00579b9 | Hubert Kario | 06 June 2014, 14:48:43 UTC | document -nextprotoneg option in man pages Add description of the option to advertise support of Next Protocol Negotiation extension (-nextprotoneg) to man pages of s_client and s_server. PR#3444 (cherry picked from commit 7efd0e777e65eaa6c60d85b1cc5c889f872f8fc4) Conflicts: doc/apps/s_server.pod | 14 July 2014, 22:43:58 UTC |
ee5a8d3 | Dr. Stephen Henson | 14 July 2014, 14:05:50 UTC | Use more common name for GOST key exchange. (cherry picked from commit 7aabd9c92fe6f0ea2a82869e5171dcc4518cee85) | 14 July 2014, 17:31:54 UTC |
7237016 | Matt Caswell | 10 July 2014, 22:47:31 UTC | Fixed valgrind complaint due to BN_consttime_swap reading uninitialised data. This is actually ok for this function, but initialised to zero anyway if PURIFY defined. This does have the impact of masking any *real* unitialised data reads in bn though. Patch based on approach suggested by Rich Salz. PR#3415 (cherry picked from commit 77747e2d9a5573b1dbc15e247ce18c03374c760c) | 13 July 2014, 21:23:10 UTC |
704422c | Peter Mosmans | 13 July 2014, 17:30:07 UTC | Add names of GOST algorithms. PR#3440 (cherry picked from commit 924e5eda2c82d737cc5a1b9c37918aa6e34825da) | 13 July 2014, 17:31:36 UTC |
8e8d7e1 | Richard Levitte | 13 July 2014, 17:11:29 UTC | * crypto/ui/ui_lib.c: misplaced brace in switch statement. Detected by dcruette@qualitesys.com (cherry picked from commit 8b5dd340919e511137696792279f595a70ae2762) | 13 July 2014, 17:15:30 UTC |
3ed6327 | Ben Laurie | 10 July 2014, 16:47:48 UTC | Don't clean up uninitialised EVP_CIPHER_CTX on error (CID 483259). (cherry picked from commit c1d1b0114e9d370c30649e46182393dbfc00e20c) | 10 July 2014, 16:52:37 UTC |
efd4f1d | Matt Caswell | 09 July 2014, 22:29:17 UTC | Fix memory leak in BIO_free if there is no destroy function. Based on an original patch by Neitrino Photonov <neitrinoph@gmail.com> PR#3439 (cherry picked from commit 66816c53bea0ecddb9448da7ea9a51a334496127) | 09 July 2014, 22:34:35 UTC |
00032b0 | David Lloyd | 07 July 2014, 12:11:48 UTC | Prevent infinite loop loading config files. PR#2985 (cherry picked from commit 9d23f422a32cb333a5e803199ae230706b1bf9f5) | 07 July 2014, 12:50:00 UTC |
a07f514 | Dr. Stephen Henson | 06 July 2014, 21:33:35 UTC | Usage for -hack and -prexit -verify_return_error (cherry picked from commit ee724df75d9ad67fd954253ac514fddb46f1e3c6) | 06 July 2014, 21:48:57 UTC |
b197c77 | Dr. Stephen Henson | 06 July 2014, 21:16:21 UTC | Document certificate status request options. (cherry picked from commit cba3f1c739f012aaadb85aaefaf8de424d2695e2) Conflicts: doc/apps/s_client.pod doc/apps/s_server.pod | 06 July 2014, 21:48:52 UTC |
b7c9762 | Dr. Stephen Henson | 06 July 2014, 21:23:01 UTC | s_server usage for certificate status requests (cherry picked from commit a44f219c009798054d6741e919cba5b2e656dbf4) | 06 July 2014, 21:45:44 UTC |
a414bc8 | Dr. Stephen Henson | 03 July 2014, 13:50:08 UTC | Update ticket callback docs. (cherry picked from commit a23a6e85d8dcd5733a343754f434201f3c9aa6f0) | 06 July 2014, 11:42:27 UTC |
98a3c3c | Dr. Stephen Henson | 05 July 2014, 23:32:44 UTC | Sanity check keylength in PVK files. PR#2277 (cherry picked from commit 733a6c882e92f8221bd03a51643bb47f5f81bb81) | 05 July 2014, 23:36:11 UTC |
157fd05 | Jeffrey Walton | 05 July 2014, 21:39:08 UTC | Added reference to platform specific cryptographic acceleration such as AES-NI | 05 July 2014, 23:04:32 UTC |
