| Commit message (Expand) | Author | Age | Files | Lines |
* | Increment the epoch in the same place for both read and write. | jsing | 2020-08-11 | 1 | -3/+3 |
* | Use 0 instead of 0x00 for memset() calls. | jsing | 2020-08-11 | 2 | -8/+8 |
* | Use SSL3_SEQUENCE_SIZE for last_write_sequence[] rather than hardcoding. | jsing | 2020-08-11 | 1 | -2/+2 |
* | In SSL_new() just 'goto err' on allocation failure. | jsing | 2020-08-11 | 1 | -11/+6 |
* | Avoid passing -1 to freezero. | tb | 2020-08-10 | 1 | -9/+10 |
* | Fix some wrapping/indent. | jsing | 2020-08-09 | 1 | -4/+3 |
* | Add P-521 to the list of curves supported by default in the client. | jsing | 2020-08-09 | 1 | -5/+18 |
* | Use CBB more correctly when writing SSL3/DTLS records. | jsing | 2020-08-09 | 2 | -66/+92 |
* | Make the explicit IV length handling in DTLS the same as SSL3/TLS. | jsing | 2020-08-09 | 1 | -8/+13 |
* | Cleanup aead_ctx | inoguchi | 2020-08-04 | 1 | -1/+3 |
* | Only parse a client's status_request in the CH | tb | 2020-08-03 | 1 | -1/+4 |
* | Ensure clients only send a status_request in the CH | tb | 2020-08-03 | 1 | -3/+7 |
* | Correctly handle server requests for an OCSP response | tb | 2020-08-03 | 1 | -1/+12 |
* | Check the return value of tls1_enc() in the write path. | jsing | 2020-08-02 | 2 | -6/+6 |
* | Clean up/simplify more of the dtls1/ssl3 record writing code: | jsing | 2020-08-01 | 2 | -73/+34 |
* | Pull record version selection code up and pass it as an argument to | jsing | 2020-08-01 | 1 | -15/+15 |
* | Have ssl_init_wbio_buffer() push the buffering BIO rather than doing it | jsing | 2020-07-30 | 1 | -5/+2 |
* | Clean up and simplify some of the SSL3/DTLS1 record writing code. | jsing | 2020-07-30 | 2 | -76/+72 |
* | Add minimal info callback support for TLSv1.3 | tb | 2020-07-30 | 3 | -3/+32 |
* | Handle SSL_MODE_AUTO_RETRY being changed during a TLSv1.3 session. | jsing | 2020-07-25 | 1 | -1/+4 |
* | Dedup the use legacy stack code. | jsing | 2020-07-14 | 1 | -56/+25 |
* | Revert the TLSv1.3 version switching fix/hack. | jsing | 2020-07-14 | 1 | -10/+1 |
* | Remove some unnecessary function pointers from SSL_METHOD_INTERNAL. | jsing | 2020-07-07 | 5 | -64/+17 |
* | Enable TLSv1.3 for the generic TLS_method(). | jsing | 2020-07-07 | 2 | -5/+52 |
* | zap trailing whitespace on one line | tb | 2020-07-03 | 1 | -2/+2 |
* | Make the message type available to the extension functions | tb | 2020-07-03 | 2 | -167/+181 |
* | Improve argument order for the internal tlsext API | tb | 2020-07-03 | 8 | -39/+39 |
* | Switch the order of the two tests in tls13_client_hello_required_extensions | tb | 2020-06-25 | 1 | -9/+9 |
* | Make tls13_legacy_shutdown() match ssl3_shutdown() semantics. | jsing | 2020-06-24 | 1 | -21/+22 |
* | Enforce restrictions for ClientHello extensions | tb | 2020-06-24 | 1 | -1/+44 |
* | We inherited the constant time CBC padding removal from BoringSSL, but | tb | 2020-06-19 | 1 | -4/+4 |
* | The check_includes step is incorrect dependency management model for | deraadt | 2020-06-09 | 1 | -11/+1 |
* | Implement a rolling hash of the ClientHello message, Enforce RFC 8446 | beck | 2020-06-06 | 6 | -7/+179 |
* | Use IANA allocated GOST ClientCertificateTypes. | jsing | 2020-06-05 | 3 | -9/+15 |
* | Stop sending GOST R 34.10-94 as a CertificateType. | jsing | 2020-06-05 | 1 | -3/+1 |
* | Handle GOST in ssl_cert_dup(). | jsing | 2020-06-05 | 1 | -1/+5 |
* | Enable GOST_SIG_FORMAT_RS_LE when verifying certificate signatures. | jsing | 2020-06-05 | 2 | -2/+15 |
* | Align tls13_server_select_certificate() with | tb | 2020-06-04 | 1 | -3/+7 |
* | Improve client certificate selection for TLSv1.3 | tb | 2020-06-04 | 1 | -16/+80 |
* | mention that TLS_method(3) also supports TLSv1.3; | schwarze | 2020-06-04 | 1 | -3/+3 |
* | Remove const modifier in return type of tls13_handshake_active_state() | tb | 2020-06-02 | 1 | -3/+3 |
* | distracting whitespace | tb | 2020-06-02 | 1 | -5/+5 |
* | Split the handling of post handshake handshake messages into its | tb | 2020-06-01 | 1 | -55/+44 |
* | Send an illegal_parameter alert if a client sends us invalid DH key | tb | 2020-06-01 | 1 | -3/+15 |
* | Add a mechanism to set an alert in those parts of the read half of | tb | 2020-06-01 | 1 | -3/+21 |
* | Replace ssl_max_server_version() with ssl_downgrade_max_version() | jsing | 2020-05-31 | 3 | -30/+6 |
* | Correct downgrade sentinels when a version pinned method is in use. | jsing | 2020-05-31 | 4 | -7/+40 |
* | Improve server certificate selection for TLSv1.3. | jsing | 2020-05-29 | 2 | -23/+94 |
* | Handle the case where we receive a valid 0 byte application data record. | jsing | 2020-05-29 | 1 | -1/+10 |
* | Wire up the servername callback in the TLSv1.3 server. | jsing | 2020-05-29 | 3 | -3/+45 |