openssl.git
14 years agoPR: 2009
Dr. Stephen Henson [Wed, 2 Sep 2009 13:20:22 +0000 (13:20 +0000)]
PR: 2009
Submitted by: "Alexei Khlebnikov" <alexei.khlebnikov@opera.com>
Approved by: steve@openssl.org

Avoid memory leak and fix error reporting in d2i_SSL_SESSION(). NB: although
the ticket mentions buffer overruns this isn't a security issue because
the SSL_SESSION structure is generated internally and it should never be
possible to supply its contents from an untrusted application (this would
among other things destroy session cache security).

14 years agoPR: 2022
Dr. Stephen Henson [Wed, 2 Sep 2009 12:53:32 +0000 (12:53 +0000)]
PR: 2022
Submitted by: Robin Seggelmann <seggelmann@fh-muenster.de>
Approved by: steve@openssl.org

Fix DTLS record header length bug.

14 years agoTidy up and fix verify callbacks to avoid structure dereference, use of
Dr. Stephen Henson [Wed, 2 Sep 2009 12:45:19 +0000 (12:45 +0000)]
Tidy up and fix verify callbacks to avoid structure dereference, use of
obsolete functions and enhance to handle new conditions such as policy
printing.

14 years agoMissing break.
Dr. Stephen Henson [Mon, 31 Aug 2009 22:21:01 +0000 (22:21 +0000)]
Missing break.

14 years agoPR: 2005
Dr. Stephen Henson [Wed, 26 Aug 2009 15:13:43 +0000 (15:13 +0000)]
PR: 2005
Submitted by: steve@openssl.org

Some systems have broken IPv6 headers and/or implementations. If
OPENSSL_USE_IPV6 is set to 0 IPv6 is not used, if it is set to 1 it is used
and if undefined an attempt is made to detect at compile time by checking
if AF_INET6 is set and excluding known problem platforms.

14 years agoPR: 2006
Dr. Stephen Henson [Wed, 26 Aug 2009 11:51:23 +0000 (11:51 +0000)]
PR: 2006
Submitted by: Robin Seggelmann <seggelmann@fh-muenster.de>
Approved by: steve@openssl.org

Do not use multiple DTLS records for a single user message

14 years agoPR: 2015
Dr. Stephen Henson [Wed, 26 Aug 2009 11:41:32 +0000 (11:41 +0000)]
PR: 2015
Submitted by: Robin Seggelmann <seggelmann@fh-muenster.de>
Approved by: steve@openssl.org

Define LIBDIR properly.

14 years agoMoving up the inclusion of e_os.h was a bad idea.
Richard Levitte [Wed, 26 Aug 2009 11:21:50 +0000 (11:21 +0000)]
Moving up the inclusion of e_os.h was a bad idea.
Put it back where it was and place an inclusion of e_os2.h to get platform
macros defined...

14 years agoMake sure ENGINES can be separately compiled as well.
Richard Levitte [Tue, 25 Aug 2009 07:30:02 +0000 (07:30 +0000)]
Make sure ENGINES can be separately compiled as well.
Make sure _XOPEN_SOURCE_EXTENDED is defined in opensslconf.h

Submitted by Zoltan Arpadffy <zoli@polarhome.com>

14 years agoRemove tmdiff.h from EXHEADERS as it doesn't exist.
Richard Levitte [Tue, 25 Aug 2009 07:28:12 +0000 (07:28 +0000)]
Remove tmdiff.h from EXHEADERS as it doesn't exist.
Don't have separate installation directory variables for VAX and AXP.

Submitted by Zoltan Arpadffy <zoli@polarhome.com>

14 years agoDefine EXE_DIR earlier.
Richard Levitte [Tue, 25 Aug 2009 07:25:55 +0000 (07:25 +0000)]
Define EXE_DIR earlier.
Make sure S_SOCKET also gets compiled with _POSIX_C_SOURCE defined.

Submitted by Zoltan Arpadffy <zoli@polarhome.com>

14 years agoMove up the inclusion of e_os.h so OPENSSL_SYS_VMS_DECC has a chance
Richard Levitte [Tue, 25 Aug 2009 07:23:21 +0000 (07:23 +0000)]
Move up the inclusion of e_os.h so OPENSSL_SYS_VMS_DECC has a chance
to be properly defined.

