Richard Levitte [Wed, 13 Sep 2000 21:20:49 +0000 (21:20 +0000)]
Merge of main trunk, conflicts resolved.
cvs2svn [Wed, 13 Sep 2000 17:27:43 +0000 (17:27 +0000)]
This commit was manufactured by cvs2svn to create branch 'BRANCH_engine'.
Dr. Stephen Henson [Wed, 13 Sep 2000 17:27:42 +0000 (17:27 +0000)]
BIO_s_fd() manual page.
Ulf Möller [Wed, 13 Sep 2000 14:24:07 +0000 (14:24 +0000)]
Point to Peter Gutmann's revised paper.
The copy at www.usenix.org is the old version.
Richard Levitte [Wed, 13 Sep 2000 12:14:39 +0000 (12:14 +0000)]
One more passed test
Richard Levitte [Wed, 13 Sep 2000 11:35:54 +0000 (11:35 +0000)]
Update info on what has been fixed
Richard Levitte [Wed, 13 Sep 2000 11:33:09 +0000 (11:33 +0000)]
Update info on what has been fixed, and switch format for failure data
Richard Levitte [Wed, 13 Sep 2000 11:29:15 +0000 (11:29 +0000)]
Make sure that Configure will defined DSO_WIN32 for the Win32 targets. I feel a bit unsure if this should really be done for Mingw32 and CygWin32
Richard Levitte [Wed, 13 Sep 2000 07:17:35 +0000 (07:17 +0000)]
3 changes:
- Make sure PCURSORINFO is defined even on systems that do not provide it.
- Change the reference to Peter Gutmann's paper.
- Make sure we don't walk the whole heap lists for performance reasons.
Jeffrey Altman suggests following Peter Gutmann's advice to keep it
to 50 heap entries per heap list.
Ulf Möller [Wed, 13 Sep 2000 02:01:35 +0000 (02:01 +0000)]
The other log message should have read "Note the DSA change".
Ulf Möller [Wed, 13 Sep 2000 01:50:24 +0000 (01:50 +0000)]
More Windows failures reported
Ulf Möller [Wed, 13 Sep 2000 01:48:05 +0000 (01:48 +0000)]
Not the DSA change.
Ulf Möller [Wed, 13 Sep 2000 01:45:54 +0000 (01:45 +0000)]
Don't set the two top bits to one when generating a random number < q.:wq
Dr. Stephen Henson [Wed, 13 Sep 2000 00:20:24 +0000 (00:20 +0000)]
Clarify some of the I/O issues.
Add case of using select() and blocking I/O with
BIOs and why you shouldn't (thanks Bodo!).
Richard Levitte [Tue, 12 Sep 2000 22:19:41 +0000 (22:19 +0000)]
A few more systems reported successfull.
Bodo Möller [Tue, 12 Sep 2000 20:28:30 +0000 (20:28 +0000)]
New SSL API mode 'SSL_MODE_AUTO_RETRY', which disables the default
behaviour that SSL_read may result in SSL_ERROR_WANT_READ.
Ulf Möller [Tue, 12 Sep 2000 16:40:59 +0000 (16:40 +0000)]
bug: RAND_poll().
Richard Levitte [Tue, 12 Sep 2000 15:46:04 +0000 (15:46 +0000)]
Holger Reif reports a few more Solaris successes.
Richard Levitte [Tue, 12 Sep 2000 10:07:19 +0000 (10:07 +0000)]
Note the failure on Win32
Richard Levitte [Tue, 12 Sep 2000 10:05:11 +0000 (10:05 +0000)]
FreeBSD and solaris with gcc passed
Richard Levitte [Tue, 12 Sep 2000 08:37:51 +0000 (08:37 +0000)]
Merge of main trunk, conflicts resolved.
Richard Levitte [Tue, 12 Sep 2000 08:12:52 +0000 (08:12 +0000)]
Better error checking for RSA and DSA signature and verification speed
tests. This was required to not get mysterious errors when they
wouldn't quite want to work.
Richard Levitte [Tue, 12 Sep 2000 06:49:03 +0000 (06:49 +0000)]
Linux in Sparc v7 passed
Richard Levitte [Tue, 12 Sep 2000 06:44:52 +0000 (06:44 +0000)]
SCO 5.0.5 with both gcc and cc passed
cvs2svn [Tue, 12 Sep 2000 01:56:57 +0000 (01:56 +0000)]
This commit was manufactured by cvs2svn to create branch 'BRANCH_engine'.
Dr. Stephen Henson [Tue, 12 Sep 2000 01:56:56 +0000 (01:56 +0000)]
More BIO docs.
Richard Levitte [Mon, 11 Sep 2000 22:21:38 +0000 (22:21 +0000)]
DSA_verify() and DSA_sign() might return -1...
