https://github.com/openssl/openssl

sort by:
Revision Author Date Message Commit Date
2b45603 Prepare for 1.0.1i release Reviewed-by: Stephen Henson <steve@openssl.org> 06 August 2014, 21:18:45 UTC
d70c0be make update Reviewed-by: Stephen Henson <steve@openssl.org> 06 August 2014, 21:18:45 UTC
9b649d9 update NEWS Reviewed-by: Kurt Roeckx <kurt@openssl.org> 06 August 2014, 19:33:25 UTC
abbd585 update CHANGES Reviewed-by: Kurt Roeckx <kurt@openssl.org> 06 August 2014, 19:33:25 UTC
d15d17b Check SRP parameters early. Check SRP parameters when they are received so we can send back an appropriate alert. Reviewed-by: Kurt Roeckx <kurt@openssl.org> 06 August 2014, 19:27:51 UTC
966fe81 Fix SRP buffer overrun vulnerability. Invalid parameters passed to the SRP code can be overrun an internal buffer. Add sanity check that g, A, B < N to SRP code. Thanks to Sean Devlin and Watson Ladd of Cryptography Services, NCC Group for reporting this issue. Reviewed-by: Kurt Roeckx <kurt@openssl.org> 06 August 2014, 19:27:51 UTC
83764a9 Fix SRP ciphersuite DoS vulnerability. If a client attempted to use an SRP ciphersuite and it had not been set up correctly it would crash with a null pointer read. A malicious server could exploit this in a DoS attack. Thanks to Joonas Kuorilehto and Riku Hietamäki from Codenomicon for reporting this issue. CVE-2014-5139 Reviewed-by: Tim Hudson <tjh@openssl.org> 06 August 2014, 19:27:51 UTC
86788e1 Fix race condition in ssl_parse_serverhello_tlsext CVE-2014-3509 Reviewed-by: Tim Hudson <tjh@openssl.org> Reviewed-by: Dr. Stephen Henson <steve@openssl.org> 06 August 2014, 19:27:51 UTC
03b04dd Fix OID handling: - Upon parsing, reject OIDs with invalid base-128 encoding. - Always NUL-terminate the destination buffer in OBJ_obj2txt printing function. CVE-2014-3508 Reviewed-by: Dr. Stephen Henson <steve@openssl.org> Reviewed-by: Kurt Roeckx <kurt@openssl.org> Reviewed-by: Tim Hudson <tjh@openssl.org> 06 August 2014, 19:27:51 UTC
88ae012 Fix DTLS anonymous EC(DH) denial of service CVE-2014-3510 Reviewed-by: Dr. Stephen Henson <steve@openssl.org> 06 August 2014, 19:27:51 UTC
fc4f4cd Fix protocol downgrade bug in case of fragmented packets CVE-2014-3511 Reviewed-by: Emilia Käsper <emilia@openssl.org> Reviewed-by: Bodo Möller <bodo@openssl.org> 06 August 2014, 19:27:51 UTC
4e0fbdc Remove some duplicate DTLS code. In a couple of functions, a sequence number would be calculated twice. Additionally, in |dtls1_process_out_of_seq_message|, we know that |frag_len| <= |msg_hdr->msg_len| so the later tests for |frag_len < msg_hdr->msg_len| can be more clearly written as |frag_len != msg_hdr->msg_len|, since that's the only remaining case. Reviewed-by: Matt Caswell <matt@openssl.org> Reviewed-by: Emilia Käsper <emilia@openssl.org> 06 August 2014, 19:27:51 UTC
0c37aed Applying same fix as in dtls1_process_out_of_seq_message. A truncated DTLS fragment would cause *ok to be clear, but the return value would still be the number of bytes read. Problem identified by Emilia Käsper, based on previous issue/patch by Adam Langley. Reviewed-by: Emilia Käsper <emilia@openssl.org> 06 August 2014, 19:27:51 UTC
