Commit Graph

  • a6b4a42ada apps: Escape control characters in DNs by default Tomas Mraz 2025-02-28 11:13:27 +01:00
  • 2411f9b662 apps: Escape control characters in DNs by default Tomas Mraz 2025-02-28 11:13:27 +01:00
  • 624a00ef41 Sync CHANGES.md with 3.4 branch and fix formatting Tomas Mraz 2025-02-28 11:09:55 +01:00
  • 4f2f5179a1 Remove empty buffer check in script_84 of quic_multistream_test Neil Horman 2025-02-28 13:58:48 -05:00
  • aaad33c5ac Move ssl_err.c into libcrypto Matt Caswell 2025-02-28 08:51:43 +00:00
  • 31b5f3f382 Further decoder tuning possibly better perf Viktor Dukhovni 2025-02-28 04:17:08 +11:00
  • 89dbc6a62c Fix no-tls-deprecated-ec documentation to match the actual option. Geert Hendrickx 2025-02-28 14:50:32 +01:00
  • d4430ef9fc Delete include/openssl/asn1_mac.h Ian Spence 2025-02-25 10:18:33 -08:00
  • 465f4d6872 doc: fix OSSL_WINCTX spelling windows notes Hugo Beauzée-Luyssen 2025-01-27 09:24:23 +01:00
  • c2ab75e30a doc: fix OSSL_WINCTX spelling windows notes Hugo Beauzée-Luyssen 2025-01-27 09:24:23 +01:00
  • fe3690760f Encoder : Fix floating pointer when OSSL_ENCODER_to_data() is called twice. slontis 2025-02-25 17:03:38 +11:00
  • 76d1ffb6f1 Encoder : Fix floating pointer when OSSL_ENCODER_to_data() is called twice. slontis 2025-02-25 17:03:38 +11:00
  • 9537245a5b Encoder : Fix floating pointer when OSSL_ENCODER_to_data() is called twice. slontis 2025-02-25 17:03:38 +11:00
  • 096a0f1ae1 Encoder : Fix floating pointer when OSSL_ENCODER_to_data() is called twice. slontis 2025-02-25 17:03:38 +11:00
  • 304922034a Encoder : Fix floating pointer when OSSL_ENCODER_to_data() is called twice. slontis 2025-02-25 17:03:38 +11:00
  • f86acc9434 EVP_DecodeUpdate() should not produce padding zeros to the decoded output (Fixes #26677) Valerii Krygin 2025-02-25 15:57:26 +00:00
  • 6ef393b89b Check full ML-KEM encoded key Viktor Dukhovni 2025-02-26 13:04:12 +11:00
  • 253a380bdb doc/, CHANGES, NEWS: add missing entries and fix existing ones when which CMP feature was added Dr. David von Oheimb 2025-02-26 09:17:25 +01:00
  • ecc174065a Update slh_dsa_test.c Andrew Dinh 2025-02-26 21:39:20 +07:00
  • 237b761ab4 Update slh_dsa_test.c Andrew Dinh 2025-02-26 21:35:47 +07:00
  • 442f1958e8 QUIC NULL checks Andrew Dinh 2025-02-26 21:30:18 +07:00
  • 9688973596 Add a note about avx-512 support for XTS to CHANGES.md Dan Pittman 2025-02-25 08:31:08 -08:00
  • ddc8529e87 fix windows calling convention in aesni-xts-avx512 dan pittman 2025-02-24 17:29:15 -08:00
  • b4116b9372 add an AVX-512-optimized ASM XTS implementation for x86_64 Dan Pittman 2024-06-26 08:11:42 -07:00
  • 374768c6cf Adds a workaround for false negative test results with TLSProxy Frederik Wedel-Heinen 2025-02-27 07:11:18 +01:00
  • c2f4d7aae1 Encoder : Fix floating pointer when OSSL_ENCODER_to_data() is called twice. slontis 2025-02-25 17:03:38 +11:00
  • 054f6c0fc1 Optimize ossl_namemap_name2num_n to avoid strndup Andrew Dinh 2025-02-21 23:55:58 +07:00
  • 18f2091ad1 Older FIPS providers require a kemop Viktor Dukhovni 2025-02-26 11:43:35 +11:00
  • 44a64029c3 Use better data type info in decoders Viktor Dukhovni 2025-02-25 18:17:02 +11:00
  • 0c37be3a7c TLSProxy: Handle partial messages with DTLS Frederik Wedel-Heinen 2025-01-22 16:48:06 +01:00
  • b396119f54 Tolerate 3.5+ FIPS providers in kem_rsa_params test Viktor Dukhovni 2025-02-26 20:59:38 +11:00
  • 812fc0be0f Tolerate 3.5+ FIPS providers in kem_rsa_params test Viktor Dukhovni 2025-02-26 20:59:38 +11:00
  • f11c10d83e Allow 0 length plaintext and aad for aes-siv SaEvangelista 2025-02-03 21:19:28 -05:00
