Jonas Maebe 
							
						 
					 
					
						
						
							
						
						462319c3e9 
					 
					
						
						
							
							JPAKE_CTX_new: check for NULL result when allocating ctx  
						
						... 
						
						
						
						Signed-off-by: Kurt Roeckx <kurt@openssl.org >
Reviewed-by: Dr. Stephen Henson <steve@openssl.org > 
						
						
					 
					
						2014-08-17 18:54:11 +02:00 
						 
				 
			
				
					
						
							
							
								Jonas Maebe 
							
						 
					 
					
						
						
							
						
						34374c2d2c 
					 
					
						
						
							
							old_hmac_encode: check for NULL result when allocating *pder  
						
						... 
						
						
						
						Signed-off-by: Kurt Roeckx <kurt@openssl.org >
Reviewed-by: Rich Salz <rsalz@openssl.org > 
						
						
					 
					
						2014-08-17 18:52:44 +02:00 
						 
				 
			
				
					
						
							
							
								Jonas Maebe 
							
						 
					 
					
						
						
							
						
						6f77f82bfc 
					 
					
						
						
							
							dev_crypto_md5_copy: return error if allocating to_md->data fails  
						
						... 
						
						
						
						Signed-off-by: Kurt Roeckx <kurt@openssl.org >
Reviewed-by: Rich Salz <rsalz@openssl.org > 
						
						
					 
					
						2014-08-17 18:52:30 +02:00 
						 
				 
			
				
					
						
							
							
								Jonas Maebe 
							
						 
					 
					
						
						
							
						
						771e0c6c7a 
					 
					
						
						
							
							dev_crypto_md5_update: check result of realloc(md_data->data) and don't leak memory if it fails  
						
						... 
						
						
						
						Signed-off-by: Kurt Roeckx <kurt@openssl.org >
Reviewed-by: Rich Salz <rsalz@openssl.org > 
						
						
					 
					
						2014-08-17 18:52:14 +02:00 
						 
				 
			
				
					
						
							
							
								Jonas Maebe 
							
						 
					 
					
						
						
							
						
						d8513b4abd 
					 
					
						
						
							
							dev_crypto_cipher: return immediately if allocating cin/cout failed  
						
						... 
						
						
						
						Signed-off-by: Kurt Roeckx <kurt@openssl.org >
Reviewed-by: Rich Salz <rsalz@openssl.org > 
						
						
					 
					
						2014-08-17 18:51:35 +02:00 
						 
				 
			
				
					
						
							
							
								Jonas Maebe 
							
						 
					 
					
						
						
							
						
						c84029dbdc 
					 
					
						
						
							
							dev_crypto_init_key: return error if allocating CDATA(ctx)->key failed  
						
						... 
						
						
						
						Signed-off-by: Kurt Roeckx <kurt@openssl.org >
Reviewed-by: Rich Salz <rsalz@openssl.org > 
						
						
					 
					
						2014-08-17 18:51:16 +02:00 
						 
				 
			
				
					
						
							
							
								Hubert Kario 
							
						 
					 
					
						
						
							
						
						750487899a 
					 
					
						
						
							
							Add support for Camellia HMAC-Based cipher suites from RFC6367  
						
						... 
						
						
						
						While RFC6367 focuses on Camellia-GCM cipher suites, it also adds a few
cipher suites that use SHA-2 based HMAC that can be very easily
added.
Tested against gnutls 3.3.5
PR#3443
Reviewed-by: Tim Hudson <tjh@openssl.org > 
						
						
					 
					
						2014-08-15 23:41:20 +01:00 
						 
				 
			
				
					
						
							
							
								Matt Caswell 
							
						 
					 
					
						
						
							
						
						f2be92b94d 
					 
					
						
						
							
							Fixed out-of-bounds read errors in ssl3_get_key_exchange.  
						
						... 
						
