Dr. Stephen Henson
|
67e217c84c
|
revert, missing commit message
|
2012-12-20 19:01:55 +00:00 |
|
Dr. Stephen Henson
|
e6b650df0a
|
oops, revert
|
2012-12-20 19:01:34 +00:00 |
|
Dr. Stephen Henson
|
7b7b667ddc
|
apps/ocsp.c
|
2012-12-20 18:59:09 +00:00 |
|
Dr. Stephen Henson
|
70cd3c6b95
|
Integrate host, email and IP address checks into X509_verify.
Add new verify options to set checks.
(backport from HEAD)
|
2012-12-19 15:14:10 +00:00 |
|
Dr. Stephen Henson
|
db05bc512d
|
Return success when the responder is active.
Don't verify our own responses.
(backport from HEAD)
|
2012-12-19 15:02:58 +00:00 |
|
Dr. Stephen Henson
|
45da1efcdb
|
Backport X509 hostname, IP address and email checking code from HEAD.
|
2012-12-19 15:01:59 +00:00 |
|
Dr. Stephen Henson
|
54a0076e94
|
Check chain is not NULL before assuming we have a validated chain. The
modification to the OCSP helper purpose breaks normal OCSP verification. It is
no longer needed now we can trust partial chains.
|
2012-12-19 15:01:32 +00:00 |
|
Andy Polyakov
|
f8cab37bc1
|
VC-32.pl: fix typo [from HEAD].
Submitted by: Pierre Delaage
|
2012-12-16 19:40:51 +00:00 |
|
Dr. Stephen Henson
|
2e65277695
|
Use new partial chain flag instead of modifying input parameters.
(backport from HEAD)
|
2012-12-14 14:31:16 +00:00 |
|
Dr. Stephen Henson
|
9a1f59cd31
|
New verify flag to return success if we have any certificate in the trusted
store instead of the default which is to return an error if we can't build
the complete chain. [backport from HEAD]
|
2012-12-14 14:30:46 +00:00 |
|
Ben Laurie
|
4e72220fd6
|
Documentation improvements by Chris Palmer (Google).
|
2012-12-14 13:29:17 +00:00 |
|
Ben Laurie
|
d65b8b2162
|
Backport OCSP fixes.
|
2012-12-14 12:53:53 +00:00 |
|
Ben Laurie
|
5dca1e338c
|
Document -pubkey option.
|
2012-12-13 16:16:48 +00:00 |
|
Ben Laurie
|
5f4cf08864
|
Make verify return errors.
|
2012-12-13 15:49:15 +00:00 |
|
Ben Laurie
|
2a2e537983
|
Ignore more.
|
2012-12-13 12:43:18 +00:00 |
|
Ben Laurie
|
d79fc8da02
|
Add my 64-bit debug target.
|
2012-12-12 13:45:32 +00:00 |
|
Dr. Stephen Henson
|
e04ccbc5cc
|
Fix two bugs which affect delta CRL handling:
Use -1 to check all extensions in CRLs.
Always set flag for freshest CRL.
|
2012-12-06 18:24:47 +00:00 |
|
Andy Polyakov
|
bc946bfb97
|
aes-s390x.pl: fix XTS bugs in z196-specific code path [from HEAD].
|
2012-12-05 17:45:09 +00:00 |
|
Dr. Stephen Henson
|
38680fa466
|
check mval for NULL too
|
2012-12-04 17:26:04 +00:00 |
|
Dr. Stephen Henson
|
a902b6bd98
|
fix leak
|
2012-12-03 16:33:15 +00:00 |
|
Andy Polyakov
|
c5e91a9ae9
|
aes-s390x.pl: harmonize software-only path [from HEAD].
|
2012-12-01 11:09:13 +00:00 |
|
Dr. Stephen Henson
|
b5f57f455a
|
PR: 2803
Submitted by: jean-etienne.schwartz@bull.net
In OCSP_basic_varify return an error if X509_STORE_CTX_init fails.
|
2012-11-29 19:15:27 +00:00 |
|
Andy Polyakov
|
ad00a52f2d
|
Intel compiler support update from HEAD.
|
2012-11-28 13:12:09 +00:00 |
|
Dr. Stephen Henson
|
e08c7f15b4
|
change inaccurate error message
|
2012-11-26 15:47:44 +00:00 |
|
Dr. Stephen Henson
|
7469af4484
|
reject zero length point format list or supported curves extensions
|
2012-11-22 14:15:36 +00:00 |
|
Dr. Stephen Henson
|
ec76d850af
|
PR: 2908
Submitted by: Dmitry Belyavsky <beldmit@gmail.com>
Fix DH double free if parameter generation fails.
|
2012-11-21 14:02:30 +00:00 |
|
Dr. Stephen Henson
|
cedf19f356
|
fix leaks
|
2012-11-20 00:28:22 +00:00 |
|
Dr. Stephen Henson
|
1d5f3f4640
|
correct docs
|
2012-11-19 20:06:57 +00:00 |
|
Andy Polyakov
|
a060fc3b8e
|
x86_64-gcc.c: resore early clobber constraint [from HEAD].
