index
:
src
cvs/HEAD
kms/intel
kms/radeon
master
OpenBSD base system
summary
refs
log
tree
commit
diff
log msg
author
committer
range
path:
root
/
lib
/
libssl
Age
Commit message (
Expand
)
Author
2020-06-09
The check_includes step is incorrect dependency management model for
Theo de Raadt
2020-06-06
Implement a rolling hash of the ClientHello message, Enforce RFC 8446
Bob Beck
2020-06-05
Use IANA allocated GOST ClientCertificateTypes.
Joel Sing
2020-06-05
Stop sending GOST R 34.10-94 as a CertificateType.
Joel Sing
2020-06-05
Handle GOST in ssl_cert_dup().
Joel Sing
2020-06-05
Enable GOST_SIG_FORMAT_RS_LE when verifying certificate signatures.
Joel Sing
2020-06-04
Align tls13_server_select_certificate() with
Theo Buehler
2020-06-04
Improve client certificate selection for TLSv1.3
Theo Buehler
2020-06-04
mention that TLS_method(3) also supports TLSv1.3;
Ingo Schwarze
2020-06-02
Remove const modifier in return type of tls13_handshake_active_state()
Theo Buehler
2020-06-02
distracting whitespace
Theo Buehler
2020-06-01
Split the handling of post handshake handshake messages into its
Theo Buehler
2020-06-01
Send an illegal_parameter alert if a client sends us invalid DH key
Theo Buehler
2020-06-01
Add a mechanism to set an alert in those parts of the read half of
Theo Buehler
2020-05-31
Replace ssl_max_server_version() with ssl_downgrade_max_version()
Joel Sing
2020-05-31
Correct downgrade sentinels when a version pinned method is in use.
Joel Sing
2020-05-29
Improve server certificate selection for TLSv1.3.
Joel Sing
2020-05-29
Handle the case where we receive a valid 0 byte application data record.
Joel Sing
2020-05-29
Wire up the servername callback in the TLSv1.3 server.
Joel Sing
2020-05-29
Mop up servername_done, which is unused.
Joel Sing
2020-05-26
minor cleanup ahead of the following work:
Ingo Schwarze
2020-05-26
Add additional length checks for TLSv1.3 plaintext and inner plaintext.
Joel Sing
2020-05-24
Fix some stylistic nits from jsing.
Theo Buehler
2020-05-23
Enforce that SNI hostnames be correct as per rfc 6066 and 5980.
Bob Beck
2020-05-23
Enable SSL_MODE_AUTO_RETRY by default.
Joel Sing
2020-05-23
Wire up SSL_MODE_AUTO_RETRY mode to retrying after PHH messages.
Joel Sing
2020-05-23
Provide the option to retry or return after post-handshake messages.
Joel Sing
2020-05-23
fix a confusingly wrapped line
Theo Buehler
2020-05-23
Do not assume that server_group != 0 or tlsext_supportedgroups != NULL
Theo Buehler
2020-05-22
Ensure we only attach an ocsp staple to a leaf certificate, because
Bob Beck
2020-05-21
Simplify: transform a dangling else into an early return and
Theo Buehler
2020-05-21
Make ssl_set_cert_masks() more consistent and closer to readable.
Joel Sing
2020-05-21
Avoid a shadowing issue by renaming cbs and cbb to cbb_hs and cbb_hs,
Theo Buehler
2020-05-21
A failure of tls13_handshake_msg_new() could lead to a NULL deref
Theo Buehler
2020-05-21
Actually set the hrr flag when sending a HelloRetryRequest.
Joel Sing
2020-05-20
Revert 1.43 - this fix for PHH in blocking mode breaks SSL_accept and
Bob Beck
2020-05-19
Replace SSL_PKEY_RSA_ENC/SSL_PKEY_RSA_SIGN with SSL_PKEY_RSA.
Joel Sing
2020-05-19
Only send ocsp staples if the client asked for ocsp certificate status.
Bob Beck
2020-05-19
Add support for TLS 1.3 server to send certificate status
Bob Beck
2020-05-17
Send alerts back correctly when handling key shares, including
Bob Beck
2020-05-17
Free handshake message correctly, noticed by tb@
Bob Beck
2020-05-17
Send a decode error alert if a server provides an empty certificate list.
Joel Sing
2020-05-16
Return TLS13_IO_WANT_POLLIN after processing post-handshake messages.
Joel Sing
2020-05-16
Ensure that a TLSv1.3 server has provided a certificate.
Joel Sing
2020-05-16
Add TLS13_ERR_NO_CERTIFICATE.
Joel Sing
2020-05-16
Avoid sending an empty certificate list from the TLSv1.3 server.
Joel Sing
2020-05-13
Fix pesky whitespace.
Joel Sing
2020-05-13
Remove a no longer relevant XXX comment.
Joel Sing
2020-05-13
Switch back to the legacy stack where the maximum is less than TLSv1.3.
Joel Sing
2020-05-13
Switch the legacy version to TLS1_2_VERSION when processing server hello.
Joel Sing
[next]