Age | Commit message (Collapse) | Author | |
---|---|---|---|
2014-07-12 | guard inclusion of sys/sysctl.h so we can detect at compile time and | Bob Beck | |
keep linux distros happy that don't have it. ok bcook@ | |||
2014-07-12 | Principle of least surprise: make CMAC_CTX_free(), OCSP_REQ_CTX_free() and | Miod Vallat | |
X509_STORE_CTX_free() accept NULL pointers as input without dereferencing them, like all the other well-behaved *_CTX_free() functions do. | |||
2014-07-12 | remove gratuitous differences, ok beck | Theo de Raadt | |
2014-07-12 | remove gratuitous differences, ok beck bcook | Theo de Raadt | |
2014-07-12 | Correct the sentence in the BUGS section. Colon chars are usable as a | YASUOKA Masahiko | |
string value and usage of it in type is documented in the other section. ok jmc | |||
2014-07-12 | Split arc4random_uniform into it's own file, to assist other projects | Theo de Raadt | |
now using this as upstream code. The particular problem is systems that contain older arc4random derivations lacking arc4random_uniform(). ok tedu miod | |||
2014-07-12 | Solaris uses a symbolic link for /dev/urandom which harms best practice of | Bob Beck | |
using O_NOFOLLOW - cope with it as best as possible by trying two different paths. - written by deraadt@ and kettenis@ | |||
2014-07-12 | Remove remnants from PSK, KRB5 and SRP. | Joel Sing | |
ok beck@ miod@ | |||
2014-07-12 | typos | Miod Vallat | |
2014-07-12 | Place comments in a block above the if statement, rather than attempting | Joel Sing | |
to interleave them within the conditions. Also fix wrapping and indentation. | |||
2014-07-12 | Make disabling last cipher work. | Philip Guenther | |
From Thijs Alkemade via OpenSSL trunk ok miod@ | |||
2014-07-12 | -DOPENSSL_NO_KRB5 is no longer needed | Theo de Raadt | |
ok guenther | |||
2014-07-12 | odds are that some ABI change occured today, no matter how careful everyone | Theo de Raadt | |
is | |||
2014-07-12 | enough churn, a crank is advised by guenther.. | Theo de Raadt | |
2014-07-12 | document sendsyslog(2); ok guenther tedu matthew | Theo de Raadt | |
2014-07-12 | Initial version of libressl - a library that provides a clean, simple, | Joel Sing | |
consistent and secure-by-default API for SSL clients (and soon servers). This is a long way from complete and the interface will likely change substantially - committing now so that further work can happen in the tree. Initiated by tedu@ and inspired by discussions with tedu@, beck@ and other developers. | |||
2014-07-11 | As reported by David Ramos, most consumer of ssl_get_message() perform late | Miod Vallat | |
bounds check, after reading the 2-, 3- or 4-byte size of the next chunk to process. But the size fields themselves are not checked for being entirely contained in the buffer. Since reading past your bounds is bad practice, and may not possible if you are using a secure memory allocator, we need to add the necessary bounds check, at the expense of some readability. As a bonus, a wrong size GOST session key will now trigger an error instead of a printf to stderr and it being handled as if it had the correct size. Creating this diff made my eyes bleed (in the real sense); reviewing it made guenther@'s and beck@'s eyes bleed too (in the literal sense). ok guenther@ beck@ | |||
2014-07-11 | Provide LIBRESSL_VERSION_NUMBER for people who use such things to | Bob Beck | |
detect versions distinct from OPENSSL_BLAH_WOOF.. ok jsing@ tedu@ deraadt@ | |||
2014-07-11 | missing \ | Theo de Raadt | |
2014-07-11 | formatting | Bob Beck | |
ok bcook@ | |||
2014-07-11 | add comment about format requirements | Bob Beck | |
ok miod@ | |||
2014-07-11 | Modify formatting to make portable's life a lot easier. | Bob Beck | |
ok miod@ bcook@ | |||
2014-07-11 | adapt addapt spelling to adapt; request from miod | Theo de Raadt | |
2014-07-11 | Huge documentation update for libcrypto and libssl, mostly from Matt Caswell, | Miod Vallat | |
