1. Jun 17, 2020
    • James M Snell's avatar
      e96bea6b
    • James M Snell's avatar
      deps: update archs files for OpenSSL-1.1.0 · d232a80e
      James M Snell authored
      After an OpenSSL source update, all the config files need to be
      regenerated and committed by:
        $ make -C deps/openssl/config
        $ git add deps/openssl/config/archs
        $ git add deps/openssl/openssl/include/crypto/bn_conf.h
        $ git add deps/openssl/openssl/include/crypto/dso_conf.h
        $ git add deps/openssl/openssl/include/openssl/opensslconf.h
        $ git commit
      d232a80e
    • Todd Short's avatar
      deps: add support for BoringSSL QUIC APIs · c5a88396
      Todd Short authored
      Acquired from: https://github.com/akamai/openssl/tree/OpenSSL_1_1_1f-quic
      
      Squashed:
      
      *
      https://github.com/akamai/openssl/commit/2ef7c58b2cb432abd4e371322667228d7ce2637b
      *
      https://github.com/akamai/openssl/commit/3f8eda3128f52f4d14399a1a912d1fdfacd86a86
      *
      https://github.com/akamai/openssl/commit/b37f665884be2e17e8ff4ad919138626fb13f6c9
      *
      https://github.com/akamai/openssl/commit/6b235895a16da3c0dd36a24cf8dfbe249c6cda3c
      *
      https://github.com/akamai/openssl/commit/3a793e06a5031311ce7ce094455be87fa92b8240
      
      ---
      
      This is a cherry-pick of 2a4b03a306439307e0b822b17eda3bdabddfbb68
      on the master-quic-support2 branch (2019-10-07)
      Which was a rebase/squash of master-quic-support:
      
      * 5aa62ce Add support for more secrets - Todd Short/Todd Short (master-quic-support)
      * 58e0643 Tweeks to quic_change_cipher_state() - Todd Short/Todd Short
      * 8169702 Move QUIC code out of tls13_change_cipher_state() - Todd Short/Todd Short
      * a08cfe6 Correctly disable middlebox compat - Todd Short/Todd Short
      * 3a9eabf Add OPENSSL_NO_QUIC wrapper - Todd Short/Todd Short
      * f550eca Add client early traffic secret storage - Todd Short/Todd Short
      * 1b787ae Quick fix: s2c to c2s for early secret - Todd Short/Todd Short
      * f97e6a9 Don't process an incomplete message - Todd Short/Todd Short
      * 81f0ce2 Reset init state in SSL_process_quic_post_handshake() - Todd Short/Todd Short
      * 5d59cf9 Fix quic_transport constructors/parsers - Todd Short/Todd Short
      * 5e5f91c Fix INSTALL nit. - Todd Short/Todd Short
      * bd290ab Fix duplicate word in docs - Todd Short/Todd Short
      * 699590b fixup! Handle partial handshake messages - Todd Short/Todd Short
      * a472a8d Handle partial handshake messages - Todd Short/Todd Short
      * 363cf3d fixup! Use proper secrets for handshake - Todd Short/Todd Short
      * b03fee6 Use proper secrets for handshake - Todd Short/Todd Short
      * 2ab1aa0 Move QUIC transport params to encrypted extensions - Todd Short/Todd Short
      * 0d16af9 Make temp secret names less confusing - Todd Short/Todd Short
      * abb6f39 New method to get QUIC secret length - Todd Short/Todd Short
      * 05fdae9 Add support for BoringSSL QUIC APIs - Todd Short/Todd Short
      
      This adds a compatible API for BoringSSL's QUIC support, based
      on the current |draft-ietf-quic-tls|.
      
      Based on BoringSSL commit 3c034b2cf386b3131f75520705491871a2e0cafe
      Based on BoringSSL commit c8e0f90f83b9ec38ea833deb86b5a41360b62b6a
      Based on BoringSSL commit 3cbb0299a28a8bd0136257251a78b91a96c5eec8
      Based on BoringSSL commit cc9d935256539af2d3b7f831abf57c0d685ffd81
      Based on BoringSSL commit e6eef1ca16a022e476bbaedffef044597cfc8f4b
      Based on BoringSSL commit 6f733791148cf8a076bf0e95498235aadbe5926d
      Based on BoringSSL commit 384d0eaf1930af1ebc47eda751f0c78dfcba1c03
      Based on BoringSSL commit a0373182eb5cc7b81d49f434596b473c7801c942
      Based on BoringSSL commit b1b76aee3cb43ce11889403c5334283d951ebd37
      
      New method to get QUIC secret length
      
      Make temp secret names less confusing
      
      Move QUIC transport params to encrypted extensions
      
      Use proper secrets for handshake
      
      fixup! Use proper secrets for handshake
      
      Handle partial handshake messages
      
      fixup! Handle partial handshake messages
      
      Fix duplicate word in docs
      
      Fix INSTALL nit.
      
      Fix quic_transport constructors/parsers
      
      Reset init state in SSL_process_quic_post_handshake()
      
      Don't process an incomplete message
      
      Quick fix: s2c to c2s for early secret
      
      Add client early traffic secret storage
      
      Add OPENSSL_NO_QUIC wrapper
      
      Correctly disable middlebox compat
      
      Move QUIC code out of tls13_change_cipher_state()
      
      Create quic_change_cipher_state() that does the minimal required
      to generate the QUIC secrets. (e.g. encryption contexts are not
      initialized).
      
      Tweeks to quic_change_cipher_state()
      
      Add support for more secrets
      
      Fix resumption secret
      
      (cherry picked from commit 16fafdf4e0ec6cddd5705f407e5dca26cb30914d)
      
      QUIC: Handle EndOfEarlyData and MaxEarlyData
      
      QUIC: Increase HKDF_MAXBUF to 2048
      
      Fall-through for 0RTT
      c5a88396
  2. Jun 16, 2020
  3. Jun 15, 2020
  4. Jun 14, 2020
  5. Jun 13, 2020
  6. Jun 12, 2020
  7. Jun 11, 2020
  8. Jun 10, 2020
  9. Jun 09, 2020