Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | Fix cast-pasto's in comments | guenther | 2017-10-07 | 1 | -3/+3 | |
| | ||||||
* | Remove SSLv23 padding mode. | jsing | 2017-08-28 | 2 | -7/+5 | |
| | ||||||
* | Switch to -Werror with clang for libressl. | doug | 2017-08-13 | 1 | -2/+2 | |
| | | | | | Discussed with beck@ and jsing@ ok beck@ | |||||
* | Remove NPN support - the -nextprotoneg options now become no-ops. | jsing | 2017-08-12 | 4 | -113/+13 | |
| | | | | ok bcook@ beck@ doug@ | |||||
* | grammar was ass backwards; | jmc | 2017-07-15 | 1 | -7/+7 | |
| | ||||||
* | Add a "-T tlscompat" option to nc(1), which enables the use of all TLS | jsing | 2017-07-15 | 2 | -5/+12 | |
| | | | | | | | | | | protocols and "compat" ciphers. This allows for TLS connections to TLS servers that are using less than ideal cipher suites, without having to resort to "-T tlsall" which enables all known cipher suites. Diff from Kyle J. McKay <mackyle at gmail dot com> ok beck@ | |||||
* | remove redundant variable declarations in Makefiles, since those arelibressl-v2.6.0 | espie | 2017-07-09 | 1 | -2/+1 | |
| | | | | | | the default. okay millert@ | |||||
* | Continue the flattening of the pledge logic started in r1.184 and place | tb | 2017-06-11 | 1 | -8/+8 | |
| | | | | | | a blank space somewhere else. suggested by and ok jsing | |||||
* | Simple style(9) fixes from Juuso Lapinlampi, mostly whitespace and | tb | 2017-06-11 | 1 | -33/+35 | |
| | | | | | | | omitting parentheses in return statements. Binary change because of return instead of exit(3) from main and because help() is now __dead. ok awolk | |||||
* | If -P and -c were given, a second pledge call tried to add "rpath" to the | tb | 2017-06-10 | 1 | -8/+5 | |
| | | | | | | | | | | | | first pledge promises, so nc exited with EPERM. To fix this, merge the pledge of the Pflag && usetls case into the first pledge block. This allows us to get rid of the second pledge block and thus to simplify the logic a bit. While there, add a missing blank to an error string. Joint effort by the #openbsd-daily code reading group, problem found and initial patch by <rain1 openmailbox org>. ok awolk | |||||
* | Fix gcc warnings triggered by WARNINGS=yes. | bluhm | 2017-05-26 | 1 | -9/+9 | |
| | | | | OK florian@ | |||||
* | typo: ket -> key. | tb | 2017-05-16 | 1 | -3/+3 | |
| | | | | from "fenderq" on freenode via tj | |||||
* | Implement nc -W recvlimit to terminate netcat after receiving a | bluhm | 2017-05-10 | 2 | -8/+28 | |
| | | | | | | number of packets. This allows to send a UDP request, receive a reply and check the result on the command line. input jmc@; OK millert@ | |||||
* | simplify startdate/enddate validation | beck | 2017-05-08 | 1 | -27/+5 | |
| | | | | ok jsing@ | |||||
* | Limit -Werror to gcc4 as was done in libcrypto/libssl/libtls to avoid | jsg | 2017-05-07 | 1 | -3/+7 | |
| | | | | | | failed builds with different compilers. ok jsing@ | |||||
* | Fix the ca command so that certs it generates have RFC5280 conformant time. | beck | 2017-05-04 | 1 | -16/+56 | |
| | | | | Problem noticed by Harald Dunkel <harald.dunkel@aixigo.de> | |||||
* | use freezero() instead of 4-line conditional explicit_bzero + free | deraadt | 2017-04-18 | 4 | -28/+10 | |
| | ||||||
* | Move comments into a block and uses {} to unconfuse reading. | deraadt | 2017-04-16 | 1 | -12/+13 | |
| | ||||||
* | - -Z before -z in options list | jmc | 2017-04-05 | 2 | -7/+9 | |
| | | | | - add -Z to help and usage() | |||||
* | Allow nc to save the peer certificate and chain in a pem file specified | beck | 2017-04-05 | 2 | -4/+39 | |
| | | | | | with -Z ok jsing@ | |||||
* | The netcat server did not print the correct TLS error message if | bluhm | 2017-03-09 | 1 | -2/+2 | |
| | | | | | | the handshake after accept had failed. Use the context of the accepted TLS connection. OK beck@ | |||||
* | When netcat was started with -Uz, the exit status was always 1. If | bluhm | 2017-02-09 | 1 | -3/+4 | |
| | | | | | | the unix connect is successful, let nc -z close the socket and exit with 0. OK jca@ | |||||
