Age | Commit message (Collapse) | Author | |
---|---|---|---|
2019-11-18 | Provide a clean interface for sending TLSv1.3 alerts. | Joel Sing | |
ok beck@ | |||
2019-11-17 | Change tls13_record_layer_phh() to take a CBS as this avoids ownership | Joel Sing | |
issues and makes call sites cleaner. ok beck@ | |||
2019-11-17 | Correct update of application traffic secrets to use an empty context | Bob Beck | |
rather than the hash of an empty context ok jsing@ | |||
2019-11-17 | Bring back the ssl_shutdown internal method pointer. | Joel Sing | |
For now ssl3_shutdown() is called in all cases, however TLSv1.3 will soon get its own version. ok beck@ | |||
2019-11-17 | Add a reference for the non-standard post-handshake handshake (PHH). | Theo Buehler | |
ok beck, jsing | |||
2019-11-17 | Ensure that we are never operating in plaintext mode once the handshake | Joel Sing | |
is complete, which should never occur. ok beck@ | |||
2019-11-17 | Provide framework for sending alerts and post-handshake handshake messages. | Joel Sing | |
Discussed at length with beck@ ok beck@ tb@ | |||
2019-11-17 | indent with a tab instead of 8 spaces | Theo Buehler | |
2019-11-17 | Move the TLSv1.3 server message handling stubs. | Joel Sing | |
2019-11-17 | Add the initial framework for the TLSv1.3 server. | Joel Sing | |
ok beck@ | |||
2019-11-17 | tls13_connect() should be static. | Joel Sing | |
2019-11-17 | Fix backoff to legacy when in client auth mode. | Bob Beck | |
ok jsing@ | |||
2019-11-17 | Drop back to the legacy tls method if we are doing client authenticaiton | Bob Beck | |
from a tls 1.3 connection, for now. ok jsing@ | |||
2019-11-17 | Separate the callbacks for recieved and completed post handshake messages | Bob Beck | |
from the record layer ok jsing@ | |||
2019-11-16 | Allow 1.3 ciphers in libtls. | Bob Beck | |
ok jsing@ | |||
2019-11-16 | Revert previous deduplication diff, I broke portable in a strange way. | Bob Beck | |
I'll figure it out a bit later. Found and diagnosed by inoguchi@ | |||
2019-11-16 | Allow portable to override the default CA bundle location | Bob Beck | |
ok kinichiro@ jsing@ | |||
2019-11-15 | Deduplicate some extension processing code. | Bob Beck | |
ok tb@ inoguchi@ | |||
2019-11-15 | Fix a segmentation fault in ncurses. | Frederic Cambus | |
This is a backported patch [1] from ncurses-5.7-20100501. It takes begx and begy values into account when calculating lengths, in order to avoid writing data past the end of the buffer when calling memset in wredrawln(). From upstream NEWS file: 20100501 + correct limit-check in wredrawln, accounting for begy/begx values (patch by David Benjamin). [1] https://lists.gnu.org/archive/html/bug-ncurses/2010-04/msg00017.html OK nicm@ | |||
2019-11-15 | our older gcc requires forced -std=c99 | Theo de Raadt | |
2019-11-14 | LDADD for libcbor and libusbhid | Damien Miller | |
2019-11-14 | extra whitespace | Theo de Raadt | |
2019-11-14 | add libcbor and libfido2 | Damien Miller | |
2019-11-14 | import libfido2 (git HEAD). This library allows communication with | Damien Miller | |
U2F/FIDO2 devices over USB. feedback and "start the churn" deraadt@ | |||
2019-11-14 | Add libcbor; an implementation of the Concise Binary Object | Damien Miller | |
