Age | Commit message (Collapse) | Author | Files | Lines | |
---|---|---|---|---|---|
2001-02-10 | Fix CRL printing to correctly show when there are no revoked certificates. | Dr. Stephen Henson | 3 | -1/+3 | |
Make ca.c correctly initialize the revocation date. Make ASN1_UTCTIME_set_string() and ASN1_GENERALIZEDTIME_set_string() set the string type: so they can initialize ASN1_TIME structures properly. | |||||
2001-02-10 | Simplify BN_rand_range | Bodo Möller | 3 | -9/+5 | |
2001-02-09 | Fix "wierd" typo as submitted by Jeroen Ruigrok/Asmodai <asmodai@wxs.nl>. | Lutz Jänicke | 1 | -1/+1 | |
2001-02-09 | Various Win32 related fixed. Make no-krb5 work in mkdef.pl . | Dr. Stephen Henson | 3 | -11/+2 | |
Fix warning in apps/engine.c Remove definitions of deleted functions. Add missing definition of X509_VAL. | |||||
2001-02-08 | The check for request including a nonce and response not having it was | Richard Levitte | 1 | -1/+1 | |
inversed. Corrected. Hopefully, this will make it work without dumping core. | |||||
2001-02-08 | use <= instead of == | Ulf Möller | 1 | -1/+1 | |
2001-02-08 | point out that RAND_load_file() etc are only for seed files, not for | Ulf Möller | 1 | -0/+3 | |
entropy devices or sockets. | |||||
2001-02-08 | Another comment change. (Previous comment does not apply | Bodo Möller | 1 | -2/+2 | |
for range = 11000000... or range = 100000...) | |||||
2001-02-08 | Change comments. (The expected number of iterations in BN_rand_range | Bodo Möller | 1 | -2/+2 | |
never exceeds 1.333...). | |||||
2001-02-08 | oops -- remove observation code | Bodo Möller | 1 | -4/+0 | |
2001-02-08 | Integrate my implementation of a countermeasure against | Bodo Möller | 4 | -8/+63 | |
Bleichenbacher's DSA attack. With this implementation, the expected number of iterations never exceeds 2. New semantics for BN_rand_range(): BN_rand_range(r, min, range) now generates r such that min <= r < min+range. (Previously, BN_rand_range(r, min, max) generated r such that min <= r < max. It is more convenient to have the range; also the previous prototype was misleading because max was larger than the actual maximum.) | |||||
2001-02-08 | platform specific CFLAGS don't belong into this Makefile | Bodo Möller | 1 | -1/+2 | |
2001-02-07 | Bleichenbacher's DSA attack | Ulf Möller | 3 | -7/+13 | |
2001-02-07 | Modify access to EGD socket to deal with EINTR etc that can appear | Lutz Jänicke | 1 | -67/+156 | |
during connect() and other calls. First seen on Unixware-7. Unify access to EGD-socket for all RAND_egd_*() methods. | |||||
2001-02-07 | Fix AES code. | Dr. Stephen Henson | 16 | -4977/+1860 | |
Update Rijndael source to v3.0 Add AES OIDs. Change most references of Rijndael to AES. Add new draft AES ciphersuites. | |||||
2001-02-06 | Rijdael CBC mode and partial undebugged SSL support. | Ben Laurie | 8 | -9/+174 | |
2001-02-06 | Avoid coredumps for CONF_get_...(NULL, ...) | Bodo Möller | 1 | -18/+41 | |
2001-02-06 | format strings | Ulf Möller | 1 | -1/+1 | |
2001-02-06 | Fix potential buffer overrun for EBCDIC. | Ulf Möller | 1 | -6/+20 | |
2001-02-05 | Fix a memory leak in BIO_get_accept_socket(). This leak was small and | Richard Levitte | 1 | -4/+4 | |
only happened when the port number wasn't parsable ot the host wasn't possible to convert to an IP address. Contributed by Niko Baric <Niko.Baric@epost.de> | |||||
2001-02-05 | Include string.h (whis is in all relevant standards) instead of | Bodo Möller | 1 | -1/+1 | |
memory.h (which is not). | |||||
2001-02-05 | New function to copy nonce values from OCSP | Dr. Stephen Henson | 2 | -12/+17 | |
request to response. | |||||
2001-02-04 | Make depend. | Ben Laurie | 17 | -1830/+2004 | |
2001-02-04 | Can't remember why this was needed? | Ben Laurie | 1 | -1/+2 | |
2001-02-04 | Fix a warning. | Ben Laurie | 1 | -0/+1 | |
2001-02-04 | Fix ASN1_TIME_to_generlizedtime(). | Dr. Stephen Henson | 5 | -11/+35 | |
Add protoype for OCSP_response_create(). Add OCSP_request_sign() and OCSP_basic_sign() private key and certificate checks and make OCSP_NOCERTS consistent with PKCS7_NOCERTS | |||||
