Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						b60272b01f 
					 
					
						
						
							
							PKCS#8 support for alternative PRFs.  
						
						 
						
						... 
						
						
						
						Add option to set an alternative to the default hmacWithSHA1 PRF
for PKCS#8 private key encryptions. This is used automatically
by PKCS8_encrypt if the nid specified is a PRF.
Add option to pkcs8 utility.
Update docs. 
						
						
					 
					
						2014-03-01 23:14:08 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Scott Schaefer 
							
						 
					 
					
						
						
							
						
						0413ea5801 
					 
					
						
						
							
							Fix various spelling errors  
						
						 
						
						... 
						
						
						
						(cherry picked from commit 2b4ffc659e ) 
						
						
					 
					
						2014-02-14 22:35:15 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Scott Schaefer 
							
						 
					 
					
						
						
							
						
						2f6fba6772 
					 
					
						
						
							
							Document pkcs12 -password behavior  
						
						 
						
						... 
						
						
						
						apps/pkcs12.c accepts -password as an argument.  The document author
almost certainly meant to write "-password, -passin".
However, that is not correct, either.  Actually the code treats
-password as equivalent to -passin, EXCEPT when -export is also
specified, in which case -password as equivalent to -passout.
(cherry picked from commit 856c6dfb09 ) 
						
						
					 
					
						2014-02-14 22:35:15 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Scott Deboy 
							
						 
					 
					
						
						
							
						
						038bec784e 
					 
					
						
						
							
							Add callbacks supporting generation and retrieval of supplemental data entries, facilitating RFC 5878 (TLS auth extensions)  
						
						 
						
						... 
						
						
						
						Removed prior audit proof logic - audit proof support was implemented using the generic TLS extension API
Tests exercising the new supplemental data registration and callback api can be found in ssltest.c.
Implemented changes to s_server and s_client to exercise supplemental data callbacks via the -auth argument, as well as additional flags to exercise supplemental data being sent only during renegotiation.
(cherry picked from commit 36086186a9 )
Conflicts:
	Configure
	apps/s_client.c
	apps/s_server.c
	ssl/ssl.h
	ssl/ssl3.h
	ssl/ssltest.c 
						
						
					 
					
						2014-02-08 16:12:15 -08:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						024dbfd44c 
					 
					
						
						
							
							Document RSAPublicKey_{in,out} options.  
						
						 
						
						... 
						
						
						
						(cherry picked from commit 7040d73d22987532faa503630d6616cf2788c975) 
						
						
					 
					
						2013-11-09 15:09:22 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						a78b21fc67 
					 
					
						
						
							
							Update cms docs.  
						
						 
						
						... 
						
						
						
						(cherry picked from commit dfcb42c68e ) 
						
						
					 
					
						2013-10-01 14:01:19 +01:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						dddb38834e 
					 
					
						
						
							
							Update cms docs.  
						
						 
						
						... 
						
						
						
						Document use of -keyopt to use RSA-PSS and RSA-OAEP modes.
(cherry picked from commit 4bf4a6501c ) 
						
						
					 
					
						2013-10-01 14:01:18 +01:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						c9ea4df8f9 
					 
					
						
						
							
							Document -force_pubkey option.  
						
						 
						
						... 
						
						
						
						(cherry picked from commit b093a06866bf632a97a9a0286e2d08f69c3cf7dd) 
						
						
					 
					
						2013-08-21 13:41:17 +01:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Trevor 
							
						 
					 
					
						
						
							
						
						e27711cfdd 
					 
					
						
						
							
							Trying cherrypick:  
						
						 
						
						... 
						