						
						
						PR#3450
Reviewed-by: Emilia Käsper <emilia@openssl.org > 
						
						
					 
					
						2014-08-15 23:27:34 +01:00 
						 
				 
			
				
					
						
							
							
								Rich Salz 
							
						 
					 
					
						
						
							
						
						c9a81b3026 
					 
					
						
						
							
							RT2751: Declare get_issuer_sk() earlier.  
						
						... 
						
						
						
						Add a declaration for get_issuer_sk() so that other
functions in x509_vf.c could use it.  (Planned work
around cross-certification chains.)
Reviewed-by: Kurt Roeckx <kurt@openssl.org > 
						
						
					 
					
						2014-08-15 17:49:03 -04:00 
						 
				 
			
				
					
						
							
							
								Jonas Maebe 
							
						 
					 
					
						
						
							
						
						d6f69ae547 
					 
					
						
						
							
							cryptodev_digest_copy: return error if allocating dstate->mac_data fails  
						
						... 
						
						
						
						Signed-off-by: Kurt Roeckx <kurt@openssl.org >
Reviewed-by: Rich Salz <rsalz@openssl.org > 
						
						
					 
					
						2014-08-15 22:38:51 +02:00 
						 
				 
			
				
					
						
							
							
								Jonas Maebe 
							
						 
					 
					
						
						
							
						
						349e6b2b0a 
					 
					
						
						
							
							cryptodev_digest_update: don't leak original state->mac_data if realloc fails  
						
						... 
						
						
						
						Signed-off-by: Kurt Roeckx <kurt@openssl.org >
Reviewed-by: Rich Salz <rsalz@openssl.org > 
						
						
					 
					
						2014-08-15 22:38:36 +02:00 
						 
				 
			
				
					
						
							
							
								Jonas Maebe 
							
						 
					 
					
						
						
							
						
						36f7ed5040 
					 
					
						
						
							
							cms_SignerInfo_content_sign: free sig on failure path  
						
						... 
						
						
						
						Signed-off-by: Kurt Roeckx <kurt@openssl.org >
Reviewed-by: Rich Salz <rsalz@openssl.org > 
						
						
					 
					
						2014-08-15 22:38:19 +02:00 
						 
				 
			
				
					
						
							
							
								Jonas Maebe 
							
						 
					 
					
						
						
							
						
						4e64f671c9 
					 
					
						
						
							
							rtcp_new: return failure if allocation of bi->ptr failed  
						
						... 
						
						
						
						Signed-off-by: Kurt Roeckx <kurt@openssl.org >
Reviewed-by: Rich Salz <rsalz@openssl.org > 
						
						
					 
					
						2014-08-15 22:38:05 +02:00 
						 
				 
			
				
					
						
							
							
								Jonas Maebe 
							
						 
					 
					
						
						
							
						
						1c4b688cb4 
					 
					
						
						
							
							multi_split: check for NULL when allocating parts and bpart, and for failure of sk_BIO_push()  
						
						... 
						
						
						
						Signed-off-by: Kurt Roeckx <kurt@openssl.org >
Reviewed-by: Rich Salz <rsalz@openssl.org > 
						
						
					 
					
						2014-08-15 22:37:48 +02:00 
						 
				 
			
				
					
						
							
							
								Jonas Maebe 
							
						 
					 
					
						
						
							
						
						bd4acbc70e 
					 
					
						
						
							
							BIO_new_dgram_sctp, dgram_sctp_read: zero entire authchunks  
						
						... 
						
						
						
						Signed-off-by: Kurt Roeckx <kurt@openssl.org >
Reviewed-by: Rich Salz <rsalz@openssl.org > 
						
						
					 
					
						2014-08-15 22:37:28 +02:00 
						 
				 
			
				
					
						
							
							
								Jonas Maebe 
							
						 
					 
					
						
						
							
						
						8957278869 
					 
					
						
						
							
							mime_hdr_addparam: free tmpname, tmpval and mparam on error path, and check whether sk_MIME_PARAM_push succeeds  
						
						... 
						
