openssl.git
18 years agoThe default flag should be for default passwords only. Otherwise,
Richard Levitte [Tue, 19 Jun 2001 15:54:47 +0000 (15:54 +0000)]
The default flag should be for default passwords only.  Otherwise,
someone having a default that is not a password will be confused.

18 years agoEnhance the user interface with better support for dialog box
Richard Levitte [Tue, 19 Jun 2001 15:52:00 +0000 (15:52 +0000)]
Enhance the user interface with better support for dialog box
prompting, application-defined prompts, the possibility to use
defaults (for example default passwords from somewhere else) and
interrupts/cancelations.

18 years agomake apps compile again
Dr. Stephen Henson [Tue, 19 Jun 2001 00:23:47 +0000 (00:23 +0000)]
make apps compile again

18 years agoDon't set pointer if add_lock_callback used.
Dr. Stephen Henson [Tue, 19 Jun 2001 00:04:57 +0000 (00:04 +0000)]
Don't set pointer if add_lock_callback used.

18 years agoOne feature wasn't quite commited yet
Richard Levitte [Mon, 18 Jun 2001 06:30:12 +0000 (06:30 +0000)]
One feature wasn't quite commited yet

18 years agoProvide an application-common setup function for engines and use it
Richard Levitte [Mon, 18 Jun 2001 06:22:33 +0000 (06:22 +0000)]
Provide an application-common setup function for engines and use it
everywhere.

18 years agoFix a memory leak (there's another around here somewhere, though).
Ben Laurie [Sun, 17 Jun 2001 14:42:57 +0000 (14:42 +0000)]
Fix a memory leak (there's another around here somewhere, though).
PR:

18 years agoDelete a redundant line.
Ben Laurie [Sat, 16 Jun 2001 21:51:26 +0000 (21:51 +0000)]
Delete a redundant line.

18 years agopay attention to blocksize before attempting decryption
Bodo Möller [Fri, 15 Jun 2001 18:05:09 +0000 (18:05 +0000)]
pay attention to blocksize before attempting decryption

18 years agoFor MSDOS, the tty filename still is "con", not "/dev/tty" ...
Bodo Möller [Mon, 11 Jun 2001 15:21:33 +0000 (15:21 +0000)]
For MSDOS, the tty filename still is "con", not "/dev/tty" ...

18 years agoGet rid of "possible WAW dependency" warnings.
Andy Polyakov [Mon, 11 Jun 2001 12:47:52 +0000 (12:47 +0000)]
Get rid of "possible WAW dependency" warnings.

Submitted by:
Reviewed by:
PR:

18 years agoeven use of default engines leaks memory
Bodo Möller [Mon, 11 Jun 2001 09:55:54 +0000 (09:55 +0000)]
even use of default engines leaks memory

18 years agoAdd directory name to the entry on /crypto/ui/.
Bodo Möller [Mon, 11 Jun 2001 09:55:20 +0000 (09:55 +0000)]
Add directory name to the entry on /crypto/ui/.

18 years agoEarlier OpenSSL versions printed prompts to stderr.
Bodo Möller [Mon, 11 Jun 2001 09:54:28 +0000 (09:54 +0000)]
Earlier OpenSSL versions printed prompts to stderr.
In the new crypto/ui/, this was changed into tty (which is usually
/dev/tty), i.e. the FILE * used for reading passwords from the user.
However stdio buffering for read/write streams is not without pitfalls
(passwords would be echoed on some systems).
To avoid problems, split tty into tty_in and tty_out (which are
opened separately).

18 years agoMake update
Dr. Stephen Henson [Mon, 11 Jun 2001 00:48:09 +0000 (00:48 +0000)]
Make update

18 years agoInitialize UI ex_data.
Dr. Stephen Henson [Mon, 11 Jun 2001 00:45:33 +0000 (00:45 +0000)]
Initialize UI ex_data.

18 years agoAdd support for MS CSP Name PKCS#12 attribute.
Dr. Stephen Henson [Mon, 11 Jun 2001 00:43:20 +0000 (00:43 +0000)]
Add support for MS CSP Name PKCS#12 attribute.