9f510ce | Matt Caswell | 05 July 2014, 21:31:05 UTC | Fixed error in pod files with latest versions of pod2man (cherry picked from commit 07255f0a76d9d349d915e14f969b9ff2ee0d1953) | 05 July 2014, 23:04:32 UTC |
675b1c2 | Alan Hryngle | 05 July 2014, 21:24:03 UTC | Return smaller of ret and f. PR#3418. (cherry picked from commit fdea4fff8fb058be928980600b24cf4c62ef3630) | 05 July 2014, 21:38:44 UTC |
c923132 | Dr. Stephen Henson | 05 July 2014, 12:19:12 UTC | Don't limit message sizes in ssl3_get_cert_verify. PR#319 (reoponed version). (cherry picked from commit 7f6e9578648728478e84246fd3e64026b8b6a48e) | 05 July 2014, 12:30:55 UTC |
1864e3b | Dr. Stephen Henson | 04 July 2014, 12:50:26 UTC | typo (cherry picked from commit 2cfbec1caea8f9567bdff85d33d22481f2afb40a) (cherry picked from commit a9661e45acda0bedcb2413b412f9ffc3f9fb2354) | 04 July 2014, 17:43:55 UTC |
af7bcd7 | Dr. Stephen Henson | 04 July 2014, 17:41:45 UTC | Add license info. (cherry picked from commit 55707a36cce3584457f687ff020842c079624ee8) | 04 July 2014, 17:43:50 UTC |
3fa2fff | Rich Salz | 03 July 2014, 02:44:53 UTC | Merge branch 'rsalz-docfixes' | 03 July 2014, 16:53:36 UTC |
b372a64 | Rich Salz | 03 July 2014, 04:07:04 UTC | Close 3170, remove reference to Ariel Glenn's old 0.9.8 doc (cherry picked from commit f1112985e847286033ac573e70bdee752d26f46f) | 03 July 2014, 16:51:33 UTC |
e432336 | Andy Polyakov | 02 July 2014, 17:35:50 UTC | bn_exp.c: fix x86_64-specific crash with one-word modulus. PR: #3397 (cherry picked from commit eca441b2b4d33d2a18d163ef9b4b3aff14251c73) | 02 July 2014, 19:21:02 UTC |
f3b0e02 | Dr. Stephen Henson | 02 July 2014, 17:32:03 UTC | update release notes | 02 July 2014, 17:32:03 UTC |
a6cc0e0 | Matt Smart | 02 July 2014, 02:43:42 UTC | Fix doc typo. ERR_get_error(3) references the non-existent ERR_get_last_error_line_data instead of the one that does exist, ERR_peek_last_error_line_data. PR#3283 (cherry picked from commit 5cc99c6cf5e908df6b00b04af7f08e99c0698c7b) | 02 July 2014, 02:45:07 UTC |
b2cb6dc | Thijs Alkemade | 02 July 2014, 02:32:19 UTC | Make disabling last cipher work. (cherry picked from commit 7cb472bd0d0fd9da3d42bed1acc56c3a79fc5328) | 02 July 2014, 02:32:50 UTC |
f87f88a | Geoff Thorpe | 25 April 2014, 05:20:16 UTC | util/mkerr.pl: fix perl warning Gets rid of this; defined(@array) is deprecated at ../util/mkerr.pl line 792. (Maybe you should just omit the defined()?) defined(@array) is deprecated at ../util/mkerr.pl line 800. (Maybe you should just omit the defined()?) Signed-off-by: Geoff Thorpe <geoff@openssl.org> (cherry picked from commit 647f360e2e86818cee1f2d0429e071d14814e0b5) | 02 July 2014, 00:50:51 UTC |
6d87cd2 | Dr. Stephen Henson | 01 July 2014, 23:57:57 UTC | ASN1 sanity check. Primitive encodings shouldn't use indefinite length constructed form. PR#2438 (partial). (cherry picked from commit 398e99fe5e06edb11f55a39ce0883d9aa633ffa9) | 02 July 2014, 00:00:18 UTC |
2db3ea2 | Ben Laurie | 23 April 2014, 17:13:20 UTC | Fix possible buffer overrun. | 01 July 2014, 22:39:17 UTC |
c28b055 | Dr. Stephen Henson | 30 June 2014, 11:57:29 UTC | Fix copy for CCM, GCM and XTS. Internal pointers in CCM, GCM and XTS contexts should either be NULL or set to point to the appropriate key schedule. This needs to be adjusted when copying contexts. (cherry picked from commit c2fd5d79ffc4fc9d120a0faad579ce96473e6a2f) | 30 June 2014, 13:00:00 UTC |
