summaryrefslogtreecommitdiffstats
path: root/ssl
AgeCommit message (Expand)Author
2013-05-15RFC6689 support: add missing commit (git noob alert).Andy Polyakov
2013-05-15ssl/dnssec.c: compilation errors.Andy Polyakov
2013-05-13Initial support for RFC6689, a.k.a. DANE.Andy Polyakov
2013-04-08Set s->d1 to NULL after freeing it.Dr. Stephen Henson
2013-03-19Disable compression for DTLS.Dr. Stephen Henson
2013-03-18Avoid unnecessary fragmentation.Michael Tuexen
2013-02-26Fix error codes.Dr. Stephen Henson
2013-02-12Check DTLS_BAD_VER for version number.David Woodhouse
2013-02-11Fix in ssltest is no-ssl2 configuredDr. Stephen Henson
2013-02-08s3_cbc.c: make CBC_MAC_ROTATE_IN_PLACE universal.Andy Polyakov
2013-02-08s3_cbc.c: get rid of expensive divisions [from master].Andy Polyakov
2013-02-08ssl/[d1|s3]_pkt.c: harmomize orig_len handling.Andy Polyakov
2013-02-08Fix IV check and padding removal.Dr. Stephen Henson
2013-02-08Fix for EXP-RC2-CBC-MD5Adam Langley
2013-02-06e_aes_cbc_hmac_sha1.c: address the CBC decrypt timing issues.Andy Polyakov
2013-02-06ssl/*: remove SSL3_RECORD->orig_len to restore binary compatibility.Andy Polyakov
2013-02-06Don't access EVP_MD_CTX internals directly.Dr. Stephen Henson
2013-02-06s3/s3_cbc.c: allow for compilations with NO_SHA256|512.Andy Polyakov
2013-02-06ssl/s3_cbc.c: md_state alignment portability fix.Andy Polyakov
2013-02-06ssl/s3_cbc.c: uint64_t portability fix.Andy Polyakov
2013-02-06typo.Dr. Stephen Henson
2013-02-06Timing fix mitigation for FIPS mode.Dr. Stephen Henson
2013-02-06Oops. Add missing file.Ben Laurie
2013-02-06Update DTLS code to match CBC decoding in TLS.Ben Laurie
2013-02-06Don't crash when processing a zero-length, TLS >= 1.1 record.Ben Laurie
2013-02-06Make CBC decoding constant time.Ben Laurie
2013-02-06Add and use a constant-time memcmp.Ben Laurie
2013-02-04Fix for trace code: SSL3 doesn't include a length value forDr. Stephen Henson
2013-01-24Fix warning: lenmax isn't used any more.Dr. Stephen Henson
2013-01-19Remove extraneous brackets (clang doesn't like them).Ben Laurie
2013-01-19Can't check a size_t for < 0.Ben Laurie
2013-01-15make updateDr. Stephen Henson
2013-01-15Add support for broken protocol tests (backport from master branch)Dr. Stephen Henson
2013-01-15Make whitespace consistent with master branch.Dr. Stephen Henson
2012-12-30stop warning when compiling with no-compDr. Stephen Henson
2012-12-29add SSL_CONF functions and documentation (backport from HEAD)Dr. Stephen Henson
2012-12-26SSL/TLS record tracing code (backport from HEAD).Dr. Stephen Henson
2012-12-26Reject zero length ec point format list.Dr. Stephen Henson
2012-12-26handle point format list retrieval for clients too (from HEAD)Dr. Stephen Henson
2012-12-26Add support for printing out and retrieving EC point formats extension.Dr. Stephen Henson
2012-12-26return error if Suite B mode is selected and TLS 1.2 can't be used.Dr. Stephen Henson
2012-12-26set auto ecdh parameter selction for Suite BDr. Stephen Henson
2012-12-26add Suite B 128 bit mode offering only combination 2Dr. Stephen Henson
2012-12-26Use client version when deciding which cipher suites to disable.Dr. Stephen Henson
2012-12-26Use default point formats extension for server side as well as clientDr. Stephen Henson
2012-12-26Add ctrl and utility functions to retrieve raw cipher list sent by client inDr. Stephen Henson
2012-12-26new ctrl to retrive value of received temporary key in server key exchange me...Dr. Stephen Henson
2012-12-26store and print out message digest peer signed with in TLS 1.2Dr. Stephen Henson
2012-12-26perform sanity checks on server certificate type as soon as it is received in...Dr. Stephen Henson
2012-12-26give more meaningful error if presented with wrong certificate type by serverDr. Stephen Henson