summaryrefslogtreecommitdiff
path: root/src/lib/libssl (follow)
Commit message (Expand)AuthorAgeFilesLines
...
* Only reset TLS extension state when parsing client hello or server hello.jsing2020-05-101-5/+7
* Correct tlsext_ocsp_resplen check.jsing2020-05-101-2/+2
* Back out server side CCS sending. It breaks TLSv1.3 client communicationtb2020-05-093-34/+3
* Forcibly ensure that only PSS may be used with RSA in TLS 1.3.beck2020-05-091-2/+8
* Send dummy ChangeCipherSpec messages from the TLSv1.3 servertb2020-05-093-3/+34
* Send dummy ChangeCipherSpec messages from the TLSv1.3 client.jsing2020-05-094-6/+45
* Correct return value check to handle TLS13_IO_EOF case.jsing2020-05-091-2/+2
* Add a middlebox_compat flag and condition session ID randomisation on it.jsing2020-05-093-4/+7
* Add support for certificate status requests in TLS 1.3 clientbeck2020-05-094-12/+81
* Make the test for the legacy_compression_method vector in the ClientHellotb2020-05-091-12/+7
* Drop a redundant test. It's effectively doing the same test twicetb2020-05-091-3/+2
* On receiving an overlong session ID terminate with an illegal_parametertb2020-05-091-1/+6
* Add support for HelloRetryRequests in the TLSv1.3 server.jsing2020-05-092-10/+73
* crazy whitespace on one linetb2020-05-091-2/+2
* Pull the sending of alerts up into tls13_handshake_perform().jsing2020-05-091-14/+11
* Refactor tls13_server_hello_sent().jsing2020-05-091-30/+36
* On receiving a handshake or alert record with empty inner plaintext,tb2020-05-071-1/+11
* Accept two ChangeCipherSpec messages during a TLSv1.3 handshake.jsing2020-05-031-3/+3
* Add const to TLS1.3 internal vectorsinoguchi2020-05-022-14/+14
* tls13_record_layer internal functions to static in libsslinoguchi2020-04-291-4/+4
* tls13_handshake internal functions to static in libsslinoguchi2020-04-291-11/+12
* Move legacy stack interfacing functions into tls13_legacy.c.jsing2020-04-284-199/+206
* Rename tls13_client_synthetic_handshake_message() and move to tls13_lib.c.jsing2020-04-283-47/+48
* Shuffle some functions around.jsing2020-04-272-329/+328
* Switch to NEGOTIATED when using WITHOUT_HRR.jsing2020-04-251-4/+9
* Move unsupported, obsolete ciphers and deprecated aliases out ofschwarze2020-04-251-31/+29
* tweak the wording to make it clearer under which conditions exactlyschwarze2020-04-251-4/+4
* Improve TLSv1.3 state machine for HelloRetryRequest handling.jsing2020-04-225-66/+104
* Handle TLSv1.3 key shares other than X25519 on the server side.jsing2020-04-212-16/+34
* Consolidate TLSv1.3 constants.jsing2020-04-213-40/+47
* Provide TLSv1.3 cipher suite aliases to match the names used in RFC 8446.jsing2020-04-191-2/+25
* Fix wrapping/indentation.jsing2020-04-181-4/+3
* Expose the peer ephemeral public key used for TLSv1.3 key exchange.jsing2020-04-185-36/+79
* Tweak previous active cipher suite code.jsing2020-04-181-6/+5
* Allow more key share groups for TLSv1.3.jsing2020-04-181-21/+12
* Only include TLSv1.3 cipher suites if there are active cipher suites.jsing2020-04-171-2/+10
* Generate client key share using our preferred group.jsing2020-04-174-25/+37
* Update in several respects:schwarze2020-04-141-13/+11
* add the missing sentence "LibreSSL no longer provides any suchschwarze2020-04-141-2/+3
* Delete the three sentences listing the ciphers currently includedschwarze2020-04-141-15/+2
* Document the TLSv1.3 control word, update the description of theschwarze2020-04-111-4/+30
* Include TLSv1.3 cipher suites unless cipher string references TLSv1.3.jsing2020-04-091-6/+19
* Tidy line wrapping and remove an extra blank line.jsing2020-04-091-4/+3
* ssl_aes_is_accelerated() returns a boolean - treat it as such, rather thanjsing2020-04-091-2/+2
* Ensure legacy session ID is persistent during client TLS session.jsing2020-04-081-9/+14
* Send a zero-length session identifier if TLSv1.3 is not enabled.jsing2020-04-061-4/+7
* Void functions obviously do not return values; no need to elaborate.schwarze2020-03-305-31/+10
* Void functions obviously do not return values; no need to elaborate.schwarze2020-03-291-5/+2
* Consistently spell 'unsigned' as 'unsigned int', as style(9) seemstb2020-03-167-44/+45
* The RFC is clear (section 5.3) that sequence number should never wrap.tb2020-03-161-5/+12