Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | | stupid stupid bug ja ja ja ja | deraadt | 2002-06-19 | 1 | -1/+1 | |
| | | ||||||
* | | unbreak sshd with privsep: open /dev/crypto, keep fd, and call | markus | 2002-06-18 | 1 | -5/+20 | |
| | | | | | | | | CRIOGET per EVP_Init(); ok niklas@, miod@ | |||||
* | | per-evp state is now sizeof(struct dev_crypto_state) instead sizeof(struct ↵ | markus | 2002-06-18 | 1 | -6/+6 | |
| | | | | | | | | session_op) | |||||
* | | keep a FD per EVP_init, use a global FD for all asym operations; | markus | 2002-06-13 | 1 | -83/+85 | |
| | | | | | | | | ok beck@ | |||||
* | | KNF | deraadt | 2002-06-11 | 1 | -19/+16 | |
| | | ||||||
* | | add "dsa_dsa_mod_exp" - This mimics the software dsa_mod_exp funtion | beck | 2002-06-11 | 1 | -3/+37 | |
| | | | | | | | | | | | | | | using two mod_exp operations - otherwise we use BN_mod_exp2 entirely in software, which makes dsa verifications glacially slow while signatures, (which use mod_exp) are fast. This lets cards that can only do bn_mod_exp decently offload most of dsa. | |||||
* | | Make DSA work now... at least for things that can do bn_mod_exp. | beck | 2002-06-11 | 1 | -7/+4 | |
| | | ||||||
* | | Make asymmetric crypto work in userland | beck | 2002-06-11 | 1 | -36/+114 | |
| | | | | | | | | | | this will only be used if you both have a card that supports it with a working driver and you set sysctl kern.userasymcrypto=1 | |||||
* | | Pass the right arguments for RSA, DSA, and modexp operations. Fix the | angelos | 2002-06-09 | 1 | -30/+37 | |
| | | | | | | | | translation between the crypto framework's format and the BN structure. | |||||
* | | After much horrible and painful slogging through asn1 code, | beck | 2002-06-08 | 1 | -0/+1 | |
| | | | | | | | | | | | | | | | | | | | | this fixes the source of connection problems with ssl/tls connections between sparc64 and other things. The punchline, we just found a bug in floating point emulation on sparc64 when this script produces off-by-one output on sparc64. This fix is annoyingly easy for the effort expended. | |||||
* | | do not propose IDEA cipher on SSL connection. tested by beck | itojun | 2002-06-07 | 5 | -0/+18 | |
| | | | | | | | | noticed by Sverre Froyen <sverre@viewmark.com> | |||||
* | | typo - I am a luser and a moron. | beck | 2002-06-07 | 1 | -2/+2 | |
| | | ||||||
* | | Merge OpenSSL 0.9.7-stable-20020605, | beck | 2002-06-07 | 62 | -2554/+710 | |
| | | | | | | | | correctly autogenerate obj_mac.h | |||||
* | | sig_atomic_t type must also be volatile | deraadt | 2002-06-03 | 1 | -1/+1 | |
| | | ||||||
* | | we do not need this to be Makefile.bsd-wrapper | deraadt | 2002-06-01 | 2 | -979/+976 | |
| | | ||||||
* | | do not assume scripts are executable | deraadt | 2002-05-25 | 6 | -6/+6 | |
| | | ||||||
* | | Merge openssl-0.9.7-stable-SNAP-20020519 | beck | 2002-05-21 | 25 | -199/+141 | |
| | | ||||||
* | | clean MLINK tree | deraadt | 2002-05-16 | 1 | -249/+338 | |
| | | ||||||
* | | add aes/bf/cast; ok deraadt@ | markus | 2002-05-16 | 1 | -2/+50 | |
| | | ||||||
* | | use hw_cryptodev | deraadt | 2002-05-16 | 1 | -24/+24 | |
| | | ||||||
* | | missed a few more | deraadt | 2002-05-16 | 1 | -59/+161 | |
| | | ||||||
