summaryrefslogtreecommitdiff
path: root/lib
AgeCommit message (Expand)Author
2014-08-11Remove now-unused SSL2_STATE as well as ssl2-specific state machine values.Miod Vallat
2014-08-11Currently, ssl3_put_char_by_bytes(NULL, NULL) is just a long handed wayJoel Sing
2014-08-11Provide a ssl3_get_cipher_by_id() function that allows ciphers to be lookedJoel Sing
2014-08-10Tweak cipher list comments and add missing cipher value comments.Joel Sing
2014-08-10Remove disabled (weakened export and non-ephemeral DH) cipher suites fromJoel Sing
2014-08-10Since we no longer need to support SSLv2-style cipher lists, startJoel Sing
2014-08-10debug level test for clock_gettime() calls should matchJonathan Gray
2014-08-10AF_IMPLINK and AF_BLUETOOTH are gonePhilip Guenther
2014-08-10Only need <stdint.h> and not all of <inttypes.h> herePhilip Guenther
2014-08-09Only need <stdint.h> and not <inttypes.h> herePhilip Guenther
2014-08-08Fix CVE-2014-3507, avoid allocating and then leaking a fresh fragmentPhilip Guenther
2014-08-08Fix CVE-2014-3508, pretty printing and OID validation:Philip Guenther
2014-08-07Correct test reversed during merge of fix for CVE-2014-3509Philip Guenther
2014-08-07Fix CVE-2014-3506, DTLS handshake message size checks. FromPhilip Guenther
2014-08-07Oops, revert changes commited by mistake. The previous commit was supposedMiod Vallat
2014-08-07When you expect a function to return a particular value, don't put a commentMiod Vallat
2014-08-07Fix CVE-2014-3511; TLS downgrade, verbatim diffTheo de Raadt
2014-08-07merge CVE-2014-3510; Fix DTLS anonymous EC(DH) denial of serviceTheo de Raadt
2014-08-06merge fix for CVE-2014-3509 -- basically a missing s->hit check; ok guentherTheo de Raadt
2014-08-06Prevent a possible use after free by mimicing the s3_srvr.c fixes contributed byMiod Vallat
2014-08-06Allow B64_EOF to follow a base64 padding character. This restores previousJoel Sing
2014-08-06Correct error checks in EVP_read_pw_string_min(): UI_add_input_string()Philip Guenther
2014-08-06Add support for loading the public/private key from memory, rather thanJoel Sing
2014-08-05Add $OpenBSD$ tags.Joel Sing
2014-08-04Implement ressl_accept_socket, which allocates a new server connectionJoel Sing
2014-08-04Return -1 on error (not 1).Joel Sing
2014-08-04A ressl server needs different configuration from a ressl client - provideJoel Sing
2014-08-04Provide a function that returns a server connection context.Joel Sing
2014-08-04Provide a utility function for loading a private/public keypair.Joel Sing
2014-08-04Improve ressl_{read,write} handling of non-blocking reads/writes.Joel Sing
2014-08-04Free the SSL context first and let the reference counting do its thing.Joel Sing
2014-08-04In chacha_init(), allow for a NULL iv. Reported by znz on github.Miod Vallat
2014-08-03X509_NAME_get_text_by_NID() returns -1 on error so the typeJonathan Gray
2014-07-29Fix a usage string; the proper spelling of 'alot' is 'a lot'.Bret Lambert
2014-07-28Remove SRP code. It contains a bug (this should not surprise anyone), butTed Unangst
2014-07-28The RSA, DH, and ECDH temporary key callbacks expect the number of keybitsPhilip Guenther
2014-07-25Add missing year to copyright.Joel Sing
2014-07-25BIO_free() returns immediately when the sole input is NULL.doug
2014-07-23Make queries using the search list for hostname lookups fail withEric Faurot
2014-07-23level_add_node(): if a memory allocation failure causes us to attempt to cleanMiod Vallat
2014-07-23Make sure PEM_def_callback() correctly handles negative buffer sizes; all usesMiod Vallat
2014-07-23Check the return value of the UI functions (including UI_new() which returnMiod Vallat
2014-07-22Now that DES_random_key() can be trusted, use it to generate DES keys in theMiod Vallat
2014-07-22In DES_random_key(), force the generated key to the odd parity before checkingMiod Vallat
2014-07-22Handle failure of NETSCAPE_SPKI_b64_encode() and don't leak memoryPhilip Guenther
2014-07-22Kill a bunch more BUF_strdup's - these are converted to have a check forBob Beck
2014-07-22better match proposed syscall apibcook
2014-07-21protect sysctl path with SYS__sysctl instead; from enh@google, ok bcookTheo de Raadt
2014-07-21Add pthread_sigmask() and raise() to the list of async signal safeMatthew Dempsky
2014-07-21Use explicit_bzero() instead of memset() on buffers going out of scope.Philip Guenther