18 years agoIt's rather silly to believe we'd release 0.9.7a in 2002 :-).
Richard Levitte [Tue, 31 Dec 2002 01:00:06 +0000 (01:00 +0000)]
It's rather silly to believe we'd release 0.9.7a in 2002 :-).
It's even more silly to pretend we know which year 0.9.8 will be

18 years agoMerge in changes from 0.9.7-stable.
Richard Levitte [Tue, 31 Dec 2002 00:02:10 +0000 (00:02 +0000)]
Merge in changes from 0.9.7-stable.

18 years agoMerge in changes from 0.9.7-stable.
Richard Levitte [Mon, 30 Dec 2002 23:56:09 +0000 (23:56 +0000)]
Merge in changes from 0.9.7-stable.

18 years agoMy English is definitely not good as my assembly skills:-) And it looks like
Andy Polyakov [Mon, 30 Dec 2002 20:17:20 +0000 (20:17 +0000)]
My English is definitely not good as my assembly skills:-) And it looks like
titles can't be multi-line...

18 years agoIt probably belongs in PROBLEMS, but it's more likely to be a FAQ.
Andy Polyakov [Mon, 30 Dec 2002 11:10:03 +0000 (11:10 +0000)]
It probably belongs in PROBLEMS, but it's more likely to be a FAQ.

18 years agoSince we're including Kerberos 5 headers in our exported header files (when
Richard Levitte [Sun, 29 Dec 2002 23:03:12 +0000 (23:03 +0000)]
Since we're including Kerberos 5 headers in our exported header files (when
OpenSSL is configured to use Kerberos), we'd better tell pkg-config users
where they can be found.
PR: 421

18 years agoAdd information about AES cipher suites to ciphers manual page.
Lutz Jänicke [Sun, 29 Dec 2002 21:24:50 +0000 (21:24 +0000)]
Add information about AES cipher suites to ciphers manual page.

If no authentication method is mentioned in the cipher suite name (e.g.
AES128-SHA), RSA authentication is used (PR #396).

18 years agoFix wrong handling of session ID in SSLv2 client code.
Lutz Jänicke [Sun, 29 Dec 2002 20:59:35 +0000 (20:59 +0000)]
Fix wrong handling of session ID in SSLv2 client code.

PR: 377

18 years agoCorrect asm exclusions.
Ben Laurie [Sun, 29 Dec 2002 17:57:09 +0000 (17:57 +0000)]
Correct asm exclusions.

18 years agoOS/2 does binary by default, apparently.
Richard Levitte [Sun, 29 Dec 2002 10:19:58 +0000 (10:19 +0000)]
OS/2 does binary by default, apparently.
Reported by Brian Havard <>.

18 years agomake update
Richard Levitte [Sun, 29 Dec 2002 01:38:15 +0000 (01:38 +0000)]
make update

18 years agoFinally get rid of all the algorithm inclusions that were done from
Richard Levitte [Sun, 29 Dec 2002 01:37:35 +0000 (01:37 +0000)]
Finally get rid of all the algorithm inclusions that were done from

Application authors BEWARE!  If you have had the habit to count on
evp.h to provide all those lower-level algorithm functions, you need
to think again!  Please change your programs NOW, or you will be sorry
when 0.9.8 gets release (it's quite some time away...).

18 years agomake update
Richard Levitte [Sat, 28 Dec 2002 02:42:05 +0000 (02:42 +0000)]
make update

18 years agoMerge from 0.9.7-stable.
Richard Levitte [Sat, 28 Dec 2002 02:41:17 +0000 (02:41 +0000)]
Merge from 0.9.7-stable.

18 years agoI can't confirm the claim being removed and nobody seems to speak up for it.
Andy Polyakov [Fri, 27 Dec 2002 15:04:45 +0000 (15:04 +0000)]
I can't confirm the claim being removed and nobody seems to speak up for it.

18 years agoUltraSPARC performance "tune-up."
Andy Polyakov [Fri, 27 Dec 2002 14:51:49 +0000 (14:51 +0000)]
UltraSPARC performance "tune-up."

