Lutz Jänicke [Fri, 12 Jul 2002 15:27:01 +0000 (15:27 +0000)]
Rewording: some algorithms are also patented in Europe, so choose more
defensive phrases...
Submitted by:
Reviewed by:
PR:
Richard Levitte [Thu, 11 Jul 2002 09:12:37 +0000 (09:12 +0000)]
In UI_UTIL_read_pw(), we should look at the size parameter, not at BUFSIZ.
Submitted by Götz Babin-Ebell <babinebell@trustcenter.de>
Lutz Jänicke [Wed, 10 Jul 2002 19:47:55 +0000 (19:47 +0000)]
Discussion about Redhat's specialties for the FAQ.
Submitted by: John.Airey@rnib.org.uk
Reviewed by:
PR: 128
Lutz Jänicke [Wed, 10 Jul 2002 19:34:47 +0000 (19:34 +0000)]
Typos in links between manual pages
Submitted by: Richard.Koenning@fujitsu-siemens.com
Reviewed by:
PR: 129
Lutz Jänicke [Wed, 10 Jul 2002 17:51:14 +0000 (17:51 +0000)]
Sun's official statement with respect to /dev/random support.
Submitted by: Garrett Anderson garrett@dirsec.com
Reviewed by:
PR: 120
Lutz Jänicke [Wed, 10 Jul 2002 17:33:55 +0000 (17:33 +0000)]
Minor typos
Submitted by: jufi@nerdnet.de
Reviewed by:
PR: 138
Bodo Möller [Wed, 10 Jul 2002 08:38:34 +0000 (08:38 +0000)]
remove obsolete comment
Lutz Jänicke [Wed, 10 Jul 2002 06:57:54 +0000 (06:57 +0000)]
Reorder inclusion of header files:
des_old.h redefines crypt:
#define crypt(b,s)\
DES_crypt((b),(s))
This scheme leads to failure, if header files with the OS's true definition
of crypt() are processed _after_ des_old.h was processed. This is e.g. the
case on HP-UX with unistd.h.
As evp.h now again includes des.h (which includes des_old.h), this problem
only came up after this modification.
Solution: move header files (indirectly) including e_os.h before the header
files (indirectly) including evp.h.
Submitted by:
Reviewed by:
PR:
Lutz Jänicke [Wed, 10 Jul 2002 06:40:18 +0000 (06:40 +0000)]
Ciphers with NULL encryption were not properly handled because they were
not covered by the strength bit mask.
Submitted by:
Reviewed by:
PR: 130
Bodo Möller [Tue, 9 Jul 2002 10:52:30 +0000 (10:52 +0000)]
fix synopsis
Submitted by: Nils Larsch
Bodo Möller [Tue, 9 Jul 2002 08:48:49 +0000 (08:48 +0000)]
emtpy fragments are not necessary for SSL_eNULL
(but noone uses it anyway)
fix t1_enc.c: use OPENSSL_NO_RC4, not NO_RC4
Geoff Thorpe [Mon, 8 Jul 2002 15:06:39 +0000 (15:06 +0000)]
oops, there were other cases of "ENGINE_ID" to change too.
Geoff Thorpe [Mon, 8 Jul 2002 14:48:44 +0000 (14:48 +0000)]
Correct an error in the README.ENGINE file.
Submitted by: Jan Tschirschwitz <Jan.Tschirschwitz@cluster-labs.de>
Bodo Möller [Thu, 4 Jul 2002 08:50:33 +0000 (08:50 +0000)]
AES cipher suites are now official (RFC3268)
Lutz Jänicke [Sun, 30 Jun 2002 19:38:01 +0000 (19:38 +0000)]
README and INSTALL should contain information about the request tracker
(noted by Jonathan Louie <jlouie@recourse.com>).
Submitted by:
Reviewed by:
PR:
Richard Levitte [Sat, 29 Jun 2002 22:04:16 +0000 (22:04 +0000)]
Do not define crypt() on OpenBSD. Notified by Bob Beck of OpenBSD.
Richard Levitte [Thu, 27 Jun 2002 17:20:16 +0000 (17:20 +0000)]
opensslconf.h doesn't define what we want, e_os2.h does.
PR 123
Richard Levitte [Thu, 27 Jun 2002 17:06:41 +0000 (17:06 +0000)]
Try to avoid double declaration of ERR_load_PEM_strings().