						
						
						Add support for arbitrary TLS extensions.
Contributed by Trevor Perrin.
Conflicts:
	CHANGES
	ssl/ssl.h
	ssl/ssltest.c
	test/testssl
Fix compilation due to #endif.
Cherrypicking more stuff.
Cleanup of custom extension stuff.
serverinfo rejects non-empty extensions.
Omit extension if no relevant serverinfo data.
Improve error-handling in serverinfo callback.
Cosmetic cleanups.
s_client documentation.
s_server documentation.
SSL_CTX_serverinfo documentation.
Cleaup -1 and NULL callback handling for custom extensions, add tests.
Cleanup ssl_rsa.c serverinfo code.
Whitespace cleanup.
Improve comments in ssl.h for serverinfo.
Whitespace.
Cosmetic cleanup.
Reject non-zero-len serverinfo extensions.
Whitespace.
Make it build.
Conflicts:
	test/testssl 
						
						
					 
					
						2013-07-03 11:53:30 +01:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Ben Laurie 
							
						 
					 
					
						
						
							
						
						4e72220fd6 
					 
					
						
						
							
							Documentation improvements by Chris Palmer (Google).  
						
						 
						
						
						
						
					 
					
						2012-12-14 13:29:17 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Ben Laurie 
							
						 
					 
					
						
						
							
						
						5dca1e338c 
					 
					
						
						
							
							Document -pubkey option.  
						
						 
						
						
						
						
					 
					
						2012-12-13 16:16:48 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						1d5f3f4640 
					 
					
						
						
							
							correct docs  
						
						 
						
						
						
						
					 
					
						2012-11-19 20:06:57 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						cdb41713a4 
					 
					
						
						
							
							Document RFC5114 "generation" options.  
						
						 
						
						... 
						
						
						
						(backport from HEAD) 
						
						
					 
					
						2012-04-07 20:42:17 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Andy Polyakov 
							
						 
					 
					
						
						
							
						
						1fb07a7de8 
					 
					
						
						
							
							doc/apps: formatting fixes [from HEAD].  
						
						 
						
						... 
						
						
						
						PR: 2683
Submitted by: Annie Yousar 
						
						
					 
					
						2012-01-11 21:58:42 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						0172ad2902 
					 
					
						
						
							
							Minor documentation fixes, PR#2345  
						
						 
						
						
						
						
					 
					
						2010-10-04 13:28:27 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						d9aa352ff0 
					 
					
						
						
							
							Minor documentation fixes, PR#2344  
						
						 
						
						
						
						
					 
					
						2010-10-04 13:24:07 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						6507653e72 
					 
					
						
						
							
							The meaning of the X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT_LOCALLY and  
						
						 
						
						... 
						
						
						
						X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT error codes were reversed in
the verify application documentation. 
						
						
					 
					
						2010-02-23 14:09:22 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						39f0a4d8e9 
					 
					
						
						
							
							typo  
						
						 
						
						
						
						
					 
					
						2010-01-21 18:46:28 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						93fac08ec3 
					 
					
						
						
							
							PR: 2136  
						
						 
						
						... 
						
						
						
						Submitted by: Willy Weisz <weisz@vcpc.univie.ac.at >
Add options to output hash using older algorithm compatible with OpenSSL
versions before 1.0.0 
						
						
					 
					
						2010-01-12 17:27:11 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						6e94156199 
					 
					
						
						
							
							Remove tabs on blank lines: they produce warnings in pod2man  
						
						 
						
						
						
						
					 
					
						2010-01-05 17:17:20 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						50425bc137 
					 
					
						
						
							
							Change version from 0.9.9 to 1.0.0 in docs  
						
						 
						
						
						
						
					 
					
						2009-09-30 23:40:52 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						7483896e15 
					 
					
						
						
							
							Correction: salt is now default  
						
						 
						
						
						
						
					 
					
						2009-09-04 12:27:01 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						710c1c34d1 
					 
					
						
						
							
							Allow checking of self-signed certifictes if a flag is set.  
						
						 
						
						
						
						
					 
					
						2009-06-26 11:28:52 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						6fda4d7e5d 
					 
					
						
						
							
							PR: 1887  
						
						 
						
						... 
						
