summaryrefslogtreecommitdiff
path: root/src/lib (follow)
Commit message (Expand)AuthorAgeFilesLines
* Let realloc handle and produce moved pointers for allocations betweenlibressl-v2.5.1otto2017-02-011-20/+37
* tweak previous;jmc2017-01-312-12/+8
* Add tls_config_[add|set]keypair_ocsp functions so that ocsp staples may bebeck2017-01-316-58/+209
* Disable client-initiated renegotiation for libtls servers.jsing2017-01-311-1/+3
* Provide an SSL_OP_NO_CLIENT_RENEGOTIATION option that disallowsjsing2017-01-312-2/+12
* LibreSSL : Truncated packet could crash via OOB readinoguchi2017-01-312-3/+10
* Document functions returning standard moduli for DH key exchange.schwarze2017-01-312-1/+136
* tweak previous;jmc2017-01-303-11/+11
* Document BN_set_flags(3) and BN_get_flags(3).schwarze2017-01-306-13/+159
* Seriously warn against calling BN_init(3), BN_MONT_CTX_init(3),schwarze2017-01-293-12/+75
* Marko Kreen contributed significantly to the ocsp stuff for libtlsbeck2017-01-291-2/+3
* Move the ocsp staple to being part of the keypair structure internally,beck2017-01-293-14/+32
* Send the function codes from the error functions to the bit bucket,beck2017-01-29275-3892/+2400
* Put comment back in the right place.jsing2017-01-291-9/+9
* Avoid clearing the mac_packet flag in the wrong place.jsing2017-01-291-2/+1
* add HISTORY and AUTHORSschwarze2017-01-2812-24/+256
* Fix Copyright notices; ok beck@ jsing@ tedu@schwarze2017-01-2711-28/+43
* More s/OSCP/OCSP/ typostom2017-01-271-1/+1
* fix Dt;jmc2017-01-261-3/+3
* Use a flag to track when we need to call SSL_shutdown(). This avoids anjsing2017-01-264-5/+11
* Bump TLS_API due to new features being added earlier this week.jsing2017-01-261-2/+2
* Bump libtls minor due to symbol additions earlier this week.jsing2017-01-261-1/+1
* knfbeck2017-01-261-6/+11
* Convert ssl3_get_client_hello() to CBS.jsing2017-01-261-76/+71
* Finish the fallout of the SSLerr->SSLerror cleanup to get rid of the uglybeck2017-01-2618-653/+335
* Hide SSLerr() under #ifndef LIBRESSL_INTERNAL since we shouldn't bebeck2017-01-261-2/+4
* Send the error function codes to rot in the depths of hell where they belongbeck2017-01-2624-798/+572
* Merge the single two line function from ssl_err2.c into ssl_err.c.jsing2017-01-263-76/+12
* english is hard.beck2017-01-261-2/+2
* Limit the number of sequential empty records that we will processbeck2017-01-264-7/+30
* Refactor the code to generate a WANT_READ into a function, as we arebeck2017-01-261-18/+20
* Remove most of SSL3_ENC_METHOD - we can just inline the function callsjsing2017-01-2611-135/+63
* Move relatively new version range code from ssl_lib.c into a separatejsing2017-01-263-158/+175
* Rename s3_{both,clnt,pkt_srvr}.c to have an ssl_ prefix since they are nojsing2017-01-265-6/+6
* Merge the client/server version negotiation into the existing (currentlyjsing2017-01-2616-1229/+395
* Document ERR_load_BN_strings(3).schwarze2017-01-261-11/+47
* Remove ssl3_undef_enc_method - if we have internal bugs we want to segfaultjsing2017-01-265-36/+8
* Remove a sess_cert reference from a comment in the public header.jsing2017-01-261-5/+2
* split the tls_init(3) that had grown fat to allow healthy future growth;schwarze2017-01-2515-888/+1474
* document BN_asc2bn(3);schwarze2017-01-251-3/+27
* Limit enabled version range by the versions configured on the SSL_CTX/SSL,jsing2017-01-253-23/+84
* Change the SSL_IS_DTLS() macro to check the version, rather than using ajsing2017-01-252-7/+4
* Construct a BN_gcd_nonct, based on BN_mod_inverse_no_branch, as suggestedbeck2017-01-256-10/+170
* Provide ssl3_packet_read() and ssl3_packet_extend() functions that improvejsing2017-01-253-35/+59
* Provide defines for SSL_CTRL_SET_CURVES/SSL_CTRL_SET_CURVES_LIST for thingsjsing2017-01-251-1/+15
* BUF_MEM_free(), X509_STORE_free() and X509_VERIFY_PARAM_free() all checkjsing2017-01-242-18/+10
* sk_free() checks for NULL so do not bother doing it from the callers.jsing2017-01-244-10/+9
* sk_pop_free() checks for NULL so do not bother doing it from the callers.jsing2017-01-247-50/+31
* Within libssl a SSL_CTX * is referred to as a ctx - fix this forjsing2017-01-241-29/+29
* in resolver(3), document that _EDNS0 and _DNSSEC are no ops;jmc2017-01-241-6/+17