Bodo Möller [Wed, 8 Nov 2000 10:05:34 +0000 (10:05 +0000)]
BN_CTX-related fixes.
Richard Levitte [Tue, 7 Nov 2000 23:43:21 +0000 (23:43 +0000)]
Constification of LHASH. Contributed by "Paul D. Smith" <psmith@gnu.org>
I didn't apply all his patches yet, since I have some hesitance about
unconstifying. To be pondered.
Richard Levitte [Tue, 7 Nov 2000 14:31:53 +0000 (14:31 +0000)]
Document that the Nuron hardware has been added and remove the
requirement for an engine utility since we now have that.
Richard Levitte [Tue, 7 Nov 2000 14:30:37 +0000 (14:30 +0000)]
Constify DH-related code.
Richard Levitte [Tue, 7 Nov 2000 13:54:39 +0000 (13:54 +0000)]
Constify DSA-related code.
Richard Levitte [Tue, 7 Nov 2000 13:53:21 +0000 (13:53 +0000)]
Make sure ERR_get_error() is declared.
Richard Levitte [Tue, 7 Nov 2000 13:49:46 +0000 (13:49 +0000)]
A few more constifications of some RSA routines that I forgot
yesterday.
Richard Levitte [Tue, 7 Nov 2000 13:23:16 +0000 (13:23 +0000)]
Lutz tells me HP cc uses the same syntax for flags that should be
passed down to ld as GNU cc.
Richard Levitte [Tue, 7 Nov 2000 13:21:09 +0000 (13:21 +0000)]
When ENGINE_by_id() couldn't find the given engine id, it generates an
error. When checking like engine_add() is, those errors are actually
good, so remove them.
Richard Levitte [Tue, 7 Nov 2000 11:25:26 +0000 (11:25 +0000)]
shl_load() also needs to load along a path given through an
environment variable, SHLIB_PATH. This change makes that possible.
Bodo Möller [Tue, 7 Nov 2000 09:39:51 +0000 (09:39 +0000)]
Handle BN_copy failure after successful BN_new.
Bodo Möller [Tue, 7 Nov 2000 09:35:19 +0000 (09:35 +0000)]
handle the case when BN_new returns NULL
Richard Levitte [Mon, 6 Nov 2000 23:29:52 +0000 (23:29 +0000)]
Document recent constifications.
Richard Levitte [Mon, 6 Nov 2000 23:24:59 +0000 (23:24 +0000)]
Constification of CRYPTO_get_ex_data() needed for the sake of
RSA_get_ext_data().
Richard Levitte [Mon, 6 Nov 2000 23:16:04 +0000 (23:16 +0000)]
The consequence of constification is that to pass the address to a
pointer to a const double pointe parameter, the pointer must point to
const data as well.
Richard Levitte [Mon, 6 Nov 2000 23:15:03 +0000 (23:15 +0000)]
Constify the RSAref glue code.
Richard Levitte [Mon, 6 Nov 2000 23:04:15 +0000 (23:04 +0000)]
Constify the RSA parts of the ASN.1 library. Note some ugly casts
that are needed in the ASN.1 macros. Hopefully, we can get rid of
those in an elegant way in the future.
Richard Levitte [Mon, 6 Nov 2000 22:49:05 +0000 (22:49 +0000)]
Constify the RSA library.
Richard Levitte [Mon, 6 Nov 2000 22:34:17 +0000 (22:34 +0000)]
Constify the RSA library.
Richard Levitte [Mon, 6 Nov 2000 22:15:50 +0000 (22:15 +0000)]
As a consequence of the BIGNUM constification, the ENGINE code needs a
few small constifying changes, and why not throw in a couple of extras
while I'm at it?
Richard Levitte [Mon, 6 Nov 2000 22:03:00 +0000 (22:03 +0000)]
Make all engines available in the openssl application.
Ulf Möller [Mon, 6 Nov 2000 21:28:38 +0000 (21:28 +0000)]
looks like a cut&paste error
Richard Levitte [Mon, 6 Nov 2000 21:15:54 +0000 (21:15 +0000)]
Constify the BIGNUM routines a bit more. The only trouble were the
two functions that did expansion on in parameters (BN_mul() and
BN_sqr()). The problem was solved by making bn_dup_expand() which is
a mix of bn_expand2() and BN_dup().