02e8d46 | Jeffrey Walton | 29 June 2014, 22:34:21 UTC | Clarified that the signature's buffer size, `s`, is not used as an IN parameter. Under the old docs, the only thing stated was "at most EVP_PKEY_size(pkey) bytes will be written". It was kind of misleading since it appears EVP_PKEY_size(pkey) WILL be written regardless of the signature's buffer size. (cherry picked from commit 6e6ba36d980f67b6e5c7b139f78da7acbbf8ec76) | 29 June 2014, 22:36:51 UTC |
105a3db | ZNV | 29 June 2014, 21:01:28 UTC | Make EVP_CIPHER_CTX_copy work in GCM mode. PR#3272 (cherry picked from commit 370bf1d708e6d7af42e1752fb078d0822c9bc73d) | 29 June 2014, 21:02:42 UTC |
295befe | Dr. Stephen Henson | 29 June 2014, 12:51:30 UTC | Fix memory leak. PR#2531 (cherry picked from commit 44724beeadf95712a42a8b21dc71bf110e89a262) | 29 June 2014, 12:52:03 UTC |
cb34cb1 | Ken Ballou | 29 June 2014, 12:38:55 UTC | Typo. PR#3173 (cherry picked from commit 76ed5a42ea68dd08bba44e4003b7e638e5d8a4a3) | 29 June 2014, 12:39:24 UTC |
86f393c | Dr. Stephen Henson | 29 June 2014, 12:31:57 UTC | Show errors on CSR verification failure. If CSR verify fails in ca utility print out error messages. Otherwise some errors give misleading output: for example if the key size exceeds the library limit. PR#2875 (cherry picked from commit a30bdb55d1361b9926eef8127debfc2e1bb8c484) | 29 June 2014, 12:34:44 UTC |
d6d3243 | Dr. Stephen Henson | 29 June 2014, 02:02:51 UTC | Make no-ssl3 no-ssl2 do more sensible things. (cherry picked from commit 7ae6a4b659facfd7ad8131238aa1d349cb3fc951) | 29 June 2014, 02:05:37 UTC |
14999bc | Dr. Stephen Henson | 28 June 2014, 20:54:13 UTC | Clarify protocols supported. Update protocols supported and note that SSLv2 is effectively disabled by default. PR#3184 (cherry picked from commit 1b13a4f38dfc385d5e776f6b3e06c5795874cf9b) | 28 June 2014, 23:04:43 UTC |
046e288 | Dr. Stephen Henson | 28 June 2014, 11:42:04 UTC | Typo. PR#3107 (cherry picked from commit 7c206db9280865ae4af352dbc14e9019a6c4795d) | 28 June 2014, 11:43:18 UTC |
d8b11e7 | Dr. Stephen Henson | 27 June 2014, 23:54:32 UTC | Don't disable state strings with no-ssl2 Some state strings were erronously not compiled when no-ssl2 was set. PR#3295 (cherry picked from commit 0518a3e19e18cfc441cab261b28441b8c8bd77bf) | 27 June 2014, 23:56:42 UTC |
0df7959 | yogesh nagarkar | 27 June 2014, 23:40:26 UTC | Fix compilation with -DSSL_DEBUG -DTLS_DEBUG -DKSSL_DEBUG PR#3141 (cherry picked from commit d183545d4589f1e7a40190400b8b99ea3d1f7f97) | 27 June 2014, 23:41:49 UTC |
5894eb1 | Andreas Westfeld | 27 June 2014, 23:04:56 UTC | Fix typo in ideatest.c (cherry picked from commit d1d4382dcb3fdcad4758ef7e7dd7b61dbf5abbfe) | 27 June 2014, 23:06:40 UTC |
6daba1d | Ken Ballou | 27 June 2014, 22:17:47 UTC | Remove redundant check. PR#3174 (cherry picked from commit fd331c0bb9b557903dd2ce88398570a3327b5ef0) | 27 June 2014, 22:18:21 UTC |
69b8f28 | Dr. Stephen Henson | 27 June 2014, 21:56:37 UTC | Fix for EVP_PBE_alg_add(). In EVP_PBE_alg_add don't use the underlying NID for the cipher as it may have a non-standard key size. PR#3206 (cherry picked from commit efb7caef637a1de8468ca109efd355a9d0e73a45) | 27 June 2014, 21:58:55 UTC |