18 years agomore error codes fixed
Ulf Möller [Fri, 8 Jun 2001 14:16:39 +0000 (14:16 +0000)]
more error codes fixed

18 years agoERR_peek_error() returns "unsigned long".
Lutz Jänicke [Thu, 7 Jun 2001 17:20:50 +0000 (17:20 +0000)]
ERR_peek_error() returns "unsigned long".

18 years agoUse memmove() instead of memcpy() on areas that may overlap.
Richard Levitte [Thu, 7 Jun 2001 04:42:34 +0000 (04:42 +0000)]
Use memmove() instead of memcpy() on areas that may overlap.
Spotted by Nalin Dahyabhai <nalin@redhat.com>

18 years agoDon't forget to initialise.
Richard Levitte [Wed, 6 Jun 2001 23:12:41 +0000 (23:12 +0000)]
Don't forget to initialise.

18 years agoOAEP fix
Bodo Möller [Wed, 6 Jun 2001 21:44:28 +0000 (21:44 +0000)]
OAEP fix

18 years agowhen checking OAEP, signal just a single kind of 'decoding error'
Bodo Möller [Wed, 6 Jun 2001 18:48:49 +0000 (18:48 +0000)]
when checking OAEP, signal just a single kind of 'decoding error'

18 years agomove check to avoid memory leak.
Ulf Möller [Wed, 6 Jun 2001 17:23:23 +0000 (17:23 +0000)]
move check to avoid memory leak.

18 years agomake sure we don't write to seed[-1]
Ulf Möller [Wed, 6 Jun 2001 17:17:53 +0000 (17:17 +0000)]
make sure we don't write to seed[-1]

18 years ago'make update'
Richard Levitte [Tue, 5 Jun 2001 20:32:36 +0000 (20:32 +0000)]
'make update'

18 years agoDefining __USE_XOPEN_EXTENDED was the wrong thing. Instead, define
Richard Levitte [Tue, 5 Jun 2001 20:29:26 +0000 (20:29 +0000)]
Defining __USE_XOPEN_EXTENDED was the wrong thing.  Instead, define
_XOPEN_SOURCE.

18 years agoA good use of the UI interface is as a password callback replacement
Richard Levitte [Tue, 5 Jun 2001 19:05:52 +0000 (19:05 +0000)]
A good use of the UI interface is as a password callback replacement
(for new functions...).  One might still want to be able to pass down
a user-data pointer to be used by the UI.  However, ex_data doesn't
quite cut it, since that means the appropriate index to it might need
to be shared between parts that aren't really related in that sense,
and would require the currently hidden (static) index holders to be
uncovered.  Not a good thing.  Therefore, add the possibility to add a
user-data pointer to a UI.

18 years agoSmall detail about AIX forgotten...
Richard Levitte [Tue, 5 Jun 2001 04:41:57 +0000 (04:41 +0000)]
Small detail about AIX forgotten...

18 years agoAccept digits in symbol names. Spotted by Brian Havard <brianh@kheldar.apana.org.au>
Richard Levitte [Mon, 4 Jun 2001 16:34:31 +0000 (16:34 +0000)]
Accept digits in symbol names.  Spotted by Brian Havard <brianh@kheldar.apana.org.au>

18 years agoMore info on SRP.
Richard Levitte [Mon, 4 Jun 2001 16:23:15 +0000 (16:23 +0000)]
More info on SRP.

18 years agoAdded more info in SRP.
Richard Levitte [Mon, 4 Jun 2001 06:51:43 +0000 (06:51 +0000)]
Added more info in SRP.

18 years agoConfusion between algorithms resolved.
Richard Levitte [Fri, 1 Jun 2001 15:30:13 +0000 (15:30 +0000)]
Confusion between algorithms resolved.

18 years agonCipher callbacks shall return 0 on success, something else otherwise.
Richard Levitte [Fri, 1 Jun 2001 15:29:32 +0000 (15:29 +0000)]
nCipher callbacks shall return 0 on success, something else otherwise.

18 years agoStop mishandling the type number in dynlock locking
Richard Levitte [Fri, 1 Jun 2001 15:21:01 +0000 (15:21 +0000)]
Stop mishandling the type number in dynlock locking

18 years agoFix Bleichenbacher PKCS #1 1.5 countermeasure.
Bodo Möller [Fri, 1 Jun 2001 09:41:25 +0000 (09:41 +0000)]
Fix Bleichenbacher PKCS #1 1.5 countermeasure.
(The attack against SSL 3.1 and TLS 1.0 is impractical anyway,
otherwise this would be a security relevant patch.)

