| Commit message (Expand) | Author | Age | Files | Lines |
* | remove unneded variable "time" | beck | 2020-09-14 | 1 | -3/+2 |
* | fix bug introduced on review where refactor made it possible to | beck | 2020-09-14 | 1 | -2/+2 |
* | re-enable new x509 chain verifier as the default | beck | 2020-09-14 | 1 | -3/+1 |
* | Correctly fix double free introduced on review. | beck | 2020-09-14 | 2 | -3/+3 |
* | Fix double free - review moved the pop_free of roots to x509_verify_ctx_free | beck | 2020-09-14 | 1 | -2/+1 |
* | revert previous, need to fix a problem | beck | 2020-09-14 | 1 | -1/+3 |
* | Enable the use of the new x509 chain validator by default. | beck | 2020-09-14 | 1 | -3/+1 |
* | Implement SSL_{CTX_,}set_ciphersuites(). | jsing | 2020-09-13 | 5 | -13/+211 |
* | Add new x509 certificate chain validator in x509_verify.c | beck | 2020-09-13 | 10 | -59/+1191 |
* | Improve handling of BIO_read()/BIO_write() failures in the TLSv1.3 stack. | jsing | 2020-09-13 | 1 | -1/+9 |
* | Use the correct type for tls1_set_ec_id() | tb | 2020-09-12 | 1 | -3/+3 |
* | Simplify tls1_set_ec_id() a bit | tb | 2020-09-12 | 1 | -24/+19 |
* | Unindent a bit of code that performs a few too many checks to | tb | 2020-09-12 | 1 | -10/+8 |
* | Avoid an out-of-bounds access in BN_rand() | tb | 2020-09-12 | 1 | -3/+8 |
* | Change over to use the new x509 name constraints verification. | beck | 2020-09-12 | 1 | -28/+7 |
* | Include machine/endian.h in gost2814789.c | inoguchi | 2020-09-12 | 1 | -1/+3 |
* | Add x509_constraints.c - a new implementation of x509 name constraints, with | beck | 2020-09-11 | 3 | -2/+1272 |
* | Remove cipher_list_by_id. | jsing | 2020-09-11 | 7 | -89/+32 |
* | Simplify SSL_get_ciphers(). | jsing | 2020-09-11 | 1 | -13/+7 |
* | Rename ssl_cipher_is_permitted() | jsing | 2020-09-11 | 3 | -10/+10 |
* | Some SSL_AD_* defines snuck into the TLSv1.3 code - replace them with | jsing | 2020-09-11 | 2 | -10/+10 |
* | Add issuer cache, to be used by upcoming changes to validation code. | beck | 2020-09-11 | 3 | -1/+216 |
* | Various ciphers related clean up. | jsing | 2020-09-11 | 1 | -41/+36 |
* | Set alpn_selected_len = 0 when alpn_selected is NULL | inoguchi | 2020-09-09 | 1 | -1/+4 |
* | Import latest OPENSSL_NO_* flags from OpenSSL 1.1.1g | inoguchi | 2020-09-09 | 1 | -0/+8 |
* | Mention that EC_KEY_get0_public_key returns a public key. | tb | 2020-09-08 | 1 | -3/+5 |
* | Garbage collect renew_ticket in tls_decrypt_ticket | tb | 2020-09-07 | 1 | -8/+5 |
* | For page-sized and larger allocations do not put the pages we're | otto | 2020-09-06 | 1 | -21/+18 |
* | Clean up asn1/x_info.c | tb | 2020-09-03 | 1 | -22/+9 |
* | Remove unnecessary zeroing after recallocarray(3) | tb | 2020-09-03 | 1 | -3/+1 |
* | KNF and comment tweaks | tb | 2020-09-02 | 1 | -8/+10 |
* | Zero out data to avoid leaving stack garbage in the tail of | tb | 2020-09-01 | 1 | -1/+3 |
* | The bumping of sess_cb_hit stats can wait until handling of | tb | 2020-09-01 | 1 | -4/+3 |
* | In the explanatory comment of ssl_get_prev_session fix the spelling of | tb | 2020-09-01 | 1 | -5/+6 |
* | Split session retrieval out of ssl_get_prev_session() | tb | 2020-09-01 | 1 | -78/+92 |
* | copy session id directly in ssl_get_prev_session | tb | 2020-09-01 | 3 | -27/+23 |
* | indent the only other label in this file | tb | 2020-09-01 | 1 | -2/+2 |
* | Indent label and remove dangling else | tb | 2020-09-01 | 1 | -4/+4 |
* | Zap NULL check before SSL_SESSION_free() | tb | 2020-09-01 | 1 | -3/+2 |
* | Rename the session pointer ret to sess | tb | 2020-09-01 | 1 | -25/+25 |
* | Hoist ERR_clear_error() call into the derr: label | tb | 2020-09-01 | 1 | -4/+2 |
* | simplify tls1_process_ticket() exit path | tb | 2020-09-01 | 2 | -19/+7 |
* | Return code tweaks for session ticket handlers | tb | 2020-08-31 | 3 | -47/+51 |
* | Send alert on ssl_get_prev_session failure | tb | 2020-08-31 | 4 | -20/+32 |
* | Start replacing the existing TLSv1.2 record layer. | jsing | 2020-08-30 | 7 | -195/+614 |
* | define OPENSSL_NO_SSL_TRACE in opensslfeatures.h | inoguchi | 2020-08-29 | 1 | -1/+1 |
* | Send an unexpected message alert if no valid content type is found. | jsing | 2020-08-11 | 1 | -2/+5 |
* | Increment the epoch in the same place for both read and write. | jsing | 2020-08-11 | 1 | -3/+3 |
* | Use 0 instead of 0x00 for memset() calls. | jsing | 2020-08-11 | 2 | -8/+8 |
* | Use SSL3_SEQUENCE_SIZE for last_write_sequence[] rather than hardcoding. | jsing | 2020-08-11 | 1 | -2/+2 |