Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | | | lint clean (and don't mixup signed/unsigned). from martin husemann | itojun | 2002-07-01 | 1 | -12/+12 | |
| | | | ||||||
* | | | make more pedantic check on strtoul. from deraadt, sync w/kame | itojun | 2002-07-01 | 1 | -8/+12 | |
| | | | ||||||
* | | | correct port range check. from deraadt. sync w/kame. bind-bugs have ↵ | itojun | 2002-06-29 | 1 | -2/+3 | |
| | | | | | | | | | | | | already notified. | |||||
* | | | Replace strtou?q() with the more standard strtou?ll(), using weak | millert | 2002-06-29 | 5 | -42/+108 | |
| | | | | | | | | | | | | aliases to fake up strtou?q(). espie@ OK. | |||||
* | | | %d -> %u. mostly in #ifdef DEBUG. | itojun | 2002-06-27 | 5 | -34/+34 | |
| | | | ||||||
* | | | %d/%u mixup (in #ifdef DEBUG) | itojun | 2002-06-27 | 2 | -5/+5 | |
| | | | ||||||
* | | | ntohs() returns unsigned value | itojun | 2002-06-27 | 1 | -2/+2 | |
| | | | ||||||
* | | | correct bad practice in the code - it uses two changing variables | itojun | 2002-06-26 | 2 | -26/+22 | |
| | | | | | | | | | | | | | | | | | | | | | to manage buffer (buf and buflen). we eliminate buflen and use fixed point (ep) as the ending pointer. this fix is NOT critical. | |||||
* | | | avoid remote buffer overrun on hostbuf[]. From: Joost Pol <joost@pine.nl> | itojun | 2002-06-26 | 2 | -43/+33 | |
| | | | | | | | | | | | | | | | | | | | | | | | | correct bad practice in the code - it uses two changing variables to manage buffer (buf and buflen). we eliminate buflen and use fixed point (ep) as the ending pointer. this fix is critical. | |||||
* | | | remove support for RC4 via /dev/crypto, suggested by Niels; ok provos@ | markus | 2002-06-20 | 2 | -36/+0 | |
| | | | ||||||
* | | | do not syslog from libraries! | deraadt | 2002-06-19 | 2 | -20/+2 | |
| | | | ||||||
* | | | KNF, -Wall, and other cleanups. still does not failover 100% correctly | deraadt | 2002-06-19 | 2 | -44/+104 | |
| | | | | | | | | | | | | for operations when /dev/crypto is missing, for instance in chroot | |||||
* | | | stupid stupid bug ja ja ja ja | deraadt | 2002-06-19 | 2 | -2/+2 | |
| | | | ||||||
* | | | unbreak sshd with privsep: open /dev/crypto, keep fd, and call | markus | 2002-06-18 | 2 | -10/+40 | |
| | | | | | | | | | | | | CRIOGET per EVP_Init(); ok niklas@, miod@ | |||||
* | | | per-evp state is now sizeof(struct dev_crypto_state) instead sizeof(struct ↵ | markus | 2002-06-18 | 2 | -12/+12 | |
| | | | | | | | | | | | | session_op) | |||||
* | | | keep a FD per EVP_init, use a global FD for all asym operations; | markus | 2002-06-13 | 2 | -166/+170 | |
| | | | | | | | | | | | | ok beck@ | |||||
* | | | KNF | deraadt | 2002-06-11 | 2 | -38/+32 | |
| | | | ||||||
* | | | add "dsa_dsa_mod_exp" - This mimics the software dsa_mod_exp funtion | beck | 2002-06-11 | 2 | -6/+74 | |
| | | | | | | | | | | | | | | | | | | | | | using two mod_exp operations - otherwise we use BN_mod_exp2 entirely in software, which makes dsa verifications glacially slow while signatures, (which use mod_exp) are fast. This lets cards that can only do bn_mod_exp decently offload most of dsa. | |||||
* | | | Make DSA work now... at least for things that can do bn_mod_exp. | beck | 2002-06-11 | 2 | -14/+8 | |
| | | | ||||||
* | | | Make asymmetric crypto work in userland | beck | 2002-06-11 | 2 | -72/+228 | |
| | | | | | | | | | | | | | | | this will only be used if you both have a card that supports it with a working driver and you set sysctl kern.userasymcrypto=1 | |||||
* | | | spelling; moritz@jodeit.org | deraadt | 2002-06-09 | 1 | -2/+4 | |
| | | | ||||||
* | | | Pass the right arguments for RSA, DSA, and modexp operations. Fix the | angelos | 2002-06-09 | 2 | -60/+74 | |
| | | | | | | | | | | | | translation between the crypto framework's format and the BN structure. | |||||