18 years agoFAQ addenum as discussed in RT#417.
Andy Polyakov [Fri, 27 Dec 2002 14:27:48 +0000 (14:27 +0000)]
FAQ addenum as discussed in RT#417.

18 years agoKenneth R. Robinette just told me the latest snapshot works well with
Richard Levitte [Fri, 27 Dec 2002 14:01:40 +0000 (14:01 +0000)]
Kenneth R. Robinette just told me the latest snapshot works well with
MIT Kerberos.

18 years agoCan't find the referense to errors on XP with Kerberos
Richard Levitte [Fri, 27 Dec 2002 08:09:08 +0000 (08:09 +0000)]
Can't find the referense to errors on XP with Kerberos

18 years agoAdd SPKM among the related stanrds.
Richard Levitte [Thu, 26 Dec 2002 22:35:04 +0000 (22:35 +0000)]
Add SPKM among the related stanrds.

18 years agoUpdates
Richard Levitte [Thu, 26 Dec 2002 22:25:02 +0000 (22:25 +0000)]

18 years agoUpdate our list of implemented and related standards.
Richard Levitte [Thu, 26 Dec 2002 00:21:53 +0000 (00:21 +0000)]
Update our list of implemented and related standards.

18 years agoUpdate our list of implemented and related standards.
Richard Levitte [Thu, 26 Dec 2002 00:17:46 +0000 (00:17 +0000)]
Update our list of implemented and related standards.

18 years agoSpelling error.
Richard Levitte [Wed, 25 Dec 2002 22:16:56 +0000 (22:16 +0000)]
Spelling error.
This patch was taken from the OpenBSD copy of OpenSSL 0.9.7 beta3 with patches

18 years agoAvoid double definition of config.
Richard Levitte [Tue, 24 Dec 2002 23:53:46 +0000 (23:53 +0000)]
Avoid double definition of config.
PR: 420

18 years agoUpdates
Richard Levitte [Tue, 24 Dec 2002 23:52:07 +0000 (23:52 +0000)]

18 years agoSome more adjustments
Lutz Jänicke [Tue, 24 Dec 2002 21:55:57 +0000 (21:55 +0000)]
Some more adjustments
Submitted by: Jeffrey Altman <>, "Kenneth R. Robinette" <>

18 years agoCygwin needs the library locatin for .DLLs to be set in PATH. Unfortunately,
Richard Levitte [Tue, 24 Dec 2002 10:50:11 +0000 (10:50 +0000)]
Cygwin needs the library locatin for .DLLs to be set in PATH.  Unfortunately,
the conditional was set to add the library directory to PATH when the
platform is NOT Cygwin.  Corrected.
PR: 404

18 years agoAll VMS-specific problems have been solved.
Richard Levitte [Tue, 24 Dec 2002 10:38:05 +0000 (10:38 +0000)]
All VMS-specific problems have been solved.
Confirmed by Mark Daniel <>

18 years agoFinally, a bn_div_words() in VAX assembler that goes through all tests.
Richard Levitte [Mon, 23 Dec 2002 11:25:51 +0000 (11:25 +0000)]
Finally, a bn_div_words() in VAX assembler that goes through all tests.
PR: 413

18 years agoStop a possible memory leak.
Richard Levitte [Sat, 21 Dec 2002 23:49:21 +0000 (23:49 +0000)]
Stop a possible memory leak.
(I wonder why s2_connect() handles the initial buffer allocation slightly
PR: 416

18 years agoMake AES_ENCRYPT and AES_DECRYPT macros instead of static constants.
Richard Levitte [Fri, 20 Dec 2002 18:21:35 +0000 (18:21 +0000)]
Make AES_ENCRYPT and AES_DECRYPT macros instead of static constants.
PR: 411

18 years agoFix for "shift count too large" when compiling for hpux-parisc2 and
Andy Polyakov [Fri, 20 Dec 2002 18:11:30 +0000 (18:11 +0000)]
Fix for "shift count too large" when compiling for hpux-parisc2 and
irix-mips. The bug was introduced with accelerated support for x86_64.
My fault! Fixed now.

18 years agoMore accurate comments.
Richard Levitte [Fri, 20 Dec 2002 16:38:36 +0000 (16:38 +0000)]
More accurate comments.

