Dr. Stephen Henson [Wed, 1 Jul 2009 11:32:40 +0000 (11:32 +0000)]
Update from 1.0.0-stable
Dr. Stephen Henson [Tue, 30 Jun 2009 22:29:24 +0000 (22:29 +0000)]
Make text line up.
Dr. Stephen Henson [Tue, 30 Jun 2009 22:20:46 +0000 (22:20 +0000)]
PR: 1960
Approved by: steve@openssl.org
Encode compression id in {i2d,d2i}_SSL_SESSION().
Dr. Stephen Henson [Tue, 30 Jun 2009 20:55:19 +0000 (20:55 +0000)]
Typo.
Dr. Stephen Henson [Tue, 30 Jun 2009 11:42:50 +0000 (11:42 +0000)]
Update from 1.0.0-stable.
Dr. Stephen Henson [Tue, 30 Jun 2009 11:32:36 +0000 (11:32 +0000)]
PR: 1822
Submitted by: "Philip A. Prindeville" <philipp_subx@redfish-solutions.com>
Reviewed by: steve@openssl.org
Use $(EXE_EXT) when invoking fips_standalone_sha1
Dr. Stephen Henson [Tue, 30 Jun 2009 11:22:25 +0000 (11:22 +0000)]
Update from 1.0.0-stable.
Dr. Stephen Henson [Sun, 28 Jun 2009 16:23:05 +0000 (16:23 +0000)]
PR: 1942
Submitted by: David Woodhouse <dwmw2@infradead.org>
Approved by: steve@openssl.org
Replace ad-hoc chain builder with X509_verify_cert().
Dr. Stephen Henson [Fri, 26 Jun 2009 23:56:10 +0000 (23:56 +0000)]
Oops, moved too much.
Dr. Stephen Henson [Fri, 26 Jun 2009 22:52:18 +0000 (22:52 +0000)]
PR: 1961
Submitted by: Martin Gerbershagen <martin.gerbershagen@nsn.com>
Approved by: steve@openssl.org
Avoid memory leak if RAND_bytes() fails.
Dr. Stephen Henson [Fri, 26 Jun 2009 15:02:01 +0000 (15:02 +0000)]
PR: 1949
Submitted by: David.Smith@cern.ch
Approved by: steve@openssl.org
When checking whether to flush the output BIO use BIO_CTRL_WPENDING instead
of BIO_CTRL_INFO. In most cases this will have no effect since the following
BIOs wont buffer. In the case of a following buffering BIO this will check
for any pending data in the whole chain and not just the single BIO.
See:
https://issues.apache.org/bugzilla/show_bug.cgi?id=46952
for a detailed analysis of this issue.
Dr. Stephen Henson [Fri, 26 Jun 2009 11:34:22 +0000 (11:34 +0000)]
Update from 1.0.0-stable.
Dr. Stephen Henson [Thu, 25 Jun 2009 17:12:26 +0000 (17:12 +0000)]
Fix from HEAD.
Dr. Stephen Henson [Mon, 22 Jun 2009 10:32:27 +0000 (10:32 +0000)]
Ooops, apply PR #1946 to 0.9.8 too.
Dr. Stephen Henson [Wed, 17 Jun 2009 12:11:53 +0000 (12:11 +0000)]
Fix broken config entries.
Dr. Stephen Henson [Wed, 17 Jun 2009 11:58:17 +0000 (11:58 +0000)]
Correct CHANGES entry.
Dr. Stephen Henson [Wed, 17 Jun 2009 11:55:51 +0000 (11:55 +0000)]
PR: 1943
Submitted by: Guenter <lists@gknw.net>
Approved by: steve@openssl.org
Rename uni2asc and asc2uni on Netware to avoid a name clash.
Dr. Stephen Henson [Wed, 17 Jun 2009 11:49:18 +0000 (11:49 +0000)]
Update from 1.0.0-stable.
Dr. Stephen Henson [Wed, 17 Jun 2009 11:26:39 +0000 (11:26 +0000)]
Update from HEAD.
