summaryrefslogtreecommitdiffstats
path: root/ssl (follow)
Commit message (Expand)AuthorAgeFilesLines
...
* Restore sensible "sess_accept" counter trackingBenjamin Kaduk2018-11-041-1/+1
* Don't call the client_cert_cb immediately in TLSv1.3Matt Caswell2018-10-302-1/+24
* ssl/statem: Don't compare size_t with less than zeroRichard Levitte2018-10-292-4/+7
* Add automatic initializations support for EVP_MAC objectsRichard Levitte2018-10-291-1/+2
* Properly handle duplicated messages from the next epochMatt Caswell2018-10-261-4/+1
* Buffer a ClientHello with a cookie received via DTLSv1_listenMatt Caswell2018-10-193-28/+47
* Use the read and write buffers in DTLSv1_listen()Matt Caswell2018-10-193-30/+19
* Fix a DTLS memory leakMatt Caswell2018-10-191-1/+3
* Fix tls_cbc_digest_record is slow using SHA-384 and short messagesarmfazh2018-10-191-2/+3
* Add a missing check on s->s3->tmp.pkeyMansour Ahmadi2018-10-171-0/+6
* ssl/s3_enc.c: fix logical errors in ssl3_final_finish_mac.Andy Polyakov2018-10-121-3/+5
* Remove SSL_version_strRichard Levitte2018-10-031-2/+0
* Fix no-pskMatt Caswell2018-09-251-1/+5
* Reduce stack usage in tls13_hkdf_expandBernd Edlinger2018-09-241-4/+12
* Fix the max psk len for TLSv1.3Matt Caswell2018-09-211-1/+1
* Delay setting the sig algs until after the cert_cb has been calledMatt Caswell2018-09-211-15/+17
* Reset TLS 1.3 ciphers in SSL_CTX_set_ssl_version()Benjamin Kaduk2018-09-191-0/+4
* ssl/ssl_ciph.c: make set_ciphersuites staticDr. Matthias St. Pierre2018-09-182-2/+1
* Fix a possible recursion in SSLfatal handlingBernd Edlinger2018-09-121-2/+3
* Update copyright yearMatt Caswell2018-09-111-1/+1
* Do not reset SNI data in SSL_do_handshake()Matt Caswell2018-09-072-7/+5
* Simplify SSL_get_servername() to avoid session referencesBen Kaduk2018-09-071-11/+7
* Restore historical SSL_get_servername() behaviorBen Kaduk2018-09-071-5/+2
* Ensure certificate callbacks work correctly in TLSv1.3Matt Caswell2018-09-071-2/+3
* Process KeyUpdate and NewSessionTicket messages after a close_notifyMatt Caswell2018-09-073-27/+49
* key zeroization fix for a branch path of tls13_final_finish_macShane Lontis2018-09-041-0/+1
* Don't use an RSA-PSS cert for RSA key exchangeMatt Caswell2018-09-041-3/+7
* Send a NewSessionTicket after using an external PSKMatt Caswell2018-09-041-0/+2
* Ignore EPIPE when sending NewSessionTickets in TLSv1.3Matt Caswell2018-09-041-1/+32
* Rename SSL[_CTX]_add1_CA_list -> SSL[_CTX]_add1_to_CA_listRichard Levitte2018-09-031-2/+6
* Fix ssl/t1_trce.c to parse certificate chainsErik Forsberg2018-09-011-10/+17
* Fix a mem leak on error in the PSK codeMatt Caswell2018-08-301-0/+1
* Don't detect a downgrade where the server has a protocol version holeMatt Caswell2018-08-221-3/+10
* Use the same min-max version range on the client consistentlyMatt Caswell2018-08-225-63/+79
* Allow TLS-1.3 ciphersuites in @SECLEVEL=3 and aboveTomas Mraz2018-08-221-1/+2
* Add support for SSL_CTX_set_post_handshake_auth()Matt Caswell2018-08-202-0/+9
* Change Post Handshake auth so that it is opt-inMatt Caswell2018-08-203-20/+5
* Turn on TLSv1.3 downgrade protection by defaultMatt Caswell2018-08-152-4/+2
* Update code for the final RFC version of TLSv1.3 (RFC8446)Matt Caswell2018-08-155-67/+5
* Move SSL_DEBUG md fprintf after assignmentDmitry Yakovlev2018-08-141-3/+5
* Improve fallback protectionMatt Caswell2018-08-091-0/+3
* Tolerate encrypted or plaintext alertsMatt Caswell2018-08-086-14/+44
* Ensure that we write out alerts correctly after early_dataMatt Caswell2018-08-087-15/+36
* Fix a missing call to SSLfatalMatt Caswell2018-08-081-9/+13
* Fix setting of ssl_strings_inited.Rich Salz2018-08-071-1/+1
* ssl/*: switch to switch to Thread-Sanitizer-friendly primitives.Andy Polyakov2018-08-076-80/+49
* Harmonize use of sk_TYPE_find's return value.Andy Polyakov2018-08-071-4/+1
* Ensure we send an alert on error when processing a ticketMatt Caswell2018-08-061-4/+10
* Fix some TLSv1.3 alert issuesMatt Caswell2018-07-312-1/+6
* Improve backwards compat for SSL_get_servername()Benjamin Kaduk2018-07-261-1/+4