						
						
						Signed-off-by: Kurt Roeckx <kurt@openssl.org >
Reviewed-by: Rich Salz <rsalz@openssl.org > 
						
						
					 
					
						2014-08-15 22:37:14 +02:00 
						 
				 
			
				
					
						
							
							
								Jonas Maebe 
							
						 
					 
					
						
						
							
						
						15297d962c 
					 
					
						
						
							
							mime_hdr_new: free mhdr, tmpname, tmpval on error path  
						
						... 
						
						
						
						Signed-off-by: Kurt Roeckx <kurt@openssl.org >
Reviewed-by: Rich Salz <rsalz@openssl.org > 
						
						
					 
					
						2014-08-15 22:36:54 +02:00 
						 
				 
			
				
					
						
							
							
								Jonas Maebe 
							
						 
					 
					
						
						
							
						
						c9c63b0180 
					 
					
						
						
							
							ASN1_verify, ASN1_item_verify: cleanse and free buf_in on error path  
						
						... 
						
						
						
						Signed-off-by: Kurt Roeckx <kurt@openssl.org >
Reviewed-by: Rich Salz <rsalz@openssl.org > 
						
						
					 
					
						2014-08-15 22:36:34 +02:00 
						 
				 
			
				
					
						
							
							
								Jonas Maebe 
							
						 
					 
					
						
						
							
						
						b9b9f853b5 
					 
					
						
						
							
							SetBlob: free rgSetBlob on error path  
						
						... 
						
						
						
						Signed-off-by: Kurt Roeckx <kurt@openssl.org >
Reviewed-by: Rich Salz <rsalz@openssl.org > 
						
						
					 
					
						2014-08-15 22:35:11 +02:00 
						 
				 
			
				
					
						
							
							
								Istvan Noszticzius 
							
						 
					 
					
						
						
							
						
						865886553d 
					 
					
						
						
							
							Fix use after free bug.  
						
						... 
						
						
						
						Reviewed-by: Stephen Henson <steve@openssl.org >
Reviewed-by: Emilia Käsper <emilia@openssl.org > 
						
						
					 
					
						2014-08-15 16:50:16 +01:00 
						 
				 
			
				
					
						
							
							
								Frdric Giudicelli 
							
						 
					 
					
						
						
							
						
						c753e71e0a 
					 
					
						
						
							
							RT783: Minor optimization to ASN1_INTEGER_set  
						
						... 
						
						
						
						Remove local variable and avoid extra assignment.
Reviewed-by: Emilia Kasper <emilia@silkandcyanide.net > 
						
						
					 
					
						2014-08-15 10:54:43 -04:00 
						 
				 
			
				
					
						
							
							
								Rob Austein 
							
						 
					 
					
						
						
							
						
						cf8bac4456 
					 
					
						
						
							
							RT2465: Silence some gcc warnings  
						
						... 
						
						
						
						"Another machine, another version of gcc, another batch
of compiler warnings."  Add "=NULL" to some local variable
declarations that are set by passing thier address into a
utility function; confuses GCC it might not be set.
Reviewed-by: Emilia Ksper <emilia@silkandcyanide.net > 
						
						
					 
					
						2014-08-15 10:52:06 -04:00 
						 
				 
			
				
					
						
							
							
								Hans Wennborg 
							
						 
					 
					
						
						
							
						
						01e438f288 
					 
					
						
						
							
							RT3023: Redundant logical expressions  
						
						... 
						
						
						
						Remove some redundant logical expressions
Reviewed-by: Emilia Kasper <emilia@silkandcyanide.net > 
						
						
					 
					
						2014-08-15 10:45:00 -04:00 
						 
				 
			
				
					
						
							
							
								Rich Salz 
							
						 
					 
					
						
						
							
						
						5effa35610 
					 
					
						
						
							
							Merge branch 'master' of git.openssl.org:openssl  
						
						
						
						
					 
					
						2014-08-15 10:41:50 -04:00 
						 
				 
			
				
					
						
							
							
								Claus Assmann 
							
						 
					 
					
						
						
							
						
						14e961921a 
					 
					
						
						
							
							RT3268: Fix spelling errors in CHANGES file.  
						
