summaryrefslogtreecommitdiff
path: root/src (follow)
Commit message (Collapse)AuthorAgeFilesLines
* add Copyright and licenseschwarze2016-11-111-4/+51
| | | | | and delete useless and incorrect sentence "None of the functions presented here return any value."
* import ASN1_TYPE_get(3) from OpenSSL,schwarze2016-11-112-1/+213
| | | | | deleting ASN1_TYPE_unpack_sequence() and ASN1_TYPE_pack_sequence() which we don't have
* minor cleanup;jmc2016-11-101-6/+6
|
* import from OpenSSL,schwarze2016-11-101-0/+246
| | | | deleting ASN1_TIME_diff() which we don't have
* various cleanup;jmc2016-11-107-57/+52
|
* Copyright and licenseschwarze2016-11-102-4/+102
|
* Add the correct Copyright and license.schwarze2016-11-101-5/+55
| | | | | Mention that ASN1_STRING_free(NULL) is OK. Delete the obvious statement that a void function returns no value.
* Copyright and licenseschwarze2016-11-101-2/+51
|
* Add the correct Copyright and license.schwarze2016-11-101-2/+55
| | | | Mention that ASN1_OBJECT_free(NULL) is OK.
* some cleanup;jmc2016-11-0811-63/+62
|
* When using an union including a type known for having strong alignmentmiod2016-11-081-7/+15
| | | | | | | | constraints, in order to force the union to have the same constraint, use the actual type instead of `double'. And add a comment explaining why we want such an alignment in there. ok beck@
* Check for stack push failure, and correctly destroy the object we failedmiod2016-11-081-20/+47
| | | | | | | to push in that case. While there replace an inline version of X509_OBJECT_free_contents() by a call to said function. ok beck@
* Use more homogeneous types and avoid a possible right shift by 32 inmiod2016-11-081-17/+11
| | | | | | lh_strhash(). ok guenther@
* Stricter checks of ASN1_INTEGER to reject ASN1_NEG_INTEGER in places whenmiod2016-11-085-14/+32
| | | | | | they don't make sense. ok beck@
* Reduce the ternary operator abuseguenther2016-11-081-3/+8
| | | | ok miod@
* Use __{BEGIN,END}_HIDDEN_DECLS to avoid exporting the internal symbolsguenther2016-11-071-6/+2
| | | | ok jsing@
* various cleanup;jmc2016-11-0721-200/+193
|
* some cleanup;jmc2016-11-061-31/+28
|
* sort SEE ALSO;jmc2016-11-061-2/+2
|
* Remove unused SSLv3 from ssl3_cbc_record_digest_supported().jsing2016-11-063-77/+33
| | | | | | From Markus Uhlin <markus.uhlin at bredband dot net> ok beck@ bcooK@
* don't dereference a if NULLbcook2016-11-061-2/+2
|
* document EVP_PKEY_get_default_digest_nid(3) in one page, not in twoschwarze2016-11-062-8/+4
|
* some minor cleanup;jmc2016-11-065-43/+42
|
* Set the callback on the correct ssl_ctx for the SNI case, instead ofbeck2016-11-061-2/+2
| | | | | the master only. ok jsing@
* spacing between macro args and punctuation;jmc2016-11-062-4/+4
|
* document ENGINE_add_conf_module(3) in one page, not in twoschwarze2016-11-061-3/+2
|
* document BIO_set_fd() and BIO_get_fd() in one manual page, not in two;schwarze2016-11-062-60/+32
| | | | general direction discussed yesterday with bcook@
* delete prototypes available in other pages and add a missing .Xr linkschwarze2016-11-061-102/+2
|
* delete prototypes available in other pages and add two missing .Xr linksschwarze2016-11-064-756/+216
|
* first pass; ok schwarzejmc2016-11-06185-249/+620
|
* delete prototypes available in other pages and add three missing .Xr linksschwarze2016-11-061-179/+7
|
* delete prototypes available in other pages and add two missing .Xr linksschwarze2016-11-061-158/+3
|
* Split ssl3_get_client_key_exchange() into separate per algorithm functions.jsing2016-11-061-320/+388
| | | | ok beck@
* Remove pointless check - without fixed ECDH, there is only one way to reachjsing2016-11-061-8/+1
| | | | | | this code path. ok beck@ bcook@
* tweak previous;jmc2016-11-061-3/+3
|
* simplify error handling in c2i_ASN1_OBJECTbcook2016-11-061-10/+12
| | | | ok beck@, miod@
* Split out the DHE and ECDHE code paths fromjsing2016-11-061-203/+221
| | | | | | ssl3_send_server_key_exchange(). ok beck@ bcook@
* rename tlslegacy to tlsall, and better describe what it does.beck2016-11-062-8/+8
| | | | ok jsing@
* Adjust cipher suite strengths - move MD5 to LOW, RC4 to LOW and 3DES tojsing2016-11-061-13/+13
| | | | | | MEDIUM. ok beck@ bcook@
* Update regress for IDEA cipher suite removal.jsing2016-11-061-83/+83
|
* Remove the single IDEA cipher suite. There is no good reason to supportjsing2016-11-063-29/+3
| | | | | | this. ok beck@ bcook@
* unifdef -m -UOPENSSL_NO_CHACHA -UOPENSSL_NO_POLY1305jsing2016-11-062-6/+2
| | | | ok beck@
* Add regress test script for openssl command.inoguchi2016-11-063-2/+966
| | | | ok beck@
* Avoid compiling in an unused function.jsing2016-11-061-0/+2
| | | | Spotted by guenther@
* adjust guards to elide unused Bi arraybcook2016-11-061-2/+0
| | | | ok jsing@
* Rework X509_verify_cert to support alt chains on certificate verification,beck2016-11-061-117/+265
| | | | | via boringssl. ok jsing@ miod@
* The upcoming x509 alt chains diff tightens the trust requirementsbeck2016-11-061-1/+17
| | | | | | | for certificates. This (from OpenSSL) ensures that the current "default" behaviour remains the same. We should revisit this later ok jsing@
* Commit a reminder that the default is not the default. This needs tobeck2016-11-061-1/+2
| | | | | be revisited. ok jsing@
* remove unused variablebcook2016-11-061-6/+3
|
* use the correct function for freebcook2016-11-061-2/+2
| | | | ok beck@