099ccdb Fix return code for truncated DTLS fragment. Previously, a truncated DTLS fragment in |dtls1_process_out_of_seq_message| would cause *ok to be cleared, but the return value would still be the number of bytes read. This would cause |dtls1_get_message| not to consider it an error and it would continue processing as normal until the calling function noticed that *ok was zero. I can't see an exploit here because |dtls1_get_message| uses |s->init_num| as the length, which will always be zero from what I can see. Reviewed-by: Matt Caswell <matt@openssl.org> Reviewed-by: Emilia Käsper <emilia@openssl.org> 06 August 2014, 19:27:51 UTC
9871417 Fix memory leak from zero-length DTLS fragments. The |pqueue_insert| function can fail if one attempts to insert a duplicate sequence number. When handling a fragment of an out of sequence message, |dtls1_process_out_of_seq_message| would not call |dtls1_reassemble_fragment| if the fragment's length was zero. It would then allocate a fresh fragment and attempt to insert it, but ignore the return value, leaking the fragment. This allows an attacker to exhaust the memory of a DTLS peer. Fixes CVE-2014-3507 Reviewed-by: Matt Caswell <matt@openssl.org> Reviewed-by: Emilia Käsper <emilia@openssl.org> 06 August 2014, 19:27:51 UTC
fc7804e Fix DTLS handshake message size checks. In |dtls1_reassemble_fragment|, the value of |msg_hdr->frag_off+frag_len| was being checked against the maximum handshake message size, but then |msg_len| bytes were allocated for the fragment buffer. This means that so long as the fragment was within the allowed size, the pending handshake message could consume 16MB + 2MB (for the reassembly bitmap). Approx 10 outstanding handshake messages are allowed, meaning that an attacker could consume ~180MB per DTLS connection. In the non-fragmented path (in |dtls1_process_out_of_seq_message|), no check was applied. Fixes CVE-2014-3506 Wholly based on patch by Adam Langley with one minor amendment. Reviewed-by: Emilia Käsper <emilia@openssl.org> 06 August 2014, 19:27:51 UTC
e7b9d9b Added comment for the frag->reassembly == NULL case as per feedback from Emilia Reviewed-by: Emilia Käsper <emilia@openssl.org> 06 August 2014, 19:27:51 UTC
2172d4f Avoid double free when processing DTLS packets. The |item| variable, in both of these cases, may contain a pointer to a |pitem| structure within |s->d1->buffered_messages|. It was being freed in the error case while still being in |buffered_messages|. When the error later caused the |SSL*| to be destroyed, the item would be double freed. Thanks to Wah-Teh Chang for spotting that the fix in 1632ef74 was inconsistent with the other error paths (but correct). Fixes CVE-2014-3505 Reviewed-by: Matt Caswell <matt@openssl.org> Reviewed-by: Emilia Käsper <emilia@openssl.org> 06 August 2014, 19:27:51 UTC
c34091d make update Reviewed-by: Tim Hudson <tjh@openssl.org> 01 August 2014, 20:23:49 UTC
a9f4ebd Fix error discrepancy. We can't rename ssleay_rand_bytes to md_rand_bytes_lock as this will cause an error code discrepancy. Instead keep ssleay_rand_bytes and add an extra parameter: since ssleay_rand_bytes is not part of the public API this wont cause any binary compatibility issues. Reviewed-by: Kurt Roeckx <kurt@openssl.org > (cherry picked from commit 8068a675a7d1a657c54546f24e673e59e6707f03) 01 August 2014, 17:42:40 UTC
