Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						1d7392f219 
					 
					
						
						
							
							PR: 2602  
						
						 
						
						... 
						
						
						
						Submitted by: Robin Seggelmann <seggelmann@fh-muenster.de >
Reviewed by: steve
Fix DTLS bug which prevents manual MTU setting 
						
						
					 
					
						2011-09-23 13:34:48 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						28dd49faec 
					 
					
						
						
							
							Expand range of ctrls for AES GCM to support retrieval and setting of  
						
						 
						
						... 
						
						
						
						invocation field.
Add complete support for AES GCM ciphersuites including all those in
RFC5288 and RFC5289. 
						
						
					 
					
						2011-08-03 15:37:22 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						d09677ac45 
					 
					
						
						
							
							Add HMAC ECC ciphersuites from RFC5289. Include SHA384 PRF support and  
						
						 
						
						... 
						
						
						
						prohibit use of these ciphersuites for TLS < 1.2 
						
						
					 
					
						2011-07-25 20:41:32 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						f37f20ffd3 
					 
					
						
						
							
							PR: 2295  
						
						 
						
						... 
						
						
						
						Submitted by: Alexei Khlebnikov <alexei.khlebnikov@opera.com >
Reviewed by: steve
OOM checking. Leak in OOM fix. Fall-through comment. Duplicate code
elimination. 
						
						
					 
					
						2011-05-20 14:56:29 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						8f82912460 
					 
					
						
						
							
							Process signature algorithms during TLS v1.2 client authentication.  
						
						 
						
						... 
						
						
						
						Make sure message is long enough for signature algorithms. 
						
						
					 
					
						2011-05-12 14:38:01 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						a2f9200fba 
					 
					
						
						
							
							Initial TLS v1.2 client support. Include a default supported signature  
						
						 
						
						... 
						
						
						
						algorithms extension (including everything we support). Swicth to new
signature format where needed and relax ECC restrictions.
Not TLS v1.2 client certifcate support yet but client will handle case
where a certificate is requested and we don't have one. 
						
						
					 
					
						2011-05-09 15:44:01 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						6b7be581e5 
					 
					
						
						
							
							Continuing TLS v1.2 support: add support for server parsing of  
						
						 
						
						... 
						
						
						
						signature algorithms extension and correct signature format for
server key exchange.
All ciphersuites should now work on the server but no client support and
no client certificate support yet. 
						
						
					 
					
						2011-05-06 13:00:07 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						7409d7ad51 
					 
					
						
						
							
							Initial incomplete TLS v1.2 support. New ciphersuites added, new version  
						
						 
						
						... 
						
						
						
						checking added, SHA256 PRF support added.
At present only RSA key exchange ciphersuites work with TLS v1.2 as the
new signature format is not yet implemented. 
						
						
					 
					
						2011-04-29 22:56:51 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Ben Laurie 
							
						 
					 
					
						
						
							
						
						edc032b5e3 
					 
					
						
						
							
							Add SRP support.  
						
						 
						
						
						
						
					 
					
						2011-03-12 17:01:19 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Ben Laurie 
							
						 
					 
					
						
						
							
						
						bf48836c7c 
					 
					
						
						
							
							Fixes to NPN from Adam Langley.  
						
						 
						
						
						
						
					 
					
						2010-09-05 17:14:01 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Ben Laurie 
							
						 
					 
					
						
						
							
						
						ee2ffc2794 
					 
					
						
						
							
							Add Next Protocol Negotiation.  
						
						 
						
						
						
						
					 
					
						2010-07-28 10:06:55 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						8025e25113 
					 
					
						
						
							
							PR: 2121  
						
						 
						
						... 
						
						
						
						Submitted by: Robin Seggelmann <seggelmann@fh-muenster.de >
Add extension support to DTLS code mainly using existing implementation for
TLS. 
						
						
					 
					
						2009-12-08 11:37:40 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						637f374ad4 
					 
					
						
						
							
							Initial experimental TLSv1.1 support  
						
						 
						
						
						
						
					 
					
						2009-12-07 13:31:02 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						499684404c 
					 
					
						
						
							
							PR: 2115  
						
						 
						
						... 
						
						
						
						Submitted by: Robin Seggelmann <seggelmann@fh-muenster.de >
Approved by: steve@openssl.org 
Add Renegotiation extension to DTLS, fix DTLS ClientHello processing bug. 
						
						
					 
					
						2009-12-01 17:42:15 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						e0e7997212 
					 
					
						
						
							
							First cut of renegotiation extension. (port to HEAD)  
						
						 
						
						
						
						
					 
					
						2009-11-09 19:03:34 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						b972fbaa8f 
					 
					
						
						
							
							PR: 1997  
						
						 
						
						... 
						
						
						
						Submitted by: Robin Seggelmann <seggelmann@fh-muenster.de >
Approved by: steve@openssl.org 
DTLS timeout handling fix. 
						
						
					 
					
						2009-08-12 13:19:54 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						9289f21b7d 
					 
					
						
						
							
							Update from 1.0.0 stable branch.  
						