Richard Levitte [Mon, 11 Sep 2000 22:17:31 +0000 (22:17 +0000)]
Actually, that was perfectly correct. The fault is in the checking
elsewhere.
Richard Levitte [Mon, 11 Sep 2000 22:15:53 +0000 (22:15 +0000)]
cswift_dsa_verify() incorrectly return -1 on error.
Richard Levitte [Mon, 11 Sep 2000 22:02:07 +0000 (22:02 +0000)]
A couple more HP-UX targets tested.
Richard Levitte [Mon, 11 Sep 2000 21:57:27 +0000 (21:57 +0000)]
debug-linux-elf and debug-linux-elf-efence need to be linked with
libdl just as linux-elf...
Richard Levitte [Mon, 11 Sep 2000 20:32:35 +0000 (20:32 +0000)]
Failure on Solaris when using the CSwift card.
Richard Levitte [Mon, 11 Sep 2000 20:04:58 +0000 (20:04 +0000)]
mkdef.pl still needed better logic. Also, the semantics of the
platforms list is clarified (it's however not quite followed in the
RSAREF case...).
RSAREF is also checked now.
Ben Laurie [Mon, 11 Sep 2000 17:58:09 +0000 (17:58 +0000)]
Document an old change.
Richard Levitte [Mon, 11 Sep 2000 17:31:05 +0000 (17:31 +0000)]
mkdef.pl has erroneous conditions to check if a symbol is excluded
from the given target. Fixed, I hope.
Richard Levitte [Mon, 11 Sep 2000 17:10:21 +0000 (17:10 +0000)]
linux-elf passed
Richard Levitte [Mon, 11 Sep 2000 16:46:35 +0000 (16:46 +0000)]
OpenBSD doesn't support timeb.
Richard Levitte [Mon, 11 Sep 2000 16:37:36 +0000 (16:37 +0000)]
Don't include e_os.h before the system headers
Richard Levitte [Mon, 11 Sep 2000 16:36:14 +0000 (16:36 +0000)]
Reports for OpenBSD 2.7 and HP-UX 10.20
Richard Levitte [Mon, 11 Sep 2000 13:28:35 +0000 (13:28 +0000)]
Time to build the beta of the engine branch. Change version number
texts accordingly.
Richard Levitte [Mon, 11 Sep 2000 13:23:47 +0000 (13:23 +0000)]
Merge of main trunk, no conflicts this time.
make update
Richard Levitte [Mon, 11 Sep 2000 13:06:48 +0000 (13:06 +0000)]
Last minute update, in time to make it to 0.9.6-beta1
Richard Levitte [Mon, 11 Sep 2000 12:39:43 +0000 (12:39 +0000)]
Time to release a beta. Change the status accordingly.
Richard Levitte [Mon, 11 Sep 2000 12:31:36 +0000 (12:31 +0000)]
Time to release a beta. Change the version numbers and dates
accordingly.
Richard Levitte [Mon, 11 Sep 2000 11:45:02 +0000 (11:45 +0000)]
I started with a make update, but a rewrite was actually needed.
Perhaps we should make rewrites the default thing to do?
Richard Levitte [Mon, 11 Sep 2000 11:43:35 +0000 (11:43 +0000)]
A cast is needed or Borland C will complain.
Richard Levitte [Mon, 11 Sep 2000 10:18:56 +0000 (10:18 +0000)]
Merge of main trunk, no conflicts this time
cvs2svn [Mon, 11 Sep 2000 01:04:10 +0000 (01:04 +0000)]
This commit was manufactured by cvs2svn to create branch 'BRANCH_engine'.
Dr. Stephen Henson [Mon, 11 Sep 2000 01:04:09 +0000 (01:04 +0000)]
Docs for cipher and base64 BIOs.
Dr. Stephen Henson [Sun, 10 Sep 2000 17:36:15 +0000 (17:36 +0000)]
More new BIO docs, correct some old ones.
Richard Levitte [Sun, 10 Sep 2000 14:45:19 +0000 (14:45 +0000)]
Marin Kraemer <Martin.Kraemer@MchP.Siemens.De> sent us patches to make
the OpenSSL commands x50 and req work better on a EBCDIC system.
Dr. Stephen Henson [Sun, 10 Sep 2000 01:52:26 +0000 (01:52 +0000)]
More preliminary BIO docs...
Incomplete and possibly inaccurate. Hope somone is
checking these :-)
Richard Levitte [Sat, 9 Sep 2000 18:10:35 +0000 (18:10 +0000)]
Merge of main trunk, no conflicts this time
Richard Levitte [Sat, 9 Sep 2000 18:05:27 +0000 (18:05 +0000)]
More VMS synchronisation
Richard Levitte [Sat, 9 Sep 2000 07:14:43 +0000 (07:14 +0000)]
Since C compilers on VMS (perhaps with gcc being the great exception)
do not quite follow the same rules as on Unix, we need to use the
FLAT_INC tweak to include the vendor-specific header files.