						... 
						
						
						
						Fix a bunch of typo's and speling (sic) errors in the CHANGES file.
Reviewed-by: Tim Hudson <tjh@cryptsoft.com > 
						
						
					 
					
						2014-08-15 10:41:13 -04:00 
						 
				 
			
				
					
						
							
							
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						b83294fe30 
					 
					
						
						
							
							Revision of custom extension code.  
						
						... 
						
						
						
						Move custom extension structures from SSL_CTX to CERT structure.
This change means the form can be revised in future without binary
compatibility issues. Also since CERT is part of SSL structures
so per-SSL custom extensions could be supported in future as well as
per SSL_CTX.
Reviewed-by: Rich Salz <rsalz@openssl.org >
Reviewed-by: Emilia Käsper <emilia@openssl.org > 
						
						
					 
					
						2014-08-15 12:20:04 +01:00 
						 
				 
			
				
					
						
							
							
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						06f5d12f51 
					 
					
						
						
							
							Include error messages on extension check failure.  
						
						... 
						
						
						
						Reviewed-by: Emilia Käsper <emilia@openssl.org > 
						
						
					 
					
						2014-08-15 12:16:16 +01:00 
						 
				 
			
				
					
						
							
							
								Emilia Kasper 
							
						 
					 
					
						
						
							
						
						f0ca9ccaef 
					 
					
						
						
							
							make depend  
						
						... 
						
						
						
						Reviewed-by: Dr. Stephen Henson <steve@openssl.org > 
						
						
					 
					
						2014-08-14 15:24:58 +02:00 
						 
				 
			
				
					
						
							
							
								Bodo Moeller 
							
						 
					 
					
						
						
							
						
						16602b5cd5 
					 
					
						
						
							
							Further improve/fix ec_GFp_simple_points_make_affine (ecp_smpl.c) and  
						
						... 
						
						
						
						group_order_tests (ectest.c).  Also fix the EC_POINTs_mul documentation (ec.h).
Reviewed-by: emilia@openssl.org  
						
						
					 
					
						2014-08-13 17:37:19 +02:00 
						 
				 
			
				
					
						
							
							
								Matt Caswell 
							
						 
					 
					
						
						
							
						
						690a2b1fa2 
					 
					
						
						
							
							RT1665: Fix podpath to get xref's right  
						
						... 
						
						
						
						In Makefile, when build manpages, put the current directory
at the start of the podpath so that cross-refs find the
local directory first.
Reviewed-by: Tim Hudson <tjh@cryptosoft.com > 
						
						
					 
					
						2014-08-13 00:31:02 -04:00 
						 
				 
			
				
					
						
							
							
								Ingo Schwarze 
							
						 
					 
					
						
						
							
						
						bebbb11d13 
					 
					
						
						
							
							RT3239: Extra comma in NAME lines of two manpages  
						
						... 
						
						
						
						In two OpenSSL manual pages, in the NAME section, the last word of the
name list is followed by a stray trailing comma. While this may seem
minor, it is worth fixing because it may confuse some makewhatis(8)
implementations.
While here, also add the missing word "size" to the one line
description in SSL_CTX_set_max_cert_list(3).
Reviewed by: Dr Stephen Henson <shenson@drh-consultancy.co.uk > 
						
						
					 
					
						2014-08-12 15:59:18 -04:00 
						 
				 
			
				
					
						
							
							
								Rich Salz 
							
						 
					 
					
						
						
							
						
						1c5be3d7f0 
					 
					
						
						
							
							Merge branch 'master' of git.openssl.org:openssl  
						
						
						
						
					 
					
						2014-08-12 15:33:36 -04:00 
						 
				 
			
				
					
						
							
							
								nnposter@users.sourceforge.net 
							
						 
					 
					
						
						
							
						
						cde8ad1a28 
					 
					
						
						
							
							PR 719: Configure not exiting with child status  
						
						... 
						
