summaryrefslogtreecommitdiffstats
path: root/ssl
AgeCommit message (Expand)Author
2014-01-04Restore SSL_OP_MSIE_SSLV2_RSA_PADDINGDr. Stephen Henson
2013-12-20Fix DTLS retransmission from previous session.Dr. Stephen Henson
2013-09-10Remove empty line.Rob Stradling
2013-09-10Tidy up comments.Rob Stradling
2013-09-10Use TLS version supplied by client when fingerprinting Safari.Rob Stradling
2013-09-09Backport TLS 1.1/1.2 #definesRob Stradling
2013-09-09Don't prefer ECDHE-ECDSA ciphers when the client appears to be Safari on OS X.Rob Stradling
2013-08-13DTLS message_sequence number wrong in rehandshake ServerHelloMichael Tuexen
2013-08-08DTLS handshake fix.Michael Tuexen
2013-04-08Set s->d1 to NULL after freeing it.Dr. Stephen Henson
2013-03-19Disable compression for DTLS.Dr. Stephen Henson
2013-03-18Avoid unnecessary fragmentation.Michael Tuexen
2013-02-12Check DTLS_BAD_VER for version number.David Woodhouse
2013-02-11Fix in ssltest is no-ssl2 configuredDr. Stephen Henson
2013-02-11Fix for SSL_get_certificateDr. Stephen Henson
2013-02-09ssl/s3_[clnt|srvr].c: fix warnings and linking error.Andy Polyakov
2013-02-08s3_cbc.c: make CBC_MAC_ROTATE_IN_PLACE universal.Andy Polyakov
2013-02-08s3_cbc.c: get rid of expensive divisions [from master].Andy Polyakov
2013-02-08ssl/[d1|s3]_pkt.c: harmomize orig_len handling.Andy Polyakov
2013-02-08Fix IV check and padding removal.Dr. Stephen Henson
2013-02-07ssl/*: remove SSL3_RECORD->orig_len to restore binary compatibility.Andy Polyakov
2013-02-06Fix for EXP-RC2-CBC-MD5Adam Langley
2013-02-05make updateDr. Stephen Henson
2013-02-05Fix error codes.Dr. Stephen Henson
2013-02-05s3/s3_cbc.c: allow for compilations with NO_SHA256|512.Andy Polyakov
2013-02-05ssl/s3_cbc.c: md_state alignment portability fix.Andy Polyakov
2013-02-05ssl/s3_cbc.c: uint64_t portability fix.Andy Polyakov
2013-02-05Update DTLS code to match CBC decoding in TLS.Ben Laurie
2013-02-05Don't crash when processing a zero-length, TLS >= 1.1 record.Ben Laurie
2013-02-05Fixups from previous commit.Ben Laurie
2013-02-05Oops. Add missing file.Ben Laurie
2013-02-05Make CBC decoding constant time.Ben Laurie
2013-02-05Add and use a constant-time memcmp.Ben Laurie
2012-12-10PR: 2888Dr. Stephen Henson
2012-11-22reject zero length point format list or supported curves extensionsDr. Stephen Henson
2012-10-05backport OCSP fix enhancementDr. Stephen Henson
2012-10-04Backport OCSP Stapling fix.Ben Laurie
2012-09-21* ssl/t1_enc.c (tls1_change_cipher_state): Stupid bug. Fortunately inRichard Levitte
2012-05-16s2_clnt.c: compensate for compiler bug [from HEAD].Andy Polyakov
2012-05-10Sanity check record length before skipping explicit IV in DTLSDr. Stephen Henson
2012-04-16OPENSSL_NO_SOCK fixes [from HEAD].Andy Polyakov
2012-04-15s3_srvr.c: fix typo [from HEAD].Andy Polyakov
2012-03-31PR: 2778(part)Dr. Stephen Henson
2012-03-12fix error codeDr. Stephen Henson
2012-03-09PR: 2756Dr. Stephen Henson
2012-03-06PR: 2755Dr. Stephen Henson
2012-03-06PR: 2748Dr. Stephen Henson
2012-02-16Fix bug in CVE-2011-4619: check we have really received a client helloDr. Stephen Henson
2012-01-18Fix for DTLS DoS issue introduced by fix for CVE-2011-4109.Dr. Stephen Henson
2012-01-05Fix for builds without DTLS support.Bodo Möller