summaryrefslogtreecommitdiff
path: root/src/lib/libssl (follow)
Commit message (Collapse)AuthorAgeFilesLines
...
* | | | * Fix another instance of directly writing to the target with a utilityschwarze2014-03-181-4/+6
| | | | | | | | | | | | | | | | | | | | | | | | | | | | that might fail. * Keep the build log clean. * Make sure syntax checks run again when doing: make clean; make ok espie@
* | | | prevent failed command from generating bogus fileespie2014-03-181-2/+2
| | | | | | | | | | | | | | | | okay guenther@
* | | | prepare manpages for new perl.espie2014-03-1818-40/+46
| | | | | | | | | | | | | | | | | | | | | | | | | | | | Note that I missed two of these in the diff shown initially, thx to the atrocious Makefile rule... okay millert@, sthen@, basically
* | | | SECURITY fixes backported from openssl-1.0.1f. ok mikeb@jca2014-02-2712-26/+82
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | CVE-2013-4353 NULL pointer dereference with crafted Next Protocol Negotiation record in TLS handshake. Upstream: 197e0ea CVE-2013-6449 Fix crash with crafted traffic from a TLS 1.2 client. Upstream: ca98926, 0294b2b CVE-2013-6450 Fix DTLS retransmission from previous session. Upstream: 3462896
* | | | Install a bunch more of OpenSSL manpages. ok deraadt@jca2013-12-231-1/+49
| | | |
* | | | Reliability fix for SHA384 SSL/TLS ciphers on strict alignmentjca2013-12-191-1/+8
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | architectures. ok miod@ djm@ Upstream patch: commit cdd1acd788020d2c525331da1712ada778f1373c Author: Andy Polyakov <appro@openssl.org> Date: Wed Dec 18 21:27:35 2013 +0100
* | | | Switch time_t, ino_t, clock_t, and struct kevent's ident and dataguenther2013-08-133-3/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | members to 64bit types. Assign new syscall numbers for (almost all) the syscalls that involve the affected types, including anything with time_t, timeval, itimerval, timespec, rusage, dirent, stat, or kevent arguments. Add a d_off member to struct dirent and replace getdirentries() with getdents(), thus immensely simplifying and accelerating telldir/seekdir. Build perl with -DBIG_TIME. Bump the major on every single base library: the compat bits included here are only good enough to make the transition; the T32 compat option will be burned as soon as we've reached the new world are are happy with the snapshots for all architectures. DANGER: ABI incompatibility. Updating to this kernel requires extra work or you won't be able to login: install a snapshot instead. Much assistance in fixing userland issues from deraadt@ and tedu@ and build assistance from todd@ and otto@
* | | | Remove no longer needed vax CFLAGS workarounds.miod2013-07-131-13/+1
| | | |
* | | | VAX ELF userland bits. Consists mostly of register prefix additions.miod2013-07-051-151/+151
| | | |
* | | | Switch to using unhyphenated VIA padlock mnemonics. VIA abandoned thematthew2013-05-301-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | hyphen in their official programming guide sometime between 2003 and 2005, and Clang's integrated assembler does not support hyphenated mnemonics. ok jsg, deraadt
* | | | cherry pick bugfixes for http://www.openssl.org/news/secadv_20130205.txtmarkus2013-02-1425-515/+2348
| | | | | | | | | | | | | | | | | | | | from the openssl git (changes between openssl 1.0.1c and 1.0.1d). ok djm@
* | | | remove ACSS, crank libcrypto major; ok markus@ deraadt@djm2013-01-269-480/+4
| | | |
* | | | New CA root certificates, ok beck@.sthen2012-12-031-99/+1705
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | - additional cert's from GlobalSign. - additional cert's from VeriSign and replace existing ones with 'Signature Algorithm: md2WithRSAEncryption' with their currently distributed sha1WithRSAEncryption versions. - new CAs: AddTrust (root for most Comodo certificates also heavily used in academic networks), Comodo (most of their certs are rooted in AddTrust but TERENA use the Comodo AAA Certificate Services root for some things so add that separately), UserTrust Network/UTN (part of Comodo) and Starfield (part of Go Daddy).
* | | | Additional CA root certificates: GeoTrust/Equifax, Go Daddy, StartCom, thawte.sthen2012-12-011-0/+1187
| | | | | | | | | | | | | | | | ok beck@ william@ todd@
* | | | Regenerate the text information for all certificates with recent opensslsthen2012-11-301-439/+465
| | | | | | | | | | | | | | | | | | | | | | | | and include sha1 signatures for all certs (some were missing). No certificate changes, this is just for consistency. ok beck@
* | | | Remove retired Thawte/Verisign certificates.sthen2012-11-301-499/+0
| | | | | | | | | | | | | | | | | | | | | | | | Remove intermediate GoDaddy certificate, this file should just contain roots. ok beck@ phessler@
* | | | On amd64 OPENSSL_cpuid_setup and OPENSSL_ia32cap_P are now hidden so we don'tkettenis2012-10-314-9/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | have to go through the PLT/GOT to get at them anymore. In fact going through the GOT now fails since we no longer have a GOT entry for OPENSSL_ia32cap_P. Fixes the problem spotted by jasper@ and sthen@. Based on a diff from mikeb@ who did most of the actual work of tracking down the issue. ok millert@, mikeb@
* | | | Restore r1.10, lost during last update:miod2012-10-221-1/+1
| | | | | | | | | | | | | | | | Disable use of dladdr() on a.out arches, they do not provide it (yet);
* | | | Makefile and header changes for OpenSSL-1.0.1cdjm2012-10-1320-139/+361
| | | | | | | | | | | | | | | | major cranks
* | | | import files that CVS missed; sighdjm2012-10-135-0/+749
| | | |
* | | | resolve conflictsdjm2012-10-13309-4740/+23179
| | | |
* | | | This commit was generated by cvs2git to track changes on a CVS vendordjm2012-10-1328-554/+421
|\| | | | | | | | | | | branch.
