summaryrefslogtreecommitdiff
path: root/src/lib/libssl (follow)
Commit message (Collapse)AuthorAgeFilesLines
* MFC:OPENBSD_4_7djm2011-02-111-1/+7
| | | | | | | | | | | ---------------------------- revision 1.8 date: 2011/02/10 22:40:27; author: djm; state: Exp; lines: +7 -1 fix for CVE-2011-0014 "OCSP stapling vulnerability"; ok markus@ jasper@ miod@ AFAIK nothing in base uses this, though apache2 from ports may be affected. ----------------------------
* Security fix for CVE-2010-4180 as mentioned in ↵jasper2010-12-152-0/+8
| | | | | | | | | | | http://www.openssl.org/news/secadv_20101202.txt. where clients could modify the stored session cache ciphersuite and in some cases even downgrade the suite to weaker ones. This code is not enabled by default. ok djm@
* - Apply security fix for CVE-2010-3864.jasper2010-11-171-4/+14
| | | | ok djm@ deraadt@
* ecurity fix for CVE-2010-0740jasper2010-03-311-3/+4
| | | | | | | | | "In TLS connections, certain incorrectly formatted records can cause an OpenSSL client or server to crash due to a read attempt at NULL." http://openssl.org/news/secadv_20100324.txt ok djm@ sthen@
* This commit was manufactured by cvs2git to create branch 'OPENBSD_4_7'.cvs2svn2010-03-1095-38285/+0
|
* cherrypick patch from OpenSSL 0.9.8m:djm2010-03-044-8/+11
| | | | | *) Always check bn_wexpend() return values for failure. (CVE-2009-3245) [Martin Olsson, Neel Mehta]
* Use MACHINE_CPU instead of MACHINE_ARCH to pick the correct machine dependentmiod2010-02-031-6/+8
| | | | | | | files or directories when applicable. The inspiration and name of MACHINE_CPU come from NetBSD, although the way to provide it to Makefiles is completely different. ok kettenis@
* add a fix from OpenSSL CVS for SA38200.jasper2010-01-311-10/+7
| | | | | | | | "Modify compression code so it avoids using ex_data free functions. This stops applications that call CRYPTO_free_all_ex_data() prematurely leaking memory." looks ok to markus@
* new ipsca root.dlg2009-12-311-0/+108
|
* ipsca has expireddlg2009-12-311-51/+0
|
* plug a memory leak; found by parfait, ok djmderaadt2009-12-111-0/+2
|
* pull Ben Lauries blind prefix injection fix for CVE-2009-3555 frommarkus2009-11-1010-12/+40
| | | | openssl 0.9.8l; crank minor version; ok djm@ deraadt@; initially from jsg@
* s/Mhz/MHz/, MHz is a multiple of the SI unit hertz (whose symbol is Hz).sobrado2009-10-312-4/+4
|
* another cert that makes godaddy.com and launchpad.net (among others) happy.fgsch2009-10-121-0/+51
| | | | | found by Guillaume Protet (guillaume dot protet at mortheres dot info) while testing bzr update. deraadt@ ok
* remove expired certificates and add startcom ltd.fgsch2009-08-081-839/+148
| | | | beck@ ok
* pull string for memcpy; ok hshoexer@martynas2009-08-071-1/+2
|
* add ipsCA as a valid authority.dlg2009-05-251-0/+51
| | | | ok beck@
* resync libssl/libcrypto pod documentation - quite a few more pages anddjm2009-04-101-27/+242
| | | | MLINKS; feedback and ok jmc@
* crankus majorisdjm2009-04-063-3/+3
|
* resolve conflictsdjm2009-04-0652-176/+308
|
* This commit was generated by cvs2git to track changes on a CVS vendordjm2009-04-067-11/+18
|\ | | | | branch.
| * import of OpenSSL 0.9.8kdjm2009-04-0664-173/+330
| |
* | This commit was generated by cvs2git to track changes on a CVS vendordjm2009-04-0634-117/+18119
|\ \ | | | | | | branch.
