Martin Olsson 
							
						 
					 
					
						
						
							
						
						610ac0525d 
					 
					
						
						
							
							RT2843: Remove another spurious close-comment token  
						
						 
						
						... 
						
						
						
						Reviewed-by: Dr. Stephen Henson <steve@openssl.org >
(cherry picked from commit 683cd7c948 ) 
						
						
					 
					
						2014-09-08 10:52:19 -04:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						22db480daf 
					 
					
						
						
							
							Remove all RFC5878 code.  
						
						 
						
						... 
						
						
						
						Remove RFC5878 code. It is no longer needed for CT and has numerous bugs. 
						
						
					 
					
						2014-07-04 13:42:05 +01:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						6411b83e52 
					 
					
						
						
							
							Set TLS padding extension value.  
						
						 
						
						... 
						
						
						
						Enable TLS padding extension using official value from:
http://www.iana.org/assignments/tls-extensiontype-values/tls-extensiontype-values.xhtml 
(cherry picked from commit cd6bd5ffda )
Conflicts:
	CHANGES 
						
						
					 
					
						2014-04-05 20:49:09 +01:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Scott Deboy 
							
						 
					 
					
						
						
							
						
						19a28a8aa3 
					 
					
						
						
							
							Updating DTCP authorization type to expected value  
						
						 
						
						
						
						
					 
					
						2014-02-08 16:18:11 -08:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Scott Deboy 
							
						 
					 
					
						
						
							
						
						038bec784e 
					 
					
						
						
							
							Add callbacks supporting generation and retrieval of supplemental data entries, facilitating RFC 5878 (TLS auth extensions)  
						
						 
						
						... 
						
						
						
						Removed prior audit proof logic - audit proof support was implemented using the generic TLS extension API
Tests exercising the new supplemental data registration and callback api can be found in ssltest.c.
Implemented changes to s_server and s_client to exercise supplemental data callbacks via the -auth argument, as well as additional flags to exercise supplemental data being sent only during renegotiation.
(cherry picked from commit 36086186a9 )
Conflicts:
	Configure
	apps/s_client.c
	apps/s_server.c
	ssl/ssl.h
	ssl/ssl3.h
	ssl/ssltest.c 
						
						
					 
					
						2014-02-08 16:12:15 -08:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Adam Langley 
							
						 
					 
					
						
						
							
						
						b0d6f3c58f 
					 
					
						
						
							
							Support ALPN.  
						
						 
						
						... 
						
						
						
						This change adds support for ALPN[1] in OpenSSL. ALPN is the IETF
blessed version of NPN and we'll be supporting both ALPN and NPN for
some time yet.
Cherry-picked from 6f017a8f9d .
[1] https://tools.ietf.org/html/draft-ietf-tls-applayerprotoneg-00  
						
						
					 
					
						2013-09-13 11:27:22 -04:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						ccf6a19e2d 
					 
					
						
						
							
							Add three Suite B modes to TLS code, supporting RFC6460.  
						
						 
						
						... 
						
						
						
						(backport from HEAD) 
						
						
					 
					
						2012-12-26 16:17:40 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						623a5e24cb 
					 
					
						
						
							
							Add certificate callback. If set this is called whenever a certificate  
						
						 
						
						... 
						
						
						
						is required by client or server. An application can decide which
certificate chain to present based on arbitrary criteria: for example
supported signature algorithms. Add very simple example to s_server.
This fixes many of the problems and restrictions of the existing client
certificate callback: for example you can now clear existing certificates
and specify the whole chain.
(backport from HEAD) 
						
						
					 
					
						2012-12-26 14:43:51 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						c70a1fee71 
					 
					
						
						
							
							Reorganise supported signature algorithm extension processing.  
						
						 
						
						... 
						
						
						
						Only store encoded versions of peer and configured signature algorithms.
Determine shared signature algorithms and cache the result along with NID
equivalents of each algorithm.
(backport from HEAD) 
						
						
					 
					
						2012-12-26 14:26:16 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						0b362de5f5 
					 
					
						
						
							
							Add support for application defined signature algorithms for use with  
						
						 
						
						... 
						