* | Document that -x can take an ipv6 address enclosed in square brackets. | jca | 2017-02-09 | 1 | -2/+5 | |
| | ||||||
* | When getaddrinfo fails, print the requested host and port. | jca | 2017-02-09 | 1 | -2/+3 | |
| | | | | Should make debugging easier, especially when using -x literal_ipv6_address | |||||
* | Avoid a busy loop in netcat's tls_close(). Reuse the tls_handshake() | bluhm | 2017-02-08 | 1 | -18/+8 | |
| | | | | | wrapper that calls poll(2) and handles the -w timeout. OK beck@ | |||||
* | Avoid double close(2) in netcat. After every call to readwrite() | bluhm | 2017-02-08 | 1 | -13/+5 | |
| | | | | | there is already a close(2), so do not do it in readwrite(). OK beck@ | |||||
* | Due to non-blocking sockets, tls_handshake() could wait in a busy | bluhm | 2017-02-08 | 1 | -21/+42 | |
| | | | | | | loop. Use an additional poll(2) during the handshake and also respect the -w timeout option there. From Shuo Chen; OK beck@ | |||||
* | Support IPv6 proxy addresses | jca | 2017-02-05 | 1 | -10/+24 | |
| | | | | ok beck@ | |||||
* | oscp -> ocsp; | jmc | 2017-01-26 | 1 | -3/+3 | |
| | | | | from holger mikolon, plus one more in nc; | |||||
* | Add a -groups option to openssl s_client, which allows supported EC curves | jsing | 2017-01-24 | 1 | -7/+17 | |
| | | | | | | to be specified as a colon separated list. ok beck@ | |||||
* | whitespace | deraadt | 2017-01-21 | 2 | -5/+5 | |
| | ||||||
* | rearrange pledge promises into the canonical order; easier to eyeball | deraadt | 2017-01-20 | 39 | -77/+77 | |
| | ||||||
* | fix pledge for openssl ocsp - we will need tty to ask for a cert pw | beck | 2017-01-20 | 1 | -2/+2 | |
| | ||||||
* | fix openssl ocsp to not report sucess when the ocsp responder rejects us | beck | 2017-01-19 | 1 | -3/+3 | |
| | | | | ok deraadt@ krw@ | |||||
* | consistently spell ASN.1; | jmc | 2017-01-03 | 1 | -12/+12 | |
| | ||||||
* | Display details of the server ephemeral key, based on OpenSSL. | jsing | 2016-12-30 | 3 | -3/+44 | |
| | | | | ok doug@ | |||||
* | Expand ASN1_ITEM_rptr macros here as well... used with NETSCAPE_X509 of all | jsing | 2016-12-30 | 2 | -4/+4 | |
| | | | | things... | |||||
* | Stop using M_PKCS12_* compatibility macros here as well. | jsing | 2016-12-30 | 1 | -3/+3 | |
| | ||||||
* | Check return value of tls_config_set_protocols(3) and tls_config_set_ciphers(3) | mestre | 2016-11-30 | 1 | -3/+6 | |
| | | | | | | and bail out in case of failure Feedback and OK jsing@ | |||||
* | tweak previous; | jmc | 2016-11-06 | 1 | -3/+3 | |
| | ||||||
* | rename tlslegacy to tlsall, and better describe what it does. | beck | 2016-11-06 | 2 | -8/+8 | |
| | | | | ok jsing@ | |||||
* | zap trailing whitespace, and add -o to usage() and help (-h); | jmc | 2016-11-05 | 2 | -6/+9 | |
| | ||||||
* | Add support for server side OCSP stapling to libtls. | beck | 2016-11-05 | 2 | -4/+19 | |
| | | | | Add support for server side OCSP stapling to netcat. | |||||
* | new sentence, new line, and zap trailing whitespace; | jmc | 2016-11-04 | 1 | -3/+4 | |
| | ||||||
* | Add ocsp_require_stapling config option for tls - allows a connection | beck | 2016-11-04 | 2 | -6/+12 | |
| | | | | | | to indicate that it requires the peer to provide a stapled OCSP response with the handshake. Provide a "-T muststaple" for nc that uses it. ok jsing@, guenther@ | |||||
* | make OCSP_URL only show up when an OCSP url is actually present in the cert | beck | 2016-11-03 | 1 | -2/+3 | |
| | ||||||
* | Make OCSP Stapling: only appear if there is stapling info present. | beck | 2016-11-03 | 1 | -5/+3 | |
| | ||||||
* | Add OCSP client side support to libtls. | beck | 2016-11-02 | 1 | -1/+37 | |
| | | | | | | | | | | | | | - Provide access to certificate OCSP URL - Provide ability to check a raw OCSP reply against an established TLS ctx - Check and validate OCSP stapling info in the TLS handshake if a stapled OCSP response is provided.` Add example code to show OCSP URL and stapled info into netcat. ok jsing@ | |||||
* | typo | naddy | 2016-10-06 | 1 | -3/+3 | |
| | ||||||
* | trim STANDARDS; ok jsinglibressl-v2.5.0 | jmc | 2016-09-22 | 1 | -13/+1 | |
| |