18 years agoA little debugging.
Richard Levitte [Fri, 20 Dec 2002 16:38:06 +0000 (16:38 +0000)]
A little debugging.

18 years agoPropagate MAKEDEPPROG to the subdirs under crypto/.
Richard Levitte [Fri, 20 Dec 2002 15:28:42 +0000 (15:28 +0000)]
Propagate MAKEDEPPROG to the subdirs under crypto/.

18 years agoFix Kerberos5/SSL interaction
Lutz Jänicke [Fri, 20 Dec 2002 12:48:00 +0000 (12:48 +0000)]
Fix Kerberos5/SSL interaction
Submitted by: "Kenneth R. Robinette" <>
Reviewed by:

18 years agoKeep the internal lowercase 'surname', for programmer's sake.
Richard Levitte [Fri, 20 Dec 2002 09:39:34 +0000 (09:39 +0000)]
Keep the internal lowercase 'surname', for programmer's sake.

18 years agoBe consistent with capitalisation of object names.
Richard Levitte [Fri, 20 Dec 2002 09:24:17 +0000 (09:24 +0000)]
Be consistent with capitalisation of object names.

18 years agoBe consistent with capitalisation of object names.
Richard Levitte [Fri, 20 Dec 2002 09:18:18 +0000 (09:18 +0000)]
Be consistent with capitalisation of object names.

18 years agoThere was a mixup between INSTALLTOP and OPENSSLDIR...
Richard Levitte [Fri, 20 Dec 2002 07:51:03 +0000 (07:51 +0000)]
There was a mixup between INSTALLTOP and OPENSSLDIR...

18 years agoWe stupidly had a separate LIBKRB5 variable for KRB5 library dependencies,
Richard Levitte [Thu, 19 Dec 2002 22:10:12 +0000 (22:10 +0000)]
We stupidly had a separate LIBKRB5 variable for KRB5 library dependencies,
and then didn't support it very well.  And that when there already is a
useful variable for exactly this kind of thing; EX_LIBS...

18 years agoBecause the contents of openssl.pc may have to change when a configuration
Richard Levitte [Thu, 19 Dec 2002 21:56:40 +0000 (21:56 +0000)]
Because the contents of openssl.pc may have to change when a configuration
has been performed (and possibly changed), have it depend on Makefile.ssl.

18 years agoSmall tweaks for code consistency.
Richard Levitte [Thu, 19 Dec 2002 21:55:48 +0000 (21:55 +0000)]
Small tweaks for code consistency.

18 years agoTo avoid any future programming glitches, let's make each and every
Richard Levitte [Thu, 19 Dec 2002 21:13:29 +0000 (21:13 +0000)]
To avoid any future programming glitches, let's make each and every
assignment (modulo those I missed) individual statements.

18 years agoI have no idea what possesed me to compile s_socket.c as POSIXly code.
Richard Levitte [Thu, 19 Dec 2002 19:42:53 +0000 (19:42 +0000)]
I have no idea what possesed me to compile s_socket.c as POSIXly code.
Incidently, it now compiles so much better without _POSIX_C_SOURCE.

18 years agoIf _XOPEN_SOURCE_EXTENDED or _XOPEN_SOURCE are defined, _POSIX_C_SOURCE gets
Richard Levitte [Thu, 19 Dec 2002 19:39:30 +0000 (19:39 +0000)]
defined in DECC$TYPES.H.  If _POSIX_C_SOURCE is defined, certain types do
not get defined (u_char, u_int, ...).  DECC.H gets included by assert.h
and others.  Now, in6.h uses the types u_char, u_int and so on, and gets
included as part of other header inclusions, and will of course fail because
of the missing types.

On the other hand, _XOPEN_SOURCE_EXTENDED is needed to get gethostname()
properly declared...

Solution: define _XOPEN_SOURCE_EXTENDED much later, so DECC$TYPES.H has
a chance to be included *first*, so the otherwise missing types get defined

Personal: *mumble* *mumble*

18 years agoIt was pointed out to me that .pc files are normally stored in
Richard Levitte [Thu, 19 Dec 2002 17:44:42 +0000 (17:44 +0000)]
It was pointed out to me that .pc files are normally stored in
${prefix}/lib/pkgconfig, not ${prefix}/lib/pkginfo.

