summaryrefslogtreecommitdiff
path: root/usr.bin/openssl
AgeCommit message (Collapse)Author
2019-11-28Add manual for openssl(1) cmsKinichiro Inoguchi
ok and comments jmc@
2019-11-19More return value check in openssl(1) cmsKinichiro Inoguchi
Checking return value of sk_.*_new_null(). ok beck@ jsing@
2019-11-19Add manual descriptions for openssl(1) req -addextKinichiro Inoguchi
ok jmc@
2019-11-18Remove typedef and check sk_push return value in openssl(1) cmsKinichiro Inoguchi
- Remove typedef and use 'struct cms_key_param' instead - Check return value of sk_X509_push and sk_OPENSSL_STRING_push - Add a blank line to separate variable declarations from code comments from jsing@
2019-11-18Add -keyopt opiton to openssl(1) cms subcommandKinichiro Inoguchi
This provides rsa_padding_mode:oaep for cms -encrypt, and rsa_padding_mode:pss for cms -sign. ok jsing@
2019-11-06Check return value and remove unnecessary variableKinichiro Inoguchi
- Check NCONF_new() return value - Remove unnecessary 'i' comments from jsing@
2019-11-06Add -addext option to openssl(1) req subcommandKinichiro Inoguchi
First step of adding -addext option to openssl(1) req from OpenSSL 1.1.1d. ok jsing@
2019-11-04Indent labels for diffability.Joel Sing
2019-11-04Remove spaces between * and variable names.Joel Sing
2019-11-04Remove explicit NULL checks before *_free() calls.Joel Sing
2019-11-04Hook openssl(1) cms back up.Joel Sing
2019-11-04Currently we need to include pem.h before cms.h...Joel Sing
2019-11-04Remove engine argument from load_cert() calls.Joel Sing
This was cleaned up after cms went to the attic.
2019-11-04Bring openssl(1) cms back from the attic.Joel Sing
2019-10-04Avoid a path traversal bug in s_server on Windows.Brent Cook
openssl s_server has an arbitrary read vulnerability on Windows when run with the -WWW or -HTTP options, due to an incomplete path check logic. Thanks to Jobert Abma for reporting. ok tb@
2019-10-04the formatting for the mini synopses in this page did not render wellJason McIntyre
on html or groff. the solution, to replace the non-standard .nr macros with a hang list, was provided by ingo - thanks! ok schwarze
2019-08-30Remove unnecessary NULL check before free function in openssl(1) dgstKinichiro Inoguchi
2019-08-30Wrap lines over 80 cols and put space before goto label in openssl(1) dgstKinichiro Inoguchi
2019-08-30Simplify checking and more readable descriptions in openssl(1) dgstKinichiro Inoguchi
suggested from jsing@
2019-08-30Convert openssl(1) dgst to the newer style of option handlingKinichiro Inoguchi
Adapt openssl(1) dgst command to new option handling. Added dgst_options struct and option handlers, and replaced for-if-strcmp handling with options_parse(). ok bcook@ jsing@
2019-08-05Remove -port option from s_server since it is same as -acceptKinichiro Inoguchi
ok schwarze@
2019-07-29Moving variables into struct in openssl(1) dgstKinichiro Inoguchi
First step to adapt openssl(1) dgst command to new option handling. There is no functional changes by this diff, and just moving variables into dgst_config struct. ok bcook@
2019-07-26Code clean up openssl(1) pkcs12Kinichiro Inoguchi
- Add a space before 'export_end:' - Remove space after '*' - Wrap lines by 80 columns
2019-07-26Remove unnecessary NULL checks before free in openssl(1) pkcs12Kinichiro Inoguchi
ok bcook@ tb@
2019-07-25remove superfluous commentBrent Cook
2019-07-25zero tmpkeyiv buffer after use when encryptingBrent Cook
from Steven Roberts
2019-07-24Capitalize cipher name and mode in help message as sync with pkcs12Kinichiro Inoguchi
2019-07-24Convert openssl(1) pkcs12 to the newer style of option handlingKinichiro Inoguchi
Adapt openssl(1) pkcs12 command to new option handling. Added pkcs12_options struct, and replaced for-if-strcmp handling with options_parse(). ok and comments jsing@
2019-07-23Moving variables into struct in openssl(1) pkcs12Kinichiro Inoguchi
First step to adapt openssl(1) pkcs12 command to new option handling. There is no functional changes by this diff, and just moving variables into pkcs12_config struct. I still keep long lines more than 80 for this review to minimize diffs. ok jsing@ tb@
2019-07-16Fix long line by wrapping with 80 charsKinichiro Inoguchi
2019-07-16Move option handlers up to option definition struct in gendsa.cKinichiro Inoguchi
As we did in other openssl sub command, move up option handlers above option definition struct. No functional changes and just move up and remove prototype.