18 years agoincrease DEFAULT_BUFFER_SIZE (4K instead of just 1K)
Bodo Möller [Fri, 1 Jun 2001 08:38:29 +0000 (08:38 +0000)]
increase DEFAULT_BUFFER_SIZE (4K instead of just 1K)

18 years agoDon't decrement the reference counter twice when destroying dynamic
Richard Levitte [Thu, 31 May 2001 22:25:30 +0000 (22:25 +0000)]
Don't decrement the reference counter twice when destroying dynamic
links.

18 years agoFix a memory leak in 'sk_dup' in the case a realloc() fails. Also, tidy up
Geoff Thorpe [Thu, 31 May 2001 19:01:08 +0000 (19:01 +0000)]
Fix a memory leak in 'sk_dup' in the case a realloc() fails. Also, tidy up
a bit of weird code in sk_new.

18 years agoGet rid of RAW dependency warnings.
Andy Polyakov [Wed, 30 May 2001 22:01:33 +0000 (22:01 +0000)]
Get rid of RAW dependency warnings.

Submitted by:
Reviewed by:
PR:

18 years agoExtend all the loading functions to take an engine pointer, a pass
Richard Levitte [Wed, 30 May 2001 15:29:28 +0000 (15:29 +0000)]
Extend all the loading functions to take an engine pointer, a pass
string (some engines may have certificates protected by a PIN!) and
a description to put into error messages.

Also, have our own password callback that we can send both a password
and some prompt info to.  The default password callback in EVP assumes
that the passed parameter is a password, which isn't always the right
thing, and the ENGINE code (at least the nCipher one) makes other
assumptions...

Also, in spite of having the functions to load keys, some utilities
did the loading all by themselves...  That's changed too.

18 years agoA wish was expressed.
Richard Levitte [Wed, 30 May 2001 14:59:14 +0000 (14:59 +0000)]
A wish was expressed.

18 years agoDon't forget responsible person so that its clear who is to blame.
Lutz Jänicke [Tue, 29 May 2001 13:52:21 +0000 (13:52 +0000)]
Don't forget responsible person so that its clear who is to blame.

18 years agoAssembler support for IA-64. See the source code commentary for further
Andy Polyakov [Mon, 28 May 2001 20:02:51 +0000 (20:02 +0000)]
Assembler support for IA-64. See the source code commentary for further
details (performance numbers and accompanying discussions:-). Note that
the code is not engaged in ./Configure yet. I'll add it later this week
along with updates for .spec file.

Submitted by:
Reviewed by:
PR:

18 years agoDocument the latest change in ENGINEs.
Richard Levitte [Sat, 26 May 2001 16:58:34 +0000 (16:58 +0000)]
Document the latest change in ENGINEs.

18 years agoWe had the password callback for ENGINEs pretty much wrong. And
Richard Levitte [Fri, 25 May 2001 21:08:56 +0000 (21:08 +0000)]
We had the password callback for ENGINEs pretty much wrong.  And
passwords that were given to the key loading functions were completely
ignored, at least in the ncipher code, and then we made the assumption
that the callback wanted a prompt as user argument.

All that is now changed, and the application author is forced to give
a callback function of type pem_callback_cb and possibly an argument
for it, just as for all other functions that want to generate password
prompting.

NOTE: this change creates binary and source incompatibilities with
previous versions of OpenSSL [engine].  It's worth it this time, to
get it right (or at least better and with a chance that it'll work).

18 years agoAdd missing variable length cipher flag for Blowfish.
Dr. Stephen Henson [Thu, 24 May 2001 22:58:35 +0000 (22:58 +0000)]
Add missing variable length cipher flag for Blowfish.

Only use trust settings if either trust or reject settings
are present, otherwise use compatibility mode. This stops
root CAs being rejected if they have alias of keyid set.

18 years agoVMS doesn't support more than on period in a file name
Richard Levitte [Tue, 22 May 2001 12:47:38 +0000 (12:47 +0000)]
VMS doesn't support more than on period in a file name

18 years agoAdd examples to EVP_EncryptInit manual page.
Dr. Stephen Henson [Thu, 17 May 2001 13:03:20 +0000 (13:03 +0000)]
Add examples to EVP_EncryptInit manual page.