PR 71
Richard Levitte [Thu, 27 Jun 2002 16:56:36 +0000 (16:56 +0000)]
A few changes to BC-32.pl didn't get properly applied.
This completes PR 123
Richard Levitte [Thu, 27 Jun 2002 16:44:52 +0000 (16:44 +0000)]
Pass CFLAG to dependency makers, so non-standard system include paths are
handled properly.
Part of PR 75
Richard Levitte [Thu, 27 Jun 2002 16:32:15 +0000 (16:32 +0000)]
DJGPP has some needed header files that other MSDOS/Windows compilers don't have.
Part of PR 75
Richard Levitte [Thu, 27 Jun 2002 16:30:18 +0000 (16:30 +0000)]
Update the information on Cygwin.
Part of PR 75
Richard Levitte [Thu, 27 Jun 2002 16:28:28 +0000 (16:28 +0000)]
Forgot to change the second $ENV{DJDIR} to /dev/env/DJDIR.
Part of PR 75
Richard Levitte [Thu, 27 Jun 2002 15:11:08 +0000 (15:11 +0000)]
The new stuff is for Borland Bulider 5, so document it appropriately
Richard Levitte [Thu, 27 Jun 2002 15:07:43 +0000 (15:07 +0000)]
Document the new way of building with Borland Builder.
This concludes the changes from PR 123
Richard Levitte [Thu, 27 Jun 2002 14:58:06 +0000 (14:58 +0000)]
Use underscores instead of dashes in temporary file names.
This is due to weird Borland compilers.
Part of PR 123
Richard Levitte [Thu, 27 Jun 2002 14:56:02 +0000 (14:56 +0000)]
When compiling for Windows, make sure we have the windows definitions declared.
Part of PR 123
Richard Levitte [Thu, 27 Jun 2002 14:54:39 +0000 (14:54 +0000)]
Use 32-bit sections instead of the default, 16-bit ones.
Part of PR 123
Richard Levitte [Thu, 27 Jun 2002 10:26:52 +0000 (10:26 +0000)]
have 'openssl pkcs7' exit with code 1 on error instead of 0.
PR: 119
Richard Levitte [Thu, 27 Jun 2002 10:19:54 +0000 (10:19 +0000)]
gcc requires -m64 to link 64-bit shared libraries on Solaris.
PR: 117
Richard Levitte [Thu, 27 Jun 2002 09:54:14 +0000 (09:54 +0000)]
Use bg instead of bag as argument to macros, to avoid clashes with
structure field names.
PR: 112
Richard Levitte [Thu, 27 Jun 2002 09:18:30 +0000 (09:18 +0000)]
There is no RSAREF any more, so do not ty to install it.
PR: 106
Richard Levitte [Thu, 27 Jun 2002 09:13:11 +0000 (09:13 +0000)]
The general debug target must specify that it doesn't use assembler routines.
PR: 105
Richard Levitte [Thu, 27 Jun 2002 05:03:12 +0000 (05:03 +0000)]
A number of includes were removed from evp.h some time ago. The reason
was that they weren't really needed any more for EVP itself. However,
it seems like soma applications (I know about OpenSSH, but there may
be more) used evp.h as the 'load all' header file, which makes sense
since we try our best to promote the use of EVP instead of the lower
level crypto algorithms. Therefore, I put the inclusions back so
the application authors don't get too shocked by all the errors they
would otherwise get.
Thanks to Theo de Raadt for making us aware of this.
Bodo Möller [Wed, 26 Jun 2002 14:29:10 +0000 (14:29 +0000)]
Make sure buffers are large enough even for weird parameters
Submitted by: Nils Larsch
Bodo Möller [Wed, 26 Jun 2002 14:22:39 +0000 (14:22 +0000)]
update an entry on EVP changes
Richard Levitte [Tue, 25 Jun 2002 11:41:25 +0000 (11:41 +0000)]
For some reason, we need to return the full path to perl
Geoff Thorpe [Fri, 21 Jun 2002 02:48:57 +0000 (02:48 +0000)]
Make sure any ENGINE control commands make local copies of string
pointers passed to them whenever necessary. Otherwise it is possible the
caller may have overwritten (or deallocated) the original string data
when a later ENGINE operation tries to use the stored values.
Submitted by: Götz Babin-Ebell <babinebell@trustcenter.de>
Reviewed by: Geoff Thorpe
PR: 98
Lutz Jänicke [Thu, 20 Jun 2002 20:13:12 +0000 (20:13 +0000)]
<sys/select.h> is included for AIX, when USE_SOCKETS is defined.