						
						
						Submitted by: "Victor B. Wagner" <vitus@cryptocom.ru >
Approved by: steve@openssl.org 
Document/clarify use of some options and include details of GOST algorihthm
usage. 
						
						
					 
					
						2009-04-10 16:42:28 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						36a252ea46 
					 
					
						
						
							
							Typo.  
						
						 
						
						
						
						
					 
					
						2009-04-10 11:35:31 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						a31a195246 
					 
					
						
						
							
							PR: 1887 (part, modified)  
						
						 
						
						... 
						
						
						
						Submitted by: "Victor B. Wagner" <vitus@cryptocom.ru >
Approved by: steve@openssl.org 
Use correct command names in -engine description and fix typo. 
						
						
					 
					
						2009-04-10 11:25:54 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						fab4447179 
					 
					
						
						
							
							PR: 1880  
						
						 
						
						... 
						
						
						
						Document -ocsp_uri command line switch to x509 utility. 
						
						
					 
					
						2009-04-01 15:06:28 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						c28a9165f2 
					 
					
						
						
							
							PR: 1862  
						
						 
						
						... 
						
						
						
						Typo. 
						
						
					 
					
						2009-03-12 17:13:15 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Bodo Möller 
							
						 
					 
					
						
						
							
						
						7ca1cfbac3 
					 
					
						
						
							
							-hex option for openssl rand  
						
						 
						
						... 
						
						
						
						PR: 1831
Submitted by: Damien Miller 
						
						
					 
					
						2009-02-02 00:01:28 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						db50661fce 
					 
					
						
						
							
							X509 verification fixes.  
						
						 
						
						... 
						
						
						
						Ignore self issued certificates when checking path length constraints.
Duplicate OIDs in policy tree in case they are allocated.
Use anyPolicy from certificate cache and not current tree level. 
						
						
					 
					
						2008-07-13 14:25:36 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Lutz Jänicke 
							
						 
					 
					
						
						
							
						
						51e00db226 
					 
					
						
						
							
							Document "openssl s_server" -crl_check* options  
						
						 
						
						... 
						
						
						
						Submitted by: Daniel Black <daniel.subs@internode.on.net > 
						
						
					 
					
						2008-05-19 07:52:15 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Lutz Jänicke 
							
						 
					 
					
						
						
							
						
						a92ebf2290 
					 
					
						
						
							
							Provide information about "openssl dgst" -hmac option.  
						
						 
						
						
						
						
					 
					
						2008-05-19 07:43:34 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						c386f8ac38 
					 
					
						
						
							
							Typo.  
						
						 
						
						
						
						
					 
					
						2008-05-01 23:35:36 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						4a954b56c9 
					 
					
						
						
							
							Use "cont" consistently in cms-examples.pl  
						
						 
						
						... 
						
						
						
						Add a -certsout option to output any certificates in a message.
Add test for example 4.11 
						
						
					 
					
						2008-05-01 23:30:06 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						41f81a0143 
					 
					
						
						
							
							Update docs.  
						
						 
						
						
						
						
					 
					
						2008-03-29 00:54:24 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						7122aafce5 
					 
					
						
						
							
							Preliminary documentation for CMS utility.  
						
						 
						
						
						
						
					 
					
						2008-03-21 13:09:26 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						0d7f6fc76a 
					 
					
						
						
							
							Clarification and fix typo.  
						
						 
						
						
						
						
					 
					
						2008-02-25 18:11:47 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Lutz Jänicke 
							
						 
					 
					
						
						
							
						
						7c1722c60d 
					 
					
						
						
							
							Add missing colon in manpage  
						
						 
						
						... 
						
						
						
						Submitted by: Richard Hartmann <richih.mailinglist@gmail.com > 
						
						
					 
					
						2008-01-30 08:26:59 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						cec2538ca9 
					 
					
						
						
							
							Submitted by: Victor B. Wagner <vitus@cryptocom.ru>, steve  
						
						 
						
						... 
						
