Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | Add key length multiple | lloyd | 2013-12-05 | 2 | -5/+8 |
| | |||||
* | Turn off asking for client cert in TLS server example | lloyd | 2013-12-05 | 1 | -2/+10 |
| | |||||
* | Add SIV | lloyd | 2013-12-05 | 11 | -54/+452 |
| | |||||
* | Support the normal names for CCM in TLS policy config | lloyd | 2013-12-04 | 5 | -34/+33 |
| | |||||
* | Better check | lloyd | 2013-12-02 | 1 | -1/+1 |
| | |||||
* | Add a check on API revisions | lloyd | 2013-12-02 | 1 | -1/+4 |
| | |||||
* | Python 3 fix | lloyd | 2013-12-01 | 1 | -1/+1 |
| | |||||
* | First pass at automatic OCSP checks | lloyd | 2013-11-29 | 8 | -60/+112 |
| | |||||
* | Remove timeout from HTTP | lloyd | 2013-11-29 | 2 | -23/+16 |
| | |||||
* | Disable RC4 in TLS by default | lloyd | 2013-11-29 | 3 | -3/+5 |
| | |||||
* | Move OCSP to x509 subdir as they are quite entangled | lloyd | 2013-11-29 | 6 | -8/+1 |
| | |||||
* | Split chain creation and checking | lloyd | 2013-11-29 | 2 | -87/+104 |
| | |||||
* | Have OCSP responses return an enum allowing a range of conditions to be ↵ | lloyd | 2013-11-29 | 11 | -315/+368 |
| | | | | | | | | | | expressed (good status, cert revoked, some other error, etc). Add a certificate store backed by files (requiring boost filesystem). Change Certificate_Store interface somewhat to support retrieval without copying. | ||||
* | Remove trailing null byte from X509_Time::to_string | lloyd | 2013-11-29 | 1 | -8/+16 |
| | | | | Make invalid tag case report the value | ||||
* | Add OCSP example. Fix minor compile issues. | lloyd | 2013-11-28 | 5 | -4/+28 |
| | |||||
* | Add OCSP::online_check which queries the certs responder | lloyd | 2013-11-28 | 3 | -3/+42 |
| | |||||
* | Fix URL parsing | lloyd | 2013-11-28 | 1 | -7/+15 |
| | |||||
* | Don't reject a signature using an untrusted hash if it is the self | lloyd | 2013-11-28 | 1 | -1/+1 |
| | | | | signature of a root cert | ||||
* | Print OCSP and CRL locations in X509_Certificate::to_string | lloyd | 2013-11-28 | 1 | -0/+5 |
| | |||||
* | Support HTTP POST (many OCSP responders don't like GET-based requests) | lloyd | 2013-11-28 | 6 | -132/+243 |
| | |||||
* | Test fix | lloyd | 2013-11-28 | 1 | -4/+5 |
| | |||||
* | Give everything setting a feature test macro in build.h a version code | lloyd | 2013-11-28 | 184 | -189/+195 |
| | | | | | | so application code can check for the specific API it expects without having to keep track of what versions APIs x,y,z changed. Arbitrarily set all current API versions to 20131128. | ||||
* | wget it ourselves, and include the hash of the file in the output | lloyd | 2013-11-28 | 2 | -24/+57 |
| | |||||
* | Fix file rename in info.txt and add a check for this in configure | lloyd | 2013-11-28 | 2 | -1/+5 |
| | |||||
* | TLS in-memory session manager now requires a rng object as a | lloyd | 2013-11-28 | 4 | -16/+31 |
| | | | | | constructor argument, previously it used the global rng which caused a serialization point across server threads. | ||||
* | Add a simple HTTP 1.0 GET using asio (for CRLs and OCSP) | lloyd | 2013-11-27 | 6 | -2/+139 |
| | |||||
* | Include Perl's build flags. Bug 254 | lloyd | 2013-11-23 | 1 | -1/+1 |
| | |||||
* | merge of '68c716734951de7d2d263d5ed5162e963d6c32be' | lloyd | 2013-11-20 | 6 | -55/+19 |
|\ | | | | | | | and '714a603d145c840eec1464ea31d0d07c2bf640fa' | ||||
| * | merge of '022cd3c92c37dee696d0c3c0c197f8df8981ccbb' | lloyd | 2013-11-20 | 1 | -0/+5 |
| |\ | | | | | | | | | | and '83151ac7a83013a2874f78978df5c4739b879775' | ||||
| | * | Direct people interested in TLS to 1.11 | lloyd | 2013-11-20 | 1 | -0/+5 |
| | | | |||||
| * | | Compile fixes for Python wrapper | lloyd | 2013-11-20 | 5 | -55/+14 |
| | | | |||||
* | | | Only service small allocations out of the mlock pool | lloyd | 2013-11-20 | 2 | -2/+5 |
| | | | |||||
* | | | Add a basic DTLS policy | lloyd | 2013-11-20 | 1 | -0/+13 |
| | | | |||||
* | | | Fix old style cast warnings | lloyd | 2013-11-20 | 1 | -30/+30 |
|/ / | |||||
* | | Generalize file reading test runner, use it for KDF and PBKDF | lloyd | 2013-11-18 | 10 | -726/+1196 |
| | | |||||
* | | Generalize the HKDF file reading | lloyd | 2013-11-17 | 1 | -12/+30 |
| | | |||||
* | | Add HKDF | lloyd | 2013-11-17 | 8 | -0/+257 |
| | | |||||
* | | Fix get_cipher_mode for OCB and GCM with short tags | lloyd | 2013-11-17 | 1 | -2/+2 |
| | | |||||
* | | Inline kdf.cpp as all are simple forwarding calls | lloyd | 2013-11-17 | 2 | -62/+24 |
| | | |||||
* | | Enable all the GCC warning flags, as we now require at least GCC 4.7 anyway | lloyd | 2013-11-16 | 8 | -9/+12 |
| | | | | | | | | Fix a few nullptr and cast warnings. | ||||
* | | Enable maintainer mode checks in all builds of non-release versions. | lloyd | 2013-11-16 | 1 | -1/+10 |
| | | | | | | | | Use new --release-mode option to disable. | ||||
* | | Add includes needed by OS X | lloyd | 2013-11-12 | 1 | -0/+2 |
| | | |||||
* | | Forgot to relnote this | lloyd | 2013-11-10 | 1 | -0/+4 |
|/ | |||||
* | Remove download link to 1.8 | lloyd | 2013-11-10 | 1 | -8/+0 |
| | |||||
* | Release 1.11.51.11.5 | lloyd | 2013-11-10 | 2 | -7/+7 |
| | |||||
* | Split off Unix_EntropySource's fast_poll to a new source | lloyd | 2013-11-10 | 3 | -25/+14 |
| | |||||
* | Add 1.10.6 release notes | lloyd | 2013-11-10 | 2 | -0/+49 |
| | |||||
* | Avoid warning | lloyd | 2013-11-09 | 1 | -1/+1 |
| | |||||
* | Return a value | lloyd | 2013-11-09 | 1 | -1/+1 |
| | |||||
* | Add to build.h template | lloyd | 2013-11-09 | 1 | -0/+7 |
| |