18 years agoIt was pointed out to me that .pc files are normally stored in
Richard Levitte [Thu, 19 Dec 2002 17:42:23 +0000 (17:42 +0000)]
It was pointed out to me that .pc files are normally stored in
${prefix}/lib/pkgconfig, not ${prefix}/lib/pkginfo.

18 years agoUpdate the current status
Richard Levitte [Wed, 18 Dec 2002 10:24:02 +0000 (10:24 +0000)]
Update the current status

18 years agoBetter wording?
Andy Polyakov [Wed, 18 Dec 2002 09:42:51 +0000 (09:42 +0000)]
Better wording?

18 years agoFix for RT#405, Solaris refuses to invoke preprocessor if egrep returns 1.
Andy Polyakov [Wed, 18 Dec 2002 09:03:48 +0000 (09:03 +0000)]
Fix for RT#405, Solaris refuses to invoke preprocessor if egrep returns 1.
Linux for example doesn't exhibit this behaviour, but I add "exit 0" to all
potentially affected rules, just to be on the safe side.

18 years agoMake "perl a.out" work, see RT#402
Andy Polyakov [Tue, 17 Dec 2002 08:05:49 +0000 (08:05 +0000)]
Make "perl a.out" work, see RT#402

18 years ago'a=b c=$a; echo $c' doesn't necessarily prints "b", '' vs. "", $s in
Andy Polyakov [Mon, 16 Dec 2002 23:35:17 +0000 (23:35 +0000)]
'a=b c=$a; echo $c' doesn't necessarily prints "b", '' vs. "", $s in
Makefiles... I suppose it wasn't tested very much...

18 years agoTransfer the Solaris shared library building changes from
Richard Levitte [Mon, 16 Dec 2002 20:33:38 +0000 (20:33 +0000)]
Transfer the Solaris shared library building changes from

18 years agoProtect loading routines with a lock.
Richard Levitte [Mon, 16 Dec 2002 06:06:03 +0000 (06:06 +0000)]
Protect loading routines with a lock.
PR: 373

18 years agoSynchronise with Makefiles.
Richard Levitte [Sun, 15 Dec 2002 20:59:24 +0000 (20:59 +0000)]
Synchronise with Makefiles.

18 years agoAlways forget this one...
Andy Polyakov [Sun, 15 Dec 2002 16:01:21 +0000 (16:01 +0000)]
Always forget this one...

18 years agoDES PIC-ification. "Cygwin" companion. Problem was that preprocessor macro
Andy Polyakov [Sun, 15 Dec 2002 10:06:27 +0000 (10:06 +0000)]
DES PIC-ification. "Cygwin" companion. Problem was that preprocessor macro
is not expanded if prepended with a $-sign.

18 years agoMake sure manual pages are properly linked to on systems that have case
Richard Levitte [Sun, 15 Dec 2002 06:45:43 +0000 (06:45 +0000)]
Make sure manual pages are properly linked to on systems that have case
insensitive file names, as well as those that do not have symlinks.
Incidently, both these cases apply on DOS/Windows...

18 years agoUpdate the make system for installations:
Richard Levitte [Sun, 15 Dec 2002 05:59:13 +0000 (05:59 +0000)]
Update the make system for installations:

- define a HERE variable to indicate where the source tree is (used
  very little right now)
- make more use of copying and making attribute changes to {file}.new,
  and then move it to {file}
- use 'mv -f' to avoid all those questions to the user when the file
  in question doesn't have write attributes for that user.

18 years agoDon't define macros in terms of asm() when __STRICT_ANSI is defined.
Richard Levitte [Sun, 15 Dec 2002 05:54:56 +0000 (05:54 +0000)]
Don't define macros in terms of asm() when __STRICT_ANSI is defined.