						
						
						Use default algorithms for OCSP request and response signing. New command
line option to support other digest use for OCSP certificate IDs. 
						
						
					 
					
						2007-12-04 12:41:28 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Richard Levitte 
							
						 
					 
					
						
						
							
						
						28f7e60d47 
					 
					
						
						
							
							Change submitted by Doug Kaufman.  He writes:  
						
						 
						
						... 
						
						
						
						I just compiled the 9.9-dev version from the 12022007 tarball under
  DJGPP. There were only 2 changes needed, one for b_sock.c, since
  DJGPP with WATT32 doesn't define socklen_t and one for testtsa to
  handle DOS style path separators. I also noted what seems to be a
  typographical error in ts.pod. The test suite passes. The patch is
  attached.
  Since I am in the US, I have sent notifications to the Bureau of
  Industry and Security and to the NSA. 
						
						
					 
					
						2007-12-03 09:02:29 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						a529a80108 
					 
					
						
						
							
							Update from stable branch.  
						
						 
						
						
						
						
					 
					
						2007-09-17 17:54:31 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Andy Polyakov 
							
						 
					 
					
						
						
							
						
						330591fdfc 
					 
					
						
						
							
							Mention aes in enc.pod.  
						
						 
						
						... 
						
						
						
						PR: 1529 
						
						
					 
					
						2007-09-17 16:42:35 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Andy Polyakov 
							
						 
					 
					
						
						
							
						
						c7503f5240 
					 
					
						
						
							
							Mention SHA2 in openssl.pod.  
						
						 
						
						... 
						
						
						
						PR: 1575 
						
						
					 
					
						2007-09-17 15:56:55 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						d24a9c8f5a 
					 
					
						
						
							
							Docs and usage messages for RFC4507bis support.  
						
						 
						
						
						
						
					 
					
						2007-08-23 11:34:48 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Dr. Stephen Henson 
							
						 
					 
					
						
						
							
						
						76b46e7707 
					 
					
						
						
							
							Document streaming options.  
						
						 
						
						
						
						
					 
					
						2007-05-11 12:08:38 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Bodo Möller 
							
						 
					 
					
						
						
							
						
						96afc1cfd5 
					 
					
						
						
							
							Add SEED encryption algorithm.  
						
						 
						
						... 
						
						
						
						PR: 1503
Submitted by: KISA
Reviewed by: Bodo Moeller 
						
						
					 
					
						2007-04-23 23:48:59 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Richard Levitte 
							
						 
					 
					
						
						
							
						
						85c6749216 
					 
					
						
						
							
							Add STARTTLS support for IMAP and FTP.  
						
						 
						
						... 
						
						
						
						Submitted by Kees Cook <kees@outflux.net > 
						
						
					 
					
						2007-02-16 18:12:16 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Nils Larsch 
							
						 
					 
					
						
						
							
						
						bcb38217c4 
					 
					
						
						
							
							add note about 56 bit ciphers  
						
						 
						
						... 
						
						
						
						PR: 1461 
						
						
					 
					
						2007-02-06 19:41:01 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Nils Larsch 
							
						 
					 
					
						
						
							
						
						0501f02b06 
					 
					
						
						
							
							fix documentation  
						
						 
						
						... 
						
						
						
						PR: 1466 
						
						
					 
					
						2007-02-03 10:28:08 +00:00  
					
					
						 
						
						
							
							
							 
							
							
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Nils Larsch 
							
						 
					 
					
						
						
							
						
						ec1edeb5fa 
					 
					
						
						
							
							update pkcs12 help message + manpage  
						
						 
						
						... 
						
						
						
						PR: 1443
Submitted by: Artem Chuprina <ran@cryptocom.ru > 
						
						
					 
					
						2006-12-21 20:36:15 +00:00