Submitted by: Bernhard Simon <bs@bsws.zid.tuwien.ac.at>
Reviewed by:
PR:
Lutz Jänicke [Thu, 20 Jun 2002 19:55:58 +0000 (19:55 +0000)]
HP-UX: shared libraries MUST be +x and SHOULD be -w.
Submitted by:
Reviewed by:
PR:
Lutz Jänicke [Thu, 20 Jun 2002 19:47:59 +0000 (19:47 +0000)]
Fix path to find util/pod2man.pl from the execution directory.
Make sure to use the predefined PERL.
Submitted by: Bernhard Simon <bs@bsws.zid.tuwien.ac.at>
Reviewed by:
PR:
Lutz Jänicke [Thu, 20 Jun 2002 17:31:12 +0000 (17:31 +0000)]
AIX (V3) requires <sys/select.h> (included via e_os.h) for fd_set.
Submitted by: Bernhard Simon <bs@bsws.zid.tuwien.ac.at>
Reviewed by:
PR:
Geoff Thorpe [Thu, 20 Jun 2002 15:17:02 +0000 (15:17 +0000)]
This apparently fixes compilation on OSX that was failing in 0.9.7 betas.
Submitted by: Pieter Bowman <bowman@math.utah.edu>
Lutz Jänicke [Tue, 18 Jun 2002 17:44:01 +0000 (17:44 +0000)]
load_netscape_key is static.
Submitted by:
Reviewed by:
PR:
Bodo Möller [Tue, 18 Jun 2002 09:35:29 +0000 (09:35 +0000)]
always include <string.h> (we do this in various other header files,
so it can't be bad)
PR: 102
Bodo Möller [Mon, 17 Jun 2002 13:59:36 +0000 (13:59 +0000)]
typo
Lutz Jänicke [Sun, 16 Jun 2002 11:27:44 +0000 (11:27 +0000)]
Roll OpenSSL-0.9.7-beta2
Submitted by:
Reviewed by:
PR:
Lutz Jänicke [Sun, 16 Jun 2002 10:29:55 +0000 (10:29 +0000)]
Use -dumpversion to obtain gcc's version.
Submitted by: ross.alexander@uk.neceur.com, allenh@eecs.berkeley.edu
Reviewed by:
PR: 96
Lutz Jänicke [Sun, 16 Jun 2002 10:16:42 +0000 (10:16 +0000)]
OpenSSL_add_all_algorithms has been replaced by configuration dependent
functions and is redirected by macros. Switch it off now, possible removal
later.
Submitted by:
Reviewed by:
PR:
Dr. Stephen Henson [Sat, 15 Jun 2002 12:29:28 +0000 (12:29 +0000)]
Make update
Lutz Jänicke [Fri, 14 Jun 2002 20:10:24 +0000 (20:10 +0000)]
Initial support for hpux64-parisc-gcc
Submitted by: ross.alexander@uk.neceur.com
Reviewed by:
PR: 96
Lutz Jänicke [Fri, 14 Jun 2002 18:59:53 +0000 (18:59 +0000)]
Some more prototype fixes.
Use DECLARE macros in asn1* instead of direct declaration.
Submitted by: Goetz Babin-Ebell <babinebell@trustcenter.de>
Reviewed by:
PR: 89
Bodo Möller [Fri, 14 Jun 2002 12:20:27 +0000 (12:20 +0000)]
New option SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS for disabling CBC
vulnerability workaround (included in SSL_OP_ALL).
PR: #90
Richard Levitte [Thu, 13 Jun 2002 23:38:11 +0000 (23:38 +0000)]
make update
Richard Levitte [Thu, 13 Jun 2002 23:37:26 +0000 (23:37 +0000)]
Merge from HEAD.
Richard Levitte [Thu, 13 Jun 2002 21:44:01 +0000 (21:44 +0000)]
Tentatively add support for UWIN, a Unix-like environment on top of Windows.
PR: 62
Richard Levitte [Thu, 13 Jun 2002 21:11:57 +0000 (21:11 +0000)]
Make sure that any dash in the prefix before the version number is removed.
PR: 96
Richard Levitte [Thu, 13 Jun 2002 20:44:38 +0000 (20:44 +0000)]
Add support for DJGPP.