Dr. Stephen Henson [Tue, 16 Jun 2009 16:50:08 +0000 (16:50 +0000)]
PR: 1957
Submitted by: Mark Ashley <mark@ibiblio.org>
Reviewed by: steve@openssl.org
Quote FIPSLD_CC and CC in Makefiles.
Dr. Stephen Henson [Mon, 15 Jun 2009 14:52:38 +0000 (14:52 +0000)]
Don't check self-signed signature in X509_verify_cert(), the check just
wastes processing time and doesn't add any security.
Dr. Stephen Henson [Fri, 5 Jun 2009 15:05:10 +0000 (15:05 +0000)]
Update from 1.0.0-stable.
Dr. Stephen Henson [Fri, 5 Jun 2009 11:53:49 +0000 (11:53 +0000)]
Fix from 1.0.0-stable.
Dr. Stephen Henson [Tue, 2 Jun 2009 11:31:32 +0000 (11:31 +0000)]
PR: 1937
Submitted by: Mark Phalan <Mark.Phalan@Sun.COM>
Reviewed by: steve@openssl.org
Fix misuse of st_mode field in struct stat.
Dr. Stephen Henson [Tue, 2 Jun 2009 11:23:51 +0000 (11:23 +0000)]
Update from HEAD.
Dr. Stephen Henson [Tue, 2 Jun 2009 11:19:54 +0000 (11:19 +0000)]
PR: 1939
Submitted by: Sean Boudreau <seanb@qnx.com>
Reviewed by: steve@openssl.org
Better QNX6 support.
Dr. Stephen Henson [Tue, 2 Jun 2009 11:06:54 +0000 (11:06 +0000)]
Update from HEAD.
Mark J. Cox [Tue, 2 Jun 2009 09:20:52 +0000 (09:20 +0000)]
Update changelog to show fix for PR1679 as per Tomas Hoger's testing:
http://thread.gmane.org/gmane.comp.security.oss.general/1769/focus=1814
Dr. Stephen Henson [Mon, 1 Jun 2009 12:18:21 +0000 (12:18 +0000)]
PR: 1944
Submitted by: Guenter <lists@gknw.net>
Reviewed by: steve@openssl.org
Fix gcc warning on mingw.
Dr. Stephen Henson [Mon, 1 Jun 2009 12:14:53 +0000 (12:14 +0000)]
Update from HEAD.
Dr. Stephen Henson [Fri, 29 May 2009 14:01:35 +0000 (14:01 +0000)]
Use correct values for lookup method.
Dr. Stephen Henson [Fri, 29 May 2009 12:09:07 +0000 (12:09 +0000)]
Oops, forgot #endif...
Dr. Stephen Henson [Fri, 29 May 2009 12:00:22 +0000 (12:00 +0000)]
Update from 1.0.0-stable.
Dr. Stephen Henson [Thu, 28 May 2009 20:47:59 +0000 (20:47 +0000)]
Update ordinals.
Mark J. Cox [Tue, 26 May 2009 08:21:56 +0000 (08:21 +0000)]
Add the corresponding CVE names to the CHANGES entry for 0.9.8 branch
Dr. Stephen Henson [Mon, 18 May 2009 17:34:16 +0000 (17:34 +0000)]
Add CHANGES entries for security relate issues PR#1923, PR#1930 and PR#1931.
Dr. Stephen Henson [Mon, 18 May 2009 16:22:43 +0000 (16:22 +0000)]
0.9.8 version of PR#1931 fix.
Dr. Stephen Henson [Mon, 18 May 2009 16:12:56 +0000 (16:12 +0000)]
Fix from 1.0.0-stable branch.
Dr. Stephen Henson [Sun, 17 May 2009 16:48:19 +0000 (16:48 +0000)]
Formatting fix.
Dr. Stephen Henson [Sun, 17 May 2009 16:42:14 +0000 (16:42 +0000)]
Modified PR#1929 update from 1.0.0-stable.