Richard Levitte [Mon, 6 Nov 2000 21:12:21 +0000 (21:12 +0000)]
mode used too early in EVP_PKEY_save_parameters.
Spotted by Ken Lalonde <ken@torus.ca>
Richard Levitte [Mon, 6 Nov 2000 06:52:47 +0000 (06:52 +0000)]
Make sure that shared libraries get the internal name engine with the
full version number and not just 0. This should mark the shared
libraries as not backward compatible. Of course, this should be
changed again when we can guarantee backward binary compatibility.
Ulf Möller [Sat, 4 Nov 2000 03:33:26 +0000 (03:33 +0000)]
Set the CryptoAPI randomness estimate back to 0.
The randomness may not actually be very good (we don't know).
Ulf Möller [Fri, 3 Nov 2000 23:07:01 +0000 (23:07 +0000)]
increase the value a bit
Geoff Thorpe [Fri, 3 Nov 2000 17:09:19 +0000 (17:09 +0000)]
Richard moved hw_nuron.c over to DSO-land recently, so this include isn't
needed now.
Ulf Möller [Fri, 3 Nov 2000 16:35:31 +0000 (16:35 +0000)]
Minor corrections (HPUX).
From: Lutz Jaenicke <Lutz.Jaenicke@aet.TU-Cottbus.DE>
Bodo Möller [Fri, 3 Nov 2000 15:40:10 +0000 (15:40 +0000)]
avoid memory leak
Richard Levitte [Fri, 3 Nov 2000 00:59:49 +0000 (00:59 +0000)]
Instead of just STACK, use STACK_OF(ASN1_OBJECT).
Richard Levitte [Thu, 2 Nov 2000 22:55:14 +0000 (22:55 +0000)]
Update the standards list to the current status
Richard Levitte [Thu, 2 Nov 2000 20:33:04 +0000 (20:33 +0000)]
Change the engine library so the application writer has to explicitely
load the "external" built-in engines (those that require DSO). This
makes linking with libdl or other dso libraries non-mandatory.
Change 'openssl engine' accordingly.
Change the engine header files so some declarations (that differed at
that!) aren't duplicated, and make sure engine_int.h includes
engine.h. That way, there should be no way of missing the needed
info.
Richard Levitte [Thu, 2 Nov 2000 19:24:48 +0000 (19:24 +0000)]
'openssl engine' can now list engine capabilities. The current
implementation is contained in the application, and the capability
string building part should really be part of the engine library.
This is therefore an experimental hack, and will be changed in the
near future.
Richard Levitte [Thu, 2 Nov 2000 18:58:43 +0000 (18:58 +0000)]
Better error reporting in 'openssl engine'
Richard Levitte [Thu, 2 Nov 2000 18:53:25 +0000 (18:53 +0000)]
make update
Bodo Möller [Thu, 2 Nov 2000 10:35:10 +0000 (10:35 +0000)]
Never call load_dh_param(NULL) because this leads to an illegal
fopen(NULL).
Richard Levitte [Wed, 1 Nov 2000 23:55:45 +0000 (23:55 +0000)]
-t is supported, so display some help about it.
Geoff Thorpe [Wed, 1 Nov 2000 23:14:19 +0000 (23:14 +0000)]
oops, remove comments that are no longer true.
Geoff Thorpe [Wed, 1 Nov 2000 23:12:01 +0000 (23:12 +0000)]
Explanation, tips, etc.
Geoff Thorpe [Wed, 1 Nov 2000 23:11:19 +0000 (23:11 +0000)]
This is a demo that performs SSL tunneling (client and/or server) and is
built using an abstracted state machine with a non-blocking IP wrapper
around it. README will follow in the next commit.
Richard Levitte [Wed, 1 Nov 2000 02:57:35 +0000 (02:57 +0000)]
Add application to enumerate, list and test engines with.
