codebeck2018-11-101-14/+1
| | | | ok jsing@
* Stop keeping track of sigalgs by guessing it from digest and pkey,beck2018-11-101-16/+5
| | | | | | just keep the sigalg around so we can remember what we actually decided to use. ok jsing@
* Ensure we only choose sigalgs from our prefernce list, not the whole listbeck2018-11-091-4/+11
| | | | ok jsing@
* Add the ability to have a separate priority list for sigalgs.beck2018-11-091-6/+34
| | | | | Add a priority list for tls 1.2 ok jsing@
* Reimplement the sigalgs processing code into a new implementationbeck2018-11-091-0/+218
that will be usable with TLS 1.3 with less eye bleed. ok jsing@ tb@