Richard Levitte [Thu, 13 Jun 2002 20:40:49 +0000 (20:40 +0000)]
Add support for DJGPP.
PR: 75
Richard Levitte [Thu, 13 Jun 2002 19:59:26 +0000 (19:59 +0000)]
Check for the executable $openssl, not just the file.
Part of PR: 75
Richard Levitte [Thu, 13 Jun 2002 19:50:26 +0000 (19:50 +0000)]
Parse directory using both slashes and backslashes as separators.
Do file copying in term of perl statements instead of using cp.
Part of PR: 75
Richard Levitte [Thu, 13 Jun 2002 19:42:06 +0000 (19:42 +0000)]
Making a softlink from crypto/des/asm/perlasm to crypto/perlasm isn't
strictly necessary, so let's not do that.
Lutz Jänicke [Thu, 13 Jun 2002 17:38:58 +0000 (17:38 +0000)]
Add missing prototypes.
Submitted by: Goetz Babin-Ebell <babinebell@trustcenter.de>
Reviewed by:
PR: 89
Dr. Stephen Henson [Thu, 13 Jun 2002 12:54:52 +0000 (12:54 +0000)]
Fix ext_dat.h extension ordering.
Reinstate -reqout code.
Avoid coredump in ocsp if setup_verify
fails.
Fix typo in ocsp usage message.
Lutz Jänicke [Thu, 13 Jun 2002 11:51:31 +0000 (11:51 +0000)]
Add OIDs for Secure Electronic Transactions (SET)
Submitted by: Vadim Fedukovich <vf@unity.net>
Reviewed by: Lutz Jaenicke
PR: 80
Lutz Jänicke [Thu, 13 Jun 2002 08:52:25 +0000 (08:52 +0000)]
Clarify formulation (proposed by Bodo Moeller).
Submitted by:
Reviewed by:
PR:
Dr. Stephen Henson [Thu, 13 Jun 2002 00:43:59 +0000 (00:43 +0000)]
The new ASN1 code automatically allocates
structures for fields that are not OPTIONAL.
However in the AUTHORITY_INFO_ACCESS case
the 'location' field was set to NULL in
the old code.
So in 0.9.7+ we should free up the field before
overwriting it in v2i_AUTHORITY_INFO_ACCESS.
Lutz Jänicke [Wed, 12 Jun 2002 20:42:04 +0000 (20:42 +0000)]
Make change uniqueIdentifier -> x500UniqueIdentifier clearly visible.
Submitted by:
Reviewed by:
PR: 82
Lutz Jänicke [Wed, 12 Jun 2002 20:14:04 +0000 (20:14 +0000)]
Correct wrong usage information.
Submitted by:
Reviewed by:
PR: 95
Lutz Jänicke [Wed, 12 Jun 2002 12:25:42 +0000 (12:25 +0000)]
Support building the distribution .tar file on platforms with limited
argument list length. This requires Gnu-tar. As we use the non-standard
"tardy" software anyway, it doesn't hurt too much to require Gnu-tar.
"make dist" will probably only be used by team-members anyway.
Submitted by:
Reviewed by:
PR:
Ben Laurie [Tue, 11 Jun 2002 11:41:26 +0000 (11:41 +0000)]
Handle read failures better.
Bodo Möller [Mon, 10 Jun 2002 11:45:21 +0000 (11:45 +0000)]
fix for 'make update'
Lutz Jänicke [Mon, 10 Jun 2002 08:11:20 +0000 (08:11 +0000)]
Make sure that flags are passed to "make" subprocesses.
Submitted by:
Reviewed by:
PR:
Lutz Jänicke [Thu, 6 Jun 2002 10:19:33 +0000 (10:19 +0000)]
For the main directory, Makefile.org is significant :-)
Submitted by:
Reviewed by:
PR:
Lutz Jänicke [Thu, 6 Jun 2002 10:14:16 +0000 (10:14 +0000)]
Make sure that settings are passed back and forth when walking around
in the tree during build.
Reinstall default PERL settings in Makefiles, as the real reason for the
failure was that the settings were not passed.
Submitted by:
Reviewed by:
PR:
Lutz Jänicke [Thu, 6 Jun 2002 07:30:45 +0000 (07:30 +0000)]
New OID for X509 usage: pseudonym
Submitted by: Michael Bell <michael.bell@rz.hu-berlin.de>
Reviewed by: Lutz Jaenicke
PR: 83
Richard Levitte [Wed, 5 Jun 2002 14:10:31 +0000 (14:10 +0000)]
Make perl replacement for dirname, for system that lack the latter.