						
						
						TLS v1.2. These are sent as an extension for clients and during a certificate
request for servers.
TODO: add support for shared signature algorithms, respect shared algorithms
when deciding which ciphersuites and certificates to permit.
(backport from HEAD) 
						
						
					 
					
						2012-12-26 14:25:29 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Ben Laurie 
							
						 
					 
					
						
						
							
						
						8a02a46a5c 
					 
					
						
						
							
							RFC 5878 support.  
						
						 
						
						
						
						
					 
					
						2012-05-29 17:27:48 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						5505818199 
					 
					
						
						
							
							New ctrls to retrieve supported signature algorithms and curves and  
						
						 
						
						... 
						
						
						
						extensions to s_client and s_server to print out retrieved valued.
Extend CERT structure to cache supported signature algorithm data.
(backport from HEAD) 
						
						
					 
					
						2012-04-06 19:29:49 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						267c950c5f 
					 
					
						
						
							
							Submitted by: Peter Sylvester <peter.sylvester@edelweb.fr>  
						
						 
						
						... 
						
						
						
						Add more extension names in s_cb.c extension printing code. 
						
						
					 
					
						2012-03-09 18:37:41 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						bd6941cfaa 
					 
					
						
						
							
							PR: 2658  
						
						 
						
						... 
						
						
						
						Submitted by: Robin Seggelmann <seggelmann@fh-muenster.de >
Reviewed by: steve
Support for TLS/DTLS heartbeats. 
						
						
					 
					
						2011-12-31 23:00:36 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Ben Laurie 
							
						 
					 
					
						
						
							
						
						e87afb1518 
					 
					
						
						
							
							SSL export fixes (from Adam Langley).  
						
						 
						
						
						
						
					 
					
						2011-12-13 14:25:11 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						2c7d978c2d 
					 
					
						
						
							
							PR: 1794  
						
						 
						
						... 
						
						
						
						Submitted by: Peter Sylvester <peter.sylvester@edelweb.fr >
Reviewed by: steve
Make SRP conformant to rfc 5054.
Changes are:
- removal of the addition state after client hello
- removal of all pre-rfc srp alert ids
- sending a fatal alert when there is no srp extension but when the
server wants SRP
- removal of unnecessary code in the client. 
						
						
					 
					
						2011-11-25 00:18:10 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Ben Laurie 
							
						 
					 
					
						
						
							
						
						b1d7429186 
					 
					
						
						
							
							Add TLS exporter.  
						
						 
						
						
						
						
					 
					
						2011-11-15 23:51:22 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Ben Laurie 
							
						 
					 
					
						
						
							
						
						060a38a2c0 
					 
					
						
						
							
							Add DTLS-SRTP.  
						
						 
						
						
						
						
					 
					
						2011-11-15 23:02:16 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Ben Laurie 
							
						 
					 
					
						
						
							
						
						68b33cc5c7 
					 
					
						
						
							
							Add Next Protocol Negotiation.  
						
						 
						
						
						
						
					 
					
						2011-11-13 21:55:42 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						b08b158b44 
					 
					
						
						
							
							use client version when eliminating TLS v1.2 ciphersuites in client hello  
						
						 
						
						
						
						
					 
					
						2011-10-07 15:07:36 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						aed53d6c5a 
					 
					
						
						
							
							Backport GCM support from HEAD.  
						
						 
						
						
						
						
					 
					
						2011-08-04 11:13:28 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						c8c6e9ecd9 
					 
					
						
						
							
							Add HMAC ECC ciphersuites from RFC5289. Include SHA384 PRF support and  
						
						 
						
						... 
						
						
						
						prohibit use of these ciphersuites for TLS < 1.2 
						
						
					 
					
						2011-07-25 21:45:17 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						277f8a34f4 
					 
					
						
						
							
							use TLS1_get_version macro to check version so TLS v1.2 changes don't interfere with DTLS  
						
						 
						
						
						
						
					 
					
						2011-05-25 11:43:17 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						9472baae0d 
					 
					
						
						
							
							Backport TLS v1.2 support from HEAD.  
						