604c994 Update $default_depflags to match current defaults. 01 August 2014, 17:07:57 UTC
281720c Simplify and fix ec_GFp_simple_points_make_affine (which didn't always handle value 0 correctly). Reviewed-by: emilia@openssl.org Conflicts: CHANGES 01 August 2014, 15:50:26 UTC
2a9023f Avoid multiple lock using FIPS DRBG. Don't use multiple locks when SP800-90 DRBG is used outside FIPS mode. PR#3176 Reviewed-by: Rich Salz <rsalz@openssl.org> (cherry picked from commit a3efe1b6e9d2aa2ce5661e4d4b97262eae743fa7) 30 July 2014, 20:09:20 UTC
36e8c39 Add conditional unit testing interface. Don't call internal functions directly call them through SSL_test_functions(). This also makes unit testing work on Windows and platforms that don't export internal functions from shared libraries. By default unit testing is not enabled: it requires the compile time option "enable-unit-test". Reviewed-by: Geoff Thorpe <geoff@openssl.org> (cherry picked from commit e0fc7961c4fbd27577fb519d9aea2dc788742715) Conflicts: ssl/Makefile util/mkdef.pl 24 July 2014, 18:43:25 UTC
e3f009c "EC_POINT_invert" was checking "dbl" function pointer instead of "invert". PR#2569 Reviewed-by: Rich Salz <rsalz@openssl.org> (cherry picked from commit cba11f57ce161fd301a72194827327128191de7e) 21 July 2014, 21:28:40 UTC
fbe3baa Remove old unused and unmaintained demonstration code. Reviewed-by: Dr. Stephen Henson <steve@openssl.org> (cherry picked from commit 62352b8138018775a4c085a105fccd9cdcb6323f) 21 July 2014, 21:26:35 UTC
690998f Minor documentation update removing "really" and a statement of opinion rather than a fact. Reviewed-by: Dr. Stephen Henson <steve@openssl.org> Reviewed-by: Rich Salz <rsalz@openssl.org> (cherry picked from commit c8d133e4b6f1ed1b7ad3c1a6d2c62f460e26c050) 21 July 2014, 10:24:47 UTC
3221da8 Fix documentation for RSA_set_method(3) PR#1675 Reviewed-by: Matt Caswell <matt@openssl.org> (cherry picked from commit 197400c3f0d617d71ad8167b52fb73046d334320) 19 July 2014, 17:26:12 UTC
9aeb410 Fix typo, add reference. PR#3456 Reviewed-by: Stephen Henson <steve@openssl.org> Reviewed-by: Matt Caswell <matt@openssl.org> (cherry picked from commit d48e78f0cf22aaddb563f4bcfccf25b1a45ac8a4) 17 July 2014, 11:08:52 UTC
bf4519c Disabled XTS mode in enc utility as it is not supported PR#3442 Reviewed-by: Tim Hudson <tjh@openssl.org> Reviewed-by: Rich Salz <rsalz@openssl.org> (cherry picked from commit 2097a17c576f2395a10b05f14490688bc5f45a07) 16 July 2014, 20:05:10 UTC
e967b94 Add Matt Caswell's fingerprint, and general update on the fingerprints file to bring it up to date Reviewed-by: Tim Hudson <tjh@openssl.org> (cherry picked from commit 3bd548192a03142c80cf8bc68659d79dea20a738) 15 July 2014, 22:24:26 UTC
2316286 Clarify -Verify and PSK. PR#3452 (cherry picked from commit ca2015a617842fed3d36ed4dcbbf8d5e27bc5216) 15 July 2014, 19:23:35 UTC
67bde7d Fix DTLS certificate requesting code. Use same logic when determining when to expect a client certificate for both TLS and DTLS. PR#3452 (cherry picked from commit c8d710dc5f83d69d802f941a4cc5895eb5fe3d65) 15 July 2014, 17:23:44 UTC
cd63f94 Don't allow -www etc options with DTLS. The options which emulate a web server don't make sense when doing DTLS. Exit with an error if an attempt is made to use them. PR#3453 (cherry picked from commit 58a2aaeade8bdecd0f9f0df41927f7cff3012547) 15 July 2014, 11:25:39 UTC