18 years agoFix for new UI functions under Win32.
Dr. Stephen Henson [Thu, 17 May 2001 11:47:08 +0000 (11:47 +0000)]
Fix for new UI functions under Win32.

For some unknown reason fopen("con", "w") is the
only way to make this work. Using "r+" and "w+"
causes the fopen call to fail and the fallback
(using stdin) doesn't work because writing to stdin
fails.

18 years agoAdd a requirements section for OpenVMS.
Richard Levitte [Thu, 17 May 2001 04:21:00 +0000 (04:21 +0000)]
Add a requirements section for OpenVMS.

18 years agoAdd a few more details on what one might need. make and a development
Richard Levitte [Thu, 17 May 2001 04:16:19 +0000 (04:16 +0000)]
Add a few more details on what one might need.  make and a development
environment were a part of a Unix operating systems, but these days
you see an increasing number of installations that do not necessarely
have these crucial parts by default, so it's needs mentioning.

18 years agoAdd missing item(s) SSL_ERROR_WANT_CONNECT, SSL_ERROR_WANT_ACCEPT.
Lutz Jänicke [Wed, 16 May 2001 09:43:51 +0000 (09:43 +0000)]
Add missing item(s) SSL_ERROR_WANT_CONNECT, SSL_ERROR_WANT_ACCEPT.

18 years agoNew internal function OPENSSL_gmtime, which is intended to do the same
Richard Levitte [Wed, 16 May 2001 08:44:09 +0000 (08:44 +0000)]
New internal function OPENSSL_gmtime, which is intended to do the same
as gmtime_r() on the systems where that is defined.

18 years agoIncrease ENTROPY_NEEDED to support Rijndael's larger key size.
Lutz Jänicke [Tue, 15 May 2001 16:02:35 +0000 (16:02 +0000)]
Increase ENTROPY_NEEDED to support Rijndael's larger key size.

18 years agoDo not forget to increment the pointers...
Richard Levitte [Tue, 15 May 2001 15:49:54 +0000 (15:49 +0000)]
Do not forget to increment the pointers...

18 years agoLow-case the names of the system routines, since some versions of
Richard Levitte [Tue, 15 May 2001 05:15:47 +0000 (05:15 +0000)]
Low-case the names of the system routines, since some versions of
DEC C only have them declared that way (it doesn't really matter,
since the linker is case-insensitive by default)

18 years agobranch on equal is beql, not beq...
Richard Levitte [Mon, 14 May 2001 22:10:09 +0000 (22:10 +0000)]
branch on equal is beql, not beq...

18 years agoMake sure strdup() is properly declared.
Richard Levitte [Mon, 14 May 2001 12:23:28 +0000 (12:23 +0000)]
Make sure strdup() is properly declared.

18 years agoMake sure memset() is properly declared.
Richard Levitte [Mon, 14 May 2001 12:22:58 +0000 (12:22 +0000)]
Make sure memset() is properly declared.

18 years agoui was forgotten when installing libcrypto and it's headers.
Richard Levitte [Mon, 14 May 2001 12:22:27 +0000 (12:22 +0000)]
ui was forgotten when installing libcrypto and it's headers.

18 years agoui_compat.h was forgotten in the "symlinking" routine.
Richard Levitte [Mon, 14 May 2001 12:21:16 +0000 (12:21 +0000)]
ui_compat.h was forgotten in the "symlinking" routine.

18 years agoRemove the password reading objects from LIB_DES.
Richard Levitte [Mon, 14 May 2001 11:59:02 +0000 (11:59 +0000)]
Remove the password reading objects from LIB_DES.

18 years agoMake more short aliases for symbols that are longer than 31
Richard Levitte [Mon, 14 May 2001 11:58:08 +0000 (11:58 +0000)]
Make more short aliases for symbols that are longer than 31
characters.

18 years agolen is a size_t, which is an unsigned integer. Therefore, some
Richard Levitte [Mon, 14 May 2001 11:56:47 +0000 (11:56 +0000)]
len is a size_t, which is an unsigned integer.  Therefore, some
compilers will complain against the check for less than zero.