Dr. Stephen Henson [Sun, 17 May 2009 16:28:13 +0000 (16:28 +0000)]
Reverted fix to PR#1931.. breaks compilation in 0.9.8.
Dr. Stephen Henson [Sun, 17 May 2009 14:48:57 +0000 (14:48 +0000)]
Update from 1.0.0-stable
Richard Levitte [Sun, 17 May 2009 07:22:18 +0000 (07:22 +0000)]
Stupid typo
Dr. Stephen Henson [Sat, 16 May 2009 16:23:35 +0000 (16:23 +0000)]
Fix from 1.0.0-stable.
Dr. Stephen Henson [Sat, 16 May 2009 16:18:45 +0000 (16:18 +0000)]
Update from 1.0.0-stable.
Dr. Stephen Henson [Sat, 16 May 2009 15:51:59 +0000 (15:51 +0000)]
Updates from 1.0.0-stable.
Dr. Stephen Henson [Fri, 15 May 2009 23:07:59 +0000 (23:07 +0000)]
Update from HEAD.
Richard Levitte [Fri, 15 May 2009 16:37:29 +0000 (16:37 +0000)]
Functional VMS changes submitted by sms@antinode.info (Steven M. Schweda).
Thank you\!
(note: not tested for now, a few nightly builds should give indications though)
Richard Levitte [Fri, 15 May 2009 16:15:03 +0000 (16:15 +0000)]
make update
Richard Levitte [Fri, 15 May 2009 16:05:43 +0000 (16:05 +0000)]
make update
Richard Levitte [Fri, 15 May 2009 16:01:45 +0000 (16:01 +0000)]
Have mkdef.pl also handle VAX and Non-VAX differences for VMS
Richard Levitte [Fri, 15 May 2009 16:00:11 +0000 (16:00 +0000)]
Add a comment about libeay.num and ssleay.num
Dr. Stephen Henson [Wed, 13 May 2009 11:52:29 +0000 (11:52 +0000)]
Update from 1.0.0-stable.
Andy Polyakov [Tue, 5 May 2009 19:18:26 +0000 (19:18 +0000)]
e_capi.c: update from HEAD.
Richard Levitte [Tue, 5 May 2009 08:48:02 +0000 (08:48 +0000)]
Update from HEAD
Dr. Stephen Henson [Tue, 28 Apr 2009 22:02:16 +0000 (22:02 +0000)]
Update from 1.0.0-stable.
Richard Levitte [Tue, 28 Apr 2009 13:11:05 +0000 (13:11 +0000)]
Update from HEAD
Dr. Stephen Henson [Sun, 26 Apr 2009 15:51:44 +0000 (15:51 +0000)]
Fix to escape backslashes in prefix
Dr. Stephen Henson [Wed, 22 Apr 2009 17:37:47 +0000 (17:37 +0000)]
Update from 1.0.0-stable.
Dr. Stephen Henson [Sun, 19 Apr 2009 18:08:12 +0000 (18:08 +0000)]
PR: 1751
Submitted by: David Woodhouse <dwmw2@infradead.org>
Approved by: steve@openssl.org
Compatibility patches for Cisco VPN client DTLS.
Dr. Stephen Henson [Sun, 19 Apr 2009 15:17:49 +0000 (15:17 +0000)]
Update .cvsignore
Dr. Stephen Henson [Sun, 19 Apr 2009 15:16:21 +0000 (15:16 +0000)]
Typo.
Dr. Stephen Henson [Sun, 19 Apr 2009 14:04:55 +0000 (14:04 +0000)]
PQGVer support.
Dr. Stephen Henson [Sun, 19 Apr 2009 13:44:43 +0000 (13:44 +0000)]
Minor format change to match expected PQGVer format.
Dr. Stephen Henson [Sat, 18 Apr 2009 22:41:46 +0000 (22:41 +0000)]
Add DES3 CFB1 mode tests.