Richard Levitte [Sat, 9 Sep 2000 07:07:54 +0000 (07:07 +0000)]
Synchronise VMS with Unix.
Richard Levitte [Sat, 9 Sep 2000 07:03:02 +0000 (07:03 +0000)]
Merge of main trunk, no conflicts this time
Ulf Möller [Sat, 9 Sep 2000 04:45:18 +0000 (04:45 +0000)]
Fix some CygWin problems.
cvs2svn [Sat, 9 Sep 2000 01:01:36 +0000 (01:01 +0000)]
This commit was manufactured by cvs2svn to create branch 'BRANCH_engine'.
Dr. Stephen Henson [Sat, 9 Sep 2000 01:01:35 +0000 (01:01 +0000)]
Really add BIO_read this time...
Dr. Stephen Henson [Sat, 9 Sep 2000 00:59:37 +0000 (00:59 +0000)]
Add BIO_read() (etc.) docs.
Add an ASN1 FAQ because I'm sick of answering it :-)
Richard Levitte [Fri, 8 Sep 2000 22:19:27 +0000 (22:19 +0000)]
Clarify how one should behave when make fails. The fault is not
necessarely ours.
Richard Levitte [Fri, 8 Sep 2000 20:25:49 +0000 (20:25 +0000)]
Synchronise the VMS build with the Unix one.
Richard Levitte [Fri, 8 Sep 2000 06:28:09 +0000 (06:28 +0000)]
Two places where I forgot to change vms_idhacks to symhacks.
Dr. Stephen Henson [Fri, 8 Sep 2000 00:53:58 +0000 (00:53 +0000)]
Update verify docs.
New option to verify program to print out diagnostics.
Dr. Stephen Henson [Thu, 7 Sep 2000 23:14:26 +0000 (23:14 +0000)]
Two new PKCS#12 demo programs.
Update PKCS12_parse().
Make the keyid in certificate aux info more usable.
Dr. Stephen Henson [Thu, 7 Sep 2000 17:42:25 +0000 (17:42 +0000)]
Ugh, BIO_find_type() cannot be passed a NULL.
Fix doc example, and fix BIO_find_type().
Fix PKCS7_verify(). It was using 'i' for both the
loop variable and the verify return value.
Geoff Thorpe [Thu, 7 Sep 2000 17:09:05 +0000 (17:09 +0000)]
Fix a little glitch before I forget about it. (I noticed it while reading
through the diff from Richard's last commit.)
Richard Levitte [Thu, 7 Sep 2000 16:19:27 +0000 (16:19 +0000)]
Integrate engine in most utilities. Now really tested yet.
Dr. Stephen Henson [Thu, 7 Sep 2000 13:04:27 +0000 (13:04 +0000)]
Add docs for BIO_find_type() and friends.
Added function BIO_next() otherwise you can't
traverse a chain without accessing BIO internals.
Richard Levitte [Thu, 7 Sep 2000 10:59:04 +0000 (10:59 +0000)]
Merge main trunk to engine branch, all conflicts resolved.
Richard Levitte [Thu, 7 Sep 2000 08:46:51 +0000 (08:46 +0000)]
'make update'
Richard Levitte [Thu, 7 Sep 2000 08:44:13 +0000 (08:44 +0000)]
*.num rewitten to include the extra information.
Richard Levitte [Thu, 7 Sep 2000 08:43:08 +0000 (08:43 +0000)]
Major hack of mkdef.pl. There should be no more need to redo the
process when some symbols are missing. Instead, all needed info is
saved in the .num files, including what conditions are needed for a
specific symbol to exist.
This was needed for the work I'm doing with shared libraries under
VMS.
cvs2svn [Thu, 7 Sep 2000 08:18:06 +0000 (08:18 +0000)]
This commit was manufactured by cvs2svn to create branch 'BRANCH_engine'.
Richard Levitte [Thu, 7 Sep 2000 08:18:05 +0000 (08:18 +0000)]
It's not just VMS that needs some symbols to be hacked. Let's
centralise those hacks in crypto/symhacks.h and use it everywhere it's
needed.
Richard Levitte [Thu, 7 Sep 2000 08:14:46 +0000 (08:14 +0000)]
Another thing I'm working on.
Bodo Möller [Thu, 7 Sep 2000 08:07:55 +0000 (08:07 +0000)]
clarification (source/sink BIOs are usually *both* source and sink)
Richard Levitte [Thu, 7 Sep 2000 05:50:14 +0000 (05:50 +0000)]
Change the printing mahine used by BIO_printf() and friends so it can
handle an externally provided "static" buffer as well a a dynamic
buffer. The "static" buffer is filled first, but if overflowed, the
dynamic buffer is used instead, being allocated somewhere i the heap.