0ace876 | Dr. Stephen Henson | 27 June 2014, 17:49:32 UTC | Tolerate critical AKID in CRLs. PR#3014 (cherry picked from commit 11da66f8b1fbe5777fe08cc6ace9e1f2c1576a50) | 27 June 2014, 17:50:33 UTC |
e9daf8a | Tom Greenslade | 27 June 2014, 16:30:59 UTC | Handle IPv6 addresses in OCSP_parse_url. PR#2783 (cherry picked from commit b36f35cda964544a15d53d3fdfec9b2bab8cacb1) | 27 June 2014, 16:31:44 UTC |
cf01566 | Tomas Mraz | 27 June 2014, 15:49:22 UTC | Don't advertise ECC ciphersuits in SSLv2 compatible client hello. PR#3374 (cherry picked from commit 0436369fccd128cb7f6a8538d5fed1c876c437af) | 27 June 2014, 15:52:05 UTC |
86cac6d | Jeffrey Walton | 27 June 2014, 15:33:06 UTC | Clarify docs. Document that the certificate passed to SSL_CTX_add_extra_chain_cert() should not be freed by the application. PR#3409 (cherry picked from commit 0535c2d67ca2d684087ef90be35d5fb207aab227) Add restrictions section present in other branches. Conflicts: doc/ssl/SSL_CTX_add_extra_chain_cert.pod | 27 June 2014, 15:41:45 UTC |
f46ea1d | Dr. Stephen Henson | 26 June 2014, 11:36:44 UTC | Remove ancient obsolete files under pkcs7. (cherry picked from commit 7be6b27aaf5ed77f13c93dc89a2c27a42082db3f) | 27 June 2014, 12:54:45 UTC |
0980992 | Dr. Stephen Henson | 27 June 2014, 02:21:10 UTC | Memory leak and NULL derefernce fixes. PR#3403 | 27 June 2014, 02:21:10 UTC |
38a503f | Dr. Stephen Henson | 27 June 2014, 02:17:15 UTC | Fix OID encoding for one component. OIDs with one component don't have an encoding. PR#2556 (Bug#1) | 27 June 2014, 02:17:15 UTC |
fef58ce | Huzaifa Sidhpurwala | 26 June 2014, 22:45:58 UTC | Make sure BN_sqr can never return a negative value. PR#3410 (cherry picked from commit e14e764c0d5d469da63d0819c6ffc0e1e9e7f0bb) | 26 June 2014, 22:50:36 UTC |
da0d5e7 | Jenny Yung | 26 June 2014, 22:30:57 UTC | Memory allocation checks. PR#3399. | 26 June 2014, 22:32:17 UTC |
ad212c1 | Miod Vallat | 04 June 2014, 07:59:58 UTC | Fix off-by-one errors in ssl_cipher_get_evp() In the ssl_cipher_get_evp() function, fix off-by-one errors in index validation before accessing arrays. Bug discovered and fixed by Miod Vallat from the OpenBSD team. PR#3375 | 22 June 2014, 22:20:39 UTC |
e1bce59 | Matt Caswell | 22 June 2014, 22:20:19 UTC | Revert "Fix off-by-one errors in ssl_cipher_get_evp()" This reverts commit 29411a0c7a00a73e4ca42be8b5a7401d3bb5107a. Incorrect attribution. | 22 June 2014, 22:20:19 UTC |
9beb75d | Dr. Stephen Henson | 14 June 2014, 21:24:08 UTC | Accept CCS after sending finished. Allow CCS after finished has been sent by client: at this point keys have been correctly set up so it is OK to accept CCS from server. Without this renegotiation can sometimes fail. PR#3400 (cherry picked from commit 99cd6a91fcb0931feaebbb4832681d40a66fad41) | 14 June 2014, 21:26:10 UTC |
042ef46 | Matt Caswell | 10 June 2014, 22:24:28 UTC | Fixed incorrect return code handling in ssl3_final_finish_mac. Based on an original patch by Joel Sing (OpenBSD) who also originally identified the issue. | 13 June 2014, 14:53:29 UTC |
01736e6 | Matt Caswell | 13 June 2014, 14:53:08 UTC | Revert "Fixed incorrect return code handling in ssl3_final_finish_mac" This reverts commit 9ab788aa23feaa0e3b9efc2213e0c27913f8d987. Missing attribution | 13 June 2014, 14:53:08 UTC |
29411a0 | Kurt Cancemi | 04 June 2014, 07:59:58 UTC | Fix off-by-one errors in ssl_cipher_get_evp() In the ssl_cipher_get_evp() function, fix off-by-one errors in index validation before accessing arrays. PR#3375 | 12 June 2014, 20:15:54 UTC |