Richard Levitte [Wed, 1 Nov 2000 00:05:04 +0000 (00:05 +0000)]
Add support for shared libraries under Irix.
Submitted by Albert Chin-A-Young <china@thewrittenword.com>
Richard Levitte [Tue, 31 Oct 2000 23:39:08 +0000 (23:39 +0000)]
Rename true64 to the correct tru64.
Suggested by Albert Chin-A-Young <china@thewrittenword.com>
Richard Levitte [Tue, 31 Oct 2000 23:26:32 +0000 (23:26 +0000)]
Improvements to openssl.spec.
Submitted by Damien Miller <djm@mindrot.org>
This change has been CC:ed to crypt@bxa.doc.gov
Richard Levitte [Tue, 31 Oct 2000 23:14:19 +0000 (23:14 +0000)]
Add configuration option to build on Linux on both big-endian and
little-endian MIPS.
Submitted by Ralf Baechle <ralf@uni-koblenz.de>
Richard Levitte [Tue, 31 Oct 2000 11:58:56 +0000 (11:58 +0000)]
Make flag variables int instead of char. This avoids getting into trouble on systems where char is unsigned by default
Ulf Möller [Mon, 30 Oct 2000 20:14:27 +0000 (20:14 +0000)]
_lrotl() is a call to the C runtime library!
Geoff Thorpe [Mon, 30 Oct 2000 18:47:27 +0000 (18:47 +0000)]
DSO_load() should also work when it is passed a NULL - a new DSO is created
automatically, however some code was still referring to the original
pointer rather than the internal one (and thus to NULL instead of the
created pointer).
Richard Levitte [Sat, 28 Oct 2000 22:44:03 +0000 (22:44 +0000)]
Document the change.
Richard Levitte [Sat, 28 Oct 2000 22:40:40 +0000 (22:40 +0000)]
Add the possibility to use keys handled by engines in more
applications.
Richard Levitte [Sat, 28 Oct 2000 22:21:04 +0000 (22:21 +0000)]
Small documentation change
Ulf Möller [Fri, 27 Oct 2000 20:43:18 +0000 (20:43 +0000)]
-engine is gone.
Richard Levitte [Fri, 27 Oct 2000 20:28:37 +0000 (20:28 +0000)]
NetBSD doesn't use ftime().
Richard Levitte [Fri, 27 Oct 2000 11:22:17 +0000 (11:22 +0000)]
Document the OCSP addition.
Richard Levitte [Fri, 27 Oct 2000 11:09:52 +0000 (11:09 +0000)]
make update
Richard Levitte [Fri, 27 Oct 2000 11:05:35 +0000 (11:05 +0000)]
The majority of the OCSP code from CertCo.
Ulf Möller [Thu, 26 Oct 2000 22:24:49 +0000 (22:24 +0000)]
.
Richard Levitte [Thu, 26 Oct 2000 21:07:28 +0000 (21:07 +0000)]
Merge the engine branch into the main trunk. All conflicts resolved.
At the same time, add VMS support for Rijndael.
Geoff Thorpe [Thu, 26 Oct 2000 20:02:33 +0000 (20:02 +0000)]
Add a note about the recent DSO changes in CHANGES.
Richard Levitte [Thu, 26 Oct 2000 18:42:35 +0000 (18:42 +0000)]
On HP-UX, at least when shl_* are used, the libraries have the
extension .sl instead of .so.
Richard Levitte [Thu, 26 Oct 2000 18:30:34 +0000 (18:30 +0000)]
For the operating systems where it matters, it is sometimes good to
translate library names by only adding ".so" to them without
prepending them with "lib". Add the flag DSO_FLAG_NAME_TRANSLATION_EXT_ONLY
for that purpose.
Geoff Thorpe [Thu, 26 Oct 2000 17:38:59 +0000 (17:38 +0000)]
This changes the behaviour of the DSO mechanism for determining an
appropriate filename translation on the host system. Apart from this point,
users should also note that there's a slight change in the API functions
too. The DSO now contains its own to-be-converted filename
("dso->filename"), and at the time the DSO loads the "dso->loaded_filename"
value is set to the translated form. As such, this also provides an impicit
way of determining if the DSO is currently loaded or not. Except, perhaps,
VMS .... :-)
The various DSO_METHODs have been updated for this mechanism except VMS
which is deliberately broken for now, Richard is going to look at how to
fit it in (the source comments in there explain "the issue").
