| Commit message (Expand) | Author | Files | Lines |
2020-01-23 | If we are building a legacy server hello, check to see if we are | beck | 1 | -1/+20 |
2020-01-23 | Add checking int the client to check the magic values which are | beck | 3 | -3/+30 |
2020-01-23 | Add code to build and send a server hello for tls 1.3 | beck | 1 | -3/+40 |
2020-01-23 | Save the legacy session id in the client, and enforce that it is returned | beck | 2 | -7/+18 |
2020-01-23 | Implement pending for TLSv1.3. | jsing | 4 | -6/+42 |
2020-01-23 | The X509_LOOKUP code tries to grope around in /etc/ssl/cert/ to find | tb | 1 | -30/+67 |
2020-01-23 | Remove lies from the SSL_pending man page, Our implementation never | beck | 1 | -22/+3 |
2020-01-23 | Make -peekaboo mode also use SSL_pending after peeking, to ensure | beck | 1 | -2/+9 |
2020-01-23 | Switch back to a function pointer for ssl_pending. | jsing | 3 | -14/+24 |
2020-01-23 | Add a TLS13_IO_ALERT return value so that we can explicitly signal when | jsing | 3 | -11/+22 |
2020-01-23 | Pass a CBB to TLSv1.3 send handlers. | jsing | 4 | -50/+44 |
2020-01-22 | The length of the IV of EVP_chacha20 is currently 64 bits, not 96. | tb | 1 | -3/+3 |
2020-01-22 | Wire up the TLSv1.3 server. | jsing | 3 | -6/+182 |
2020-01-22 | Pass a handshake message content CBS to TLSv1.3 receive handlers. | jsing | 5 | -85/+70 |
2020-01-22 | Fix things so that `make -DTLS1_3` works again. | jsing | 1 | -1/+3 |
2020-01-22 | Send alerts on certificate verification failures of server certs | beck | 1 | -2/+2 |
2020-01-22 | Rename failure into alert_desc in tlsext_ocsp_server_parse(). | tb | 1 | -5/+5 |
2020-01-22 | fix previous: alert_desc needs to be an int. | tb | 1 | -2/+2 |
2020-01-22 | Avoid modifying alert in the success path. | tb | 1 | -11/+17 |
2020-01-22 | Enable the TLSv1.3 client in libssl. | jsing | 1 | -2/+3 |
2020-01-22 | Correct includes check for libtls. | jsing | 1 | -2/+2 |
2020-01-22 | Add checks to ensure that lib{crypto,ssl,tls} public headers have actually | jsing | 3 | -3/+33 |
2020-01-22 | delete wasteful ;; | deraadt | 1 | -2/+2 |
2020-01-22 | Move guards from public to internal headers, and fix not use values. | beck | 2 | -8/+7 |
2020-01-22 | Simplify header installation by combining the HDRS and HDRS_GEN loops. | jsing | 1 | -9/+2 |
2020-01-22 | Note in the man page that the default protocols list includes 1.3 | beck | 1 | -4/+4 |
2020-01-22 | Enable TLS version 1.3 in the default protocols for libtls. | beck | 1 | -2/+2 |
2020-01-22 | Simplify the peekaboo code. | jsing | 1 | -35/+6 |
2020-01-22 | Implement support for SSL_peek() in the TLSv1.3 record layer. | jsing | 3 | -14/+39 |
2020-01-22 | After the ClientHello has been sent or received and before the peer's | tb | 4 | -8/+22 |
2020-01-22 | Add -peekaboo option to s_client, to test SSL_peek | beck | 1 | -4/+66 |
2020-01-22 | Correctly set the legacy version when TLSv1.3 is building a client hello. | jsing | 1 | -4/+11 |
2020-01-22 | Don't add an extra unknown error if we got a fatal alert | beck | 1 | -2/+3 |
2020-01-22 | The legacy_record_version must be set to TLS1_2_VERSION except | tb | 4 | -9/+30 |
2020-01-22 | Hook up the TLSv1.3 legacy shutdown code. | jsing | 1 | -2/+2 |
2020-01-22 | Add minimal support for hello retry request for RFC conformance. | beck | 4 | -11/+71 |
2020-01-22 | Split the TLSv1.3 guards into separate client and server guards. | jsing | 3 | -6/+13 |
2020-01-22 | Implement close-notify and SSL_shutdown() handling for the TLSv1.3 client. | jsing | 3 | -9/+76 |
2020-01-21 | Correct legacy fallback for TLSv1.3 client. | jsing | 3 | -9/+30 |
2020-01-21 | Remove redundant ASN1_INTEGER_set call in PKCS7_set_type | inoguchi | 1 | -2/+1 |
2020-01-21 | Provide SSL_R_UNKNOWN. | jsing | 3 | -5/+7 |
2020-01-21 | Clear and free the tls13_ctx that hangs off an SSL *s from | tb | 2 | -2/+8 |
2020-01-21 | Add alert processing in tls client code, by adding alert to the | beck | 3 | -19/+30 |
2020-01-20 | Add alerts to the tls 1.3 record layer and handshake layer | beck | 2 | -49/+29 |
2020-01-20 | Provide an error framework for use with the TLSv1.3 code. | jsing | 5 | -7/+151 |
2020-01-20 | Update libtls config regress to include TLSv1.3. | jsing | 1 | -9/+16 |
2020-01-20 | Add support for TLSv1.3 as a protocol to libtls. | jsing | 4 | -11/+20 |
2020-01-17 | Free pss in RSA_free | inoguchi | 1 | -1/+2 |
2020-01-16 | Check fpu functions without setjmp/longjmp before testing the latter. | bluhm | 3 | -13/+71 |
2020-01-14 | bump to 3.1.0 | bcook | 1 | -3/+3 |