| * | | import OpenSSL-1.0.1cdjm2012-10-13290-3994/+14133
| | | |
* | | | This commit was generated by cvs2git to track changes on a CVS vendordjm2012-10-13193-1354/+53656
|\ \ \ \ | | |/ / | |/| | branch.
| * | | import OpenSSL-1.0.1cdjm2012-10-13218-2281/+58716
| | | |
* | | | This commit was generated by cvs2git to track changes on a CVS vendordjm2012-10-139-18/+869
|\ \ \ \ | | |_|/ | |/| | branch.
| * | | import OpenSSL-1.0.1cdjm2012-10-1342-501/+5785
| | | |
* | | | When deciding whether we're PIC in a (generated) asm file, check for both PICpascal2012-08-211-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | and __PIC__ defines. Makes things easier for PIE. ok djm@
* | | | remove leftover NOLINT, WANTLINT, LINTFLAGS, LOBJ vars and lint targets.okan2012-08-022-4/+2
| | | | | | | | | | | | | | | | ok guenther@
* | | | Skip printing another SSLv2-only command in s_client's usage text.sthen2012-07-121-0/+2
| | | | | | | | | | | | | | | | jmc@ noticed this in the manpage while updating it, but it applies here too.
* | | | Disable SSLv2 in OpenSSL. No objections from djm.sthen2012-07-1119-7/+94
| | | | | | | | | | | | | | | | Brad, jasper and naddy helped with test builds, fixing ports, etc.
* | | | cherrypick fix for CVE-2012-2110: libcrypto ASN.1 parsing heap overflowdjm2012-04-193-14/+61
| | | | | | | | | | | | | | | | ok miod@ deraadt@
* | | | OpenSSL 1.0.0f: crank minordjm2012-01-053-3/+3
| | | |
* | | | OpenSSL 1.0.0f: mergedjm2012-01-0551-186/+526
| | | |
* | | | This commit was generated by cvs2git to track changes on a CVS vendordjm2012-01-052-8/+24
|\| | | | | | | | | | | branch.
| * | | OpenSSL 1.0.0f: import upstream sourcedjm2012-01-0516-28/+90
| | | |
* | | | This commit was generated by cvs2git to track changes on a CVS vendordjm2012-01-051-1/+1
|\ \ \ \ | | |_|/ | |/| | branch.
| * | | OpenSSL 1.0.0f: import upstream sourcedjm2012-01-0534-115/+358
| | | |
* | | | This commit was generated by cvs2git to track changes on a CVS vendordjm2012-01-057-17/+114
|\ \ \ \ | | |_|/ | |/| | branch.
| * | | OpenSSL 1.0.0f: import upstream sourcedjm2012-01-0511-69/+217
| | | |
* | | | crank major for openssl-1.0.0edjm2011-11-033-3/+3
| | | |
* | | | openssl-1.0.0e: resolve conflictsdjm2011-11-03180-1657/+3506
| | | |
* | | | This commit was generated by cvs2git to track changes on a CVS vendordjm2011-11-0318-131/+1470
|\ \ \ \ | | |/ / | |/| | branch.
| * | | import OpenSSL 1.0.0edjm2011-11-03166-1620/+4772
| | | |
* | | | This commit was generated by cvs2git to track changes on a CVS vendordjm2011-11-034-76/+117
|\ \ \ \ | | |_|/ | |/| | branch.
| * | | import OpenSSL 1.0.0edjm2011-11-0319-193/+284
| | | |
* | | | This commit was generated by cvs2git to track changes on a CVS vendordjm2011-11-0354-507/+1154
|\ \ \ \ | | |_|/ | |/| | branch.
| * | | import OpenSSL 1.0.0edjm2011-11-0371-595/+1304
| | | |
* | | | Add support for hppa64 based on the defaults for 64-bit HP-UX as found in thekettenis2011-08-031-0/+253
| | | | | | | | | | | | | | | | | | | | | | | | Configure script. ok deraadt@
* | | | - Replace digicert 2nd-level cert with the root which issued it.sthen2011-07-201-114/+247
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Allows https checkouts from github to work. - Add digicert's other root certs. Fingerprints carefully checked against those in the built-in roots supplied with Mozilla. ok dcoppa@ jcs@