b66f59a | Dr. Stephen Henson | 11 June 2014, 13:31:08 UTC | Fix compilation with no-comp (cherry picked from commit 7239a09c7b5757ed8d0e9869f3e9b03c0e11f4d1) | 11 June 2014, 13:33:32 UTC |
9ab788a | Matt Caswell | 10 June 2014, 22:24:28 UTC | Fixed incorrect return code handling in ssl3_final_finish_mac | 10 June 2014, 22:28:10 UTC |
87887a7 | Hubert Kario | 10 June 2014, 12:13:33 UTC | backport changes to ciphers(1) man page Backport of the patch: add ECC strings to ciphers(1), point out difference between DH and ECDH and few other changes applicable to the 1.0.1 code base. * Make a clear distinction between DH and ECDH key exchange. * Group all key exchange cipher suite identifiers, first DH then ECDH * add descriptions for all supported *DH* identifiers * add ECDSA authentication descriptions * add example showing how to disable all suites that offer no authentication or encryption * backport listing of elliptic curve cipher suites. * backport listing of TLS 1.2 cipher suites, add note that DH_RSA and DH_DSS is not implemented in this version * backport of description of PSK and listing of PSK cipher suites * backport description of AES128, AES256 and AESGCM options * backport description of CAMELLIA128, CAMELLIA256 options | 10 June 2014, 19:56:39 UTC |
5a0d057 | Mike Bland | 07 June 2014, 17:05:50 UTC | Create test/testutil.h for unit test helper macros Defines SETUP_TEST_FIXTURE and EXECUTE_TEST, and updates ssl/heartbeat_test.c using these macros. SETUP_TEST_FIXTURE makes use of the new TEST_CASE_NAME macro, defined to use __func__ or __FUNCTION__ on platforms that support those symbols, or to use the file name and line number otherwise. This should fix several reported build problems related to lack of C99 support. | 10 June 2014, 18:27:45 UTC |
aa59369 | Dr. Stephen Henson | 10 June 2014, 13:47:29 UTC | Fix null pointer errors. PR#3394 (cherry picked from commit 7a9d59c148b773f59a41f8697eeecf369a0974c2) | 10 June 2014, 13:48:07 UTC |
18c7f2f | Dr. Stephen Henson | 09 June 2014, 11:03:12 UTC | SRP ciphersuite correction. SRP ciphersuites do not have no authentication. They have authentication based on SRP. Add new SRP authentication flag and cipher string. (cherry picked from commit a86b88acc373ac1fb0ca709a5fb8a8fa74683f67) | 09 June 2014, 11:09:49 UTC |
6a8d6f0 | Dr. Stephen Henson | 09 June 2014, 07:55:37 UTC | Update strength_bits for 3DES. Fix strength_bits to 112 for 3DES. (cherry picked from commit 837c203719205ab19b5609b2df7151be8df05687) | 09 June 2014, 11:09:49 UTC |
5ff9c21 | Kurt Roeckx | 07 June 2014, 11:32:23 UTC | Link heartbeat_test with the static version of the libraries It's using an internal API that that might not be available in the shared library. | 08 June 2014, 23:13:06 UTC |
5c52c04 | Jakub Wilk | 07 June 2014, 12:37:17 UTC | Create ~/.rnd with mode 0600 instead of 0666 Because of a missing include <fcntl.h> we don't have O_CREATE and don't create the file with open() using mode 0600 but fall back to using fopen() with the default umask followed by a chmod(). Problem found by Jakub Wilk <jwilk@debian.org>. | 08 June 2014, 20:25:43 UTC |
6c86bf7 | Dr. Stephen Henson | 07 June 2014, 17:18:41 UTC | update NEWS | 07 June 2014, 17:19:03 UTC |