2054eb7 Add ECC extensions with DTLS. PR#3449 15 July 2014, 11:20:30 UTC
ea0ceb1 Use case insensitive compare for servername. PR#3445 (cherry picked from commit 1c3e9a7c67ccdc5e770829fe951e5832e600d377) 14 July 2014, 23:00:03 UTC
00579b9 document -nextprotoneg option in man pages Add description of the option to advertise support of Next Protocol Negotiation extension (-nextprotoneg) to man pages of s_client and s_server. PR#3444 (cherry picked from commit 7efd0e777e65eaa6c60d85b1cc5c889f872f8fc4) Conflicts: doc/apps/s_server.pod 14 July 2014, 22:43:58 UTC
ee5a8d3 Use more common name for GOST key exchange. (cherry picked from commit 7aabd9c92fe6f0ea2a82869e5171dcc4518cee85) 14 July 2014, 17:31:54 UTC
7237016 Fixed valgrind complaint due to BN_consttime_swap reading uninitialised data. This is actually ok for this function, but initialised to zero anyway if PURIFY defined. This does have the impact of masking any *real* unitialised data reads in bn though. Patch based on approach suggested by Rich Salz. PR#3415 (cherry picked from commit 77747e2d9a5573b1dbc15e247ce18c03374c760c) 13 July 2014, 21:23:10 UTC
704422c Add names of GOST algorithms. PR#3440 (cherry picked from commit 924e5eda2c82d737cc5a1b9c37918aa6e34825da) 13 July 2014, 17:31:36 UTC
8e8d7e1 * crypto/ui/ui_lib.c: misplaced brace in switch statement. Detected by dcruette@qualitesys.com (cherry picked from commit 8b5dd340919e511137696792279f595a70ae2762) 13 July 2014, 17:15:30 UTC
3ed6327 Don't clean up uninitialised EVP_CIPHER_CTX on error (CID 483259). (cherry picked from commit c1d1b0114e9d370c30649e46182393dbfc00e20c) 10 July 2014, 16:52:37 UTC
efd4f1d Fix memory leak in BIO_free if there is no destroy function. Based on an original patch by Neitrino Photonov <neitrinoph@gmail.com> PR#3439 (cherry picked from commit 66816c53bea0ecddb9448da7ea9a51a334496127) 09 July 2014, 22:34:35 UTC
00032b0 Prevent infinite loop loading config files. PR#2985 (cherry picked from commit 9d23f422a32cb333a5e803199ae230706b1bf9f5) 07 July 2014, 12:50:00 UTC
a07f514 Usage for -hack and -prexit -verify_return_error (cherry picked from commit ee724df75d9ad67fd954253ac514fddb46f1e3c6) 06 July 2014, 21:48:57 UTC
b197c77 Document certificate status request options. (cherry picked from commit cba3f1c739f012aaadb85aaefaf8de424d2695e2) Conflicts: doc/apps/s_client.pod doc/apps/s_server.pod 06 July 2014, 21:48:52 UTC
b7c9762 s_server usage for certificate status requests (cherry picked from commit a44f219c009798054d6741e919cba5b2e656dbf4) 06 July 2014, 21:45:44 UTC
a414bc8 Update ticket callback docs. (cherry picked from commit a23a6e85d8dcd5733a343754f434201f3c9aa6f0) 06 July 2014, 11:42:27 UTC
98a3c3c Sanity check keylength in PVK files. PR#2277 (cherry picked from commit 733a6c882e92f8221bd03a51643bb47f5f81bb81) 05 July 2014, 23:36:11 UTC
157fd05 Added reference to platform specific cryptographic acceleration such as AES-NI 05 July 2014, 23:04:32 UTC
9f510ce Fixed error in pod files with latest versions of pod2man (cherry picked from commit 07255f0a76d9d349d915e14f969b9ff2ee0d1953) 05 July 2014, 23:04:32 UTC
675b1c2 Return smaller of ret and f. PR#3418. (cherry picked from commit fdea4fff8fb058be928980600b24cf4c62ef3630) 05 July 2014, 21:38:44 UTC