						
						
						If subcommand fails, just die.
Reviewed-by: Kurt Roeckx <kurt@roeckx.be > 
						
						
					 
					
						2014-08-12 14:45:49 -04:00 
						 
				 
			
				
					
						
							
							
								nnposter@users.sourceforge.net 
							
						 
					 
					
						
						
							
						
						16caa9a43d 
					 
					
						
						
							
							PR 718: Configure not exiting with child status  
						
						... 
						
						
						
						If subcommand fails, just die.
Reviewed-by: Kurt Roeckx <kurt@roeckx.be > 
						
						
					 
					
						2014-08-12 14:44:51 -04:00 
						 
				 
			
				
					
						
							
							
								Nick Lewis 
							
						 
					 
					
						
						
							
						
						9aaa7be8d4 
					 
					
						
						
							
							PR 2580: dgst missing current SHA algorithms  
						
						... 
						
						
						
						Update the dgst.pod page to include SHA224...512 algorithms.
Update apps/progs.pl to add them to the digest command table.
Reviewed-by: Tim Hudson <tjh@cryptosoft.com > 
						
						
					 
					
						2014-08-12 11:29:20 -04:00 
						 
				 
			
				
					
						
							
							
								Rich Salz 
							
						 
					 
					
						
						
							
						
						2a1393a4a8 
					 
					
						
						
							
							Revert "RT 2820: Case-insensitive filenames on Darwin"  
						
						... 
						
						
						
						This reverts commit 691edc997a 
						
						
					 
					
						2014-08-12 11:22:50 -04:00 
						 
				 
			
				
					
						
							
							
								Nick Urbanik 
							
						 
					 
					
						
						
							
						
						42ce91cc35 
					 
					
						
						
							
							RT2609: Typo in EXAMPLE section of req.pod  
						
						... 
						
						
						
						The x509_extensions should be req_extensions in the
config example in req.pod
Reviewed-by: tjh@cryptsoft.com  
						
						
					 
					
						2014-08-12 11:16:58 -04:00 
						 
				 
			
				
					
						
							
							
								Dr Stephen Henson 
							
						 
					 
					
						
						
							
						
						b00f586a81 
					 
					
						
						
							
							Fix  d4a4370050 
						
						... 
						
						
						
						Fully remove old error, per drH
Reviewed-by: rsalz 
						
						
					 
					
						2014-08-11 17:32:57 -04:00 
						 
				 
			
				
					
						
							
							
								Jim Reid 
							
						 
					 
					
						
						
							
						
						691edc997a 
					 
					
						
						
							
							RT 2820: Case-insensitive filenames on Darwin  
						
						... 
						
						
						
						Add darwin-*-cc as one of the systems for case-insensitive
filenames.  Fixes the manpage install so it doesn't create
looping symlinks. 
						
						
					 
					
						2014-08-11 15:06:54 -04:00 
						 
				 
			
				
					
						
							
							
								Rich Salz 
							
						 
					 
					
						
						
							
						
						d9fcd8ec4c 
					 
					
						
						
							
							Merge branch 'master' of git.openssl.org:openssl  
						
						
						
						
					 
					
						2014-08-11 13:45:03 -04:00 
						 
				 
			
				
					
						
							
							
								Rich Salz 
							
						 
					 
					
						
						
							
						
						cbfc8baddb 
					 
					
						
						
							
							Undo  77bf69dced 
						
						... 
						
