Convert CRYPTO_LOCK_X509_* to new multi-threading API
[openssl.git] / crypto / x509 / x509_vfy.c
2016-03-08 Alessandro GhediniConvert CRYPTO_LOCK_X509_* to new multi-threading API
2016-02-10 Viktor DukhovniDeprecate the -issuer_checks debugging option
2016-02-08 Viktor DukhovniSuppress DANE TLSA reflection when verification fails
2016-02-05 FdaSilvaYYGH601: Various spelling fixes.
2016-02-05 Viktor DukhovniEnsure correct chain depth for policy checks with DANE...
2016-02-05 Viktor DukhovniLong overdue cleanup of X509 policy tree verification
2016-02-01 Viktor DukhovniCompat self-signed trust with reject-only aux data
2016-02-01 Viktor DukhovniCheck chain extensions also for trusted certificates
2016-01-26 Rich SalzRemove /* foo.c */ comments
2016-01-20 Viktor DukhovniCheck Suite-B constraints with EE DANE records
2016-01-18 Viktor DukhovniDrop cached certificate signature validity flag
2016-01-15 Dr. Stephen HensonAdd lookup_certs for a trusted stack.
2016-01-14 Viktor DukhovniCosmetic polish for last-resort depth 0 check
2016-01-14 Viktor DukhovniFix last-resort depth 0 check when the chain has multip...
2016-01-14 Viktor DukhovniAlways initialize X509_STORE_CTX get_crl pointer
2016-01-07 Viktor DukhovniDANE support for X509_verify_cert()
2016-01-06 Viktor DukhovniDANE support structures, constructructors and accessors
2016-01-03 Viktor DukhovniFix X509_STORE_CTX_cleanup()
2016-01-03 Viktor DukhovniX509_verify_cert() cleanup
2015-12-14 Dr. Stephen HensonNew function X509_get0_pubkey
2015-12-01 Rich Salzex_data part 2: doc fixes and CRYPTO_free_ex_index.
2015-11-26 Dr. Stephen HensonRemove X509_VERIFY_PARAM_ID
2015-11-09 Matt CaswellContinue standardising malloc style for libcrypto
2015-10-15 Dr. Stephen Hensonembed CRL serial number and signature fields
2015-09-05 mrpreIn X509_STORE_CTX_init, cleanup on failure
2015-09-05 David WoodhouseRT3951: Add X509_V_FLAG_NO_CHECK_TIME to suppress time...
2015-09-03 David WoodhouseRevert "OPENSSL_NO_xxx cleanup: RFC3779"
2015-09-03 Rich SalzAdd and use OPENSSL_zalloc
2015-09-02 Dr. Stephen Hensonmake X509_CRL opaque
2015-09-02 Viktor DukhovniBetter handling of verify param id peername field
2015-08-31 Dr. Stephen HensonAdd X509_up_ref function.
2015-08-31 Dr. Stephen HensonAdd X509_CRL_up_ref function
2015-08-28 Alessandro GhediniGH354: Memory leak fixes
2015-08-13 Ismo PuustinenGH364: Free memory on an error path
2015-08-10 Rich SalzRT3999: Remove sub-component version strings
2015-07-07 Matt CaswellExtend -show_chain option to verify to show more info
2015-07-07 Matt CaswellReject calls to X509_verify_cert that have not been...
2015-07-07 Matt CaswellFix alternate chains certificate forgery issue
2015-06-11 Emilia KasperFix length checks in X509_cmp_time to avoid out-of...
2015-05-14 Richard LevitteIdentify and move common internal libcrypto header...
2015-05-06 Gunnar KudrjavetsInitialize potentially uninitialized local variables
2015-05-06 Rich Salzmemset, memcpy, sizeof consistency fixes
2015-05-04 Rich SalzUse safer sizeof variant in malloc
2015-05-01 Rich Salzfree NULL cleanup -- coda
2015-05-01 Rich SalzRemove goto inside an if(0) block
2015-04-30 Rich Salzfree NULL cleanup 5a
2015-04-28 Rich Salzremove malloc casts
2015-03-28 Rich Salzfree NULL cleanup
2015-03-24 Dr. Stephen HensonFix verify algorithm.
2015-02-25 Matt CaswellAdd flag to inhibit checking for alternate certificate...