Submitted by: Florian Weimer
|
2012-11-19 15:02:34 +00:00 |
|
Dr. Stephen Henson
|
bda5153703
|
PR: 2880
Submitted by: "Florian Rüchel" <florian.ruechel@ruhr-uni-bochum.de>
Correctly handle local machine keys in the capi ENGINE.
|
2012-11-18 15:21:12 +00:00 |
|
Dr. Stephen Henson
|
6f539399ef
|
add "missing" TLSv1.2 cipher alias
|
2012-11-15 19:15:07 +00:00 |
|
Andy Polyakov
|
d90bf2ab21
|
[vp]aes-x86[_64].pl: update from HEAD.
|
2012-11-12 18:11:17 +00:00 |
|
Andy Polyakov
|
02620cfcd5
|
Cumulative updates from HEAD.
|
2012-10-29 22:29:29 +00:00 |
|
Dr. Stephen Henson
|
74daafaa94
|
use correct year automatically
|
2012-10-22 13:03:31 +00:00 |
|
Andy Polyakov
|
aa963813ed
|
linux-ppc: make it more robust [from HEAD].
|
2012-10-21 18:25:29 +00:00 |
|
Dr. Stephen Henson
|
9a6aff50ff
|
Don't require tag before ciphertext in AESGCM mode
|
2012-10-16 22:46:32 +00:00 |
|
Andy Polyakov
|
c7d16ac8da
|
aix[64]-cc: get MT support right [from HEAD].
PR: 2896
|
2012-10-16 08:09:20 +00:00 |
|
Bodo Möller
|
b626f0396c
|
Fix EC_KEY initialization race.
Submitted by: Adam Langley
|
2012-10-05 20:50:38 +00:00 |
|
Dr. Stephen Henson
|
9d2006d8ed
|
add -trusted_first option and verify flag (backport from HEAD)
|
2012-09-26 13:50:42 +00:00 |
|
Bodo Möller
|
abf1e32f2f
|
Fix Valgrind warning.
Submitted by: Adam Langley
|
2012-09-24 19:49:25 +00:00 |
|
Richard Levitte
|
fc1e09bf81
|
* Configure: make the debug-levitte-linux{elf,noasm} less extreme.
|
2012-09-24 18:49:07 +00:00 |
|
Richard Levitte
|
451cec33df
|
* ssl/t1_enc.c (tls1_change_cipher_state): Stupid bug. Fortunately in
debugging code that's seldom used.
|
2012-09-21 13:08:30 +00:00 |
|
Andy Polyakov
|
16c92916c7
|
Configure: allow for compiler options starting with double dash [from HEAD].
|
2012-09-19 21:00:35 +00:00 |
|
Andy Polyakov
|
988037fe18
|
MIPS assembly pack: jumbo update from HEAD.
|
2012-09-19 20:59:18 +00:00 |
|
Bodo Möller
|
9a7f80c869
|
Fix warning.
Submitted by: Chromium Authors
|
2012-09-17 17:23:43 +00:00 |
|
Andy Polyakov
|
507e5c3a61
|
e_aes.c: uninitialized variable in aes_ccm_init_key [from HEAD].
PR: 2874
Submitted by: Tomas Mraz
|
2012-09-15 08:46:08 +00:00 |
|
Dr. Stephen Henson
|
f8b90b5a5d
|
fix memory leak
|
2012-09-11 13:44:19 +00:00 |
|
Dr. Stephen Henson
|
dc14441757
|
Minor enhancement to PR#2836 fix. Instead of modifying SSL_get_certificate
change the current certificate (in s->cert->key) to the one used and then
SSL_get_certificate and SSL_get_privatekey will automatically work.
|
2012-09-11 13:35:14 +00:00 |
|
Ben Laurie
|
da8512aaff
|
Call OCSP Stapling callback after ciphersuite has been chosen, so the
right response is stapled. Also change SSL_get_certificate() so it
returns the certificate actually sent. See
http://rt.openssl.org/Ticket/Display.html?id=2836.
|
2012-09-11 12:00:25 +00:00 |
|
Andy Polyakov
|
d46a1a6178
|
bn_lcl.h: gcc removed support for "h" constraint, which broke inline
assembler [from HEAD].
|
2012-09-01 13:21:24 +00:00 |
|