* | | | After much horrible and painful slogging through asn1 code, | beck | 2002-06-08 | 2 | -0/+2 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | this fixes the source of connection problems with ssl/tls connections between sparc64 and other things. The punchline, we just found a bug in floating point emulation on sparc64 when this script produces off-by-one output on sparc64. This fix is annoyingly easy for the effort expended. | |||||
* | | | do not propose IDEA cipher on SSL connection. tested by beck | itojun | 2002-06-07 | 5 | -0/+18 | |
| | | | | | | | | | | | | noticed by Sverre Froyen <sverre@viewmark.com> | |||||
* | | | typo - I am a luser and a moron. | beck | 2002-06-07 | 1 | -2/+2 | |
| | | | ||||||
* | | | Merge OpenSSL 0.9.7-stable-20020605, | beck | 2002-06-07 | 100 | -5004/+1076 | |
| | | | | | | | | | | | | correctly autogenerate obj_mac.h | |||||
* | | | sig_atomic_t type must also be volatile | deraadt | 2002-06-03 | 2 | -2/+2 | |
| | | | ||||||
* | | | we do not need this to be Makefile.bsd-wrapper | deraadt | 2002-06-01 | 2 | -979/+976 | |
| | | | ||||||
* | | | unsigned vs unsigned int | deraadt | 2002-05-27 | 1 | -3/+3 | |
| | | | ||||||
* | | | pid_t cleanup | deraadt | 2002-05-26 | 1 | -3/+3 | |
| | | | ||||||
* | | | do not assume scripts are executable | deraadt | 2002-05-25 | 12 | -12/+12 | |
| | | | ||||||
* | | | try to use strlcpy and snprintf more; ok various | deraadt | 2002-05-24 | 9 | -38/+43 | |
| | | | ||||||
* | | | more strlcpy and snprintf | deraadt | 2002-05-22 | 3 | -47/+41 | |
| | | | ||||||
* | | | Merge openssl-0.9.7-stable-SNAP-20020519 | beck | 2002-05-21 | 36 | -235/+210 | |
| | | | ||||||
* | | | do not reverse-lookup scoped ipv6 address - it is meaningless as there's | itojun | 2002-05-18 | 1 | -1/+7 | |
| | | | | | | | | | | | | no way to pass scope id. sync w/kame | |||||
* | | | clean MLINK tree | deraadt | 2002-05-16 | 1 | -249/+338 | |
| | | | ||||||
* | | | add aes/bf/cast; ok deraadt@ | markus | 2002-05-16 | 2 | -4/+100 | |
| | | | ||||||
* | | | use hw_cryptodev | deraadt | 2002-05-16 | 2 | -48/+48 | |
| | | | ||||||
* | | | missed a few more | deraadt | 2002-05-16 | 1 | -59/+161 | |
| | | | ||||||
* | | | handle some more pods (there are still missing ones I bet) | deraadt | 2002-05-16 | 1 | -34/+80 | |
| | | | ||||||
* | | | Damn my rush to make it build again. | beck | 2002-05-15 | 2 | -5684/+0 | |
| | | | ||||||
* | | | order better | deraadt | 2002-05-15 | 1 | -3/+2 | |
| | | | ||||||
* | | | Dammit. I'm an idiot. | beck | 2002-05-15 | 1 | -2/+2 | |
| | | | ||||||
* | | | god these guys have low quality control | deraadt | 2002-05-15 | 1 | -1/+1 | |
| | | | ||||||
* | | | OpenSSL 0.9.7 stable 2002 05 08 merge | beck | 2002-05-15 | 1580 | -40842/+166504 | |
| | | | ||||||
* | | | OpenSSL 0.9.7 | beck | 2002-05-15 | 6 | -81/+122 | |
| | | | ||||||
* | | | For strncpy(), dst is not NUL terminated if strlen(src) >= len. | millert | 2002-05-13 | 1 | -6/+5 | |
| | | | | | | | | | | | | Also fix a typo; adapted from a patch by Moritz Jodeit | |||||
* | | | Kill/adjust r(login|exec)d? references now that those are no longer in | millert | 2002-05-06 | 1 | -5/+1 | |
| | | | | | | | | | | | | the tree. | |||||
* | | | o) start new sentence on a new line; | mpech | 2002-05-01 | 1 | -2/+3 | |
| | | | | | | | | | | | | | | | | | | | | | o) always close .Bl tags; o) fix usage of .Xr; millert@ ok | |||||
* | | | Initial cleanup: | mpech | 2002-04-30 | 5 | -10/+10 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | o) remove extra space in the end of line; o) remove extra blank lines in the end of file; o) remove .Pp before .Ss; o) CAVEAT -> CAVEATS; o) fix usage of .Fa; o) <blank-line> -> .Pp; o) wrap long lines; millert@ ok |