c923132 Don't limit message sizes in ssl3_get_cert_verify. PR#319 (reoponed version). (cherry picked from commit 7f6e9578648728478e84246fd3e64026b8b6a48e) 05 July 2014, 12:30:55 UTC
1864e3b typo (cherry picked from commit 2cfbec1caea8f9567bdff85d33d22481f2afb40a) (cherry picked from commit a9661e45acda0bedcb2413b412f9ffc3f9fb2354) 04 July 2014, 17:43:55 UTC
af7bcd7 Add license info. (cherry picked from commit 55707a36cce3584457f687ff020842c079624ee8) 04 July 2014, 17:43:50 UTC
3fa2fff Merge branch 'rsalz-docfixes' 03 July 2014, 16:53:36 UTC
b372a64 Close 3170, remove reference to Ariel Glenn's old 0.9.8 doc (cherry picked from commit f1112985e847286033ac573e70bdee752d26f46f) 03 July 2014, 16:51:33 UTC
e432336 bn_exp.c: fix x86_64-specific crash with one-word modulus. PR: #3397 (cherry picked from commit eca441b2b4d33d2a18d163ef9b4b3aff14251c73) 02 July 2014, 19:21:02 UTC
f3b0e02 update release notes 02 July 2014, 17:32:03 UTC
a6cc0e0 Fix doc typo. ERR_get_error(3) references the non-existent ERR_get_last_error_line_data instead of the one that does exist, ERR_peek_last_error_line_data. PR#3283 (cherry picked from commit 5cc99c6cf5e908df6b00b04af7f08e99c0698c7b) 02 July 2014, 02:45:07 UTC
b2cb6dc Make disabling last cipher work. (cherry picked from commit 7cb472bd0d0fd9da3d42bed1acc56c3a79fc5328) 02 July 2014, 02:32:50 UTC
f87f88a util/mkerr.pl: fix perl warning Gets rid of this; defined(@array) is deprecated at ../util/mkerr.pl line 792. (Maybe you should just omit the defined()?) defined(@array) is deprecated at ../util/mkerr.pl line 800. (Maybe you should just omit the defined()?) Signed-off-by: Geoff Thorpe <geoff@openssl.org> (cherry picked from commit 647f360e2e86818cee1f2d0429e071d14814e0b5) 02 July 2014, 00:50:51 UTC
6d87cd2 ASN1 sanity check. Primitive encodings shouldn't use indefinite length constructed form. PR#2438 (partial). (cherry picked from commit 398e99fe5e06edb11f55a39ce0883d9aa633ffa9) 02 July 2014, 00:00:18 UTC
2db3ea2 Fix possible buffer overrun. 01 July 2014, 22:39:17 UTC
c28b055 Fix copy for CCM, GCM and XTS. Internal pointers in CCM, GCM and XTS contexts should either be NULL or set to point to the appropriate key schedule. This needs to be adjusted when copying contexts. (cherry picked from commit c2fd5d79ffc4fc9d120a0faad579ce96473e6a2f) 30 June 2014, 13:00:00 UTC
02e8d46 Clarified that the signature's buffer size, `s`, is not used as an IN parameter. Under the old docs, the only thing stated was "at most EVP_PKEY_size(pkey) bytes will be written". It was kind of misleading since it appears EVP_PKEY_size(pkey) WILL be written regardless of the signature's buffer size. (cherry picked from commit 6e6ba36d980f67b6e5c7b139f78da7acbbf8ec76) 29 June 2014, 22:36:51 UTC
105a3db Make EVP_CIPHER_CTX_copy work in GCM mode. PR#3272 (cherry picked from commit 370bf1d708e6d7af42e1752fb078d0822c9bc73d) 29 June 2014, 21:02:42 UTC
295befe Fix memory leak. PR#2531 (cherry picked from commit 44724beeadf95712a42a8b21dc71bf110e89a262) 29 June 2014, 12:52:03 UTC
cb34cb1 Typo. PR#3173 (cherry picked from commit 76ed5a42ea68dd08bba44e4003b7e638e5d8a4a3) 29 June 2014, 12:39:24 UTC