14 years agoMake it possible to compile non-assembler routines on AXP as well.
Richard Levitte [Tue, 25 Aug 2009 07:22:08 +0000 (07:22 +0000)]
Make it possible to compile non-assembler routines on AXP as well.

Submitted by Zoltan Arpadffy <arpadffy@polarhome.com>

14 years agoMake engines compile on VMS for ia64 as well.
Richard Levitte [Tue, 25 Aug 2009 07:19:20 +0000 (07:19 +0000)]
Make engines compile on VMS for ia64 as well.
Parse file types in a more secure manner.

Submitted by sms@antinode.info (Steven M. Schweda)

14 years agoCorrect some typos and missing things.
Richard Levitte [Tue, 25 Aug 2009 07:17:13 +0000 (07:17 +0000)]
Correct some typos and missing things.

Submitted by Arpadffy Zoltan <Zoltan.Arpadffy@scientificgames.se>

14 years agoInclude proper header files for time functions.
Richard Levitte [Tue, 25 Aug 2009 07:10:09 +0000 (07:10 +0000)]
Include proper header files for time functions.

Submitted by Arpadffy Zoltan <Zoltan.Arpadffy@scientificgames.se>

14 years agoStop unused variable warning on WIN32 et al.
Dr. Stephen Henson [Tue, 18 Aug 2009 11:14:12 +0000 (11:14 +0000)]
Stop unused variable warning on WIN32 et al.

14 years agoUse SHA1 and not deprecated MD5 in demos.
Dr. Stephen Henson [Sat, 15 Aug 2009 10:51:37 +0000 (10:51 +0000)]
Use SHA1 and not deprecated MD5 in demos.

14 years agoUpdate default dependency flags.
Dr. Stephen Henson [Wed, 12 Aug 2009 17:08:44 +0000 (17:08 +0000)]
Update default dependency flags.
Make error name discrepancies a fatal error.
Fix error codes.
make update

14 years agoRe-enable mdc2 default by default as the patent is now expired.
Dr. Stephen Henson [Wed, 12 Aug 2009 16:45:35 +0000 (16:45 +0000)]
Re-enable mdc2 default by default as the patent is now expired.

14 years agoUpdate README with bug report and contribution details.
Dr. Stephen Henson [Wed, 12 Aug 2009 16:41:46 +0000 (16:41 +0000)]
Update README with bug report and contribution details.

14 years agoPR: 1997
Dr. Stephen Henson [Wed, 12 Aug 2009 13:21:26 +0000 (13:21 +0000)]
PR: 1997
Submitted by: Robin Seggelmann <seggelmann@fh-muenster.de>
Approved by: steve@openssl.org

DTLS timeout handling fix.

14 years agoTypo
Dr. Stephen Henson [Mon, 10 Aug 2009 15:53:11 +0000 (15:53 +0000)]
Typo

14 years agoPR: 1999
Dr. Stephen Henson [Mon, 10 Aug 2009 15:30:29 +0000 (15:30 +0000)]
PR: 1999
Submitted by: "Bayram Kurumahmut" <kbayram@ubicom.com>
Approved by: steve@openssl.org

Don't use HAVE_FORK in apps/speed.c it can conflict with configured version.

14 years agoPR: 2004
Dr. Stephen Henson [Mon, 10 Aug 2009 14:57:11 +0000 (14:57 +0000)]
PR: 2004
Submitted by: Peter Sylvester <peter.sylvester@edelweb.fr>
Approved by: steve@openssl.org

Handle fractional seconds properly in ASN1_GENERALIZEDTIME_print

14 years agoPR: 2003
Dr. Stephen Henson [Mon, 10 Aug 2009 14:42:05 +0000 (14:42 +0000)]
PR: 2003
Make it possible to install OpenSSL in directories with name other
than "lib" for example "lib64". Based on patch from Jeremy Utley.

14 years agoAdd COMP error strings.
Dr. Stephen Henson [Sun, 9 Aug 2009 14:58:05 +0000 (14:58 +0000)]
Add COMP error strings.

14 years agoAdd missing CHANGES entry.
Dr. Stephen Henson [Thu, 6 Aug 2009 16:29:42 +0000 (16:29 +0000)]
Add missing CHANGES entry.