0d4d2e0 | Dr. Stephen Henson | 07 June 2014, 14:21:13 UTC | Make tls_session_secret_cb work with CVE-2014-0224 fix. If application uses tls_session_secret_cb for session resumption set the CCS_OK flag. (cherry picked from commit 953c592572e8811b7956cc09fbd8e98037068b58) | 07 June 2014, 14:27:21 UTC |
151399a | Matt Caswell | 07 June 2014, 11:30:18 UTC | Fixed minor duplication in docs | 07 June 2014, 11:32:00 UTC |
049615e | Dr. Stephen Henson | 05 June 2014, 09:45:50 UTC | Prepare for 1.0.1i-dev | 05 June 2014, 09:45:50 UTC |
6b72417 | Dr. Stephen Henson | 05 June 2014, 09:45:00 UTC | Prepare for 1.0.1h release | 05 June 2014, 09:45:00 UTC |
aabbe99 | Dr. Stephen Henson | 05 June 2014, 07:56:20 UTC | Update CHANGES and NEWS | 05 June 2014, 08:04:27 UTC |
8011cd5 | Dr. Stephen Henson | 29 May 2014, 14:00:05 UTC | Fix CVE-2014-3470 Check session_cert is not NULL before dereferencing it. | 05 June 2014, 08:04:27 UTC |
d315265 | Dr. Stephen Henson | 16 May 2014, 12:00:45 UTC | Fix CVE-2014-0221 Unnecessary recursion when receiving a DTLS hello request can be used to crash a DTLS client. Fixed by handling DTLS hello request without recursion. Thanks to Imre Rad (Search-Lab Ltd.) for discovering this issue. | 05 June 2014, 08:04:27 UTC |
006cd70 | Dr. Stephen Henson | 16 May 2014, 11:55:16 UTC | Additional CVE-2014-0224 protection. Return a fatal error if an attempt is made to use a zero length master secret. | 05 June 2014, 08:04:27 UTC |
bc8923b | Dr. Stephen Henson | 16 May 2014, 11:49:48 UTC | Fix for CVE-2014-0224 Only accept change cipher spec when it is expected instead of at any time. This prevents premature setting of session keys before the master secret is determined which an attacker could use as a MITM attack. Thanks to KIKUCHI Masashi (Lepidum Co. Ltd.) for reporting this issue and providing the initial fix this patch is based on. | 05 June 2014, 08:04:27 UTC |
1632ef7 | Dr. Stephen Henson | 13 May 2014, 17:48:31 UTC | Fix for CVE-2014-0195 A buffer overrun attack can be triggered by sending invalid DTLS fragments to an OpenSSL DTLS client or server. This is potentially exploitable to run arbitrary code on a vulnerable client or server. Fixed by adding consistency check for DTLS fragments. Thanks to Jüri Aedla for reporting this issue. | 05 June 2014, 08:04:27 UTC |
f1f4fbd | Dr. Stephen Henson | 05 June 2014, 08:01:33 UTC | make update | 05 June 2014, 08:02:03 UTC |
1854c48 | Libor Krystek | 03 June 2014, 22:14:40 UTC | Corrected OPENSSL_NO_EC_NISTP_64_GCC_128 usage in ec_lcl.h. PR#3370 | 03 June 2014, 22:19:21 UTC |
ebda73f | David Benjamin | 02 June 2014, 17:55:20 UTC | Check there is enough room for extension. (cherry picked from commit 7d89b3bf42e4b4067371ab33ef7631434e41d1e4) | 02 June 2014, 18:00:02 UTC |
bcc3116 | zhu qun-ying | 02 June 2014, 13:38:52 UTC | Free up s->d1->buffered_app_data.q properly. PR#3286 (cherry picked from commit 71e95000afb2227fe5cac1c79ae884338bcd8d0b) | 02 June 2014, 13:40:18 UTC |
1dd2641 | Sami Farin | 02 June 2014, 11:24:19 UTC | Typo: set i to -1 before goto. PR#3302 (cherry picked from commit 9717f01951f976f76dd40a38d9fc7307057fa4c4) | 02 June 2014, 13:22:06 UTC |
056389e | Matt Caswell | 01 June 2014, 20:32:19 UTC | Added SSLErr call for internal error in dtls1_buffer_record | 01 June 2014, 20:38:01 UTC |
a07856a | David Ramos | 01 June 2014, 20:28:41 UTC | Delays the queue insertion until after the ssl3_setup_buffers() call due to use-after-free bug. PR#3362 | 01 June 2014, 20:37:47 UTC |