86f393c Show errors on CSR verification failure. If CSR verify fails in ca utility print out error messages. Otherwise some errors give misleading output: for example if the key size exceeds the library limit. PR#2875 (cherry picked from commit a30bdb55d1361b9926eef8127debfc2e1bb8c484) 29 June 2014, 12:34:44 UTC
d6d3243 Make no-ssl3 no-ssl2 do more sensible things. (cherry picked from commit 7ae6a4b659facfd7ad8131238aa1d349cb3fc951) 29 June 2014, 02:05:37 UTC
14999bc Clarify protocols supported. Update protocols supported and note that SSLv2 is effectively disabled by default. PR#3184 (cherry picked from commit 1b13a4f38dfc385d5e776f6b3e06c5795874cf9b) 28 June 2014, 23:04:43 UTC
046e288 Typo. PR#3107 (cherry picked from commit 7c206db9280865ae4af352dbc14e9019a6c4795d) 28 June 2014, 11:43:18 UTC
d8b11e7 Don't disable state strings with no-ssl2 Some state strings were erronously not compiled when no-ssl2 was set. PR#3295 (cherry picked from commit 0518a3e19e18cfc441cab261b28441b8c8bd77bf) 27 June 2014, 23:56:42 UTC
0df7959 Fix compilation with -DSSL_DEBUG -DTLS_DEBUG -DKSSL_DEBUG PR#3141 (cherry picked from commit d183545d4589f1e7a40190400b8b99ea3d1f7f97) 27 June 2014, 23:41:49 UTC
5894eb1 Fix typo in ideatest.c (cherry picked from commit d1d4382dcb3fdcad4758ef7e7dd7b61dbf5abbfe) 27 June 2014, 23:06:40 UTC
6daba1d Remove redundant check. PR#3174 (cherry picked from commit fd331c0bb9b557903dd2ce88398570a3327b5ef0) 27 June 2014, 22:18:21 UTC
69b8f28 Fix for EVP_PBE_alg_add(). In EVP_PBE_alg_add don't use the underlying NID for the cipher as it may have a non-standard key size. PR#3206 (cherry picked from commit efb7caef637a1de8468ca109efd355a9d0e73a45) 27 June 2014, 21:58:55 UTC
0ace876 Tolerate critical AKID in CRLs. PR#3014 (cherry picked from commit 11da66f8b1fbe5777fe08cc6ace9e1f2c1576a50) 27 June 2014, 17:50:33 UTC
e9daf8a Handle IPv6 addresses in OCSP_parse_url. PR#2783 (cherry picked from commit b36f35cda964544a15d53d3fdfec9b2bab8cacb1) 27 June 2014, 16:31:44 UTC
cf01566 Don't advertise ECC ciphersuits in SSLv2 compatible client hello. PR#3374 (cherry picked from commit 0436369fccd128cb7f6a8538d5fed1c876c437af) 27 June 2014, 15:52:05 UTC
86cac6d Clarify docs. Document that the certificate passed to SSL_CTX_add_extra_chain_cert() should not be freed by the application. PR#3409 (cherry picked from commit 0535c2d67ca2d684087ef90be35d5fb207aab227) Add restrictions section present in other branches. Conflicts: doc/ssl/SSL_CTX_add_extra_chain_cert.pod 27 June 2014, 15:41:45 UTC
f46ea1d Remove ancient obsolete files under pkcs7. (cherry picked from commit 7be6b27aaf5ed77f13c93dc89a2c27a42082db3f) 27 June 2014, 12:54:45 UTC
0980992 Memory leak and NULL derefernce fixes. PR#3403 27 June 2014, 02:21:10 UTC
38a503f Fix OID encoding for one component. OIDs with one component don't have an encoding. PR#2556 (Bug#1) 27 June 2014, 02:17:15 UTC
fef58ce Make sure BN_sqr can never return a negative value. PR#3410 (cherry picked from commit e14e764c0d5d469da63d0819c6ffc0e1e9e7f0bb) 26 June 2014, 22:50:36 UTC
da0d5e7 Memory allocation checks. PR#3399. 26 June 2014, 22:32:17 UTC
ad212c1 Fix off-by-one errors in ssl_cipher_get_evp() In the ssl_cipher_get_evp() function, fix off-by-one errors in index validation before accessing arrays. Bug discovered and fixed by Miod Vallat from the OpenBSD team. PR#3375 22 June 2014, 22:20:39 UTC
