Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | Update release note pointers1.11.9 | lloyd | 2014-04-10 | 2 | -6/+8 |
| | |||||
* | Add 1.10.8 release notes | lloyd | 2014-04-10 | 1 | -0/+12 |
| | |||||
* | Fix a bug in Miller-Rabin primality testing introduced in 1.8.3 | lloyd | 2014-04-10 | 2 | -6/+14 |
| | | | | | | | | where we chose a single random nonce and tested it repeatedly, rather than choosing new nonces each time. Reported by Jeff Marrison. Also remove a pointless comparison (also pointed out by Jeff) and add an initial test using a witness of 2. | ||||
* | Better TLS checks | lloyd | 2014-04-10 | 3 | -29/+48 |
| | |||||
* | A std::deque's memory is not guaranteed to be contiguous | lloyd | 2014-04-06 | 1 | -1/+1 |
| | |||||
* | Make X.509 extension decoding failures point back to the problem extension | lloyd | 2014-04-05 | 2 | -10/+17 |
| | |||||
* | Add ECDHE_ECDSA CCM suites | lloyd | 2014-04-05 | 1 | -2/+14 |
| | |||||
* | X.509 path validation now performs all possible tests and returns a | lloyd | 2014-04-05 | 6 | -140/+165 |
| | | | | | | set of error codes, instead of failing immediately on first error. This prevents a 'weak' error like an expired certificate from hiding a major error such as signature validation failure or hard revocation. | ||||
* | Check Content-Length of HTTP responses | lloyd | 2014-04-05 | 1 | -1/+10 |
| | |||||
* | Fix an OCSP response decoding bug, we were not decoding KeyID properly. | lloyd | 2014-04-05 | 2 | -4/+9 |
| | | | | | | | | Also prioritize checking the status code before the dates, as otherwise an attacker could substitue a valid but expired response which marked the cert as revoked and we would still just return OCSP_EXPIRED. Obviously they can still play this game with an old (valid) OCSP response, but no point making it easy. | ||||
* | Remove debug headers | lloyd | 2014-04-05 | 1 | -3/+0 |
| | |||||
* | Darwin features | lloyd | 2014-04-05 | 1 | -0/+2 |
| | |||||
* | NetBSD portability fix and some performance tweaks in locking allocator | lloyd | 2014-04-05 | 2 | -2/+12 |
| | |||||
* | Avoid a ubsan warning on GCC 4.9 due uninitialized sign enum being | lloyd | 2014-03-30 | 2 | -5/+1 |
| | | | | read during swap (in the move constructor) | ||||
* | Support 0 length salts in PSSR. Bugzilla 268 | lloyd | 2014-03-27 | 2 | -3/+12 |
| | |||||
* | Add rng command which can dump RNG outputs or raw entropy samples | lloyd | 2014-03-22 | 4 | -2/+55 |
| | |||||
* | Simpify HMAC_RNG reseeding process. Actually update HMAC_DRBG reseed counter. | lloyd | 2014-03-22 | 6 | -63/+33 |
| | |||||
* | Add RFC 6979 nonce generator. Also some HMAC_DRBG cleanups. | lloyd | 2014-03-22 | 9 | -11/+175 |
| | |||||
* | Add --program-suffix option to configure | lloyd | 2014-03-22 | 4 | -17/+18 |
| | |||||
* | Add HMAC_DRBG | lloyd | 2014-03-21 | 9 | -22/+2650 |
| | |||||
* | Let Clang choose whichever C++ library it prefers | lloyd | 2014-03-13 | 1 | -4/+3 |
| | |||||
* | Fix release script | lloyd | 2014-02-22 | 1 | -0/+1 |
| | |||||
* | Use stdint.h instead of cstdint for Clang. Bugzilla 266 | lloyd | 2014-02-21 | 2 | -7/+12 |
| | |||||
* | Fix Transformation_Filter name | lloyd | 2014-02-21 | 1 | -2/+1 |
| | |||||
* | Website tweaks | lloyd | 2014-02-19 | 4 | -22/+28 |
| | |||||
* | Transformation_Filter calls send() inside of start_msg() which means | lloyd | 2014-02-17 | 2 | -0/+7 |
| | | | | | | | | | | that any filters which follow in the pipe will get write() called on them before start_msg(), causing confusion and/or crashes. This patch fixes it for the case when start() returns an empty vector which covers all current use cases. I'll have to figure out another approach for the general case (or decide the general case isn't worth supporting and remove the return value from start). | ||||
* | Missing include for std::to_string, noticed with Clang 3.4 w/ libc++ | lloyd | 2014-02-16 | 1 | -0/+2 |
| | |||||
* | Don't assume the leading cert chain is presented in-order | lloyd | 2014-02-16 | 2 | -5/+20 |
| | |||||
* | Add missing std includes | lloyd | 2014-02-16 | 2 | -0/+2 |
| | |||||
* | Fix macro feature check | lloyd | 2014-02-15 | 1 | -1/+1 |
| | |||||
* | Tick version to 1.11.9 | lloyd | 2014-02-15 | 2 | -1/+3 |
| | |||||
* | Website tweaks | lloyd | 2014-02-15 | 2 | -28/+28 |
| | |||||
* | Sort files in the dist archive by name instead of random (inode) order | lloyd | 2014-02-15 | 1 | -1/+7 |
| | |||||
* | Release 1.11.81.11.8 | lloyd | 2014-02-14 | 3 | -8/+24 |
| | |||||
* | Add --destdir option to configure.py | lloyd | 2014-02-13 | 3 | -3/+7 |
| | |||||
* | Ignore editor temp files when looking for sources | lloyd | 2014-02-13 | 1 | -2/+1 |
| | |||||
* | Add config and version subcommands | lloyd | 2014-02-13 | 2 | -35/+83 |
| | |||||
* | Change X9.31 to automatically reseed if randomize is called while unseeded. | lloyd | 2014-02-13 | 2 | -10/+15 |
| | | | | | If no entropy sources at all are enabled in the build, throw an exception immediately rather than having the poll mysteriously fail. | ||||
* | Fix warnings | lloyd | 2014-02-13 | 3 | -5/+6 |
| | |||||
* | Cleanups | lloyd | 2014-02-13 | 5 | -41/+43 |
| | |||||
* | Also avoid tuning for 686 | lloyd | 2014-02-13 | 1 | -1/+2 |
| | |||||
* | Set expectations | lloyd | 2014-02-13 | 1 | -1/+1 |
| | |||||
* | Remove unused include | lloyd | 2014-02-13 | 1 | -1/+0 |
| | |||||
* | Remove dependency on boost string algos | lloyd | 2014-02-13 | 3 | -13/+30 |
| | |||||
* | Remove global variables | lloyd | 2014-02-13 | 1 | -71/+64 |
| | |||||
* | Check the feature macro before assuming boost.filesystem | lloyd | 2014-02-10 | 1 | -0/+7 |
| | |||||
* | Update Clang flags. Remove unneeded includes of init.h | lloyd | 2014-02-09 | 3 | -5/+4 |
| | |||||
* | Compile fixes | lloyd | 2014-02-09 | 1 | -5/+3 |
| | |||||
* | Cleaner abi flag gen | lloyd | 2014-02-09 | 1 | -3/+5 |
| | |||||
* | Fix compiler ABI flags | lloyd | 2014-02-09 | 1 | -1/+1 |
| |