PR: 81
Richard Levitte [Wed, 5 Jun 2002 13:47:15 +0000 (13:47 +0000)]
It's not good to have a pointer point at something in an inner block.
PR: 66
Richard Levitte [Wed, 5 Jun 2002 11:58:23 +0000 (11:58 +0000)]
Check errors when parsing a PKCS8INF PEM FILE, or there will be a core dump on error.
PR: 77
Richard Levitte [Wed, 5 Jun 2002 09:30:20 +0000 (09:30 +0000)]
Documentation bug corrected.
PR: 70
Richard Levitte [Wed, 5 Jun 2002 09:08:49 +0000 (09:08 +0000)]
Since there's no continuation, the ; can go as well :-)
Lutz Jänicke [Wed, 5 Jun 2002 07:56:14 +0000 (07:56 +0000)]
There is no continuation at this point.
Submitted by:
Reviewed by:
PR:
Lutz Jänicke [Wed, 5 Jun 2002 07:27:21 +0000 (07:27 +0000)]
On some systems the default "perl" may still be perl4, use the correct
version determined by "config" instead.
Submitted by:
Reviewed by:
PR:
Lutz Jänicke [Wed, 5 Jun 2002 07:01:39 +0000 (07:01 +0000)]
The correct PERL interpreter is passed via commandline.
Submitted by:
Reviewed by:
PR:
Richard Levitte [Wed, 5 Jun 2002 06:45:27 +0000 (06:45 +0000)]
Correct syntax in ssl-lib.com
maketests.com was missing the TCP/IP options TCPIP and NONE
Richard Levitte [Wed, 5 Jun 2002 05:00:41 +0000 (05:00 +0000)]
Update the recognision of GCC version numbers to handle the prefix text
that GCC 3.1 adds to the --version output
Richard Levitte [Tue, 4 Jun 2002 22:32:17 +0000 (22:32 +0000)]
make update (including adjusting libeay.num in HEAD to the changes in the
0.9.7-stable libeay.num
Lutz Jänicke [Tue, 4 Jun 2002 20:44:10 +0000 (20:44 +0000)]
Typo.
Submitted by:
Reviewed by:
PR: 72
Richard Levitte [Mon, 3 Jun 2002 15:27:52 +0000 (15:27 +0000)]
use sstrsep() to get the proper type to aoti().
Remove unneeded cast in ustrsep().
PR: 69
Lutz Jänicke [Sat, 1 Jun 2002 15:21:55 +0000 (15:21 +0000)]
Ok, we are rolling 0.9.7-beta1 now.
Submitted by:
Reviewed by:
PR:
Ben Laurie [Fri, 31 May 2002 14:34:15 +0000 (14:34 +0000)]
Fix a warning.
Ben Laurie [Fri, 31 May 2002 14:28:30 +0000 (14:28 +0000)]
Fix warnings.
Richard Levitte [Fri, 31 May 2002 13:16:37 +0000 (13:16 +0000)]
Document the AES changes.
Richard Levitte [Fri, 31 May 2002 13:13:51 +0000 (13:13 +0000)]
Add the AES test vectors from NIST document SP800-38A.
Richard Levitte [Fri, 31 May 2002 13:12:54 +0000 (13:12 +0000)]
Make it possible to give vectors only for decryption or encryption.
Richard Levitte [Fri, 31 May 2002 13:11:48 +0000 (13:11 +0000)]
For CFB and OFB modes, always create the encryption key.
Richard Levitte [Fri, 31 May 2002 13:10:24 +0000 (13:10 +0000)]
Declare the CFB and OFB modes for AES, and prepare for a declaration
of CTR mode.
Richard Levitte [Fri, 31 May 2002 13:07:45 +0000 (13:07 +0000)]
In CFB mode, the iv is always encrypted.
Richard Levitte [Thu, 30 May 2002 18:06:52 +0000 (18:06 +0000)]
Reformat the CFLAG string so it can be made part of a C string.
Incidently, this works pretty well on the command line as well.
PR: 52
Richard Levitte [Thu, 30 May 2002 17:28:23 +0000 (17:28 +0000)]
Support the newly release gcc 3.1 on 64-bit Solaris. Not automatic.
PR: 57