e1bce59 Revert "Fix off-by-one errors in ssl_cipher_get_evp()" This reverts commit 29411a0c7a00a73e4ca42be8b5a7401d3bb5107a. Incorrect attribution. 22 June 2014, 22:20:19 UTC
9beb75d Accept CCS after sending finished. Allow CCS after finished has been sent by client: at this point keys have been correctly set up so it is OK to accept CCS from server. Without this renegotiation can sometimes fail. PR#3400 (cherry picked from commit 99cd6a91fcb0931feaebbb4832681d40a66fad41) 14 June 2014, 21:26:10 UTC
042ef46 Fixed incorrect return code handling in ssl3_final_finish_mac. Based on an original patch by Joel Sing (OpenBSD) who also originally identified the issue. 13 June 2014, 14:53:29 UTC
01736e6 Revert "Fixed incorrect return code handling in ssl3_final_finish_mac" This reverts commit 9ab788aa23feaa0e3b9efc2213e0c27913f8d987. Missing attribution 13 June 2014, 14:53:08 UTC
29411a0 Fix off-by-one errors in ssl_cipher_get_evp() In the ssl_cipher_get_evp() function, fix off-by-one errors in index validation before accessing arrays. PR#3375 12 June 2014, 20:15:54 UTC
b66f59a Fix compilation with no-comp (cherry picked from commit 7239a09c7b5757ed8d0e9869f3e9b03c0e11f4d1) 11 June 2014, 13:33:32 UTC
9ab788a Fixed incorrect return code handling in ssl3_final_finish_mac 10 June 2014, 22:28:10 UTC
87887a7 backport changes to ciphers(1) man page Backport of the patch: add ECC strings to ciphers(1), point out difference between DH and ECDH and few other changes applicable to the 1.0.1 code base. * Make a clear distinction between DH and ECDH key exchange. * Group all key exchange cipher suite identifiers, first DH then ECDH * add descriptions for all supported *DH* identifiers * add ECDSA authentication descriptions * add example showing how to disable all suites that offer no authentication or encryption * backport listing of elliptic curve cipher suites. * backport listing of TLS 1.2 cipher suites, add note that DH_RSA and DH_DSS is not implemented in this version * backport of description of PSK and listing of PSK cipher suites * backport description of AES128, AES256 and AESGCM options * backport description of CAMELLIA128, CAMELLIA256 options 10 June 2014, 19:56:39 UTC
5a0d057 Create test/testutil.h for unit test helper macros Defines SETUP_TEST_FIXTURE and EXECUTE_TEST, and updates ssl/heartbeat_test.c using these macros. SETUP_TEST_FIXTURE makes use of the new TEST_CASE_NAME macro, defined to use __func__ or __FUNCTION__ on platforms that support those symbols, or to use the file name and line number otherwise. This should fix several reported build problems related to lack of C99 support. 10 June 2014, 18:27:45 UTC
aa59369 Fix null pointer errors. PR#3394 (cherry picked from commit 7a9d59c148b773f59a41f8697eeecf369a0974c2) 10 June 2014, 13:48:07 UTC
18c7f2f SRP ciphersuite correction. SRP ciphersuites do not have no authentication. They have authentication based on SRP. Add new SRP authentication flag and cipher string. (cherry picked from commit a86b88acc373ac1fb0ca709a5fb8a8fa74683f67) 09 June 2014, 11:09:49 UTC
6a8d6f0 Update strength_bits for 3DES. Fix strength_bits to 112 for 3DES. (cherry picked from commit 837c203719205ab19b5609b2df7151be8df05687) 09 June 2014, 11:09:49 UTC
back to top