14 years agoUpdate from HEAD.
Dr. Stephen Henson [Wed, 5 Aug 2009 15:52:06 +0000 (15:52 +0000)]
Update from HEAD.

14 years agoPR: 2000
Dr. Stephen Henson [Wed, 5 Aug 2009 15:29:14 +0000 (15:29 +0000)]
PR: 2000
Submitted by:  Vadim Zeitlin <vz-openssl@zeitlins.org>
Approved by: steve@openssl.org

Make no-comp compile without warnings.

14 years agoUpdate from HEAD.
Dr. Stephen Henson [Wed, 5 Aug 2009 15:04:16 +0000 (15:04 +0000)]
Update from HEAD.

14 years agoPR: 1996
Dr. Stephen Henson [Mon, 27 Jul 2009 21:21:25 +0000 (21:21 +0000)]
PR: 1996
Submitted by: steve@openssl.org

Change conflicting name "BLOCK" to "OPENSSL_BLOCK".

14 years agoChange STRING to OPENSSL_STRING etc as common words such
Dr. Stephen Henson [Mon, 27 Jul 2009 21:08:53 +0000 (21:08 +0000)]
Change STRING to OPENSSL_STRING etc as common words such
as "STRING" cause conflicts with other headers/libraries.

14 years agoFix warnings.
Ben Laurie [Sun, 26 Jul 2009 12:26:38 +0000 (12:26 +0000)]
Fix warnings.

14 years agoUpdate from 0.9.8-stable.
Dr. Stephen Henson [Fri, 24 Jul 2009 13:47:52 +0000 (13:47 +0000)]
Update from 0.9.8-stable.

14 years agoRemove MD2 test from WIN32 tests.
Dr. Stephen Henson [Fri, 24 Jul 2009 13:43:23 +0000 (13:43 +0000)]
Remove MD2 test from WIN32 tests.

14 years agoFix typo.
Dr. Stephen Henson [Fri, 24 Jul 2009 13:36:36 +0000 (13:36 +0000)]
Fix typo.

14 years agoUpdate TABLE.
Dr. Stephen Henson [Fri, 24 Jul 2009 13:29:45 +0000 (13:29 +0000)]
Update TABLE.

14 years agoAdd new debug targets.
Dr. Stephen Henson [Fri, 24 Jul 2009 13:29:13 +0000 (13:29 +0000)]
Add new debug targets.

14 years agoPR: 1990
Dr. Stephen Henson [Fri, 24 Jul 2009 13:07:08 +0000 (13:07 +0000)]
PR: 1990

Update from 0.9.8-stable.

14 years agoDoc update from HEAD.
Dr. Stephen Henson [Fri, 24 Jul 2009 13:02:55 +0000 (13:02 +0000)]
Doc update from HEAD.

14 years agoPR: 1993
Dr. Stephen Henson [Fri, 24 Jul 2009 11:52:32 +0000 (11:52 +0000)]
PR: 1993

Fix from 0.9.8-stable.

14 years agoFix from 0.9.8-stable
Dr. Stephen Henson [Fri, 24 Jul 2009 11:34:41 +0000 (11:34 +0000)]
Fix from 0.9.8-stable

14 years agoUpdate from 0.9.8-stable.
Dr. Stephen Henson [Fri, 24 Jul 2009 11:24:45 +0000 (11:24 +0000)]
Update from 0.9.8-stable.

14 years agoUpdate from 0.9.8-stable
Dr. Stephen Henson [Fri, 24 Jul 2009 11:15:55 +0000 (11:15 +0000)]
Update from 0.9.8-stable

14 years agoUpdate from 0.9.8-stable.
Dr. Stephen Henson [Fri, 24 Jul 2009 11:10:57 +0000 (11:10 +0000)]
Update from 0.9.8-stable.

14 years agoUpdate from HEAD.
Dr. Stephen Henson [Thu, 16 Jul 2009 09:54:49 +0000 (09:54 +0000)]
Update from HEAD.

14 years agoCall CMS tests with "make test"
Dr. Stephen Henson [Wed, 15 Jul 2009 17:59:17 +0000 (17:59 +0000)]
Call CMS tests with "make test"

14 years agoHandle OSX ".dynlib" DSO extension.
Dr. Stephen Henson [Wed, 15 Jul 2009 17:58:57 +0000 (17:58 +0000)]
Handle OSX ".dynlib" DSO extension.