Dr. Stephen Henson [Sat, 18 Apr 2009 22:41:17 +0000 (22:41 +0000)]
Fixes to make DES3 cfb1 work.
Dr. Stephen Henson [Thu, 16 Apr 2009 16:43:18 +0000 (16:43 +0000)]
Update from 1.0.0-stable.
Dr. Stephen Henson [Tue, 14 Apr 2009 15:20:48 +0000 (15:20 +0000)]
PR: 1829
Submitted by: Robin Seggelmann <seggelmann@fh-muenster.de>
Approved by: steve@openssl.org
DTLS timer bug fix from 1.0.0-stable with fixes.
Dr. Stephen Henson [Tue, 14 Apr 2009 14:28:33 +0000 (14:28 +0000)]
PR: 1647
Submitted by: Robin Seggelmann <seggelmann@fh-muenster.de>
Approved by: steve@openssl.org
DTLS Renogotiation bug fix.
Dr. Stephen Henson [Wed, 8 Apr 2009 15:58:26 +0000 (15:58 +0000)]
Fix from 1.0.0-stable.
Dr. Stephen Henson [Tue, 7 Apr 2009 16:28:30 +0000 (16:28 +0000)]
Submitted by: Darryl Miles <darryl-mailinglists@netbauds.net>
Approved by: steve@openssl.org
Handle non-blocking I/O properly in SSL_shutdown() call.
Dr. Stephen Henson [Tue, 7 Apr 2009 12:10:12 +0000 (12:10 +0000)]
PR: 1795
Submitted by: Peter Edwards <peter.edwards@vordel.com>
Approved by: steve@openssl.org
Avoid race condition by sorting cipher list straight away.
Dr. Stephen Henson [Fri, 3 Apr 2009 16:54:04 +0000 (16:54 +0000)]
PR: 1700
Submitted by: "Robbins, Aharon" <aharon.robbins@intel.com>
Approved by: steve@openssl.org
#undef X509_EXTENSIONS for WIN32 too.
Dr. Stephen Henson [Fri, 3 Apr 2009 16:28:20 +0000 (16:28 +0000)]
Update from 1.0.0-stable
Dr. Stephen Henson [Fri, 3 Apr 2009 11:36:49 +0000 (11:36 +0000)]
PR: 1616
Submitted by: Dequin_Eric@emc.com
Approved by: steve@openssl.org
Check tree->levels to ensure malloc worked.
Dr. Stephen Henson [Thu, 2 Apr 2009 22:34:59 +0000 (22:34 +0000)]
PR: 1827
Submitted by: Robin Seggelmann <seggelmann@fh-muenster.de>
Approved by: steve@openssl.org
Fix application data in handshake bug.
Dr. Stephen Henson [Thu, 2 Apr 2009 22:32:16 +0000 (22:32 +0000)]
PR: 1828
Submitted by: Robin Seggelmann <seggelmann@fh-muenster.de>
Approved by: steve@openssl.org
Fix DTLS retransmission bug.
Dr. Stephen Henson [Thu, 2 Apr 2009 22:28:35 +0000 (22:28 +0000)]
PR: 1826
Submitted by: Robin Seggelmann <seggelmann@fh-muenster.de>
Approved by: steve@openssl.org
Client random bug fix.
Dr. Stephen Henson [Thu, 2 Apr 2009 22:19:07 +0000 (22:19 +0000)]
Ooops, revert patch... due to non-portable gettimeofday call.
Dr. Stephen Henson [Thu, 2 Apr 2009 22:16:02 +0000 (22:16 +0000)]
PR: 1829
Submitted by: Robin Seggelmann <seggelmann@fh-muenster.de>
Approved by: steve@openssl.org
DTLS timer bug fix.
Dr. Stephen Henson [Thu, 2 Apr 2009 22:12:13 +0000 (22:12 +0000)]
PR: 1838
Submitted by: Robin Seggelmann <seggelmann@fh-muenster.de>
Approved by: steve@openssl.org
DTLS fragment bug.
