summaryrefslogtreecommitdiff
path: root/src (unfollow)
Commit message (Collapse)AuthorFilesLines
2021-04-15mention DTLS1_2_VERSIONtb1-3/+4
2021-04-15Mention DTLS1_2_VERSION here, tootb1-6/+8
2021-04-15Document SSL_OP_NO_DTLSv1{,_2}tb1-2/+15
2021-04-15Document DTLSv1_2_{,client_,server_}method(3)tb1-4/+36
2021-04-15Merge documentation for SSL_is_dtls() from OpenSSLtb1-5/+21
2021-04-15Switch back to the legacy verifier for the release.tb1-2/+2
This is disappointing as a lot of work was put into the new verifier during this cycle. However, there are still too many known bugs and incompatibilities. It is better to be faced with known broken behavior than with new broken behavior and to switch now rather than via errata. This way we have another cycle to iron out the kinks and to fix some of the remaining bugs. ok jsing
2021-04-14revert previous. some of the keyupdate tests still fail occasionallytb1-2/+11
2021-04-14Enable test-tls13-keyupdate.pytb1-9/+2
2021-04-14move test-record-size-limit.py to unsupportedtb1-4/+3
2021-04-14enable test-record-layer-fragmentation.pytb1-7/+2
2021-04-14factor argument to catch an alert mismatch into a helper functiontb1-7/+8
2021-04-13enable test-tlsfuzzer-invalid-compression-methods.pytb1-5/+10
2021-04-13enable test-large-hello.py as a slow testtb1-3/+2
2021-04-13with new defaults, test-fuzzed-plaintext.py is no longer slowtb1-3/+2
2021-04-13move a few tests to the unsupported group and fix two commentstb1-15/+15
2021-04-13annotate test-ecdhe-rsa-key-exchange-with-bad-messages.py with expectedtb1-2/+3
alerts and where to add them.
2021-04-11Update a stale comment and fix a typo.tb1-3/+3
2021-04-09An extra internal consistency check and a missing stats adjustment. ok tb@otto1-1/+4
2021-04-09Cache implementation has changed, we do not hold on to an exact numberotto1-3/+4
of pages anymore, but also cache larger regions; ok tb@
2021-04-08Enable test-cve-2016-6309.pytb1-3/+2
2021-04-07Avoid clobbering the error code when sending an alerttb1-2/+3
In order to fail gracefully on encountering a self-signed cert, curl looks at the top-most error on the stack and needs specific SSL_R_ error codes. This mechanism was broken when the tls13_alert_sent_cb() was added after people complained about unhelpful unknown errors. Fix this by only setting the error code from a fatal alert if no error has been set previously. Issue reported by Christopher Reid ok jsing
2021-04-07Use ERR_print_error_fp() to avoid leaking a BIO in fatal()tb1-2/+2
2021-04-07Check function return value in openssl(1) x509.cinoguchi1-24/+71
input from bcook@, ok and comments from tb@
2021-04-07Avoid leak in error pathinoguchi1-3/+7
ok and input from tb@
2021-04-06use errx() instead of err()tb1-8/+8
2021-04-06spaces -> tabstb1-5/+5
2021-04-06minor style tweakstb1-5/+6
2021-04-05Don't leak param->name in x509_verify_param_zero()tb1-1/+2
For dynamically allocated verify parameters, param->name is only ever set in X509_VERIFY_set1_name() where the old one is freed and the new one is assigned via strdup(). Setting it to NULL without freeing it beforehand is a leak. looks correct to millert, ok inoguchi
2021-04-04Add missing error check for AES_unwrap_key().tb1-1/+3
2021-04-04Fix two copy paste errors in error messagestb1-3/+3
2021-04-04Add tests for DTLSv1_2{,_client,_server}_method()tb1-1/+20
2021-04-04Use correct type for tmp in test_write_bytes()tb1-2/+2
2021-04-04Explicitly NULL pointers to avoid a double free.tb1-1/+3
2021-04-04Don't leak key and dh in the error path.tb1-4/+7
2021-04-04Clean up client and server tls{,_config} contexts in tls_test().tb1-2/+11
Leaks reported by Ilya Shipitsin.
2021-04-03Run the CMAC tests through EVP_PKEY_new_CMAC_key().tb1-10/+22
2021-04-02Two cases of BRE involving counts and backrefs that go wrong andotto1-1/+16
similar that have no isssues. Reported by Michael Paoli. Failing cases commented out for now.
2021-04-02Show DTLS1.2 message with openssl(1) s_server and s_clientinoguchi1-2/+6
ok jsing@ tb@
2021-04-01Compare the pointer variable explicitly with NULL in if conditioninoguchi1-18/+17
2021-03-31one of the examples needs an -N (and explanation);jmc1-4/+7
diff from robert scheck discussed with and tweaked by sthen
2021-03-31Update for DTLSv1.2 support.tb1-2/+4
2021-03-31Remove workarounds for SSL_is_dtls()tb2-11/+2
Reminded by inoguchi jsing
2021-03-31Remove workaround for missing d2i_DSAPrivateKey_fp prototypetb1-5/+1
2021-03-31Bump minors after symbol additiontb3-3/+3
2021-03-31Expose various DTLSv1.2 specific functions and definestb5-27/+8
ok bcook inoguchi jsing
2021-03-31Document SSL_set_hostflags(3) and SSL_get0_peername(3)tb1-18/+4
ok bcook inoguchi jsing
2021-03-31Expose SSL_set_hostflags(3) and SSL_get0_peername(3)tb2-3/+3
ok bcook inoguchi jsing
2021-03-31Document SSL_use_certificate_chain_file(3)tb1-11/+3
ok bcook inoguchi jsing
2021-03-31Expose SSL_use_certificate_chain_file(3)tb2-3/+2
ok bcook inoguchi jsing
2021-03-31Provide missing prototype for d2i_DSAPrivateKey_fp(3)tb1-1/+2
ok bcook inoguchi jsing