summaryrefslogtreecommitdiffstats
path: root/doc/ssl
AgeCommit message (Collapse)Author
2005-10-26Add fixes for CAN-2005-2969.Bodo Möller
(This were in 0.9.7-stable and 0.9.8-stable, but not in HEAD so far.)
2005-08-14Let the TLSv1_method() etc. functions return a const SSL_METHODNils Larsch
pointer and make the SSL_METHOD parameter in SSL_CTX_new, SSL_CTX_set_ssl_version and SSL_set_ssl_method const.
2005-04-08improve docu of SSL_CTX_use_PrivateKey()Nils Larsch
2005-03-30update docs (recent constification)Nils Larsch
2005-03-22Doc fixes.Dr. Stephen Henson
2004-11-14PR: 938Dr. Stephen Henson
Typo.
2004-06-14More precise explanation of session id context requirements.Lutz Jänicke
2003-11-29Make sure the documentation matches reality.Richard Levitte
PR: 755 Notified by: Jakub Bogusz <qboosh@pld-linux.org>
2003-06-26Clarify wording of verify_callback() behaviour.Lutz Jänicke
2003-06-03Clarify return value of SSL_connect() and SSL_accept() in case of theLutz Jänicke
WANT_READ and WANT_WRITE conditions.
2003-05-30Clarify ordering of certificates when using certificate chainsLutz Jänicke
2003-03-27Add warning about unwanted side effect when calling SSL_CTX_free():Lutz Jänicke
sessions in the external session cache might be removed. Submitted by: "Nadav Har'El" <nyh@math.technion.ac.il> PR: 547
2003-03-20Spelling errors.Richard Levitte
PR: 538
2002-12-04Missing ")"Lutz Jänicke
Submitted by: Christian Hohnstaedt <chohnstaedt@innominate.com> Reviewed by: PR:
2002-11-14No such reference to link to (found running pod2latex).Lutz Jänicke
Submitted by: Reviewed by: PR:
2002-10-29Add a HISTORY section to the man page to mention the new flags.Geoff Thorpe
2002-10-29The last character of inconsistency in my recent commits is herebyGeoff Thorpe
squashed.
2002-10-29Correct and enhance the behaviour of "internal" session caching as itGeoff Thorpe
relates to SSL_CTX flags and the use of "external" session caching. The existing flag, "SSL_SESS_CACHE_NO_INTERNAL_LOOKUP" remains but is supplemented with a complimentary flag, "SSL_SESS_CACHE_NO_INTERNAL_STORE". The bitwise OR of the two flags is also defined as "SSL_SESS_CACHE_NO_INTERNAL" and is the flag that should be used by most applications wanting to implement session caching *entirely* by its own provided callbacks. As the documented behaviour contradicted actual behaviour up until recently, and since that point behaviour has itself been inconsistent anyway, this change should not introduce any compatibility problems. I've adjusted the relevant documentation to elaborate about how this works. Kudos to "Nadav Har'El" <nyh@math.technion.ac.il> for diagnosing these anomalies and testing this patch for correctness. PR: 311
2002-08-15Missing =back.Richard Levitte
Part of PR 196
2002-07-29mention SSL_do_handshake()Bodo Möller
2002-07-19The behaviour is undefined when calling SSL_write() with num=0.Lutz Jänicke
Submitted by: Reviewed by: PR: 141
2002-07-19Manual page for SSL_do_handshake().Lutz Jänicke
Submitted by: Martin Sjögren <martin@strakt.com> PR: 137
2002-07-10Typos in links between manual pagesLutz Jänicke
Submitted by: Richard.Koenning@fujitsu-siemens.com Reviewed by: PR: 129
2002-06-14New option SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS for disabling CBCBodo Möller
vulnerability workaround (included in SSL_OP_ALL). PR: #90
2002-06-12Correct wrong usage information.Lutz Jänicke
PR: 95
2002-06-04Typo.Lutz Jänicke
PR: 72
2002-02-28Add 'void *' argument to app_verify_callback.Bodo Möller
Submitted by: D. K. Smetters <smetters@parc.xerox.com> Reviewed by: Bodo Moeller
2002-02-27SSL_clear != SSL_free/SSL_newLutz Jänicke
2002-02-15Even though it is not really practical people should know about it.Lutz Jänicke
2001-11-19Clarify reference count handling/removal of sessionLutz Jänicke
(shinagawa@star.zko.dec.com).
2001-11-10remove incorrect 'callback' prototypeBodo Möller
2001-11-10msg_callback documentationBodo Möller
2001-10-20New functions SSL[_CTX]_set_msg_callback().Bodo Möller
New macros SSL[_CTX]_set_msg_callback_arg(). Message callback imlementation for SSL 3.0/TLS 1.0 (no SSL 2.0 yet). New '-msg' option for 'openssl s_client' and 'openssl s_server' that enable a message callback that displays all protocol messages. In ssl3_get_client_hello (ssl/s3_srvr.c), generate a fatal alert if client_version is smaller than the protocol version in use. Also change ssl23_get_client_hello (ssl/s23_srvr.c) to select TLS 1.0 if the client demanded SSL 3.0 but only TLS 1.0 is enabled; then the client will at least see that alert. Fix SSL[_CTX]_ctrl prototype (void * instead of char * for generic pointer). Add/update some OpenSSL copyright notices.
2001-10-17document SSL_OP_NO_SESSION_RESUMPTION_ON_RENEGOTIATIONBodo Möller
2001-10-12Update information as a partial response to the postLutz Jänicke
From: "Chris D. Peterson" <cpeterson@aventail.com> Subject: Implementation Issues with OpenSSL To: openssl-users@openssl.org Date: Wed, 22 Aug 2001 16:13:17 -0700 The patch included in the original post may improve the internal session list handling (and is therefore worth a seperate investigation). No change to the list handling will however solve the problems of incorrect SSL_SESSION_free() calls. The session list is only one possible point of failure, dangling pointers would also occur for SSL object currently using the session. The correct solution is to only use SSL_SESSION_free() when applicable!
2001-09-13Typo.Lutz Jänicke
2001-09-13One more manual page.Lutz Jänicke
2001-09-13Rework section about return values another time (based on hints fromLutz Jänicke
Bodo Moeller).
2001-09-11Make maximum certifcate chain size accepted from the peer applicationLutz Jänicke
settable (proposed by "Douglas E. Engert" <deengert@anl.gov>).
2001-09-07ispellUlf Möller
2001-08-24More docs.Lutz Jänicke
2001-08-23Typo.Lutz Jänicke
2001-08-23More manual pages. Constify.Lutz Jänicke
2001-08-23As discussed recently on openssl-users.Lutz Jänicke
2001-08-23Make clear, that using the compression layer is currently not recommended.Lutz Jänicke
2001-08-22typo.Ulf Möller
2001-08-21One more manual page...Lutz Jänicke
2001-08-21Documentation on how to handle compression methods.Lutz Jänicke
Hopefully it is clear enough, that it is currently not recommended.
2001-08-20More interdependencies with respect to shutdown behaviour.Lutz Jänicke
2001-08-19Alert description strings for TLSv1 and documentation.Lutz Jänicke