14 years agoUpdate for next beta.
Dr. Stephen Henson [Wed, 15 Jul 2009 12:08:35 +0000 (12:08 +0000)]
Update for next beta.

14 years agoPreparation for beta3 release. OpenSSL_1_0_0-beta3
Dr. Stephen Henson [Wed, 15 Jul 2009 11:37:45 +0000 (11:37 +0000)]
Preparation for beta3 release.

14 years agoFix error codes and indentation.
Dr. Stephen Henson [Wed, 15 Jul 2009 11:32:58 +0000 (11:32 +0000)]
Fix error codes and indentation.

14 years agoPR: 1980
Dr. Stephen Henson [Wed, 15 Jul 2009 11:01:40 +0000 (11:01 +0000)]
PR: 1980
Submitted by: Victor Wagner <vitus@wagner.pp.ru>
Approved by: steve@openssl.org

Fix memory leaks.

14 years agoStop warning of signed/unsigned compare.
Dr. Stephen Henson [Tue, 14 Jul 2009 15:28:44 +0000 (15:28 +0000)]
Stop warning of signed/unsigned compare.

14 years agoOops, use right function name...
Dr. Stephen Henson [Tue, 14 Jul 2009 15:14:39 +0000 (15:14 +0000)]
Oops, use right function name...

14 years agoDocument MD2 deprecation.
Dr. Stephen Henson [Mon, 13 Jul 2009 11:57:15 +0000 (11:57 +0000)]
Document MD2 deprecation.

14 years agoPR: 1984
Dr. Stephen Henson [Mon, 13 Jul 2009 11:44:04 +0000 (11:44 +0000)]
PR: 1984
Submitted by: Michael TÃ\83¼xen <Michael.Tuexen@lurchi.franken.de>
Approved by: steve@openssl.org

Don't concatenate reads in DTLS.

14 years agoUpdate from HEAD.
Dr. Stephen Henson [Mon, 13 Jul 2009 11:40:46 +0000 (11:40 +0000)]
Update from HEAD.

14 years agoFix from 0.9.8-stable.
Dr. Stephen Henson [Sat, 11 Jul 2009 22:36:27 +0000 (22:36 +0000)]
Fix from 0.9.8-stable.

14 years agoUpdate from HEAD.
Dr. Stephen Henson [Sat, 11 Jul 2009 22:30:02 +0000 (22:30 +0000)]
Update from HEAD.

14 years agoPR: 1985
Dr. Stephen Henson [Sat, 11 Jul 2009 21:42:47 +0000 (21:42 +0000)]
PR: 1985
Submitted by: Artem Chuprina <ran@cryptocom.ru>
Approved by: steve@openssl.org

Initialise flags.

14 years agoMake update.
Dr. Stephen Henson [Wed, 8 Jul 2009 09:13:24 +0000 (09:13 +0000)]
Make update.

14 years agoDelete MD2 from algorithm tables and default compilation.
Dr. Stephen Henson [Wed, 8 Jul 2009 08:50:53 +0000 (08:50 +0000)]
Delete MD2 from algorithm tables and default compilation.

14 years agoFix from HEAD.
Dr. Stephen Henson [Sat, 4 Jul 2009 12:05:14 +0000 (12:05 +0000)]
Fix from HEAD.

14 years agoUpdate from HEAD.
Dr. Stephen Henson [Sat, 4 Jul 2009 11:44:01 +0000 (11:44 +0000)]
Update from HEAD.

14 years agoPR: 1976
Dr. Stephen Henson [Wed, 1 Jul 2009 15:46:43 +0000 (15:46 +0000)]
PR: 1976
Submitted by: David McCullough <david_mccullough@securecomputing.com>
Approved by: steve@openssl.org

Cleanup some compile time warnings/magic numbers.

14 years agoPR: 1974(partial)
Dr. Stephen Henson [Wed, 1 Jul 2009 15:42:38 +0000 (15:42 +0000)]
PR: 1974(partial)
Submitted by: David McCullough <david_mccullough@securecomputing.com>
Approved by: steve@openssl.org

Cryptodev digest support.