19ce768 | Dr. Stephen Henson | 01 June 2014, 15:25:43 UTC | Recognise padding extension. (cherry picked from commit ea2bb861f0daaa20819bf9ac8c146f7593feacd4) Conflicts: apps/s_cb.c (cherry picked from commit 14dc83ca779e91a267701a1fb05b2bbcf2cb63c4) | 01 June 2014, 15:50:37 UTC |
aaed77c | Dr. Stephen Henson | 01 June 2014, 15:36:24 UTC | Option to disable padding extension. Add TLS padding extension to SSL_OP_ALL so it is used with other "bugs" options and can be turned off. This replaces SSL_OP_SSLREF2_REUSE_CERT_TYPE_BUG which is an ancient option referring to SSLv2 and SSLREF. PR#3336 | 01 June 2014, 15:50:37 UTC |
49270d0 | Dr. Stephen Henson | 01 June 2014, 14:03:00 UTC | Set default global mask to UTF8 only. (cherry picked from commit 3009244da47b989c4cc59ba02cf81a4e9d8f8431) | 01 June 2014, 14:04:29 UTC |
673c42b | David Ramos | 01 June 2014, 13:30:10 UTC | Allocate extra space when NETSCAPE_HANG_BUG defined. Make sure there is an extra 4 bytes for server done message when NETSCAPE_HANG_BUG is defined. PR#3361 | 01 June 2014, 13:30:10 UTC |
5541b18 | David Ramos | 01 June 2014, 12:03:05 UTC | Initialise alg. PR#3313 (cherry picked from commit 7e2c6f7eb01515a990f77fbc5441be8e1a17152a) | 01 June 2014, 12:05:20 UTC |
28e117f | Dr. Stephen Henson | 30 May 2014, 12:21:43 UTC | Use correct digest when exporting keying material. PR#3319 (cherry picked from commit 84691390eae86befd33c83721dacedb539ae34e6) | 31 May 2014, 12:43:01 UTC |
46bfc05 | Dr. Stephen Henson | 30 May 2014, 12:10:08 UTC | Don't compile heartbeat test code on Windows (for now). (cherry picked from commit 2c575907d2c8601a18716f718ce309ed4e1f1783) | 31 May 2014, 12:43:01 UTC |
427a37c | Hubert Kario | 12 September 2013, 09:37:12 UTC | add description of -attime to man page the verify app man page didn't describe the usage of attime option even though it was listed as a valid option in the -help message. This patch fixes this omission. | 30 May 2014, 22:33:10 UTC |
39ae3b3 | Hubert Kario | 10 September 2013, 13:59:13 UTC | add description of -no_ecdhe option to s_server man page While the -help message references this option, the man page doesn't mention the -no_ecdhe option. This patch fixes this omission. | 30 May 2014, 22:32:54 UTC |
48f5b3e | Dr. Stephen Henson | 29 May 2014, 13:07:49 UTC | Set version number correctly. PR#3249 (cherry picked from commit 8909bf20269035d295743fca559207ef2eb84eb3) | 29 May 2014, 13:12:14 UTC |
f8dc000 | František Bořánek | 29 May 2014, 12:49:10 UTC | Fix memory leak. PR#3278 (cherry picked from commit de56fe797081fc09ebd1add06d6e2df42a324fd5) | 29 May 2014, 13:12:14 UTC |
bf8d6f9 | Martin Kaiser | 28 May 2014, 09:16:06 UTC | remove duplicate 0x for default RSASSA-PSS salt len (cherry picked from commit 3820fec3a09faecba7fe9912aa20ef7fcda8337b) | 29 May 2014, 13:12:14 UTC |
17e844a | Peter Mosmans | 27 May 2014, 22:26:11 UTC | Fix for test_bn regular expression to work on Windows using MSYS. PR#3346 | 27 May 2014, 22:26:11 UTC |
8ca7d12 | Matt Caswell | 26 May 2014, 23:26:55 UTC | Fixed Windows compilation failure | 26 May 2014, 23:26:55 UTC |
67b9c82 | Matt Caswell | 25 May 2014, 22:37:53 UTC | Fixed error in args for SSL_set_msg_callback and SSL_set_msg_callback_arg | 25 May 2014, 22:48:15 UTC |
a6f5b99 | Matt Caswell | 24 May 2014, 22:55:27 UTC | Fix for non compilation with TLS_DEBUG defined | 24 May 2014, 22:56:58 UTC |