| Commit message (Collapse) | Author | Age | Files | Lines |
... | |
| | | |
| | | |
| | | |
| | | | |
ok jmc@
|
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
about cert checking in OpenSSH. Man page wording tweaks thanks to
jmc@.
ok henning@, jmc@; positive feedback from djm@, ajacoutat@
Committing now to reuse guenther@'s libc minor bump instead of
cranking it again, as suggested by deraadt@.
|
| | | |
| | | |
| | | |
| | | |
| | | | |
to return -1 in case of an unprintable character.
ok nicm jmc
|
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
"if you have checked this I am ok with it" does not mean
1) not to pay attention to breaking news after I tell you that and
2) not to get ok's from the others this had been shown to.
I am absolutely not ok with thig going in with only *my* ok. There's a reason why we want more than one ok on important commits
ok deraadt@ for the backout
|
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
DigiCert High Assurance CA-3
Go Daddy Secure Certification Authority
COMODO High-Assurance Secure Server CA
Equifax Secure Certificate Authority
VeriSign Class 3 Public Primary Certification Authority - G5
Entrust Certification Authority - L1C
Entrust.net Secure Server Certification Authority
cross checked with mozilla
ok beck@
|
| | | |
| | | |
| | | |
| | | | |
Fixes build on NFS src with no root access. ok jasper@
|
| | | | |
|
| | | |
| | | |
| | | |
| | | | |
ok guenther
|
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
argv and don't suppress the handling of leading '-' in optstring when
POSIXLY_CORRECT is set.
Based on patch from Eric Blake.
ok and manpage update from millert@, manpage ok jmc@
|
| | | |
| | | |
| | | |
| | | | |
ok beck@ fgsch@
|
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
invokes handlers registered with __cxa_atexit().
"seems right" deraadt@
|
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
ok markus@ jasper@ miod@
AFAIK nothing in base uses this, though apache2 from ports may be affected.
|
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
test -n "`pkg-config --cflags openssl`"
don't assume that OpenSSL isn't available.
ok miod@, sthen@, ajacoutot@, djm@
|
| | | |
| | | |
| | | |
| | | | |
the \: roff escape is an optional line break.
|
| | | |
| | | |
| | | |
| | | | |
prompted by brad
|
| | | | |
|
| | | |
| | | |
| | | |
| | | | |
- zap a trailing tab
|
| | | |
| | | |
| | | |
| | | | |
common/encouraged practice
|
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
projects depend on being present (e.g. various ports).
as discussed with various porters in a hungarian spa
help/feedback from ingo@ and also OK halex@
no objections from djm@
|
| | | |
| | | |
| | | |
| | | | |
ok deraadt@ djm@
|
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
tested for a while by me.
ok otto@
|
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
file it will be used from.
requested by/ok mikeb@
|
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
which should have been declared as CRYPTO_ALGORITHM_MAX + 1,
fix this and reserve enough space for the VIA additions as well.
ok/comments from mikeb & deraadt
|
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
http://www.openssl.org/news/secadv_20101202.txt.
where clients could modify the stored session
cache ciphersuite and in some cases even downgrade the suite to weaker ones.
This code is not enabled by default.
ok djm@
|
| | | | |
|
| | | |
| | | |
| | | |
| | | | |
ok djm@ deraadt@
|
| | | | |
|
| | | |
| | | |
| | | |
| | | | |
deraadt@ nicm@ (on an earlier version)
|
| | | | |
|
| | | | |
|
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
- Update local engines for the EVP API change (len u_int => size_t)
- Use hw_cryptodev.c instead of eng_cryptodev.c
- Make x86_64-xlate.pl always write to the output file and not stdout,
fixing "make -j" builds (spotted by naddy@)
ok naddy@
|
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
There's not much use for the declassified cipher from the 80's
with a questionable license these days. According to the FIPS
drafts, Skipjack reaches its EOL in December 2010.
The libc portion will be removed after the ports hackathon.
djm and thib agree, no objections from deraadt
Thanks to jsg for digging up FIPS drafts.
|
| | | |
| | | |
| | | |
| | | | |
Revert the "set -e" additions and kill unneeded subshells. ok djm@
|
| | | |
| | | |
| | | |
| | | | |
u_long on i386. suggested by deraadt@ and kettenis@
|
| | | |
| | | |
| | | |
| | | | |
amd64
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | | |
|
|\ \ \ \
| | |/ /
| |/| | |
branch.
|
| | | | |
|
| | | | |
|
|\ \ \ \
| | |_|/
| |/| | |
branch.
|
| | | | |
|
|\ \ \ \
| | |_|/
| |/| | |
branch.
|
| | | | |
|
| | | | |
|
| | | |
| | | |
| | | |
| | | | |
OK deraadt@
|
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
kernel in kern(9), and remove it from OpenSSH.
ok deraadt@, djm@
|
| | | |
| | | |
| | | |
| | | | |
OK deraadt@, millert@
|