  • 20599e480f ML-DSA Add Wycheproof test vectors. slontis 2025-02-25 10:06:26 +11:00
  • fed9be39ff Make RFC8422 deprecated TLS EC curves disablable Viktor Dukhovni 2025-02-23 19:46:24 +11:00
  • 69d15b28af FIPS POST: Change PBKDF2 CAST to use less iterations. slontis 2025-02-25 13:31:46 +11:00
  • 83f9d840ad Tolerate 3.5+ FIPS providers in kem_rsa_params test Viktor Dukhovni 2025-02-26 20:59:38 +11:00
  • e312608b76 Tolerate 3.5+ FIPS providers in kem_rsa_params test Viktor Dukhovni 2025-02-26 20:59:38 +11:00
  • 23cdc77328 Tolerate 3.5+ FIPS providers in kem_rsa_params test Viktor Dukhovni 2025-02-26 20:59:38 +11:00
  • c0eb5c57f7 fix slh-dsa incorrect prediction of result code Neil Horman 2025-02-24 07:55:33 -05:00
  • 45f9dc0e8d Add record overflow test to tlsfuzzer external tests Neil Horman 2025-02-24 08:14:36 -05:00
  • c932099d8f Change cipher suite alert for 0 length cipher_suites Neil Horman 2025-02-16 08:35:38 -05:00
  • f8daf7905b Add record overflow test to tlsfuzzer external tests Neil Horman 2025-02-24 08:14:36 -05:00
  • 8b95673740 Change cipher suite alert for 0 length cipher_suites Neil Horman 2025-02-16 08:35:38 -05:00
  • 16e0a64f93 Add record overflow test to tlsfuzzer external tests Neil Horman 2025-02-24 08:14:36 -05:00
  • a98b476c08 Change cipher suite alert for 0 length cipher_suites Neil Horman 2025-02-16 08:35:38 -05:00
  • 83dbfde6aa Add record overflow test to tlsfuzzer external tests Neil Horman 2025-02-24 08:14:36 -05:00
  • 2ce46ad8ce Change cipher suite alert for 0 length cipher_suites Neil Horman 2025-02-16 08:35:38 -05:00
  • a7c0fa601e Add ifndef to seed-src_jitter too Dimitri John Ledkov 2025-02-23 17:50:21 +00:00
  • aa5f1b4cf5 fips-jitter: Force use jitter entropy in the FIPS 3.0.9 provider callback Dimitri John Ledkov 2024-11-09 21:32:48 +00:00
  • b4be505af3 Fix read out of buffer bounds when dealing with BIO_ADDR Alexandr Nedvedicky 2024-12-23 17:03:32 +01:00
  • f5602d71b9 Fix read out of buffer bounds when dealing with BIO_ADDR Alexandr Nedvedicky 2024-12-23 17:03:32 +01:00
  • a04a5fe8a1 Fix read out of buffer bounds when dealing with BIO_ADDR Alexandr Nedvedicky 2024-12-23 17:03:32 +01:00
  • 395a83a617 Fix read out of buffer bounds when dealing with BIO_ADDR Alexandr Nedvedicky 2024-12-23 17:03:32 +01:00
  • 78247a46ba Fix potential memory leak in policy_section() Niels Dossche 2025-01-21 12:04:44 +01:00
  • 77d6810d90 Fix potential memory leak in policy_section() Niels Dossche 2025-01-21 12:04:44 +01:00
  • 52efaa7909 Fix potential memory leak in policy_section() Niels Dossche 2025-01-21 12:04:44 +01:00
  • ececabd9ad Fix potential memory leak in policy_section() Niels Dossche 2025-01-21 12:04:44 +01:00
  • 6b95c2cb9e add_uris_recursive(): Avoid OSSL_STORE_INFO leak on error Tomas Mraz 2025-01-22 09:57:36 +01:00
  • 4d8852b8ad add_uris_recursive(): Avoid OSSL_STORE_INFO leak on error Tomas Mraz 2025-01-22 09:57:36 +01:00
  • f2d37f0a2d add_uris_recursive(): Avoid OSSL_STORE_INFO leak on error Tomas Mraz 2025-01-22 09:57:36 +01:00
  • e8d791f41c add_uris_recursive(): Avoid OSSL_STORE_INFO leak on error Tomas Mraz 2025-01-22 09:57:36 +01:00
  • 348c5d768b add_uris_recursive(): Avoid OSSL_STORE_INFO leak on error Tomas Mraz 2025-01-22 09:57:36 +01:00
  • be5965acad add_uris_recursive(): Avoid OSSL_STORE_INFO leak on error Tomas Mraz 2025-01-22 09:57:36 +01:00
  • 0edc5b05ec Fix potential leak in error path in cert_response() Niels Dossche 2025-01-22 14:35:25 +01:00
  • 9e1fb45a18 Fix potential leak in error path in cert_response() Niels Dossche 2025-01-22 14:35:25 +01:00
  • 4e475f1287 Fix potential leak in error path in cert_response() Niels Dossche 2025-01-22 14:35:25 +01:00