						 
						
						... 
						
						
						
						This includes TLS v1.2 server and client support but at present
client certificate support is not implemented. 
						
						
					 
					
						2011-05-11 13:37:52 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Ben Laurie 
							
						 
					 
					
						
						
							
						
						a149b2466e 
					 
					
						
						
							
							Add SRP.  
						
						 
						
						
						
						
					 
					
						2011-03-16 11:26:40 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						b4b15f68c0 
					 
					
						
						
							
							Backport TLS v1.1 support from HEAD, ssl/ changes  
						
						 
						
						
						
						
					 
					
						2010-06-27 14:22:11 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						73582b8117 
					 
					
						
						
							
							add missing parts of reneg port, fix apps patch  
						
						 
						
						
						
						
					 
					
						2009-11-11 14:51:29 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						6c24dd9005 
					 
					
						
						
							
							Typo.  
						
						 
						
						
						
						
					 
					
						2009-06-30 20:55:55 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						cc1cb996f1 
					 
					
						
						
							
							Submitted by: Artem Chuprina <ran@cryptocom.ru>  
						
						 
						
						... 
						
						
						
						Reviewed by: steve@openssl.org 
Fix to match latest GOST in TLS draft. 
						
						
					 
					
						2009-05-28 18:10:47 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						12bf56c017 
					 
					
						
						
							
							PR: 1574  
						
						 
						
						... 
						
						
						
						Submitted by: Jouni Malinen <j@w1.fi >
Approved by: steve@openssl.org 
Ticket override support for EAP-FAST. 
						
						
					 
					
						2008-11-15 17:18:12 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						8a2062fefe 
					 
					
						
						
							
							Update from stable branch.  
						
						 
						
						
						
						
					 
					
						2008-04-30 16:14:02 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						67c8e7f414 
					 
					
						
						
							
							Support for certificate status TLS extension.  
						
						 
						
						
						
						
					 
					
						2007-09-26 21:56:59 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Bodo Möller 
							
						 
					 
					
						
						
							
						
						761772d7e1 
					 
					
						
						
							
							Implement the Opaque PRF Input TLS extension  
						
						 
						
						... 
						
						
						
						(draft-rescorla-tls-opaque-prf-input-00.txt), and do some cleanups and
bugfixes on the way.  In particular, this fixes the buffer bounds
checks in ssl_add_clienthello_tlsext() and in ssl_add_serverhello_tlsext().
Note that the opaque PRF Input TLS extension is not compiled by default;
see CHANGES. 
						
						
					 
					
						2007-09-21 06:54:24 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						81025661a9 
					 
					
						
						
							
							Update ssl code to support digests other than MD5+SHA1 in handshake.  
						
						 
						
						... 
						
						
						
						Submitted by: Victor B. Wagner <vitus@cryptocom.ru > 
						
						
					 
					
						2007-08-31 12:42:53 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						94d511cdbd 
					 
					
						
						
							
							Add ctrls to set and get RFC4507bis keys to enable several contexts to  
						
						 
						
						... 
						
						
						
						reuse the same tickets. 
						
						
					 
					
						2007-08-28 01:08:45 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						6434abbfc6 
					 
					
						
						
							
							RFC4507 (including RFC4507bis) TLS stateless session resumption support  
						
						 
						
						... 
						
						
						
						for OpenSSL. 
						
						
					 
					
						2007-08-11 23:18:29 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						b948e2c59e 
					 
					
						
						
							
							Update ssl library to support EVP_PKEY MAC API. Include generic MAC support.  
						
						 
						
						
						
						
					 
					
						2007-06-04 17:04:40 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Bodo Möller 
							
						 
					 
					
						
						
							
						
						96afc1cfd5 
					 
					
						
						
							
							Add SEED encryption algorithm.  
						
						 
						
						... 
						