18 years agoUse ui_compat.h to get the password reading functions.
Richard Levitte [Mon, 14 May 2001 11:54:36 +0000 (11:54 +0000)]
Use ui_compat.h to get the password reading functions.

18 years agoMake it so the compiler doesn't inform me about the dollars in some
Richard Levitte [Mon, 14 May 2001 11:53:37 +0000 (11:53 +0000)]
Make it so the compiler doesn't inform me about the dollars in some
symbols.

18 years agoTypos.
Lutz Jänicke [Mon, 14 May 2001 09:52:44 +0000 (09:52 +0000)]
Typos.

18 years agoOne more point to clarify, pointed out by "Greg Stark" <ghstark@pobox.com>
Lutz Jänicke [Mon, 14 May 2001 09:02:38 +0000 (09:02 +0000)]
One more point to clarify, pointed out by "Greg Stark" <ghstark@pobox.com>

18 years agoIt seems like the removal of "extern" before "static" wasn't a
Richard Levitte [Sun, 13 May 2001 17:55:30 +0000 (17:55 +0000)]
It seems like the removal of "extern" before "static" wasn't a
mistake.

18 years agoDocument the addition.
Richard Levitte [Sun, 13 May 2001 10:37:02 +0000 (10:37 +0000)]
Document the addition.

18 years agoA randomizer for OpenVMS, using the statistics that are easily
Richard Levitte [Sun, 13 May 2001 10:34:18 +0000 (10:34 +0000)]
A randomizer for OpenVMS, using the statistics that are easily
reachable.

It's completely untested for now.  To be done in the next few days.

18 years agoDefine `ok' and better error detection.
Richard Levitte [Sun, 13 May 2001 05:34:39 +0000 (05:34 +0000)]
Define `ok' and better error detection.

18 years agomake update
Richard Levitte [Sun, 13 May 2001 05:16:58 +0000 (05:16 +0000)]
make update

18 years agoWin16 too :-).
Richard Levitte [Sun, 13 May 2001 05:01:58 +0000 (05:01 +0000)]
Win16 too :-).

18 years agodes_read_password() and des_read_2passwords() can only appear if DES
Richard Levitte [Sun, 13 May 2001 04:59:09 +0000 (04:59 +0000)]
des_read_password() and des_read_2passwords() can only appear if DES
is compiled.

18 years agoWhen doing rewrites on ssleay.num, the file was prematurely closed.
Richard Levitte [Sun, 13 May 2001 04:48:07 +0000 (04:48 +0000)]
When doing rewrites on ssleay.num, the file was prematurely closed.
Make rewrites the default, since it works, and people get confused if
changed information doesn't get rewritten automagically.

18 years agoMove the password reading functions completely away from the DES
Richard Levitte [Sun, 13 May 2001 04:40:44 +0000 (04:40 +0000)]
Move the password reading functions completely away from the DES
section.

Add ui_compat.h for inclusion by those who want the old functions and
provide all of them, not just the higher-level ones, in ui_compat.c.

18 years agoPut back a removed "extern", or many compilers will complain about
Richard Levitte [Sun, 13 May 2001 04:34:57 +0000 (04:34 +0000)]
Put back a removed "extern", or many compilers will complain about
redefined variables.

18 years ago#if 0 out deleted (?) functions to stop Win32 DLL
Dr. Stephen Henson [Sun, 13 May 2001 00:33:55 +0000 (00:33 +0000)]
#if 0 out deleted (?) functions to stop Win32 DLL
build falling over.

18 years agoChange Win32 to use EXPORT_VAR_AS_FN.
Dr. Stephen Henson [Sat, 12 May 2001 23:57:41 +0000 (23:57 +0000)]
Change Win32 to use EXPORT_VAR_AS_FN.

Fix OPENSSL_IMPLEMENT_GLOBAL.

Allow Win32 to use EXPORT_VAR_AS_FN in mkdef.pl

make update.

18 years agoClarify behaviour with respect to SSL/TLS records.
Lutz Jänicke [Sat, 12 May 2001 09:49:02 +0000 (09:49 +0000)]
Clarify behaviour with respect to SSL/TLS records.

18 years agoUnder VC++ _DLL is set to indicate that the application
Dr. Stephen Henson [Sat, 12 May 2001 00:16:56 +0000 (00:16 +0000)]
Under VC++ _DLL is set to indicate that the application
will be linked against the DLL runtime library. It is
automatically set when /MD is used.

