| Commit message (Collapse) | Author | Age | Files | Lines |
... | |
| | | |
| | | |
| | | |
| | | | |
common/encouraged practice
|
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
projects depend on being present (e.g. various ports).
as discussed with various porters in a hungarian spa
help/feedback from ingo@ and also OK halex@
no objections from djm@
|
| | | |
| | | |
| | | |
| | | | |
ok deraadt@ djm@
|
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
tested for a while by me.
ok otto@
|
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
file it will be used from.
requested by/ok mikeb@
|
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
which should have been declared as CRYPTO_ALGORITHM_MAX + 1,
fix this and reserve enough space for the VIA additions as well.
ok/comments from mikeb & deraadt
|
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
http://www.openssl.org/news/secadv_20101202.txt.
where clients could modify the stored session
cache ciphersuite and in some cases even downgrade the suite to weaker ones.
This code is not enabled by default.
ok djm@
|
| | | | |
|
| | | |
| | | |
| | | |
| | | | |
ok djm@ deraadt@
|
| | | | |
|
| | | |
| | | |
| | | |
| | | | |
deraadt@ nicm@ (on an earlier version)
|
| | | | |
|
| | | | |
|
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
- Update local engines for the EVP API change (len u_int => size_t)
- Use hw_cryptodev.c instead of eng_cryptodev.c
- Make x86_64-xlate.pl always write to the output file and not stdout,
fixing "make -j" builds (spotted by naddy@)
ok naddy@
|
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
There's not much use for the declassified cipher from the 80's
with a questionable license these days. According to the FIPS
drafts, Skipjack reaches its EOL in December 2010.
The libc portion will be removed after the ports hackathon.
djm and thib agree, no objections from deraadt
Thanks to jsg for digging up FIPS drafts.
|
| | | |
| | | |
| | | |
| | | | |
Revert the "set -e" additions and kill unneeded subshells. ok djm@
|
| | | |
| | | |
| | | |
| | | | |
u_long on i386. suggested by deraadt@ and kettenis@
|
| | | |
| | | |
| | | |
| | | | |
amd64
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | | |
|
|\ \ \ \
| | |/ /
| |/| | |
branch.
|
| | | | |
|
| | | | |
|
|\ \ \ \
| | |_|/
| |/| | |
branch.
|
| | | | |
|
|\ \ \ \
| | |_|/
| |/| | |
branch.
|
| | | | |
|
| | | | |
|
| | | |
| | | |
| | | |
| | | | |
OK deraadt@
|
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
kernel in kern(9), and remove it from OpenSSH.
ok deraadt@, djm@
|
| | | |
| | | |
| | | |
| | | | |
OK deraadt@, millert@
|
| | | | |
|
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
- wide character (noun)
- wide-character (adjective)
this is the "fix of least resistance", and appears to be in line with
posix style; a tiny fix still needed for curses, but i'll mail that
upstream;
|
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
these are not built by default, but only built when MANPS is set.
kristaps@ and jmc@ agree with the idea,
and the patch doesn't bother deraadt@ at all
|
| | | |
| | | |
| | | |
| | | | |
Update our sources appropriately. OK deraadt@ jsg@
|
| | | |
| | | |
| | | |
| | | | |
via setenv() or putenv(). OK miod@
|
| | | |
| | | |
| | | |
| | | | |
OK jmc
|
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
the REPLACE_GETOPT macro, at long last
ok millert@
|
| | | |
| | | |
| | | |
| | | | |
From Nicolas Legrand <nlegrand@ethelred.fr>; ok jmc@
|
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
SOL_SOCKET and SO_PEERCRED, only issue being that it cannot return
EFAULT for a page fault. The kernel code will soon be put into
compat, and then in 10 years or so tedu will delete it.
ok guenther millert
|
| | | | |
|
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
This is code mostly picked up from upstream OpenSSL, or to be more exact
a diff from David Woodhouse <dwmw2 at infradead dot org>.
Remember to make includes before doing a build!
no objections from djm@
OK deraadt@, reyk@ (AES is about 4.25x faster on his x201 now)
|
| | | | |
|
| | | | |
|
| | | | |
|
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
with suggestions from miod.
The codepath doesn't seem to be called yet, this will be
investigated later.
looks good miod@, ok deraadt@
|
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
version require these flags to accept the X.509 certificates from the
gateway or client; I just add both flags to make it work in both cases
and verified it with win7, for example when authenticating against iked.
go ahead beck@
|
| | | |
| | | |
| | | |
| | | |
| | | | |
and would otherwise result in overflowing the end pointer and
cause strnlen() to return 0. OK sthen@
|