* | | handle some more pods (there are still missing ones I bet) | deraadt | 2002-05-16 | 1 | -34/+80 | |
| | | ||||||
* | | Damn my rush to make it build again. | beck | 2002-05-15 | 1 | -2842/+0 | |
| | | ||||||
* | | order better | deraadt | 2002-05-15 | 1 | -3/+2 | |
| | | ||||||
* | | Dammit. I'm an idiot. | beck | 2002-05-15 | 1 | -2/+2 | |
| | | ||||||
* | | god these guys have low quality control | deraadt | 2002-05-15 | 1 | -1/+1 | |
| | | ||||||
* | | OpenSSL 0.9.7 stable 2002 05 08 merge | beck | 2002-05-15 | 948 | -23738/+101469 | |
| | | ||||||
* | | OpenSSL 0.9.7 | beck | 2002-05-15 | 6 | -81/+122 | |
| | | ||||||
* | | Vax O1 workaround no longer needed. | hugh | 2002-02-23 | 1 | -2/+1 | |
| | | ||||||
* | | Remove references to nonexistent man pages. Ok theo, millert. | kjell | 2002-02-12 | 1 | -2/+1 | |
| | | ||||||
* | | but... on vax... des_enc.c requires -O1 | deraadt | 2002-02-10 | 1 | -1/+2 | |
| | | ||||||
* | | Special case a_strnid.c on vax. | hugh | 2002-01-21 | 1 | -1/+5 | |
| | | ||||||
* | | fix to match documented behaviour. RAND_file_name must return a pointer to | beck | 2001-12-20 | 1 | -9/+13 | |
| | | | | | | | | buf, not something else. | |||||
* | | FQDN subjectAltName in certs, used in isakmpd(8) examples. beck@ ok. | ho | 2001-12-11 | 1 | -0/+7 | |
| | | ||||||
* | | Missing ssl manpages and mlinks; beck@ ok. | fgsch | 2001-11-06 | 1 | -4/+129 | |
| | | ||||||
* | | understand sparc64 | deraadt | 2001-09-18 | 2 | -26/+12 | |
| | | ||||||
* | | merge openssl 0.9.6b-engine | beck | 2001-08-01 | 62 | -341/+1030 | |
| | | | | | | | | | | Note that this is a maintenence release, API's appear *not* to have changed. As such, I have only increased the minor number on these libraries | |||||
* | | http://www.openssl.org/news/secadv_prng.txt; ok beck@ | markus | 2001-08-01 | 1 | -8/+17 | |
| | | ||||||
* | | more MLINK | deraadt | 2001-07-31 | 1 | -3/+13 | |
| | | ||||||
* | | Add missing MLINKS for various .3 man pages | krw | 2001-07-31 | 1 | -1/+16 | |
| | | ||||||
* | | more Xr completions | deraadt | 2001-07-31 | 1 | -4/+6 | |
| | | ||||||
* | | openssl-engine-0.9.6a merge | beck | 2001-06-22 | 250 | -1151/+5441 | |
| | | ||||||
* | | typo | deraadt | 2001-06-16 | 1 | -1/+0 | |
| | | ||||||
* | | crank crypto lib version, just in case | deraadt | 2001-04-23 | 1 | -1/+1 | |
| | | ||||||
* | | crank ssl lib version, just in case | deraadt | 2001-04-23 | 2 | -2/+2 | |
| | | ||||||
* | | import DSA changes from 0.9.6a (Bleichenbacher attack), ok provos@/deraadt@ | markus | 2001-04-23 | 3 | -21/+66 | |
| | | ||||||
* | | CRT and DH+SSL fix from 0.9.6a, ok provos@/deraadt@ | markus | 2001-04-22 | 3 | -1/+13 | |
| | | ||||||
* | | Add an x509v3.cnf in /etc/ssl so that creating certificate authorities | beck | 2001-04-17 | 2 | -2/+23 | |
| | | | | | | | | | | form isakmpd works. From Tim Newsham <newsham@lava.net> ok provos@ | |||||
* | | Crank major number. openssl on m68k is now compiled in 32 bit mode instead | deraadt | 2001-03-10 | 3 | -3/+3 | |
| | | | | | | | | | | of 64 bit mode. This makes ssh -2 run about 10x faster, because the 64 bit mul instructions no longer need emulation. | |||||
* | | minor irrelevant oops | deraadt | 2001-03-09 | 1 | -2/+2 | |
| | |