As a result OpenSSL shouldn't use _DLL to determine if
it should set OPENSSL_OPT_WINDLL because this will
cause linkage conflicts with static builds which do
include the /MD compiler switch.

18 years agoTypo.
Dr. Stephen Henson [Sat, 12 May 2001 00:09:04 +0000 (00:09 +0000)]
Typo.

18 years agoe_os2.h defines things like OPENSSL_SYS_MSDOS, not opensslconf.h...
Richard Levitte [Fri, 11 May 2001 11:20:26 +0000 (11:20 +0000)]
e_os2.h defines things like OPENSSL_SYS_MSDOS, not opensslconf.h...
(basically: whooops :-))

18 years agoClarify behaviour of SSL_write() by mentioning SSL_MODE_ENABLE_PARTIAL_WRITE
Lutz Jänicke [Fri, 11 May 2001 09:53:10 +0000 (09:53 +0000)]
Clarify behaviour of SSL_write() by mentioning SSL_MODE_ENABLE_PARTIAL_WRITE
flag as discussed on the mailing list.

18 years agoUpdate changelog to reflect additional changes made to the egd-locations.
Lutz Jänicke [Thu, 10 May 2001 09:45:31 +0000 (09:45 +0000)]
Update changelog to reflect additional changes made to the egd-locations.

18 years agorestore change undone in 1.831 (apparently by accident)
Bodo Möller [Thu, 10 May 2001 09:33:18 +0000 (09:33 +0000)]
restore change undone in 1.831 (apparently by accident)

18 years agoPurpose and trust setting functions for X509_STORE.
Dr. Stephen Henson [Thu, 10 May 2001 00:13:59 +0000 (00:13 +0000)]
Purpose and trust setting functions for X509_STORE.

Tidy existing code.

18 years agoFix warning with DEBUG_SAFESTACK
Dr. Stephen Henson [Thu, 10 May 2001 00:09:43 +0000 (00:09 +0000)]
Fix warning with DEBUG_SAFESTACK

18 years agoFix to allow multiple NONE libraries in mkerr.pl .
Dr. Stephen Henson [Thu, 10 May 2001 00:07:45 +0000 (00:07 +0000)]
Fix to allow multiple NONE libraries in mkerr.pl .

18 years agoAllow various X509_STORE_CTX properties to be
Dr. Stephen Henson [Wed, 9 May 2001 00:30:39 +0000 (00:30 +0000)]
Allow various X509_STORE_CTX properties to be
inherited from X509_STORE.

Add CRL checking options to other applications.

18 years agofix an old entry
Bodo Möller [Tue, 8 May 2001 12:45:55 +0000 (12:45 +0000)]
fix an old entry

18 years agoThere is no uitest
Richard Levitte [Tue, 8 May 2001 04:23:25 +0000 (04:23 +0000)]
There is no uitest

18 years agoDon't forget crypto/ui...
Richard Levitte [Tue, 8 May 2001 04:09:19 +0000 (04:09 +0000)]
Don't forget crypto/ui...

18 years agoInitial CRL based revocation checking.
Dr. Stephen Henson [Mon, 7 May 2001 22:52:50 +0000 (22:52 +0000)]
Initial CRL based revocation checking.

18 years agoClarify the license and copyright, make preprocessor dirctives a
Richard Levitte [Mon, 7 May 2001 06:33:35 +0000 (06:33 +0000)]
Clarify the license and copyright, make preprocessor dirctives a
little bit clearer and use the new OPENSSL_SYS_* macros.

18 years agomake update
Richard Levitte [Sun, 6 May 2001 23:51:37 +0000 (23:51 +0000)]
make update

18 years agoAdd a general user interface API. This is designed to replace things
Richard Levitte [Sun, 6 May 2001 23:19:37 +0000 (23:19 +0000)]
Add a general user interface API.  This is designed to replace things
like des_read_password and friends (backward compatibility functions
using this new API are provided).  The purpose is to remove prompting
functions from the DES code section as well as provide for prompting
through dialog boxes in a window system and the like.

18 years agothe backslash is significant...
Ulf Möller [Fri, 4 May 2001 15:03:59 +0000 (15:03 +0000)]
the backslash is significant...