Basically, the new callback scheme allows the filename conversion to
(a) be turned off altogether through the use of the
DSO_FLAG_NO_NAME_TRANSLATION flag,
(b) be handled in the default way using the default DSO_METHOD's converter
(c) overriden per-DSO by setting the override callback
(d) a mix of (b) and (c) - eg. implement an override callback that;
(i) checks if we're win32 "if(strstr(dso->meth->name, "win32"))..."
and if so, convert "blah" into "blah32.dll" (the default is
otherwise to make it "blah.dll").
(ii) default to the normal behaviour - eg. we're not on win32, so
finish with (return dso->meth->dso_name_converter(dso,NULL)).
(e) be retried a number of times by writing a new DSO_METHOD where the
"dso_load()" handler will call the converter repeatedly. Then the
custom converter could use state information in the DSO to suggest
different conversions or paths each time it is invoked.
Bodo Möller [Thu, 26 Oct 2000 12:05:57 +0000 (12:05 +0000)]
rsautl.c requires RSA.
Ulf Möller [Mon, 23 Oct 2000 19:13:35 +0000 (19:13 +0000)]
s_server not s_client
Bodo Möller [Mon, 23 Oct 2000 14:36:18 +0000 (14:36 +0000)]
Cert chain verification is useable by now.
Whether Steve is still working on 'proper' verification is up to
him to decide ...
Ulf Möller [Mon, 23 Oct 2000 14:02:02 +0000 (14:02 +0000)]
Correction from Tani Hosokawa <unknown@riverstyx.net>
Bodo Möller [Mon, 23 Oct 2000 08:01:41 +0000 (08:01 +0000)]
internal_verify now does know about extensions
Bodo Möller [Mon, 23 Oct 2000 07:37:03 +0000 (07:37 +0000)]
Don't ever set 'seeded' if RAND_status() returned 0
(although maybe this static variable should be abolished totally,
it was introduced before RAND_status existed).
Richard Levitte [Sun, 22 Oct 2000 21:37:39 +0000 (21:37 +0000)]
When building shared libraries on HP-UX 10.20 and HP-UX 11.00 (32bit),
ld warns that -Fl "may not be supported in future releases". We know
that, and are doing things in HP-UX 11 (64bit), so turn off that
warning with +vnocompatwarnings.
Richard Levitte [Sun, 22 Oct 2000 16:46:47 +0000 (16:46 +0000)]
It seems like grep isn't as capable as I thought on some Unix systems.
Use egrep instead.
Richard Levitte [Sun, 22 Oct 2000 12:47:01 +0000 (12:47 +0000)]
Pointer error corrected
Richard Levitte [Sun, 22 Oct 2000 12:45:33 +0000 (12:45 +0000)]
If the functions get_dh*() are declared static, they should be defined the same way
Richard Levitte [Sun, 22 Oct 2000 12:44:12 +0000 (12:44 +0000)]
On some operating systems, MAX is defined. Call ours OSSL_MAX instead
Richard Levitte [Sat, 21 Oct 2000 22:53:32 +0000 (22:53 +0000)]
Document
Richard Levitte [Sat, 21 Oct 2000 22:43:07 +0000 (22:43 +0000)]
There's no reason why app_RAND_load_file() should return 0 when
RAND_status() hasn't.
Reported by Dale Stimson <dale@accentre.com>.
Richard Levitte [Sat, 21 Oct 2000 22:18:52 +0000 (22:18 +0000)]
Krister Walfridsson <cato@df.lth.se> tells us sysctl lives in /sbin
since NetBSD 1.5.
Richard Levitte [Sat, 21 Oct 2000 22:05:03 +0000 (22:05 +0000)]
FreeBSD-elf can do threads. However, there seems to be confusion if
you should defined _THREAD_SAFE (I found that in an include file, and
that's what everybody tells me) or _THREADSAFE (that's what the gcc
manual says in the FreeBSD-specific section), so I defined both, just
to be safe.