18 years agoBring des_locl.h at the same level as in the 0.9.7 branch.
Richard Levitte [Sun, 15 Dec 2002 05:54:26 +0000 (05:54 +0000)]
Bring des_locl.h at the same level as in the 0.9.7 branch.
Don't define macros in terms of asm() when __STRICT_ANSI is defined.

18 years agoOoops! No ROTATE on some platforms after x86_64 performance patch...
Andy Polyakov [Sun, 15 Dec 2002 00:47:47 +0000 (00:47 +0000)]
Ooops! No ROTATE on some platforms after x86_64 performance patch...

18 years agoAs you might have noticed I tried to change for . prefix, because it's
Andy Polyakov [Sat, 14 Dec 2002 23:14:00 +0000 (23:14 +0000)]
As you might have noticed I tried to change for . prefix, because it's
the one to be used to denote local labels in single function scope.
Problem is that SHA uses same label set across functions, therefore I
have to switch back to $ prefix.

18 years agoSolaris shared build fix-ups. See RT#238,239 for details.
Andy Polyakov [Sat, 14 Dec 2002 21:46:46 +0000 (21:46 +0000)]
Solaris shared build fix-ups. See RT#238,239 for details.

18 years agoNew DETECT_GNU_LD procedure.
Andy Polyakov [Sat, 14 Dec 2002 20:52:19 +0000 (20:52 +0000)]
New DETECT_GNU_LD procedure.

18 years agox86_64 performance patch.
Andy Polyakov [Sat, 14 Dec 2002 20:42:05 +0000 (20:42 +0000)]
x86_64 performance patch.

18 years agoDES PIC-ification. Windows companion.
Andy Polyakov [Sat, 14 Dec 2002 17:54:30 +0000 (17:54 +0000)]
DES PIC-ification. Windows companion.

18 years agoThe ampersand is not required in these constructs, and was giving AIX
Geoff Thorpe [Fri, 13 Dec 2002 22:01:46 +0000 (22:01 +0000)]
The ampersand is not required in these constructs, and was giving AIX

Reported by: Bernhard Simon.

18 years agoIA-32 assembler modules (primarily DES) PIC-ification. Idea is to keep
Andy Polyakov [Fri, 13 Dec 2002 17:56:14 +0000 (17:56 +0000)]
IA-32 assembler modules (primarily DES) PIC-ification. Idea is to keep
shared libraries shared.

18 years agoOK, there's at least one application author who has provided dynamic locking
Richard Levitte [Fri, 13 Dec 2002 07:30:53 +0000 (07:30 +0000)]
OK, there's at least one application author who has provided dynamic locking

18 years agoBIO_new_bio_pair() was unnecessarily described in it's own page as well as in
Richard Levitte [Thu, 12 Dec 2002 22:12:02 +0000 (22:12 +0000)]
BIO_new_bio_pair() was unnecessarily described in it's own page as well as in
BIO_s_bio.pod.  The most logical is to move everything needed from
BIO_new_bio_pair.pod to BIO_s_bio.pod (including the nice example)
and toss BIO_new_bio_pair.pod.  I hope I got all the info over properly.
PR: 370

18 years agoBIO_set_nbio() is enumerated, but not explained. Remove it from enumeration
Richard Levitte [Thu, 12 Dec 2002 22:08:49 +0000 (22:08 +0000)]
BIO_set_nbio() is enumerated, but not explained.  Remove it from enumeration
since it's both enumerated and explained in BIO_s_connect.pod.
PR: 370

18 years agoI forgot one item I intend to work on.
Richard Levitte [Thu, 12 Dec 2002 19:40:55 +0000 (19:40 +0000)]
I forgot one item I intend to work on.

18 years agoSkip DH-specific tests when no-dh has been configured.
Richard Levitte [Thu, 12 Dec 2002 18:43:10 +0000 (18:43 +0000)]
Skip DH-specific tests when no-dh has been configured.
PR: 353

18 years agoDocument the modifications in 0.9.7 that will make the hw_ncipher.c
Richard Levitte [Thu, 12 Dec 2002 17:40:15 +0000 (17:40 +0000)]
Document the modifications in 0.9.7 that will make the hw_ncipher.c
engine work properly even in bad situations.