						 
						
						
						
						
					 
					
						2009-05-16 11:15:42 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						eb38b26dbc 
					 
					
						
						
							
							Update from 1.0.0-stable.  
						
						 
						
						
						
						
					 
					
						2009-05-15 22:58:40 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						e5fa864f62 
					 
					
						
						
							
							Updates from 1.0.0-stable.  
						
						 
						
						
						
						
					 
					
						2009-04-15 15:27:03 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						cc7399e79c 
					 
					
						
						
							
							Changes from 1.0.0-stable.  
						
						 
						
						
						
						
					 
					
						2009-04-07 16:33:26 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Lutz Jänicke 
							
						 
					 
					
						
						
							
						
						fceac0bc74 
					 
					
						
						
							
							Fix compilation with -no-comp by adding some more #ifndef OPENSSL_NO_COMP  
						
						 
						
						... 
						
						
						
						Some #include statements were not properly protected. This will go unnoted
on most systems as openssl/comp.h tends to be installed as a system header
file by default but may become visible when cross compiling. 
						
						
					 
					
						2009-01-05 14:43:05 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Ben Laurie 
							
						 
					 
					
						
						
							
						
						0eab41fb78 
					 
					
						
						
							
							If we're going to return errors (no matter how stupid), then we should  
						
						 
						
						... 
						
						
						
						test for them! 
						
						
					 
					
						2008-12-29 16:11:58 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Ben Laurie 
							
						 
					 
					
						
						
							
						
						6ba71a7173 
					 
					
						
						
							
							Handle the unlikely event that BIO_get_mem_data() returns -ve.  
						
						 
						
						
						
						
					 
					
						2008-12-27 02:00:38 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						e19106f5fb 
					 
					
						
						
							
							Create function of the form OBJ_bsearch_xxx() in bsearch typesafe macros  
						
						 
						
						... 
						
						
						
						with the appropriate parameters which calls OBJ_bsearch(). A compiler will
typically inline this.
This avoids the need for cmp_xxx variables and fixes unchecked const issues
with CHECKED_PTR_OF() 
						
						
					 
					
						2008-10-22 15:43:01 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						606f6c477a 
					 
					
						
						
							
							Fix a shed load or warnings:  
						
						 
						
						... 
						
						
						
						Duplicate const.
Use of ; outside function. 
						
						
					 
					
						2008-10-20 15:12:00 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Ben Laurie 
							
						 
					 
					
						
						
							
						
						babb379849 
					 
					
						
						
							
							Type-checked (and modern C compliant) OBJ_bsearch.  
						
						 
						
						
						
						
					 
					
						2008-10-12 14:32:47 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Bodo Möller 
							
						 
					 
					
						
						
							
						
						96562f2fb3 
					 
					
						
						
							
							update comment  
						
						 
						
						
						
						
					 
					
						2008-09-14 19:50:55 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						3ad74edce8 
					 
					
						
						
							
							Add SSL_FIPS flag for FIPS 140-2 approved ciphersuites and add a new  
						
						 
						
						... 
						
						
						
						strength "FIPS" to represent all FIPS approved ciphersuites without NULL
encryption. 
						
						
					 
					
						2008-09-10 16:02:09 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Bodo Möller 
							
						 
					 
					
						
						
							
						
						474b3b1cc8 
					 
					
						
						
							
							Fix error codes for memory-saving patch.  
						
						 
						
						... 
						
						
						
						Also, get rid of compile-time switch OPENSSL_NO_RELEASE_BUFFERS
because it was rather pointless (the new behavior has to be explicitly
requested by setting SSL_MODE_RELEASE_BUFFERS anyway). 
						
						
					 
					
						2008-08-04 22:10:38 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						45d3767d28 
					 
					
						
						
							
							Prevent signed/unsigned warning on VC++  
						
						 
						
						
						
						
					 
					
						2008-06-03 10:17:45 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Ben Laurie 
							
						 
					 
					
						
						
							
						
						8671b89860 
					 
					
						
						
							
							Memory saving patch.  
						
						 
						
						
						
						
					 
					
						2008-06-03 02:48:34 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						368888bcb6 
					 
					
						
						
							
							Add client cert engine to SSL routines.  
						
						 
						
						
						
						
					 
					
						2008-06-01 22:33:24 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Andy Polyakov 
							
						 
					 
					
						
						
							
						
						5d58f1bbfe 
					 
					
						
						
							
							Prohibit RC4 in DTLS.  
						
						 
						
						
						
						
					 
					
						2007-10-05 21:04:56 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						67c8e7f414 
					 
					
						
						
							
							Support for certificate status TLS extension.  
						
						 
						
						
						
						
					 
					
						2007-09-26 21:56:59 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Bodo Möller 
							
						 
					 
					
						
						
							
						
						761772d7e1 
					 
					
						
						
							
							Implement the Opaque PRF Input TLS extension  
						
						 
						
						... 
						