Dr. Stephen Henson [Wed, 25 Mar 2009 22:22:42 +0000 (22:22 +0000)]
Typo.
Dr. Stephen Henson [Wed, 25 Mar 2009 19:01:03 +0000 (19:01 +0000)]
Submitted by: Ilya O. <vrghost@gmail.com>
Approved by: steve@openssl.org
Add 2.5.4.* OIDs.
Dr. Stephen Henson [Wed, 25 Mar 2009 13:02:49 +0000 (13:02 +0000)]
Prepare for next version.
Dr. Stephen Henson [Wed, 25 Mar 2009 12:08:14 +0000 (12:08 +0000)]
Aaargh.... wrong version number....
Dr. Stephen Henson [Wed, 25 Mar 2009 10:59:22 +0000 (10:59 +0000)]
Make update.
Dr. Stephen Henson [Wed, 25 Mar 2009 10:46:56 +0000 (10:46 +0000)]
Prepare for 0.9.8k release.
Dr. Stephen Henson [Wed, 25 Mar 2009 10:42:34 +0000 (10:42 +0000)]
PR: 1868
Submitted by: Paolo Ganci <Paolo.Ganci@AdNovum.CH>
Approved by: steve@openssl.org
Don't set fields to NULL when freeing them up in ASN1 code. On some platforms
with sizeof(long) < sizeof(char *) this can cause a crash.
Dr. Stephen Henson [Wed, 25 Mar 2009 10:40:32 +0000 (10:40 +0000)]
Submitted by: Ivan Nestlerode <inestlerode@us.ibm.com>
Approved by: steve@openssl.org
Check return code properly in CMS_SignerInfo_verify_content().
Dr. Stephen Henson [Wed, 25 Mar 2009 10:35:57 +0000 (10:35 +0000)]
Reject BMPStrings and UniversalStrings of invalid length. This prevents
a crash in ASN1_STRING_print_ex() which assumes they are valid.
Dr. Stephen Henson [Mon, 23 Mar 2009 21:11:50 +0000 (21:11 +0000)]
Update from HEAD.
Andy Polyakov [Mon, 16 Mar 2009 13:43:43 +0000 (13:43 +0000)]
des_enc.m4, SPARC DES assembler, update from HEAD: make it Purify-friendly.
As side effect it introduces duplicate of 2KB DES_SPtrans table.
Dr. Stephen Henson [Sun, 15 Mar 2009 14:03:29 +0000 (14:03 +0000)]
Oops.
Dr. Stephen Henson [Sun, 15 Mar 2009 13:36:01 +0000 (13:36 +0000)]
Don't force S/MIME signing purpose: allow it to be overridden by store
settings.
Don't set default values in X509_VERIFY_PARAM_new(): it stops parameters
being inherited properly.
Dr. Stephen Henson [Sat, 14 Mar 2009 18:33:25 +0000 (18:33 +0000)]
Permit nested ASN1 string encoding but with a maximum depth to avoid
stack overflow.
Dr. Stephen Henson [Sat, 14 Mar 2009 12:40:46 +0000 (12:40 +0000)]
Update from HEAD.
Dr. Stephen Henson [Sat, 14 Mar 2009 12:26:03 +0000 (12:26 +0000)]
PR: 1863
Submitted by: Ger Hobbelt <ger@hobbelt.com>
Reviewed by: steve@openssl.org
Check return value, use OPENSSL_assert and unsigned int.
Dr. Stephen Henson [Sat, 14 Mar 2009 12:07:42 +0000 (12:07 +0000)]
PR: 1846
Submitted by: Andrea Schoenberg <asg@ftpproxy.org>
Reviewed by: steve@openssl.org
Fix for HP Nonstop(Tandem) systems.
Dr. Stephen Henson [Thu, 12 Mar 2009 17:31:18 +0000 (17:31 +0000)]
Fix from HEAD.
Dr. Stephen Henson [Thu, 12 Mar 2009 17:13:44 +0000 (17:13 +0000)]
Update from head.