| * | import of OpenSSL 0.9.8kdjm2009-04-0637-135/+18140
| | |
* | | missing ssl_sock_init() call in init_client() (used bydjm2009-01-301-3/+10
| | | | | | | | | | | | "openssl s_client"), fix an unlikely memory leak
* | | remove some gratuitous changes that do nothing other than inreasedjm2009-01-301-2/+1
| | | | | | | | | | | | the size of the diff against openssl mainline
* | | convert a strdup (into a purpose-allocated buffer) in libcrypto to adjm2009-01-121-2/+3
| | | | | | | | | | | | memcpy to avoid linker deprecation warnings; pointed out by dkrause@
* | | openssl-0.9.8j enables RFC3546 TLS extensions by default (e.g. the verydjm2009-01-0913-39/+0
| | | | | | | | | | | | | | | useful "server name indication" that allows multihomed TLS server), so remove the #define to disable it here
* | | adjust Makefile and crank major for openssl-0.9.8jdjm2009-01-0917-16/+56
| | |
* | | resolve conflictsdjm2009-01-09301-4804/+6983
| | |
* | | This commit was generated by cvs2git to track changes on a CVS vendordjm2009-01-094-9/+15
|\ \ \ | | | | | | | | branch.
| * | | import openssl-0.9.8jdjm2009-01-0923-96/+299
| | | |
* | | | This commit was generated by cvs2git to track changes on a CVS vendordjm2009-01-09127-3471/+17440
|\ \ \ \ | | |_|/ | |/| | branch.
| * | | import openssl-0.9.8jdjm2009-01-09439-7223/+24970
| | | |
* | | | This commit was generated by cvs2git to track changes on a CVS vendordjm2009-01-0943-95/+1439
|\ \ \ \ | | |_|/ | |/| | branch.
| * | | import openssl-0.9.8jdjm2009-01-0963-558/+2236
| | | |
| * | | This commit was manufactured by cvs2git to create branch 'OPENSSL'.cvs2svn2009-01-054-0/+2088
| | | |
* | | | Add a missing MLINK for BIO_new_socket.oga2009-01-081-1/+2
| | | | | | | | | | | | | | | | Noticed by blambert@. Ok jmc@.
* | | | update to openssl-0.9.8i; tested by several, especially krw@djm2009-01-05136-2902/+4741
| | | |
* | | | fix some cause of bad TEXTREL on i386 and amd64otto2008-09-195-14/+64
| | | | | | | | | | | | | | | | | | | | | | | | | | | | - global function calls in .init sections (diff makes them via PLT) - calls to global functions in aes-586.S (made static or local) - global variable accesses in rc4-x86_64.S (now made via GOT) from djm@large; ok miod@
* | | | use one call to arc4random_buf() instead of lots of arc4random()djm2008-09-101-8/+2
| | | |
* | | | turn off CAST assembler code (i.e. use C implementation) as it has baddjm2008-09-081-3/+3
| | | | | | | | | | | | | | | | | | | | relocations that lead to libcrypto.so being marked TEXTREL; linker-fu from drahn@ "go ahead" deraadt@
* | | | sparc now requires this bloated library to be -fPICderaadt2008-09-071-1/+5
| | | |
* | | | Fix merge botch.kettenis2008-09-071-3/+0
| | | | | | | | | | | | | | | | ok miod@
* | | | remove duplicate definition of OPENSSL_DSA_MAX_MODULUS_BITS spotteddjm2008-09-061-2/+0
| | | | | | | | | | | | | | | | by dtucker@
* | | | remerge local tweaks, update per-arch configuration headers, updatedjm2008-09-0626-98/+875
| | | | | | | | | | | | | | | | Makefiles, crank shlib_version
* | | | resolve conflictsdjm2008-09-06697-15897/+44294
| | | |
* | | | This commit was generated by cvs2git to track changes on a CVS vendordjm2008-09-0620-1/+7194
|\ \ \ \ | | |_|/ | |/| | branch.
| * | | import of OpenSSL 0.9.8hdjm2008-09-0662-1452/+13147
| | | |
| * | | import of openssl-0.9.7jdjm2006-06-2714-539/+650
| | | |