| Commit message (Expand) | Author | Age | Files | Lines |
... | |
* | set error_depth and current_cert to make more legacy callbacks that don't check | beck | 2020-09-15 | 1 | -1/+3 |
* | Deduplicate the time validation code between the legacy and new | beck | 2020-09-15 | 3 | -27/+8 |
* | ifdef out code that is no longer used in here. once we are certain | beck | 2020-09-15 | 1 | -2/+5 |
* | Cleanup/simplify SSL_set_ssl_method(). | jsing | 2020-09-15 | 1 | -18/+18 |
* | Mop up the get_ssl_method function pointer. | jsing | 2020-09-15 | 2 | -50/+2 |
* | Test botan TLS client with libressl, openssl, openssl11 server. | bluhm | 2020-09-15 | 4 | -6/+305 |
* | Move state initialisation from SSL_clear() to ssl3_clear(). | jsing | 2020-09-14 | 2 | -4/+4 |
* | Cleanup and simplify SSL_set_session(). | jsing | 2020-09-14 | 1 | -36/+22 |
* | Avoid NULL deref SSL_{,CTX_}set_ciphersuites | tb | 2020-09-14 | 1 | -2/+2 |
* | simplify RETURN VALUES for x509_verify(3) after beck@ made the rules | schwarze | 2020-09-14 | 1 | -7/+3 |
* | Add initial man page for new x509_verify chain validator | beck | 2020-09-14 | 1 | -0/+225 |
* | Set error if we are given an NULL ctx in x509_verify, and set error | beck | 2020-09-14 | 1 | -5/+3 |
* | nuke a stray space | tb | 2020-09-14 | 1 | -2/+2 |
* | Fix potential leak when tmpext fails to be added to | beck | 2020-09-14 | 1 | -2/+6 |
* | Change the known output to be the expected output, so that we | beck | 2020-09-14 | 1 | -1421/+1421 |
* | Use a fixed validation time in these tests so we never | beck | 2020-09-14 | 1 | -2/+4 |
* | remove unneeded variable "type". | beck | 2020-09-14 | 1 | -6/+5 |
* | Don't leak names on success | beck | 2020-09-14 | 1 | -1/+2 |
* | remove unneded variable "time1" | beck | 2020-09-14 | 1 | -6/+6 |
* | remove unneded variable "time" | beck | 2020-09-14 | 1 | -3/+2 |
* | fix bug introduced on review where refactor made it possible to | beck | 2020-09-14 | 1 | -2/+2 |
* | re-enable new x509 chain verifier as the default | beck | 2020-09-14 | 1 | -3/+1 |
* | Correctly fix double free introduced on review. | beck | 2020-09-14 | 2 | -3/+3 |
* | Fix double free - review moved the pop_free of roots to x509_verify_ctx_free | beck | 2020-09-14 | 1 | -2/+1 |
* | revert previous, need to fix a problem | beck | 2020-09-14 | 1 | -1/+3 |
* | Enable the use of the new x509 chain validator by default. | beck | 2020-09-14 | 1 | -3/+1 |
* | Connect a client to a server. Both can be current libressl, or | bluhm | 2020-09-14 | 5 | -10/+193 |
* | Add regress for SSL_{CTX_,}set_ciphersuites(). | jsing | 2020-09-13 | 2 | -7/+318 |
* | Implement SSL_{CTX_,}set_ciphersuites(). | jsing | 2020-09-13 | 5 | -13/+211 |
* | Add new x509 certificate chain validator in x509_verify.c | beck | 2020-09-13 | 11 | -68/+1281 |
* | Improve handling of BIO_read()/BIO_write() failures in the TLSv1.3 stack. | jsing | 2020-09-13 | 1 | -1/+9 |
* | Use the correct type for tls1_set_ec_id() | tb | 2020-09-12 | 1 | -3/+3 |
* | Simplify tls1_set_ec_id() a bit | tb | 2020-09-12 | 1 | -24/+19 |
* | Unindent a bit of code that performs a few too many checks to | tb | 2020-09-12 | 1 | -10/+8 |
* | If CPU does not support AES-NI, LibreSSL TLS 1.3 client prefers | bluhm | 2020-09-12 | 1 | -9/+18 |
* | Avoid an out-of-bounds access in BN_rand() | tb | 2020-09-12 | 1 | -3/+8 |
* | Change over to use the new x509 name constraints verification. | beck | 2020-09-12 | 1 | -28/+7 |
* | remove unused include that breaks regress | beck | 2020-09-12 | 1 | -1/+0 |
* | Include machine/endian.h in gost2814789.c | inoguchi | 2020-09-12 | 1 | -1/+3 |
* | Enable cert and cipher interop tests. cert just works. cipher has | bluhm | 2020-09-11 | 3 | -55/+35 |
* | Add x509_constraints.c - a new implementation of x509 name constraints, with | beck | 2020-09-11 | 5 | -7/+1767 |
* | Remove cipher_list_by_id. | jsing | 2020-09-11 | 7 | -89/+32 |
* | Simplify SSL_get_ciphers(). | jsing | 2020-09-11 | 1 | -13/+7 |
* | Rename ssl_cipher_is_permitted() | jsing | 2020-09-11 | 3 | -10/+10 |
* | Some SSL_AD_* defines snuck into the TLSv1.3 code - replace them with | jsing | 2020-09-11 | 2 | -10/+10 |
* | Add issuer cache, to be used by upcoming changes to validation code. | beck | 2020-09-11 | 3 | -1/+216 |
* | Various ciphers related clean up. | jsing | 2020-09-11 | 1 | -41/+36 |
* | Enable test-tls13-large-number-of-extensions.py | tb | 2020-09-10 | 1 | -2/+7 |
* | Wrap long lines, add space in front of goto label in openssl(1) ocsp.c | inoguchi | 2020-09-09 | 1 | -93/+118 |
* | Change SSLv23_client_method to TLS_client_method openssl(1) ocsp | inoguchi | 2020-09-09 | 1 | -2/+2 |