Representation (CBOR) encoding format defined in RFC7049. This is a dependency of libfido2, that we'll use for U2F/FIDO support in OpenSSH. feedback and "Looks good enough to me" deraadt@ | |||
2019-11-14 | Add missing cross-reference to NOTES section. | Todd C. Miller | |
OK kn@ tb@ | |||
2019-11-12 | Now that libc.so has only five PLT entries on almost all our archs, | Philip Guenther | |
link it with -znow ok kettenis@ deraadt@ jca@ | |||
2019-11-10 | Mark as 'protected' all the routines from the quad/ and softfloat/ subdirs, | Philip Guenther | |
as well as those in arch/arm/gen/divsi3.S. This cleans up the PLTs on the 32bit archs. luna88k testing by aoyama@ "looks good" kettenis@, testing and ok deraadt@ | |||
2019-11-05 | MPLSCTL_MAXINKLOOP (net.mpls.maxloop_inkernel) was removed. Adjust manpage. | Claudio Jeker | |
2019-11-04 | Allow ip addresses as argument to SSL_set1_host() but be careful to not | Otto Moerbeek | |
poison the context. ok and help jsing@ tb@ | |||
2019-11-04 | Reshuffle RSA_PSS_PARAMS and RSA_OAEP_PARAMS to avoid duplicate typedef. | Joel Sing | |
Issue spotted by bcook@ ok bcook@ inoguchi@ | |||
2019-11-02 | Sort standard_methods by pkey_id. | Kinichiro Inoguchi | |
ok jsing@ | |||
2019-11-02 | CMS didn't make the 6.6 release: adjust the text in the HISTORY sections | Ingo Schwarze | |
2019-11-02 | .Xr CMS_ContentInfo_new 3 | Ingo Schwarze | |
2019-11-02 | .Xr BIO_new_CMS 3 | Ingo Schwarze | |
2019-11-02 | document PEM_read_CMS(3), PEM_read_bio_CMS(3), PEM_write_CMS(3), and | Ingo Schwarze | |
PEM_write_bio_CMS(3) which jsing@ just enabled in Symbols.list rev. 1.91 | |||
2019-11-02 | In Symbols.list rev. 1.91, jsing enabled many CMS functions. | Ingo Schwarze | |
Install the new manual pages documenting the majority of them. | |||
2019-11-02 | Bring back some icky buffer allocation code so that pkey_rsa_print() | Joel Sing | |
works again with the horrific API that is ASN1_bn_print(). Issue spotted by inoguchi@ | |||
2019-11-02 | Bump libcrypto, libssl and libtls minors due to symbol additions. | Joel Sing | |
2019-11-02 | Provide RSA_PKCS1_OpenSSL(). | Joel Sing | |
Prompted by inoguchi@ | |||
2019-11-02 | Make RSA_padding_{add,check}_PKCS1_OAEP_mgf1() public. | Joel Sing | |
2019-11-02 | Make RSA_OAEP_PARAMs public. | Joel Sing | |
2019-11-02 | Document tls_conn_cipher_strength(). | Joel Sing | |
ok schwarze@ | |||
2019-11-02 | Enable CMS in LibreSSL. | Joel Sing | |
ok bcook@ deraadt@ inoguchi@ job@ tb@ | |||
2019-11-02 | Provide tls_conn_cipher_strength(). | Joel Sing | |
This returns the strength in bits of the symmetric cipher used for the connection. Diff from gilles@ ok tb@ | |||
2019-11-01 | In evp/pmeth_lib.c rev. 1.16, jsing@ enabled EVP_PKEY_RSA_PSS. | Ingo Schwarze | |
Document it. | |||
2019-11-01 | In rsa.h rev. 1.45, jsing@ provided | Ingo Schwarze | |
the three macro constants RSA_PSS_SALTLEN_*; document them. The wording is a combination of our existing text and the wording in the OpenSSL 1.1.1 branch, which is still under a free license. | |||
2019-11-01 | Remove duplicated header. | Martin Pieuchot | |
2019-11-01 | Add DSA CMS support. | Joel Sing | |
From OpenSSL 1.1.1d. ok tb@ | |||
2019-11-01 | Add RSA CMS support. | Joel Sing | |
From OpenSSL 1.1.1d. ok tb@ |