Age | Commit message (Collapse) | Author |
|
(cherry picked from commit 19f65ddbab30543415584ae7916e12a3c5249dba)
|
|
|
|
Allegedly formwarding to NUL: sometimes creates NUL file in file
system.
PR: 3250
(cherry picked from commit 63aff3001ef6ba2ac376cd3f237fb0d0b3e77f30)
|
|
|
|
|
|
PR: 3251
Suggested by: Thorsten Schöning
(cherry picked from commit 779c51c6446f384c2f2a7bd5cc4c3e0366baf628)
|
|
when adding duplicates in add_cert_dir.
PR: 3261
Reported by: Marian Done
(cherry picked from commit 758954e0d8232d370ed72b7f86640e40443e1778)
|
|
|
|
|
|
|
|
|
|
(cherry picked from commit d099f0ed6ca518052bb167b31e999e1e7734eebf)
|
|
When setting the current certificate check that it has a corresponding
private key.
(cherry picked from commit 358d352aa244b4f2ef655bccff6658d92d5ce03c)
|
|
New flags to build certificate chains. The can be used to rearrange
the chain so all an application needs to do is add all certificates
in arbitrary order and then build the chain to check and correct them.
Add verify error code when building chain.
Update docs.
(cherry picked from commit 13dc3ce9ab483cade378bcf3844c92bacd817316)
|
|
(cherry picked from commit daddd9a950e491c31f9500d5e570bc7eb96b2823)
|
|
|
|
|
|
(cherry picked from commit 214368ffee5736836e2dbb80a16a4fbd85f0eaf9)
|
|
|
|
|
|
|
|
Certificate/OCSP Extensions.
Add the RFC6962 OIDs to the objects table.
(backport from master branch)
|
|
(cherry picked from commit 6ecbc2bb62835a401ad6efe240d469a23b21755b)
|
|
(cherry picked from commit f3a39032601fab2c704f03338e378592d3b4e262)
|
|
|
|
|
|
|
|
(cherry picked from commit 5a7652c3e585e970e5b778074c92e617e48fde38)
|
|
This can be used to speed up SRTP with libsrtp, e.g. on TI omap/sitara based devices.
(cherry picked from commit be2c4d9bd9e81030c547a34216ae2d8e5c888190)
|
|
If you use "-newkey rsa" it's supposed to read the default number of bits from the
config file. However the value isn't used to generate the key, but it does
print it's generating such a key. The set_keygen_ctx() doesn't call
EVP_PKEY_CTX_set_rsa_keygen_bits() and you end up with the default set in
pkey_rsa_init() (1024). Afterwards the number of bits gets read from the config
file, but nothing is done with that anymore.
We now read the config first and use the value from the config file when no size
is given.
PR: 2592
(cherry picked from commit 3343220327664680420d4068e1fbe46d2236f1b0)
|
|
(cherry picked from commit e547c45f1c74e976656c042ec9d873f6eea0e756)
|
|
(cherry picked from commit 2b4ffc659eabec29f76821f0ac624a2b8c19e4c7)
|
|
apps/pkcs12.c accepts -password as an argument. The document author
almost certainly meant to write "-password, -passin".
However, that is not correct, either. Actually the code treats
-password as equivalent to -passin, EXCEPT when -export is also
specified, in which case -password as equivalent to -passout.
(cherry picked from commit 856c6dfb09d69fc82ada2611c6cd792dfc60e355)
|
|
|
|
(cherry picked from commit 701134320a94908d8c0ac513741cab41e215a7b5)
|
|
(cherry picked from commit f4d456408d9d7bca31f34765d1a05fbd9fa55826)
|
|
Improve CBC decrypt and CTR by ~13/16%, which adds up to ~25/33%
improvement over "pre-Silvermont" version. [Add performance table to
aesni-x86.pl].
(cherry picked from commit 5599c7331b90d9d29c9914c2a95c16d91485415a)
|
|
as issuer and subject names. Although this is an incompatible change
it should have little impact in pratice because self-issued certificates
that are not self-signed are rarely encountered.
(cherry picked from commit b1efb7161f409c81178b9aa95583db3390f90b1b)
|
|
When a chain is complete and ends in a trusted root checks are also
performed on the TA and the callback notified with ok==1. For
consistency do the same for chains where the TA is not self signed.
(cherry picked from commit 385b3486661628f3f806205752bf968b8114b347)
|
|
(from master)
|
|
|
|
|
|
(and remove duplicates).
|
|
(cherry picked from commit 9587429fa07a34066107e926fbc8708220f058fa)
|
|
(other processors unaffected).
(cherry picked from commit 98e143f118aedc2fa79fa0ae90f1b039da106309)
|
|
|
|
Revert libssl ordinals to OpenSSL 1.0.1 values first to tidy up and
avoid entries for deleted functions.
|
|
|
|
|
|
git://github.com/scottdeboy/openssl into scottdeboy-102_stable_tlsext_suppdata_changes
|