  • 360c0c4868 Fix potential leak in error path in cert_response() Niels Dossche 2025-01-22 14:35:25 +01:00
  • 0bd7eb2099 Fix potential leak in error path in cert_response() Niels Dossche 2025-01-22 14:35:25 +01:00
  • 56160f173d Fix potential leak in error path in cert_response() Niels Dossche 2025-01-22 14:35:25 +01:00
  • b4fab70bfb EVP_PKEY_derive_set_peer_ex(): Don't free peer on error Andrew Dinh 2025-02-19 13:29:07 +07:00
  • 87b5aa737d Rename fnv1a_hash() to ossl_fnv1a_hash() Tomas Mraz 2025-02-24 09:47:13 +01:00
  • ed853b2a2c Fix potential memory leaks in error paths in ossl_rsa_multiprime_derive() Niels Dossche 2025-01-22 15:43:14 +01:00
  • f53432a013 Fix potential memory leaks in error paths in ossl_rsa_multiprime_derive() Niels Dossche 2025-01-22 15:43:14 +01:00
  • 8cdba24cee Fix potential memory leaks in error paths in ossl_rsa_multiprime_derive() Niels Dossche 2025-01-22 15:43:14 +01:00
  • 7e80b16776 Add CHANGES.md entry for changed default TLS group list Tomas Mraz 2025-02-24 10:33:08 +01:00
  • 4c69caef48 tls1_set_groups_list(): Update raised errors Tomas Mraz 2025-02-24 09:21:00 +01:00
  • 0b40fac3fb tls_construct_ctos_key_share(): Fix handling of HRR without key share request Tomas Mraz 2025-02-21 19:28:26 +01:00
  • 192f096afd Convert test_bio_ssl to use fake time Neil Horman 2025-02-21 12:22:17 -05:00
  • bcc364896e 28-seclevel.cnf.in: Enable some groups required for high SECLEVELs Tomas Mraz 2025-02-21 17:09:22 +01:00
  • 5a9966dd3a 70-test_tls13cookie.t: Change the order of the test cases Tomas Mraz 2025-02-21 16:47:44 +01:00
  • f9aaeacbf9 Tserver must keep fake time ticking to complete a handshake sashan 2025-02-21 02:04:03 +01:00
  • a3143c2400 No valid groups is not an error Tomas Mraz 2025-02-20 16:53:10 +01:00
  • a89c99e04b Have the same default groups list for QUIC and TLS Tomas Mraz 2025-02-20 16:25:41 +01:00
  • b665a13ac0 compare_with_file(): ? at EOL matches any number of characters Tomas Mraz 2025-02-20 16:24:44 +01:00
  • 3947982e3a Fix quic multistream test Sasha Nedvedicky 2025-02-19 00:03:39 +01:00
  • 63a70d63e2 Add hybrid ML-KEM based groups to default TLS groups Viktor Dukhovni 2025-02-18 02:41:51 +11:00
  • 6a233c31de Reduce the number of mallocs in dtls1_new() by allocating message queues together with the d1 struct. Frederik Wedel-Heinen 2024-12-11 13:13:28 +01:00
  • 96075a6a40 Fix AEAD validation of initial packets in port Alexandr Nedvedicky 2025-02-18 01:34:04 +01:00
  • c14ae04613 Perform initial AEAD validation before creating a channel Alexandr Nedvedicky 2025-02-18 01:32:47 +01:00
  • 7fb4a323f1 riscv: add dl_hwcap for capability detection daichengrong 2025-02-18 16:19:01 +08:00
  • 2a65dcec25 fix: add OOM handler for x509 fuzz test Burkov Egor 2025-02-19 16:42:07 +03:00
  • 2560c117ae fix: add OOM handler for x509 fuzz test Burkov Egor 2025-02-19 16:42:07 +03:00
  • 5088cf30f2 fix: add OOM handler for x509 fuzz test Burkov Egor 2025-02-19 16:42:07 +03:00
  • 20fef71806 fix: add OOM handler for x509 fuzz test Burkov Egor 2025-02-19 16:42:07 +03:00
  • 0010856a43 fix: add OOM handler for x509 fuzz test Burkov Egor 2025-02-19 16:42:07 +03:00
  • 6d42072e0b fix: add OOM handler for x509 fuzz test Burkov Egor 2025-02-19 16:42:07 +03:00
  • ddd7ecb04b Make the KEM operating mode optional Viktor Dukhovni 2025-02-23 15:21:14 +11:00
  • 5264f24a5e doc: document that the FIPS provider doesn't support deterministic ECDSA sigs Pauli 2025-02-24 15:20:34 +11:00
  • 475343cfac doc: document that the FIPS provider doesn't support deterministic ECDSA sigs Pauli 2025-02-24 15:20:34 +11:00