This combines the benefits of putting the output in a preallocated
buffer (on the stack, for example) and in a buffer that grows
somewhere in the heap.
Dr. Stephen Henson [Thu, 7 Sep 2000 00:22:31 +0000 (00:22 +0000)]
Some BIO docs, incomplete, more to follow.
Hmmm I didn't realise BIO_pop() did that:
isn't source wonderful?
Bodo Möller [Wed, 6 Sep 2000 17:09:58 +0000 (17:09 +0000)]
Use name ...-whatever-solaris2 instead of ...-sun-solaris2
(the middle string describes the architecture).
Bodo Möller [Wed, 6 Sep 2000 15:40:52 +0000 (15:40 +0000)]
Get rid of ASN1_UTCTIME_get, which cannot work with time_t
return type (on platforms where time_t is a 32 bit value).
New function ASN1_UTCTIME_cmp_time_t as a replacement
for use in apps/x509.c.
Bodo Möller [Wed, 6 Sep 2000 14:55:11 +0000 (14:55 +0000)]
See RSA Security's press release at
http://www.rsasecurity.com/news/pr/000906-1.html (September 6, 2000):
"RSA Security Releases RSA Encryption Algorithm into Public Domain"
Bodo Möller [Wed, 6 Sep 2000 14:34:32 +0000 (14:34 +0000)]
Another superfluous pair of parentheses.
Bodo Möller [Wed, 6 Sep 2000 14:14:20 +0000 (14:14 +0000)]
Another round of indentation changes: Position braces consistently,
add some whitespace for 'if ()', 'for ()', 'while ()' to distinguish
keywords from function names, and finally remove parens around return
values (why be stingy with whitespace but fill the source code
with an abundance of parentheses that are not needed to structure
expressions for readability?).
Bodo Möller [Wed, 6 Sep 2000 13:31:44 +0000 (13:31 +0000)]
More indentation consistency: for (), while (), if (), return ()
usually get a space between keyword and opening paranthesis
so that they don't look like function calls, where no space is
used.
Bodo Möller [Wed, 6 Sep 2000 13:24:10 +0000 (13:24 +0000)]
Fix X509_STORE_CTX_init. Make indentation more consistent. Dump core less often.
Bodo Möller [Wed, 6 Sep 2000 12:34:10 +0000 (12:34 +0000)]
'make update'
Bodo Möller [Wed, 6 Sep 2000 12:25:58 +0000 (12:25 +0000)]
Changes for QNX: there is no thread support, and the previous
configuration only worked with no-asm.
Bodo Möller [Wed, 6 Sep 2000 12:18:24 +0000 (12:18 +0000)]
typo
Bodo Möller [Wed, 6 Sep 2000 11:49:43 +0000 (11:49 +0000)]
Add OAEP. Seed the PRNG.
Bodo Möller [Wed, 6 Sep 2000 10:50:33 +0000 (10:50 +0000)]
update
Bodo Möller [Wed, 6 Sep 2000 07:58:27 +0000 (07:58 +0000)]
Add rsautl.
Bodo Möller [Wed, 6 Sep 2000 07:56:03 +0000 (07:56 +0000)]
Clarification for SSL_ERROR_ZERO_RETURN
Dr. Stephen Henson [Tue, 5 Sep 2000 22:30:38 +0000 (22:30 +0000)]
Fix typo in rsautl.
Add support for settable verify time in X509_verify_cert().
Document rsautl utility.
Ben Laurie [Tue, 5 Sep 2000 18:56:55 +0000 (18:56 +0000)]
Ignore executable.
Ben Laurie [Tue, 5 Sep 2000 18:47:57 +0000 (18:47 +0000)]
Handle WANT_READ more correctly (thanks to Bodo).
Dr. Stephen Henson [Tue, 5 Sep 2000 17:53:58 +0000 (17:53 +0000)]
*BIG* verify code reorganisation.
The old code was painfully primitive and couldn't handle
distinct certificates using the same subject name.
The new code performs several tests on a candidate issuer
certificate based on certificate extensions.
It also adds several callbacks to X509_VERIFY_CTX so its
behaviour can be customised.
Unfortunately some hackery was needed to persuade X509_STORE
to tolerate this. This should go away when X509_STORE is
replaced, sometime...
This must have broken something though :-(
Ben Laurie [Tue, 5 Sep 2000 17:06:45 +0000 (17:06 +0000)]
Distinguish between assertions and conditions that should cause death.
Dr. Stephen Henson [Tue, 5 Sep 2000 13:27:57 +0000 (13:27 +0000)]
Keep a not of original encoding in certificate requests.
Add new option to PKCS7_sign to exclude S/MIME capabilities.