						
						
						(draft-rescorla-tls-opaque-prf-input-00.txt), and do some cleanups and
bugfixes on the way.  In particular, this fixes the buffer bounds
checks in ssl_add_clienthello_tlsext() and in ssl_add_serverhello_tlsext().
Note that the opaque PRF Input TLS extension is not compiled by default;
see CHANGES. 
						
						
					 
					
						2007-09-21 06:54:24 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						81025661a9 
					 
					
						
						
							
							Update ssl code to support digests other than MD5+SHA1 in handshake.  
						
						 
						
						... 
						
						
						
						Submitted by: Victor B. Wagner <vitus@cryptocom.ru > 
						
						
					 
					
						2007-08-31 12:42:53 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						956006b741 
					 
					
						
						
							
							Use SHA256 for ticket HMAC if possible.  
						
						 
						
						
						
						
					 
					
						2007-08-20 12:35:20 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						367eb1f125 
					 
					
						
						
							
							Fix warning and make no-tlsext work.  
						
						 
						
						
						
						
					 
					
						2007-08-12 18:56:14 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						6434abbfc6 
					 
					
						
						
							
							RFC4507 (including RFC4507bis) TLS stateless session resumption support  
						
						 
						
						... 
						
						
						
						for OpenSSL. 
						
						
					 
					
						2007-08-11 23:18:29 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						b948e2c59e 
					 
					
						
						
							
							Update ssl library to support EVP_PKEY MAC API. Include generic MAC support.  
						
						 
						
						
						
						
					 
					
						2007-06-04 17:04:40 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Bodo Möller 
							
						 
					 
					
						
						
							
						
						96afc1cfd5 
					 
					
						
						
							
							Add SEED encryption algorithm.  
						
						 
						
						... 
						
						
						
						PR: 1503
Submitted by: KISA
Reviewed by: Bodo Moeller 
						
						
					 
					
						2007-04-23 23:48:59 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						9981a51e42 
					 
					
						
						
							
							Stage 1 GOST ciphersuite support.  
						
						 
						
						... 
						
						
						
						Submitted by: ran@cryptocom.ru 
Reviewed by: steve@openssl.org  
						
						
					 
					
						2007-03-23 17:04:05 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Bodo Möller 
							
						 
					 
					
						
						
							
						
						52b8dad8ec 
					 
					
						
						
							
							Reorganize the data used for SSL ciphersuite pattern matching.  
						
						 
						
						... 
						
						
						
						This change resolves a number of problems and obviates multiple kludges.
A new feature is that you can now say "AES256" or "AES128" (not just
"AES", which enables both).
In some cases the ciphersuite list generated from a given string is
affected by this change.  I hope this is just in those cases where the
previous behaviour did not make sense. 
						
						
					 
					
						2007-02-17 06:45:38 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Bodo Möller 
							
						 
					 
					
						
						
							
						
						ed3ecd801e 
					 
					
						
						
							
							Error messages for client ECC cert verification.  
						
						 
						
						... 
						
						
						
						Also, change the default ciphersuite to give some prefererence to
ciphersuites with forwared secrecy (rather than using a random order). 
						
						
					 
					
						2006-06-15 19:58:22 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Bodo Möller 
							
						 
					 
					
						
						
							
						
						89bbe14c50 
					 
					
						
						
							
							Ciphersuite string bugfixes, and ECC-related (re-)definitions.  
						
						 
						
						
						
						
					 
					
						2006-06-14 17:40:31 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Bodo Möller 
							
						 
					 
					
						
						
							
						
						f3dea9a595 
					 
					
						
						
							
							Camellia cipher, contributed by NTT  
						
						 
						
						... 
						
						
						
						Submitted by: Masashi Fujita
Reviewed by: Bodo Moeller 
						
						
					 
					
						2006-06-09 15:44:59 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Bodo Möller 
							
						 
					 
					
						
						
							
						
						332737217a 
					 
					
						
						
							
							Implement Supported Elliptic Curves Extension.  
						
						 
						
						... 
						
						
						
						Submitted by: Douglas Stebila 
						
						
					 
					
						2006-03-30 02:44:56 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Bodo Möller 
							
						 
					 
					
						
						
							
						
						36ca4ba63d 
					 
					
						
						
							
							Implement the Supported Point Formats Extension for ECC ciphersuites  
						
						 
						
						... 
						
						
						
						Submitted by: Douglas Stebila 
						
						
					 
					
						2006-03-11 23:46:37 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Nils Larsch 
							
						 
					 
					
						
						
							
						
						ddac197404 
					 
					
						
						
							
							add initial support for RFC 4279 PSK SSL ciphersuites  
						
						 
						
						... 
						
						
						
						PR: 1191
Submitted by: Mika Kousa and Pasi Eronen of Nokia Corporation
Reviewed by: Nils Larsch 
						
						
					 
					
						2006-03-10 23:06:27 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Bodo Möller 
							
						 
					 
					
						
						
							
						
						58ece83395 
					 
					
						
						
							
							Further TLS extension improvements  
						
						 
						
						... 
						
						
						
						Submitted by: Peter Sylvester 
						
						
					 
					
						2006-01-13 09:21:10 +00:00