14 years ago192, 256 bit AES and RC4 support for cryptodev.
Dr. Stephen Henson [Wed, 1 Jul 2009 15:36:55 +0000 (15:36 +0000)]
192, 256 bit AES and RC4 support for cryptodev.

14 years agoPR: 1974(partial)
Dr. Stephen Henson [Wed, 1 Jul 2009 15:25:17 +0000 (15:25 +0000)]
PR: 1974(partial)
Submitted by: David McCullough <david_mccullough@securecomputing.com>
Approved by: steve@openssl.org

Fix up RSA API compliance for rsa_nocrt_mod_exp method.

14 years agoPR: 1974 (partial)
Dr. Stephen Henson [Wed, 1 Jul 2009 14:55:59 +0000 (14:55 +0000)]
PR: 1974 (partial)
Submitted by: David McCullough <david_mccullough@securecomputing.com>
Approved by: steve@openssl.org

If -DHAVE_CRYPTODEV is set enable cryptodev support

14 years agoPR: 1972
Dr. Stephen Henson [Wed, 1 Jul 2009 11:43:57 +0000 (11:43 +0000)]
PR: 1972
Submitted by: David McCullough <david_mccullough@securecomputing.com>
Approved by: steve@openssl.org

Add support for building with the uClinux-dist.

14 years agoPR: 1970
Dr. Stephen Henson [Wed, 1 Jul 2009 11:39:59 +0000 (11:39 +0000)]
PR: 1970
Submitted by: David McCullough <david_mccullough@securecomputing.com>
Reviewed by: steve@openssl.org

Fix unused variable "words" and uninitialised data "b".

14 years agoPR: 1965
Dr. Stephen Henson [Wed, 1 Jul 2009 11:35:46 +0000 (11:35 +0000)]
PR: 1965
Submitted by: David McCullough <david_mccullough@securecomputing.com>
Approved by: steve@openssl.org

Make sure defines to remove SHA are correct.

14 years agoPR: 1962
Dr. Stephen Henson [Wed, 1 Jul 2009 11:29:01 +0000 (11:29 +0000)]
PR: 1962
Submitted by: Daniel Mentz <daniel.m@sent.com>
Reviewed by: steve@openssl.org

Fix "for dtls1_get_record() returns a bad record in one edge case" bug.

14 years agoSubmitted by: "Victor B. Wagner" <vitus@cryptocom.ru>
Dr. Stephen Henson [Wed, 1 Jul 2009 11:23:07 +0000 (11:23 +0000)]
Submitted by: "Victor B. Wagner" <vitus@cryptocom.ru>
Reviewed by: steve@openssl.org

EVP_CTRL_PBE_PRF_NID suppot for Gost engine.

14 years agoUpdate from 0.9.8-stable.
Dr. Stephen Henson [Tue, 30 Jun 2009 22:26:28 +0000 (22:26 +0000)]
Update from 0.9.8-stable.

14 years agoTypo.
Dr. Stephen Henson [Tue, 30 Jun 2009 20:55:55 +0000 (20:55 +0000)]
Typo.

14 years agoUpdate from HEAD.
Dr. Stephen Henson [Tue, 30 Jun 2009 16:10:24 +0000 (16:10 +0000)]
Update from HEAD.

14 years agoPR: 1969
Dr. Stephen Henson [Tue, 30 Jun 2009 15:21:48 +0000 (15:21 +0000)]
PR: 1969
Submitted by: David McCullough <david_mccullough@securecomputing.com>
Approved by: steve@openssl.org

Don't use repeating key when testing algs.

14 years agoPR: 1967
Dr. Stephen Henson [Tue, 30 Jun 2009 15:10:54 +0000 (15:10 +0000)]
PR: 1967
Submitted by: David McCullough <david_mccullough@securecomputing.com>
Approved by: steve@openssl.org

Don't go past end of params array.

14 years agoPR: 1966
Dr. Stephen Henson [Tue, 30 Jun 2009 15:08:38 +0000 (15:08 +0000)]
PR: 1966
Submitted by: David McCullough <david_mccullough@securecomputing.com>
Reviewed by: steve@openssl.org

Make no-ocsp work properly.