						
						
						Not approved; mistakenly pushed commit that added README.md 
						
						
					 
					
						2014-08-11 13:44:25 -04:00 
						 
				 
			
				
					
						
							
							
								Scott Schaefer 
							
						 
					 
					
						
						
							
						
						d4a4370050 
					 
					
						
						
							
							RT 2517: Various typo's.  
						
						... 
						
						
						
						Reviewed-by: Emilia Kasper
Many of these were already fixed, this catches the last
few that were missed. 
						
						
					 
					
						2014-08-11 13:43:31 -04:00 
						 
				 
			
				
					
						
							
							
								Scott Schaefer 
							
						 
					 
					
						
						
							
						
						590bdcc686 
					 
					
						
						
							
							RT 2517: Various typo's.  
						
						... 
						
						
						
						Many of these were already fixed, this catches the last
few that were missed. 
						
						
					 
					
						2014-08-11 13:12:53 -04:00 
						 
				 
			
				
					
						
							
							
								Rich Salz 
							
						 
					 
					
						
						
							
						
						77bf69dced 
					 
					
						
						
							
							Add README.md  
						
						... 
						
						
						
						A small markdown README for GitHub users; points them to
the right README and the website and RT tracker. 
						
						
					 
					
						2014-08-11 11:35:32 -04:00 
						 
				 
			
				
					
						
							
							
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						9e72d496d4 
					 
					
						
						
							
							Fix SRP authentication ciphersuites.  
						
						... 
						
						
						
						The addition of SRP authentication needs to be checked in various places
to work properly. Specifically:
A certificate is not sent.
A certificate request must not be sent.
Server key exchange message must not contain a signature.
If appropriate SRP authentication ciphersuites should be chosen.
Reviewed-by: Matt Caswell <matt@openssl.org > 
						
						
					 
					
						2014-08-09 13:21:30 +01:00 
						 
				 
			
				
					
						
							
							
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						562fd0d883 
					 
					
						
						
							
							Test SRP authentication ciphersuites.  
						
						... 
						
						
						
						Reviewed-by: Matt Caswell <matt@openssl.org > 
						
						
					 
					
						2014-08-09 13:21:29 +01:00 
						 
				 
			
				
					
						
							
							
								Rich Salz 
							
						 
					 
					
						
						
							
						
						f642ebc1e2 
					 
					
						
						
							
							Undo  a90081576c 
						
						... 
						
						
						
						Undo unapproved commit that removed DJGPP and WATT32 
						
						
					 
					
						2014-08-09 08:02:20 -04:00 
						 
				 
			
				
					
						
							
							
								Viktor Szakats 
							
						 
					 
					
						
						
							
						
						693b71fa71 
					 
					
						
						
							
							RT 1988: Add "const" to SSL_use_RSAPrivateKey_ASN1  
						
						... 
						
						
						
						The "unsigned char *d" should be const.
Reviewed-by: Kurt Roeckx <kurt@roeckx.be > 
						
						
					 
					
						2014-08-09 07:56:28 -04:00 
						 
				 
			
				
					
						
							
							
								Matthieu Crapet 
							
						 
					 
					
						
						
							
						
						6d03125ccf 
					 
					
						
						
							
							RT 1505: Use SSL3_AL_FATAL not "2"  
						
						... 
						
						
						
						Use SSL3_AL_FATAL instead of the literal constant "2"
Every bit of cleanup helps.
Reviewed-by: Matt Caswell <matt@openssl.org > 
						
						
					 
					
						2014-08-08 22:47:33 -04:00 
						 
				 
			
				
					
						
							
							
								Rich Salz 
							
						 
					 
					
						
						
							
						
						a90081576c 
					 
					
						
						
							
							Remove DJGPP (and therefore WATT32) #ifdef's.  
						
						... 
						
						
						
						DJGPP is no longer a supported platform.  Remove all #ifdef, etc.,
cases that refer to it.  DJGPP also #define'd WATT32, so that
is now removed as well. 
						
						
					 
					
						2014-08-08 16:54:14 -04:00