- 06 Jan, 2014 1 commit
-
-
Dr. Stephen Henson authored
-
- 04 Jan, 2014 1 commit
-
-
Dr. Stephen Henson authored
The flag SSL_OP_MSIE_SSLV2_RSA_PADDING hasn't done anything since OpenSSL 0.9.7h but deleting it will break source compatibility with any software that references it. Restore it but #define to zero. (cherry picked from commit b17d6b8d)
-
- 02 Jan, 2014 1 commit
-
-
Dr. Stephen Henson authored
-
- 20 Dec, 2013 2 commits
-
-
Dr. Stephen Henson authored
For DTLS we might need to retransmit messages from the previous session so keep a copy of write context in DTLS retransmission buffers instead of replacing it after sending CCS. CVE-2013-6450. (cherry picked from commit 34628967) Conflicts: ssl/ssl_locl.h
-
Dr. Stephen Henson authored
(cherry picked from commit a6c62f0c)
-
- 10 Dec, 2013 1 commit
-
-
Dr. Stephen Henson authored
-
- 09 Dec, 2013 1 commit
-
-
Dr. Stephen Henson authored
-
- 27 Nov, 2013 1 commit
-
-
Dr. Stephen Henson authored
-
- 11 Nov, 2013 1 commit
-
-
Dr. Stephen Henson authored
(cherry picked from commit 16bc45ba)
-
- 09 Nov, 2013 2 commits
-
-
Dr. Stephen Henson authored
(cherry picked from commit 01be36ef70525e81fc358d2e559bdd0a0d9427a5)
-
Dr. Stephen Henson authored
(cherry picked from commit 7040d73d22987532faa503630d6616cf2788c975)
-
- 08 Nov, 2013 1 commit
-
-
Andy Polyakov authored
Original definition depended on __LONG_MAX__ that is not guaranteed to be present. As we don't support platforms with int narrower that 32 bits it's appropriate to make defition inconditional. PR: 3165 (cherry picked from commit 96180cac)
-
- 06 Nov, 2013 1 commit
-
-
Dr. Stephen Henson authored
(cherry picked from commit a4947e4e)
-
- 05 Nov, 2013 1 commit
-
-
Ben Laurie authored
<christian@python.org>. Conflicts: crypto/evp/p5_crpt2.c
-
- 04 Oct, 2013 2 commits
-
-
Ben Laurie authored
-
Rob Stradling authored
-
- 03 Oct, 2013 1 commit
-
-
Andy Polyakov authored
Submitted by: Yuriy Kaminskiy (cherry picked from commit 524b00c0) Resolved conflicts: crypto/evp/e_des3.c (cherry picked from commit eb22b7ec)
-
- 01 Oct, 2013 1 commit
-
-
Ben Laurie authored
Conflicts: crypto/buffer/buffer.c
-
- 30 Sep, 2013 1 commit
-
-
Dr. Stephen Henson authored
(cherry picked from commit 415ece73)
-
- 16 Sep, 2013 2 commits
-
-
Bodo Moeller authored
-
Bodo Moeller authored
- EC_GROUP_cmp shouldn't consider curves equal just because the curve name is the same. (They really *should* be the same in this case, but there's an EC_GROUP_set_curve_name API, which could be misused.) - EC_POINT_cmp shouldn't return 0 for ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED or EC_R_INCOMPATIBLE_OBJECTS errors because in a cmp API, 0 indicates equality (not an error). Reported by: king cope (cherry picked from commit 312a46791ab465cfa3bf26764361faed0e5df014)
-
- 10 Sep, 2013 3 commits
-
-
Rob Stradling authored
-
Rob Stradling authored
-
Rob Stradling authored
-
- 09 Sep, 2013 2 commits
-
-
Rob Stradling authored
-
Rob Stradling authored
OS X 10.8..10.8.3 has broken support for ECDHE-ECDSA ciphers.
-
- 20 Aug, 2013 1 commit
-
-
Dr. Stephen Henson authored
(cherry picked from commit 3a918ea2bbf4175d9461f81be1403d3781b2c0dc)
-
- 13 Aug, 2013 1 commit
-
-
Michael Tuexen authored
This fix ensures that * A HelloRequest is retransmitted if not responded by a ClientHello * The HelloRequest "consumes" the sequence number 0. The subsequent ServerHello uses the sequence number 1. * The client also expects the sequence number of the ServerHello to be 1 if a HelloRequest was received earlier. This patch fixes the RFC violation. (cherry picked from commit b62f4daa) Conflicts: ssl/d1_pkt.c
-
- 08 Aug, 2013 1 commit
-
-
Michael Tuexen authored
Reported by: Prashant Jaikumar <rmstar@gmail.com> Fix handling of application data received before a handshake. (cherry picked from commit 0c75eeac)
-
- 06 Aug, 2013 2 commits
-
-
Dr. Stephen Henson authored
PR #3090 Reported by: Franck Youssef <fry@open.ch> If no new reason codes are obtained after checking a CRL exit with an error to avoid repeatedly checking the same CRL. This will only happen if verify errors such as invalid CRL scope are overridden in a callback. (cherry picked from commit 4b26645c)
-
Kaspar Brand authored
PR: 3028 Fix bug introduced in PEM_X509_INFO_bio which wouldn't process RSA keys correctly if they appeared first. (cherry picked from commit 5ae8d6bc)
-
- 30 Jun, 2013 1 commit
-
-
Andy Polyakov authored
Submitted by: Bryan Drewery PR: 3075 (cherry picked from commit c256e69d)
-
- 08 Apr, 2013 1 commit
-
-
Dr. Stephen Henson authored
(cherry picked from commit 04638f2f)
-
- 31 Mar, 2013 1 commit
-
-
Dr. Stephen Henson authored
(cherry picked from commit 0ded2a06)
-
- 19 Mar, 2013 1 commit
-
-
Dr. Stephen Henson authored
The only standard compression method is stateful and is incompatible with DTLS. (cherry picked from commit e14b8410)
-
- 18 Mar, 2013 4 commits
-
-
Andy Polyakov authored
PR: 3005 (cherry picked from commit 5702e965)
-
Michael Tuexen authored
(cherry picked from commit 80ccc66d)
-
Dr. Stephen Henson authored
If an ASN1_INTEGER structure is allocated but not explicitly set encode it as zero: don't generate an invalid zero length INTEGER. (cherry picked from commit 1643edc6)
-
Dr. Stephen Henson authored
(cherry picked from commit 1546fb78)
-
- 15 Feb, 2013 1 commit
-
-
Nick Alcock authored
podlators 2.5.0 has switched to dying on POD syntax errors. This means that a bunch of long-standing erroneous POD in the openssl documentation now leads to fatal errors from pod2man, halting installation. Unfortunately POD constraints mean that you have to sort numeric lists in ascending order if they start with 1: you cannot do 1, 0, 2 even if you want 1 to appear first. I've reshuffled such (alas, I wish there were a better way but I don't know of one). (cherry picked from commit 5cc27077)
-