Richard Levitte [Sat, 21 Oct 2000 21:24:11 +0000 (21:24 +0000)]
Add what's needed to get shared libraries on HP-UX.
N.B.: This has not been tested at all, that's my next step.
Richard Levitte [Sat, 21 Oct 2000 20:15:46 +0000 (20:15 +0000)]
make update
Richard Levitte [Sat, 21 Oct 2000 20:01:34 +0000 (20:01 +0000)]
Document the change to NCONF.
Dr. Stephen Henson [Fri, 20 Oct 2000 00:36:45 +0000 (00:36 +0000)]
Fix for bug (?) in assembly language routines for SHA1. This
causes MASM to complain and not produce valid debug info.
Hopefully this wont break anything else...
Also fix typo in e_rd.c
Dr. Stephen Henson [Thu, 19 Oct 2000 23:16:47 +0000 (23:16 +0000)]
Move expired CA certificate.
Ulf Möller [Thu, 19 Oct 2000 22:02:21 +0000 (22:02 +0000)]
give pseudo prototypes instead of macro definitions for better clarity
Ulf Möller [Thu, 19 Oct 2000 19:40:35 +0000 (19:40 +0000)]
"DESCRIPTION" is required.
Ulf Möller [Thu, 19 Oct 2000 15:19:41 +0000 (15:19 +0000)]
correction from Lutz
Richard Levitte [Thu, 19 Oct 2000 08:29:27 +0000 (08:29 +0000)]
Keep binary backward compatibility by putting new method function
pointers at the end of the structure.
Richard Levitte [Thu, 19 Oct 2000 08:26:32 +0000 (08:26 +0000)]
Make it possible for methods to load from something other than a BIO,
by providing a function pointer that is given a name instead of a BIO.
For example, this could be used to load configuration data from an
LDAP server.
Richard Levitte [Thu, 19 Oct 2000 08:03:14 +0000 (08:03 +0000)]
NCONF_get_number() has no error checking at all. As a replacement,
NCONF_get_number_e() is defined (_e for "error checking") and is
promoted strongly. The old NCONF_get_number is kept around for
binary backward compatibility.
Ulf Möller [Wed, 18 Oct 2000 23:08:55 +0000 (23:08 +0000)]
Add short overview, move header files section further down.
Ulf Möller [Wed, 18 Oct 2000 22:51:34 +0000 (22:51 +0000)]
cosmetic changes
Ulf Möller [Wed, 18 Oct 2000 22:01:47 +0000 (22:01 +0000)]
cosmetic change
Richard Levitte [Wed, 18 Oct 2000 19:36:27 +0000 (19:36 +0000)]
John Denney <jdenney@ca.mdis.com> reports that we forgot to convert
Free to OPENSSL_free in the SSL demos.
Richard Levitte [Tue, 17 Oct 2000 16:16:12 +0000 (16:16 +0000)]
Two questions have been asked quite often lately.
Dr. Stephen Henson [Mon, 16 Oct 2000 22:56:10 +0000 (22:56 +0000)]
Update test server certificate in apps/server.pem (it was expired).
Ben Laurie [Mon, 16 Oct 2000 13:08:16 +0000 (13:08 +0000)]
Always return a value.
Submitted by:
Reviewed by:
PR:
Richard Levitte [Mon, 16 Oct 2000 06:01:41 +0000 (06:01 +0000)]
CRYPTO_get_ex_new_index would never return an error.
Dr. Stephen Henson [Sat, 14 Oct 2000 23:51:52 +0000 (23:51 +0000)]
Fix for typo in certificate directory lookup code.
Richard Levitte [Sat, 14 Oct 2000 20:09:54 +0000 (20:09 +0000)]
The experimental Rijndael code moved to the main trunk.
make update done.
Richard Levitte [Fri, 13 Oct 2000 16:04:20 +0000 (16:04 +0000)]
Even when you don't want to create shared libraries, it's a good idea
to have the full extension information, so residual shared libraries
can be removed so the applications and test programs do not get linked
against them by mistake...