2019-07-16Fix typo and -keyform argument in openssl(1) manualKinichiro Inoguchi
- s/outputed/outputted/ - s/trused/trusted/ - add der as argument and describe pem is the default
2019-07-14Mark the initialized struct options arrays as both static and const.Philip Guenther
This moves them from .data to .data.rel.ro ok deraadt@ inoguchi@
2019-07-12Fix manual openssl(1) s_serverKinichiro Inoguchi
- Add undocumented options below. -alpn, -cert2, -certform, -dcertform, -dkeyform, -dpass, -dtls1, -key2, -keyform, -keymatexport, -keymatexportlen, -mtu, -named_curve, -no_cache, -no_ecdhe, -no_ticket, -pass, -port, -servername, -servername_fatal, -status, -status_timeout, -status_url, -status_verbose, -timeout, -tlsextdebug, -use_srtp, -verify_return_error - Remove -hack, -psk and -psk_hint since not exist in source code. I didn't add these 5 options since these were no-op. -chain, -legacy_renegotiation, -nextprotoneg, -no_comp, -no_ssl2 This option was removed from manual in the past. -no_ssl3 ok and suggestions from jmc@
2019-07-11Fix manual openssl(1) s_clientKinichiro Inoguchi
- Add undocumented options below. -alpn, -certform, -dtls1, -host, -keyform, -keymatexport, -keymatexportlen, -legacy_server_connect, -mtu, -no_ign_eof, -no_legacy_server_connect, -pass -port, -serverpref, -sess_in, -sess_out, -status, -timeout, -use_srtp, -verify_return_error - Remove -psk and -psk_identity since not exist in source code. I didn't add these 4 options since these were no-op. -nextprotoneg, -legacy_renegotiation, -no_comp, -no_ssl2 This option was removed from manual in the past. -no_ssl3 ok jmc@
2019-07-10Add missing option openssl dsa -modulusKinichiro Inoguchi
ok bcook@ jsing@
2019-07-09Fix manual openssl(1) genrsaKinichiro Inoguchi
Add missing -camellia*/-idea description to genrsa section. ok jmc@
2019-07-09Convert openssl(1) genrsa to the newer style of option handlingKinichiro Inoguchi
ok tb@ jsing@
2019-07-08Fix manual openssl(1) dsa, ocsp, rsa and smimeKinichiro Inoguchi
- dsa : add missing -pvk-none, -pvk-strong and -pvk-weak add pvk format to -inform and -outform - ocsp : add missing -header, -ignore_err, -no_explicit and -timeout - rsa : add missing -pvk-none, -pvk-strong and -pvk-weak add missing -RSAPublicKey_in and -RSAPublicKey_out add pvk format to -inform and -outform - smime : add missing -nosmimecap - add pvk description at common format part ok jmc@
2019-07-07Fix manual openssl(1) pkcs12, req, verify and x509Kinichiro Inoguchi
- For pkcs12, add -camellia*/-idea, -LMK and -password - For req, add -multivalue-rdn, -pkeyopt and -sigopt - For verify, add -CRLfile and -trusted, and down -check_ss_sig description - For x509, add -next_serial and -sigopt - Remove the escape in -multivalue-rdn from ca section ok jmc@
2019-07-05Fix manual openssl(1) ec, enc and pkcs7Kinichiro Inoguchi
- For ec, add -param_out description - For enc, add -v usage and description - For pkcs7, add -print usage and description ok jmc@
2019-07-05Fix manual openssl(1) dgstKinichiro Inoguchi
- Add undocumented option -r ok jmc@
2019-07-04Fix manual openssl(1) crlKinichiro Inoguchi
- Add undocumented options -crlnumber, -hash_old, -nameopt and -verify ok jmc@
2019-07-04Fix manual openssl(1) caKinichiro Inoguchi
- Add undocumented options -crlsec and -sigopt - Sync argument name between usage and options description ok jmc@
2019-07-03snprintf/vsnprintf return < 0 on error, rather than -1.Theo de Raadt
2019-06-28When system calls indicate an error they return -1, not some arbitraryTheo de Raadt
value < 0. errno is only updated in this case. Change all (most?) callers of syscalls to follow this better, and let's see if this strictness helps us in the future.
2019-06-19Move variables into struct in openssl(1) genrsaKinichiro Inoguchi
- Move local variables in genrsa_main() to struct genrsa_config - Leave long lines more than 80, still ok bcook@
2019-06-07tidy up the formatting of gendsa synopsis a little;Jason McIntyre
2019-06-07Convert openssl(1) gendsa to the newer style of option handlingKinichiro Inoguchi
- Adapt openssl(1) gendsa command to new option handling. - Add lacking ciphers and passout description in openssl.1 manpage. - Describe paramfile as argument in openssl.1 manpage. ok bcook@
2019-04-01Sort.Joel Sing