2001-02-03 | Various OCSP responder utility functions. | Dr. Stephen Henson | 7 | -227/+321 | |
Delete obsolete OCSP functions. Largely untested at present... | |||||
2001-02-02 | Various function for commmon operations. | Dr. Stephen Henson | 10 | -44/+42 | |
2001-02-02 | Tidy up the mess in bss_sock.c and bss_fd.c | Dr. Stephen Henson | 2 | -130/+225 | |
by placing them socket/fd code in separate files rather than trying to have them both share the same one. | |||||
2001-02-01 | Tolerate some "variations" used in some | Dr. Stephen Henson | 1 | -2/+4 | |
certificates. One is a valid CA which has no basicConstraints but does have certSign keyUsage. Other is S/MIME signer with nonRepudiation but no digitalSignature. | |||||
2001-01-30 | Increase consistency of header data (some mail readers really do not | Richard Levitte | 1 | -3/+3 | |
like spaces before the semicolon, and besides, other parts of this file makes the values without those spaces), and move spacing of continuation lines to support BIO's that break lines after each write. | |||||
2001-01-28 | Comment and indentation | Bodo Möller | 2 | -4/+11 | |
2001-01-28 | Make sk_sort tolearate a NULL argument. | Dr. Stephen Henson | 1 | -1/+1 | |
2001-01-26 | New OCSP response verify option OCSP_TRUSTOTHER | Dr. Stephen Henson | 2 | -7/+17 | |
2001-01-24 | Add debugging info to new ASN1 code to trace memory leaks. | Dr. Stephen Henson | 4 | -13/+45 | |
Fix PKCS7 and PKCS12 memory leaks. Initialise encapsulated content type properly. | |||||
2001-01-24 | Update "OAEP reconsidered" comment | Bodo Möller | 1 | -8/+8 | |
2001-01-23 | There is no C version of bn_div_3_words | Ulf Möller | 1 | -1/+1 | |
2001-01-20 | Fix to stop X509_time_adj() using GeneralizedTime. | Dr. Stephen Henson | 1 | -3/+5 | |
2001-01-19 | Fixes to various ASN1_INTEGER routines for negative case. | Dr. Stephen Henson | 3 | -5/+36 | |
Enhance s2i_ASN1_INTEGER(). | |||||
2001-01-19 | Additional functionality in ocsp utility: print summary | Dr. Stephen Henson | 4 | -8/+35 | |
of status info. Check nonce values. Option to disable verify. Update usage message. Rename status to string functions and make them global. | |||||
2001-01-18 | Implement remaining OCSP verify checks in | Dr. Stephen Henson | 3 | -13/+175 | |
accordance with RFC2560. | |||||
2001-01-17 | Initial OCSP certificate verify. Not complete, | Dr. Stephen Henson | 8 | -10/+126 | |
it just supports a "trusted OCSP global root CA". | |||||
2001-01-14 | Change PKCS#12 key derivation routines to cope with | Dr. Stephen Henson | 4 | -9/+13 | |
non null terminated passwords. | |||||
2001-01-13 | New OCSP utility. This can generate, parse and print | Dr. Stephen Henson | 2 | -4/+6 | |
OCSP requests. It can also query reponders and parse or print out responses. Still needs some more work: OCSP response checks and of course documentation. | |||||
2001-01-12 | Disable RegQueryValueEx() call. | Bodo Möller | 1 | -0/+5 | |
Problem reported by "Wolfgang Marczy" <WMarczy@topcall.co.at> in a message to openssl-dev (19 Dec 2000 13:40:51 +0100). | |||||
2001-01-12 | isspace must be used only on *unsigned* chars | Bodo Möller | 1 | -6/+6 | |
2001-01-11 | Fix typo in OCSP ASN1 module, this caused | Dr. Stephen Henson | 3 | -4/+4 | |
invalid format in OCSP request signatures. Add spaces to OCSP HTTP header. Change X509_NAME_set() there's no reason why it should return an error if the destination points to NULL... though it should if the destination is NULL. | |||||
2001-01-11 | OCSP basic response verify. Very incomplete | Dr. Stephen Henson | 5 | -5/+157 | |
but will verify the signatures on a response and locate the signers certifcate. Still needs to implement a proper OCSP certificate verify. Fix warning in RAND_egd(). | |||||
2001-01-10 | No functional change, but slightly improved code clarity. | Bodo Möller | 1 | -3/+6 | |
2001-01-10 | After discussion with Richard, change the new API for extended memory | Bodo Möller | 1 | -56/+51 | |
allocation callbacks so that it is no longer visible to applications that these live at a different call level than conventional memory allocation callbacks. |