Age | Commit message (Expand) | Author |
2020-01-25 | Correct backwards test so that we may accept a certificate requst | Bob Beck |
2020-01-24 | Document `kern.allowdt' button. | Martin Pieuchot |
2020-01-24 | Complete the initial TLSv1.3 implementation. | Joel Sing |
2020-01-24 | Preserve the TLS transcript at additional points. | Joel Sing |
2020-01-24 | Permit 0 length writes, because openssl s_client is special | Bob Beck |
2020-01-24 | Store the legacy session identifier from the ClientHello so we can actually | Joel Sing |
2020-01-24 | Switch to encrypted records in the TLSv1.3 server. | Joel Sing |
2020-01-24 | Enable SSL_ENC_FLAG_SIGALGS on TLSv1_3_enc_data. | Joel Sing |
2020-01-24 | Add strings for SSL_aTLS1_3 and SSL_kTLS1_3 to SSL_CIPHER_description(). | Joel Sing |
2020-01-24 | Fix breakage in SSL_connect, SSL_accept, etc. by not propagating | Bob Beck |
2020-01-23 | Implement client hello processing in the TLSv1.3 server. | Joel Sing |
2020-01-23 | Correct several issues in the current TLSv1.3 server code. | Joel Sing |
2020-01-23 | When certificate validation fails, we must send a DECRYPT_ERROR alert | Bob Beck |
2020-01-23 | Remove the ssl_get_message function pointer from SSL_METHOD_INTERNAL. | Joel Sing |
2020-01-23 | Implement sending client certificate requests for 1.3 server | Bob Beck |
2020-01-23 | Correctly handle TLSv1.3 ciphers suites in ssl3_choose_cipher(). | Joel Sing |
2020-01-23 | Build the encrypted extensions for the 1.3 server | Bob Beck |
2020-01-23 | If we are building a legacy server hello, check to see if we are | Bob Beck |
2020-01-23 | Add checking int the client to check the magic values which are | Bob Beck |
2020-01-23 | Add code to build and send a server hello for tls 1.3 | Bob Beck |
2020-01-23 | Save the legacy session id in the client, and enforce that it is returned | Bob Beck |
2020-01-23 | Implement pending for TLSv1.3. | Joel Sing |
2020-01-23 | Remove lies from the SSL_pending man page, Our implementation never | Bob Beck |
2020-01-23 | Switch back to a function pointer for ssl_pending. | Joel Sing |
2020-01-23 | Add a TLS13_IO_ALERT return value so that we can explicitly signal when | Joel Sing |
2020-01-23 | Pass a CBB to TLSv1.3 send handlers. | Joel Sing |
2020-01-22 | The length of the IV of EVP_chacha20 is currently 64 bits, not 96. | Theo Buehler |
2020-01-22 | Wire up the TLSv1.3 server. | Joel Sing |
2020-01-22 | Pass a handshake message content CBS to TLSv1.3 receive handlers. | Joel Sing |
2020-01-22 | Fix things so that `make -DTLS1_3` works again. | Joel Sing |
2020-01-22 | Send alerts on certificate verification failures of server certs | Bob Beck |
2020-01-22 | Rename failure into alert_desc in tlsext_ocsp_server_parse(). | Theo Buehler |
2020-01-22 | fix previous: alert_desc needs to be an int. | Theo Buehler |
2020-01-22 | Avoid modifying alert in the success path. | Theo Buehler |
2020-01-22 | Enable the TLSv1.3 client in libssl. | Joel Sing |
2020-01-22 | Correct includes check for libtls. | Joel Sing |
2020-01-22 | Add checks to ensure that lib{crypto,ssl,tls} public headers have actually | Joel Sing |
2020-01-22 | delete wasteful ;; | Theo de Raadt |
2020-01-22 | Move guards from public to internal headers, and fix not use values. | Bob Beck |
2020-01-22 | Simplify header installation by combining the HDRS and HDRS_GEN loops. | Joel Sing |
2020-01-22 | Note in the man page that the default protocols list includes 1.3 | Bob Beck |
2020-01-22 | Enable TLS version 1.3 in the default protocols for libtls. | Bob Beck |
2020-01-22 | Implement support for SSL_peek() in the TLSv1.3 record layer. | Joel Sing |
2020-01-22 | After the ClientHello has been sent or received and before the peer's | Theo Buehler |
2020-01-22 | Correctly set the legacy version when TLSv1.3 is building a client hello. | Joel Sing |
2020-01-22 | Don't add an extra unknown error if we got a fatal alert | Bob Beck |
2020-01-22 | The legacy_record_version must be set to TLS1_2_VERSION except | Theo Buehler |
2020-01-22 | Hook up the TLSv1.3 legacy shutdown code. | Joel Sing |
2020-01-22 | Add minimal support for hello retry request for RFC conformance. | Bob Beck |
2020-01-22 | Split the TLSv1.3 guards into separate client and server guards. | Joel Sing |