18 years agoMake 'tunala' link with zlib if possible (so it works if openssl was
Geoff Thorpe [Wed, 11 Dec 2002 19:07:03 +0000 (19:07 +0000)]
Make 'tunala' link with zlib if possible (so it works if openssl was
configured with zlib support).

18 years agoIn CRYPTO_lock(), check that the application cares about locking (provided
Richard Levitte [Wed, 11 Dec 2002 08:56:35 +0000 (08:56 +0000)]
In CRYPTO_lock(), check that the application cares about locking (provided
callbacks) before attempting to lock.

18 years agosk_*_push() returns the number of items on the stack, not the index of the
Richard Levitte [Wed, 11 Dec 2002 08:33:31 +0000 (08:33 +0000)]
sk_*_push() returns the number of items on the stack, not the index of the
pushed item.  The index is the number of items - 1.  And if a NULL item was
found, actually use it.
Finally, provide a little bit of safety in CRYPTO_lock() by asserting the a
requested dynamic lock really must exist, instead of just being silent about it

18 years agoLet's not forget the other places where HEADER_DES_H and HEADER_DES_OLD_H
Richard Levitte [Wed, 11 Dec 2002 07:37:54 +0000 (07:37 +0000)]
Let's not forget the other places where HEADER_DES_H and HEADER_DES_OLD_H
were defined.

18 years agoLet's not forget the other places where HEADER_DES_H and HEADER_DES_OLD_H
Richard Levitte [Wed, 11 Dec 2002 07:24:43 +0000 (07:24 +0000)]
Let's not forget the other places where HEADER_DES_H and HEADER_DES_OLD_H
were defined.

18 years agoSince HEADER_DES_H has been the protector of des.h since libdes
Richard Levitte [Wed, 11 Dec 2002 06:59:16 +0000 (06:59 +0000)]
Since HEADER_DES_H has been the protector of des.h since libdes
(before SSLeay, maybe?), it's better to have that macro protect
the compatibility header des_old.h.  In the new des.h, let's use
a slightly different protecting macro.

The rationale is that there are application that might include (via
other header files, perhaps) both an old libdes des.h and OpenSSL's
des.h.  Whichever comes first would overshadow the other because of
the clash in protecting macro.  This fix solves that problem.

18 years agoThis stops a compiler warning from -Wmissing-prototypes.
Geoff Thorpe [Wed, 11 Dec 2002 03:34:26 +0000 (03:34 +0000)]
This stops a compiler warning from -Wmissing-prototypes.
(Noticed by Nils Larsch)

18 years agoUpdate -Olimit setting.
Lutz Jänicke [Tue, 10 Dec 2002 18:48:14 +0000 (18:48 +0000)]
Update -Olimit setting.
Submitted by: Bernhard Simon <>
Reviewed by:

18 years agotest commit (just removing tailing blanks) #2 after migration
Ralf S. Engelschall [Tue, 10 Dec 2002 12:01:39 +0000 (12:01 +0000)]
test commit (just removing tailing blanks) #2 after migration

18 years agotest commit (removing trailing blanks) after migration
Ralf S. Engelschall [Tue, 10 Dec 2002 10:51:18 +0000 (10:51 +0000)]
test commit (removing trailing blanks) after migration

18 years agotest blank-line commit after migration -- just ignore
Ralf S. Engelschall [Tue, 10 Dec 2002 10:49:22 +0000 (10:49 +0000)]
test blank-line commit after migration -- just ignore

18 years agoA memset() too many got converted into a OPENSSL_cleanse().
Richard Levitte [Tue, 10 Dec 2002 08:26:05 +0000 (08:26 +0000)]
A memset() too many got converted into a OPENSSL_cleanse().
PR: 393

18 years agoBN_sqr test failure entry.
Andy Polyakov [Mon, 9 Dec 2002 13:43:38 +0000 (13:43 +0000)]
BN_sqr test failure entry.

