aboutsummaryrefslogtreecommitdiff
path: root/CHANGES
AgeCommit message (Expand)AuthorFilesLines
2013-07-17EVP support for wrapping algorithms.Dr. Stephen Henson1-0/+6
2013-07-04Fix multiple cosmetic typos.Jeff Walton1-56/+56
2013-06-21Update CHANGESDr. Stephen Henson1-0/+4
2013-06-12Exetended OAEP support.Dr. Stephen Henson1-0/+4
2013-06-12Add support for arbitrary TLS extensions.Trevor1-0/+3
2013-04-09Dual DTLS version methods.Dr. Stephen Henson1-0/+5
2012-12-19correct CHANGESDr. Stephen Henson1-2/+2
2012-12-11Make openssl verify return errors.Ben Laurie1-0/+4
2012-12-07Fix OCSP checking.Ben Laurie1-0/+2
2012-12-06Add code to download CRLs based on CRLDP extension.Dr. Stephen Henson1-0/+4
2012-12-05Integrate host, email and IP address checks into X509_verify.Dr. Stephen Henson1-0/+4
2012-12-04initial support for delta CRL generations by diffing two full CRLsDr. Stephen Henson1-0/+4
2012-12-02New option to add CRLs for s_client and s_server.Dr. Stephen Henson1-0/+3
2012-11-28Generalise OCSP I/O functions to support dowloading of other ASN1Dr. Stephen Henson1-1/+6
2012-11-27New functions to set lookup_crls callback and to retrieve internal X509_STOREDr. Stephen Henson1-1/+5
2012-11-22Add support for printing out and retrieving EC point formats extension.Dr. Stephen Henson1-0/+4
2012-11-19new function ASN1_TIME_diff to calculate difference between two ASN1_TIME str...Dr. Stephen Henson1-0/+4
2012-11-18PR: 2909Dr. Stephen Henson1-0/+4
2012-11-16add SSL_CONF functions and documentationDr. Stephen Henson1-0/+4
2012-10-08New functions to check a hostname email or IP address against aDr. Stephen Henson1-0/+5
2012-09-19config: detect linux-mips* targets.Andy Polyakov1-0/+4
2012-09-14Add -rev test option to s_server to just reverse order of characters receivedDr. Stephen Henson1-0/+5
2012-09-12Add -brief option to s_client and s_server to summarise connection details.Dr. Stephen Henson1-0/+4
2012-09-12Add ctrl and utility functions to retrieve raw cipher list sent by client inDr. Stephen Henson1-0/+4
2012-09-11Minor enhancement to PR#2836 fix. Instead of modifying SSL_get_certificateDr. Stephen Henson1-2/+2
2012-09-11Call OCSP Stapling callback after ciphersuite has been chosen, so theBen Laurie1-0/+6
2012-08-29Harmonize CHANGES in HEAD.Andy Polyakov1-59/+67
2012-08-15Add three Suite B modes to TLS code, supporting RFC6460.Dr. Stephen Henson1-0/+6
2012-08-03add suite B chain validation flags and associated verify errorsDr. Stephen Henson1-0/+4
2012-07-27Make tls1_check_chain return a set of flags indicating checks passedDr. Stephen Henson1-0/+6
2012-07-24Abort handshake if signature algorithm used not supported by peer.Dr. Stephen Henson1-0/+6
2012-07-24check EC tmp key matches preferencesDr. Stephen Henson1-0/+3
2012-07-23Add support for certificate stores in CERT structure. This makes itDr. Stephen Henson1-0/+13
2012-07-18New function ssl_set_client_disabled to set masks for any ciphersuitesDr. Stephen Henson1-0/+5
2012-07-08Add new ctrl to retrieve client certificate types, print outDr. Stephen Henson1-0/+6
2012-07-03Separate client and server permitted signature algorithm support: by defaultDr. Stephen Henson1-0/+3
2012-06-29Add certificate callback. If set this is called whenever a certificateDr. Stephen Henson1-0/+9
2012-06-28Add new "valid_flags" field to CERT_PKEY structure which determines whatDr. Stephen Henson1-0/+12
2012-06-25Reorganise supported signature algorithm extension processing.Dr. Stephen Henson1-0/+6
2012-06-22Add support for application defined signature algorithms for use withDr. Stephen Henson1-0/+5
2012-06-18Make it possible to delete all certificates from an SSL structure.Dr. Stephen Henson1-0/+5
2012-06-15Initial record tracing code. Print out all fields in SSL/TLS recordsDr. Stephen Henson1-0/+6
2012-06-13New functions to retrieve certificate signatures and signature OID NID.Dr. Stephen Henson1-0/+4
2012-06-12print out issuer and subject unique identifier fields in certificatesDr. Stephen Henson1-0/+4
2012-05-30RFC 5878 support.Ben Laurie1-0/+3
2012-05-11PR: 2813Dr. Stephen Henson1-0/+3
2012-05-11PR: 2811Dr. Stephen Henson1-2/+7
2012-05-10Sanity check record length before skipping explicit IV in TLS 1.2, 1.1 andDr. Stephen Henson1-0/+8
2012-05-10Reported by: Solar Designer of OpenwallDr. Stephen Henson1-0/+4
2012-04-26Don't try to use unvalidated composite ciphers in FIPS modeDr. Stephen Henson1-2/+9