Jeff Trawick, Jean-Paul Calderone, Michal Bozon, Jeffrey Walton and Rich Salz, via OpenSSL trunk (with some parts not applying to us, such as SSLv2 support, at least partially removed). | |||
2014-07-11 | If the application uses tls_session_secret_cb for session resumption, set | Miod Vallat | |
the CCS_OK flag. From OpenSSL trunk. | |||
2014-07-11 | Avoid invoking EVP_CIPHER_CTX_cleanup() on uninitialized memory; from | Miod Vallat | |
Coverity via OpenSSL trunk | |||
2014-07-11 | Fix a memory leak in BIO_free() which no current BIO can trigger; OpenSSL | Miod Vallat | |
PR #3439 via OpenSSL trunk | |||
2014-07-11 | Prevent infinite loop during configuration file parsing; OpenSSL PR #2985 | Miod Vallat | |
via OpenSSL trunk. | |||
2014-07-11 | Missing bounds check in do_PVK_body(); OpenSSL RT #2277, from OpenSSL trunk, | Miod Vallat | |
but without a memory leak. | |||
2014-07-11 | OPENSSL_ALGORITHM_DEFINES has been removed from conf.h, no need for it now | Ted Unangst | |
2014-07-11 | In RSA_eay_private_encrypt(), correctly return the smaller BN; OpenSSL | Miod Vallat | |
PR #3418 via OpenSSL trunk | |||
2014-07-11 | In ssl3_get_cert_verify(), allow for larger messages to accomodate keys | Miod Vallat | |
larger than 4096-bit RSA which the most paranoid of us are using; OpenSSL PR #319 via OpenSSL trunk. | |||
2014-07-11 | it has been 4888 days since the transient feature to define short macros | Ted Unangst | |
for apps that haven't had time to make the appropriate changes was added. time's up. | |||
2014-07-11 | Apparently better fix for OpenSSL PR #3397 (Joyent bug #7704), from OpenSSL | Miod Vallat | |
trunk | |||
2014-07-11 | Also make these files parsable by pod2man.. | Bob Beck | |
ok bcook@ | |||
2014-07-11 | Make this file parsable by pod2man without errors. | Bob Beck | |
ok bcook@ | |||
2014-07-11 | In ASN1_get_object(), reject primitive encodings using the indefinite length | Miod Vallat | |
constructed form. OpenSSL PR #2438 via OpenSSL trunk | |||
2014-07-11 | Fix copy for CCM, GCM and XTS. | Miod Vallat | |
Internal pointers in CCM, GCM and XTS contexts should either be NULL or set to point to the appropriate key schedule. This needs to be adjusted when copying contexts. OpenSSL PR #3272 with further fixes, from OpenSSL trunk | |||
2014-07-11 | i'm a dumbdumb. fix build. | Ted Unangst | |
2014-07-11 | In asn1_get_length(), tolerate leading zeroes in BER encoding. | Miod Vallat | |
OpenSSL PR #2746 via OpenSSL trunk | |||
2014-07-11 | In EVP_PBE_alg_add don't use the underlying NID for the cipher | Miod Vallat | |
as it may have a non-standard key size; OpenSSL PR #3206 via OpenSSL trunk. | |||
2014-07-11 | additional features: no buffer freelists and no heartbleed | Ted Unangst | |
2014-07-11 | no compression is also a feature of libressl | Ted Unangst | |
2014-07-11 | move all the feature settings to a common header. | Ted Unangst | |
probably ok beck jsing miod | |||
2014-07-11 | Tolerate critical AKID in CRLs; OpenSSL PR #3014 via OpenSSL trunk, and | Miod Vallat | |
also update the comments to reflect what the code now does. | |||
2014-07-11 | Fix OID encoding for single components. OpenSSL PR #2556 via OpenSSL trunk. | Miod Vallat | |
(be sure to make cleandir and make includes before building) | |||
2014-07-11 | More memory leaks and unchecked allocations; OpenSSL PR #3403 via OpenSSL | Miod Vallat | |
trunk. (note we had already fixed some of the issues in that PR independently) | |||
2014-07-11 | Fix incorrect duplicate mlinks | Bob Beck | |
ok bcook@ | |||
2014-07-11 | Make sure BN_sqr never returns negative numbers. | Miod Vallat | |
OpenSSL PR #3400 via OpenSSL trunk. | |||
2014-07-11 | Accept CCS again after `finished' has been sent by the client; at this point | Miod Vallat | |
keys have been correctly set up so it is ok to accept CCS from the server. Without renegotiation can sometimes fail. OpenSSL PR #3400 via OpenSSL trunk. |