18 years agoFix wrong URI.
Lutz Jänicke [Mon, 9 Dec 2002 08:49:58 +0000 (08:49 +0000)]
Fix wrong URI.
Submitted by:
Reviewed by:
PR: 390

18 years agomake update
Richard Levitte [Mon, 9 Dec 2002 02:19:27 +0000 (02:19 +0000)]
make update

18 years agoHmm, Geoff's change made things quite interesting. We can now give
Richard Levitte [Mon, 9 Dec 2002 02:18:16 +0000 (02:18 +0000)]
Hmm, Geoff's change made things quite interesting.  We can now give
users the option of disabling deprecated functions, which should of
course be reflected in libeay.num and .def files.  Quite nice,

18 years agoNils Larsch submitted;
Geoff Thorpe [Sun, 8 Dec 2002 16:45:26 +0000 (16:45 +0000)]
Nils Larsch submitted;
  - a patch to fix a memory leak in rsa_gen.c
  - a note about compiler warnings with unions
  - a note about improving structure element names

This applies his patch and implements a solution to the notes.

18 years agoSince it's defined in draft-ietf-tls-compression-04.txt, let's make
Richard Levitte [Sun, 8 Dec 2002 09:31:41 +0000 (09:31 +0000)]
Since it's defined in draft-ietf-tls-compression-04.txt, let's make
ZLIB a known compression method, with the identity 1.

18 years agoUndefine OPENSSL_NO_DEPRECATED inside openssl application code if we are
Geoff Thorpe [Sun, 8 Dec 2002 05:38:44 +0000 (05:38 +0000)]
Undefine OPENSSL_NO_DEPRECATED inside openssl application code if we are
being built with it defined - it is not a symbol to affect how openssl
itself builds, but to alter the way openssl headers can be used from an API
point of view. The "deprecated" function wrappers will always remain inside
OpenSSL at least as long as they're still being used internally. :-)

The exception is dsaparam which has been updated to the BN_GENCB-based
functions to test the new functionality. If GENCB_TEST is defined, dsaparam
will support a "-timebomb <n>" switch to cancel parameter-generation if it
gets as far as 'n' seconds without completion.

18 years agoThis is a first-cut at improving the callback mechanisms used in
Geoff Thorpe [Sun, 8 Dec 2002 05:24:31 +0000 (05:24 +0000)]
This is a first-cut at improving the callback mechanisms used in
key-generation and prime-checking functions. Rather than explicitly passing
callback functions and caller-defined context data for the callbacks, a new
structure BN_GENCB is defined that encapsulates this; a pointer to the
structure is passed to all such functions instead.

This wrapper structure allows the encapsulation of "old" and "new" style
callbacks - "new" callbacks return a boolean result on the understanding
that returning FALSE should terminate keygen/primality processing.  The
BN_GENCB abstraction will allow future callback modifications without
needing to break binary compatibility nor change the API function
prototypes. The new API functions have been given names ending in "_ex" and
the old functions are implemented as wrappers to the new ones.  The
OPENSSL_NO_DEPRECATED symbol has been introduced so that, if defined,
declaration of the older functions will be skipped. NB: Some
openssl-internal code will stick with the older callbacks for now, so
appropriate "#undef" logic will be put in place - this is in case the user
is *building* openssl (rather than *including* its headers) with this
symbol defined.

There is another change in the new _ex functions; the key-generation
functions do not return key structures but operate on structures passed by
the caller, the return value is a boolean. This will allow for a smoother
transition to having key-generation as "virtual function" in the various
***_METHOD tables.

18 years agoFix a warning, and do some constification as a lucky side-effect :-)
Geoff Thorpe [Sun, 8 Dec 2002 05:19:43 +0000 (05:19 +0000)]
Fix a warning, and do some constification as a lucky side-effect :-)

18 years agoSince it's defined in draft-ietf-tls-compression-04.txt, let's make
Richard Levitte [Sun, 8 Dec 2002 02:41:11 +0000 (02:41 +0000)]
Since it's defined in draft-ietf-tls-compression-04.txt, let's make
ZLIB a known compression method, with the identity 1.

18 years agoImplement a stateful variant if the ZLIB compression method. The old
Richard Levitte [Sun, 8 Dec 2002 02:39:38 +0000 (02:39 +0000)]
Implement a stateful variant if the ZLIB compression method.  The old
stateless variant is kept, but isn't used anywhere.