14 years agoPR: 1963
Dr. Stephen Henson [Tue, 30 Jun 2009 14:59:59 +0000 (14:59 +0000)]
PR: 1963
Submitted by: David McCullough <david_mccullough@securecomputing.com>
Approved by: steve@openssl.org

Make build fail if makedepend not present.

14 years agoAdd "missing" functions for setting all verify parameters for SSL_CTX and SSL
Dr. Stephen Henson [Tue, 30 Jun 2009 11:57:24 +0000 (11:57 +0000)]
Add "missing" functions for setting all verify parameters for SSL_CTX and SSL
structures.

14 years agoRedundant check: s->param is always non-NULL, it is set in SSL_new().
Dr. Stephen Henson [Tue, 30 Jun 2009 11:41:35 +0000 (11:41 +0000)]
Redundant check: s->param is always non-NULL, it is set in SSL_new().

14 years agoInherit parameters properly in SSL contexts: any parameters set should
Dr. Stephen Henson [Tue, 30 Jun 2009 11:21:00 +0000 (11:21 +0000)]
Inherit parameters properly in SSL contexts: any parameters set should
replace those in the current list.

14 years agoUpdate from HEAD.
Dr. Stephen Henson [Mon, 29 Jun 2009 16:09:58 +0000 (16:09 +0000)]
Update from HEAD.

14 years agoUpdate from 0.9.8-stable.
Dr. Stephen Henson [Sun, 28 Jun 2009 16:24:11 +0000 (16:24 +0000)]
Update from 0.9.8-stable.

14 years agoFix from 0.9.8-stable
Dr. Stephen Henson [Fri, 26 Jun 2009 23:14:11 +0000 (23:14 +0000)]
Fix from 0.9.8-stable

14 years agoUpdate from 0.9.8-stable.
Dr. Stephen Henson [Fri, 26 Jun 2009 15:04:22 +0000 (15:04 +0000)]
Update from 0.9.8-stable.

14 years agoAllow checking of self-signed certifictes if a flag is set.
Dr. Stephen Henson [Fri, 26 Jun 2009 11:28:52 +0000 (11:28 +0000)]
Allow checking of self-signed certifictes if a flag is set.

14 years agoFix from HEAD.
Dr. Stephen Henson [Thu, 25 Jun 2009 17:11:48 +0000 (17:11 +0000)]
Fix from HEAD.

14 years agoPR: 1748
Dr. Stephen Henson [Thu, 25 Jun 2009 11:26:45 +0000 (11:26 +0000)]
PR: 1748

Fix nasty SSL BIO pop bug. Since this changes the behaviour of SSL BIOs and
will break applications that worked around the bug only included in 1.0.0 and
later.

14 years agoDEBUG_BN_CTX doesn't really debug anything (it is essentially verbosity) and
Ben Laurie [Thu, 25 Jun 2009 10:15:06 +0000 (10:15 +0000)]
DEBUG_BN_CTX doesn't really debug anything (it is essentially verbosity) and
has made make test far too noisy.

14 years agoUpdate from HEAD.
Dr. Stephen Henson [Wed, 24 Jun 2009 13:30:07 +0000 (13:30 +0000)]
Update from HEAD.

14 years agoUpdate from HEAD.
Dr. Stephen Henson [Wed, 17 Jun 2009 12:19:35 +0000 (12:19 +0000)]
Update from HEAD.

14 years agoUpdate from HEAD.
Dr. Stephen Henson [Wed, 17 Jun 2009 12:05:51 +0000 (12:05 +0000)]
Update from HEAD.

14 years agoCheck t too.
Dr. Stephen Henson [Wed, 17 Jun 2009 11:47:54 +0000 (11:47 +0000)]
Check t too.

14 years agoUpdate from HEAD.
Dr. Stephen Henson [Wed, 17 Jun 2009 11:38:26 +0000 (11:38 +0000)]
Update from HEAD.

14 years agoUpdate from HEAD.
Dr. Stephen Henson [Wed, 17 Jun 2009 11:33:17 +0000 (11:33 +0000)]
Update from HEAD.

14 years agoUpdate from HEAD.
Dr. Stephen Henson [Wed, 17 Jun 2009 11:26:09 +0000 (11:26 +0000)]
Update from HEAD.