2015-02-25 Matt CaswellIn certain situations the server provided certificate...
2015-02-09 Dr. Stephen HensonRemove obsolete IMPLEMENT_ASN1_SET_OF
2015-02-08 Rich SalzFinal (for me, for now) dead code cleanup
2015-02-06 Rich Salzutil/mkstack.pl now generates entire safestack.h
2015-01-27 Rich SalzOPENSSL_NO_xxx cleanup: RFC3779
2015-01-27 Rich SalzOPENSSL_NO_xxx cleanup: many removals
2015-01-22 Matt CaswellMore comment realignment master-post-reformat
2015-01-22 Matt CaswellRun util/openssl-format-source -v -c .
2015-01-22 Matt CaswellFurther comment changes for reformat (master)
2015-01-06 Matt CaswellFurther comment amendments to preserve formatting prior...
2014-09-08 Paul SuhlerRT2841: Extra return in check_issued
2014-08-15 Rich SalzRT2751: Declare get_issuer_sk() earlier.
2014-07-07 Viktor DukhovniUpdate API to use (char *) for email addresses and...
2014-07-05 Viktor DukhovniSet optional peername when X509_check_host() succeeds.
2014-06-23 Viktor DukhovniOne more typo when changing !result to result <= 0
2014-06-23 Viktor DukhovniFix typo in last commit
2014-06-23 Viktor DukhovniMultiple verifier reference identities.
2014-06-23 Viktor DukhovniX509_check_mumble() failure is <= 0, not just 0
2014-06-22 Viktor DukhovniDrop hostlen from X509_VERIFY_PARAM_ID.
2014-05-25 Dr. Stephen HensonDon't use expired certificates if possible.
2014-05-25 Dr. Stephen HensonRename vpm_int.h to x509_lcl.h
2014-05-21 Viktor DukhovniFixes to host checking.
2014-03-03 Dr. Stephen HensonFor self signed root only indicate one error.
2014-02-14 Dr. Stephen HensonInclude TA in checks/callback with partial chains.
2014-02-14 Dr. Stephen HensonDon't do loop detection for self signed check.
2014-01-09 Dr. Stephen HensonFix bug in X509_V_FLAG_IGNORE_CRITICAL CRL handling.
2013-12-13 Dr. Stephen HensonAdd opaque ID structure.
2013-12-13 Dr. Stephen HensonFix for partial chain notification.
2013-09-08 Dr. Stephen HensonPartial path fix.
2013-07-12 Dr. Stephen HensonFix verify loop with CRL checking.
2013-01-06 Ben LaurieFix warning.
2012-12-21 Dr. Stephen HensonMake partial chain checking work if we only have the...
2012-12-13 Dr. Stephen HensonNew verify flag to return success if we have any certif...
2012-12-06 Dr. Stephen HensonFix two bugs which affect delta CRL handling:
2012-12-05 Dr. Stephen HensonIntegrate host, email and IP address checks into X509_v...
2012-12-04 Dr. Stephen Hensoninitial support for delta CRL generations by diffing...
2012-08-03 Dr. Stephen HensonRename Suite B functions for consistency.
2012-08-03 Dr. Stephen Hensonadd suite B chain validation flags and associated verif...
2012-03-05 Dr. Stephen Hensondon't do loop check for single self signed certificate
2011-09-23 Dr. Stephen HensonPR: 2606
2011-09-06 Dr. Stephen HensonInitialise X509_STORE_CTX properly so CRLs with nextUpd...
2010-12-25 Dr. Stephen Hensonavoid verification loops in trusted store when path...
2010-11-02 Dr. Stephen HensonSubmitted by: Jonathan Dixon <joth@chromium.org>
2010-02-25 Dr. Stephen Hensonadd -trusted_first option and verify flag
2010-02-25 Dr. Stephen Hensontidy verify code. xn not used any more and check for...
2010-02-25 Dr. Stephen HensonExperimental support for partial chain verification...
2009-11-17 Dr. Stephen HensonPR: 2103
2009-10-31 Dr. Stephen HensonAdd missing functions to allow access to newer X509_STO...
2009-10-23 Dr. Stephen HensonIf not checking all certificates don't attempt to find...
2009-10-22 Dr. Stephen HensonNeed to check <= 0 here.
next