						
						
						PR: 1503
Submitted by: KISA
Reviewed by: Bodo Moeller 
						
						
					 
					
						2007-04-23 23:48:59 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Bodo Möller 
							
						 
					 
					
						
						
							
						
						5b57fe0a1e 
					 
					
						
						
							
							Disable invalid ciphersuites  
						
						 
						
						
						
						
					 
					
						2006-06-14 17:51:46 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Bodo Möller 
							
						 
					 
					
						
						
							
						
						f3dea9a595 
					 
					
						
						
							
							Camellia cipher, contributed by NTT  
						
						 
						
						... 
						
						
						
						Submitted by: Masashi Fujita
Reviewed by: Bodo Moeller 
						
						
					 
					
						2006-06-09 15:44:59 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Bodo Möller 
							
						 
					 
					
						
						
							
						
						b6acb8d0de 
					 
					
						
						
							
							udpate Supported Point Formats Extension code  
						
						 
						
						... 
						
						
						
						Submitted by: Douglas Stebila 
						
						
					 
					
						2006-03-13 01:24:38 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Bodo Möller 
							
						 
					 
					
						
						
							
						
						36ca4ba63d 
					 
					
						
						
							
							Implement the Supported Point Formats Extension for ECC ciphersuites  
						
						 
						
						... 
						
						
						
						Submitted by: Douglas Stebila 
						
						
					 
					
						2006-03-11 23:46:37 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Nils Larsch 
							
						 
					 
					
						
						
							
						
						ddac197404 
					 
					
						
						
							
							add initial support for RFC 4279 PSK SSL ciphersuites  
						
						 
						
						... 
						
						
						
						PR: 1191
Submitted by: Mika Kousa and Pasi Eronen of Nokia Corporation
Reviewed by: Nils Larsch 
						
						
					 
					
						2006-03-10 23:06:27 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Bodo Möller 
							
						 
					 
					
						
						
							
						
						241520e66d 
					 
					
						
						
							
							More TLS extension related changes.  
						
						 
						
						... 
						
						
						
						Submitted by: Peter Sylvester 
						
						
					 
					
						2006-01-11 06:10:40 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Bodo Möller 
							
						 
					 
					
						
						
							
						
						a13c20f603 
					 
					
						
						
							
							Further TLS extension updates  
						
						 
						
						... 
						
						
						
						Submitted by: Peter Sylvester 
						
						
					 
					
						2006-01-09 19:49:05 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Bodo Möller 
							
						 
					 
					
						
						
							
						
						01c76c6606 
					 
					
						
						
							
							There's no such things as DTLS1_AD_MISSING_HANDSHAKE_MESSAGE.  
						
						 
						
						... 
						
						
						
						For now, anyway. 
						
						
					 
					
						2006-01-07 20:44:29 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Bodo Möller 
							
						 
					 
					
						
						
							
						
						3ff94a009b 
					 
					
						
						
							
							complete and correct RFC3546 error codes  
						
						 
						
						
						
						
					 
					
						2006-01-07 20:28:11 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Bodo Möller 
							
						 
					 
					
						
						
							
						
						1aeb3da83f 
					 
					
						
						
							
							Fixes for TLS server_name extension  
						
						 
						
						... 
						
						
						
						Submitted by: Peter Sylvester 
						
						
					 
					
						2006-01-06 09:08:59 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Bodo Möller 
							
						 
					 
					
						
						
							
						
						f1fd4544a3 
					 
					
						
						
							
							Various changes in the new TLS extension code, including the following:  
						
						 
						
						... 
						
						
						
						- fix indentation
 - rename some functions and macros
 - fix up confusion between SSL_ERROR_... and SSL_AD_... values 
						
						
					 
					
						2006-01-03 03:27:19 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Bodo Möller 
							
						 
					 
					
						
						
							
						
						ed3883d21b 
					 
					
						
						
							
							Support TLS extensions (specifically, HostName)  
						
						 
						
						... 
						
						
						
						Submitted by: Peter Sylvester 
						
						
					 
					
						2006-01-02 23:14:37 +00:00