summaryrefslogtreecommitdiff
path: root/src (unfollow)
Commit message (Collapse)AuthorFilesLines
2011-02-12This commit was manufactured by cvs2git to create branch 'OPENBSD_4_9'.OPENBSD_4_9cvs2svn932-296990/+0
2011-02-12fix from pr 6207. a bit more of an explanation: we write the correctokan1-4/+18
number of bits when connecting via a SOCKS 5 proxy over ipv6, but we also need to read the same number depending on the received address type. this issue is not noticeable with ssh's SOCKS 5 support since it always set the address type as ipv4. this fixes connections via SOCKS 5 proxies which set their address type as ipv6 when using ipv6. after review with, and ok, nicm@
2011-02-10fix for CVE-2011-0014 "OCSP stapling vulnerability";djm2-2/+14
ok markus@ jasper@ miod@ AFAIK nothing in base uses this, though apache2 from ports may be affected.
2011-01-25Put -I${includedir} back into Cflags so configure script tests likenaddy1-4/+8
test -n "`pkg-config --cflags openssl`" don't assume that OpenSSL isn't available. ok miod@, sthen@, ajacoutot@, djm@
2011-01-24Correctly escape a literal colon in an enclosure;schwarze1-3/+3
the \: roff escape is an optional line break.
2011-01-21- simplify, krb5 handling is not needed.jasper2-27/+8
prompted by brad
2011-01-20a a -> alum1-3/+3
ok jmc@
2011-01-14superceded -> superseded;jmc1-3/+3
2011-01-09Minor tweaks to nc(1) man page and usage.jeremy2-16/+23
OK jmc@, nicm@, tedu@
2011-01-08Enable unix datagram support by treating ENOBUFS like EAGAIN.jeremy1-2/+2
Separate commit requested by deraadt@. OK nicm@
2011-01-08Support unix domain sockets in nc(1) with -Uu.jeremy2-25/+83
Previously, using -U with -u was an error that was not documented in the man page. Now it will use a unix socket in datagram mode. Bidirectional unix datagram communication requires a socket at both ends, so in client mode (without -l), a temporary socket is created so that responses from the server can be received. If -s is specified with -U and -u, it specifies the location of the temporary socket to create. This was mostly written way back in 2007. Since then, various improvements implemented based on suggestions from guenther@, tedu@, and nicm@. Man page help from nicm@ and jmc@. Unix datagram support requires a small change to atomicio.c in order to function correctly, this will be committed separately shortly. OK nicm@
2011-01-07Remove an extraneous return statement with the wrong return value.millert1-8/+6
Fix some gcc warnings.
2011-01-03- adjust krb5 directoriesjasper1-8/+5
- zap a trailing tab
2010-12-28- ensure ${DESTDIR}/usr/lib/pkgconfig/ as running make distrib-dirs is notjasper1-2/+3
common/encouraged practice
2010-12-28- generate and install pkg-config files for openssl, which more and morejasper2-1/+122
projects depend on being present (e.g. various ports). as discussed with various porters in a hungarian spa help/feedback from ingo@ and also OK halex@ no objections from djm@
2010-12-22remove comment that hasn't been true for quite a while now;otto1-6/+1
ok deraadt@ djm@
2010-12-16avoid pointer arithmetic on void *dhill1-5/+5
tested for a while by me. ok otto@
2010-12-16move CRYPTO_VIAC3_MAX out of cryptodev.h and into the onlyjsg2-0/+4
file it will be used from. requested by/ok mikeb@
2010-12-16The VIA ciphers are added to an array of CRYPTO_ALGORITHM_MAX lengthjsg2-4/+4
which should have been declared as CRYPTO_ALGORITHM_MAX + 1, fix this and reserve enough space for the VIA additions as well. ok/comments from mikeb & deraadt
2010-12-15Security fix for CVE-2010-4180 as mentioned in ↵jasper4-0/+16
http://www.openssl.org/news/secadv_20101202.txt. where clients could modify the stored session cache ciphersuite and in some cases even downgrade the suite to weaker ones. This code is not enabled by default. ok djm@
2010-12-12overriden -> overridden;jmc1-4/+4
2010-11-30involes -> involves; from Carlos Alberto Pereira Gomesjmc1-1/+1
2010-11-17- Apply security fix for CVE-2010-3864 (+commit 19998 which fixes the fix).jasper2-36/+84
ok djm@ deraadt@
2010-10-28remove skipjack and cast from the libc; ok deraadtmikeb3-1053/+2
2010-10-21print the pointer value that caused the error (if available); okotto1-47/+54
deraadt@ nicm@ (on an earlier version)
2010-10-18Disable use of dladdr() on a.out arches, they do not provide it (yet); ok djm@miod2-2/+2
2010-10-17various tweaks for consistency;jmc1-92/+62
2010-10-15use standard list width;jmc1-29/+29
2010-10-15nicer formatting for the various synopses;jmc1-276/+344
2010-10-15document "openssl ts";jmc1-4/+629
2010-10-14probabalistic -> probabilistic; from naddyjmc1-2/+2
2010-10-14for openssl prime, note that results are probabalistic; from djmjmc1-2/+5
2010-10-13document "openssl prime";jmc1-1/+47
2010-10-13document "openssl pkeyparam";jmc1-6/+54
2010-10-12document "openssl pkeyutl";jmc1-2/+212
2010-10-09document "openssl pkey";jmc1-1/+127
2010-10-09document "openssl genpkey";jmc1-2/+176
2010-10-08document "openssl engine";jmc1-1/+51
2010-10-08document "openssl ecparam";jmc1-1/+182
2010-10-08supply the correct value of ciphers DEFAULT; from djmjmc1-3/+3
2010-10-08document "openssl ec";jmc1-3/+209
2010-10-07OpenSSL grows another undocumented header, apparently needed on armishdjm1-1/+2
2010-10-06More OpenSSL fixes:djm7-26/+30
- Update local engines for the EVP API change (len u_int => size_t) - Use hw_cryptodev.c instead of eng_cryptodev.c - Make x86_64-xlate.pl always write to the output file and not stdout, fixing "make -j" builds (spotted by naddy@) ok naddy@
2010-10-06Retire Skipjackmikeb4-4/+0
There's not much use for the declassified cipher from the 80's with a questionable license these days. According to the FIPS drafts, Skipjack reaches its EOL in December 2010. The libc portion will be removed after the ports hackathon. djm and thib agree, no objections from deraadt Thanks to jsg for digging up FIPS drafts.
2010-10-06catch up to openssl-1.0.0a; there's some new commands, as yet undocumented,jmc1-214/+650
but i'll get to those shortly...
2010-10-04Our make already uses sh -e when executing commands.naddy1-7/+7
Revert the "set -e" additions and kill unneeded subshells. ok djm@
2010-10-03don't use non-standard CFLAGS; ok miod@, deraadt@naddy1-2/+2
2010-10-03DES_LONG should be u_int on all platforms, it was spuriouslydjm1-1/+1
u_long on i386. suggested by deraadt@ and kettenis@
2010-10-02percolate up errors from perl asm scripts, correctly enable SHA-256 asm ondjm1-9/+9
amd64
2010-10-01fix -Wall due to API changedjm2-6/+6