| Commit message (Collapse) | Author | Age | Files | Lines |
... | |
|
|
|
|
| |
move some other sections into more relevant places, and remove the example
ca file;
|
|
|
|
| |
description of -out altered on jsing's advice
|
|
|
|
|
|
|
|
| |
right to try and trim some of the excess from this page. begin now
by cutting some of the fluff from the start.
the section on pass phrase arguments goes to the end of the page: it;s in
the way for now.
|
|
|
|
|
|
|
| |
changes - map the previous configuration to the equivalent in the new
groups. This will be revisited post release.
Discussed with beck@
|
| |
|
|
|
|
|
| |
pledge to match. Also use tls_config_error() to provide friendlier error
messages.
|
| |
|
|
|
|
|
|
|
| |
This makes error messages more specific and simplifies
masking compatible sections for the portable version.
ok beck@
|
|
|
|
| |
Req by and ok blumh@
|
|
|
|
|
| |
is shown by errx
ok millert krw
|
|
|
|
|
| |
so complicated that a future refactoring could easily in introduce a bug.
ok millert krw
|
| |
|
|
|
|
|
|
|
|
|
| |
The files would only be loaded if the CAfile or CApath locations were
succesfully loaded first. Original patch from OpenSSL:
https://github.com/openssl/openssl/commit/fe9b85c3cb79f1e29e61f01de105b34ce8177190
ok beck@
|
|
|
|
|
| |
based on a diff from Andras Farkas <deepbluemistake@gmail.com>
ok deraadt@
|
|
|
|
|
|
| |
for an http proxy - we need tty in this case. Found and fixed by
Anthony Coulter <bsd@anthonycoulter.name>.
ok tb@
|
|
|
|
| |
Noticed by and a modified version of fix from <attila@stalphonsos.com>
|
|
|
|
|
|
| |
problem reported by Alexandre (kAworu)
ok beck@ deraadt@ sthen@
|
|
|
|
| |
ok beck
|
| |
|
|
|
|
|
| |
prompted by a mail from jiri navratil
help/ok sthen
|
|
|
|
| |
fix from Andreas Bartelt <obsd at bartula.de>
|
|
|
|
| |
ok beck@
|
| |
|
| |
|
|
|
|
| |
lists recently.
|
|
|
|
|
| |
to the verbose output when using tls - from rob@2keys.ca
ok mmcc@ jsing@ deraadt@
|
| |
|
| |
|
|
|
|
|
| |
this allows us to drop the rpath fromt the nc pledge.
ok deraadt@, tedu@
|
|
|
|
|
|
|
|
| |
Knuth-Fisher-Yates shuffle to make the random sequence of ports
less biased. Based on the implementation in sys/netinet/ip_id.c.
With helpful input from daniel@ and beck@
ok beck@ despite eye twitching
|
| |
|
| |
|
|
|
|
| |
ok jcs@ deraadt@ theo@
|
|
|
|
| |
ok deraadt@
|
| |
|
|
|
|
| |
From todd@
|
| |
|
| |
|
|
|
|
|
| |
bearing on the following pledge setups anymore.
ok benno
|
|
|
|
|
|
|
|
|
| |
process, before pledge(). This way the rtable can be pledged too.
the discussion about removing -V is postponed.
diff from beck@, i wrote the same diff without seeing his, and various
people at u2k15 agreed this is the right thing to do.
ok phessler@
|
| |
|
|
|
|
|
|
|
| |
in a socket option can be pretty scary and there is no better interface for this.
so if the -V option is used you get no pledge at all.. Otherwise, do what
works for the various options. Still needs refinement for tls to drop rpath,
and a better solution for the routing table stuff
|
|
|
|
| |
ok semarie@
|
|
|
|
|
|
|
|
|
|
|
| |
it is needed in order to let libssl UI_* function plays with echo on/off when
asking for password on terminal.
passwd subcommand needs additionnal "wpath cpath" in order to let it calls
fopen("/dev/tty", "w") (O_WRONLY with O_CREAT | O_TRUNC).
problem reported by several
with and ok doug@
|
|
|
|
| |
use pledge and file locking. OK deraadt@
|
|
|
|
|
|
| |
sizeof(struct sockaddr_un), so do the simple, portable thing
ok beck@ deraadt@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
openssl(1) has two mechanisms for operating: either a single execution
of one command (looking at argv[0] or argv[1]) or as an interactive
session than may execute any number of commands.
We already have a top level pledge that should cover all commands
and that's what interactive mode must continue using. However, we can
tighten up the pledges when only executing one command.
This is an initial stab at support and may contain regressions. Most
commands only need "stdio rpath wpath cpath". The pledges could be
further restricted by evaluating the situation after parsing options.
deraadt@ and beck@ are roughly fine with this approach.
|
|
|
|
|
|
|
| |
which i have put in that order). this is not important, but helps look
for outliers which might be strange. it hints that "ioctl" should be
reassessed in a few places, to see if "tty" is better; that "unix" may
be used in some places where "route" could now work.
|
| |
|
|
|
|
|
| |
all the wading in here. "proc" is for the speed command, which fork()'s.
ok doug
|