openssl/apps
Dr. David von Oheimb 1a683b80dc apps/{ca,req,x509}.c: Improve diag and doc mostly on X.509 extensions, fix multiple instances
This includes a general correction in the code (now using the X509V3_CTX_REPLACE flag)
and adding a prominent clarification in the documentation:

    If multiple entries are processed for the same extension name,
    later entries override earlier ones with the same name.

This is due to an RFC 5280 requirement - the intro of its section 4.2 says:

    A certificate MUST NOT include more than one instance of a particular extension.

Reviewed-by: Tomas Mraz <tmraz@fedoraproject.org>
(Merged from https://github.com/openssl/openssl/pull/13614)
2020-12-10 15:19:55 +01:00
..
demoSRP
include APPS: Adapt load_key() and load_pubkey() for the engine: loader 2020-12-02 20:19:31 +01:00
lib apps/{req,x509,ca}.c: Cleanup: move shared X509{,_REQ,_CRL} code to apps/lib/apps.c 2020-12-10 15:19:55 +01:00
asn1pars.c Fix safestack issues in asn1.h 2020-09-13 11:10:40 +01:00
build.info Remove openssl provider app 2020-09-26 07:13:22 +10:00
ca-cert.srl
ca-key.pem
ca-req.pem
ca.c apps/{ca,req,x509}.c: Improve diag and doc mostly on X.509 extensions, fix multiple instances 2020-12-10 15:19:55 +01:00
CA.pl.in
cert.pem
ciphers.c Fix safestack issues in ssl.h 2020-09-13 11:09:45 +01:00
client.pem
cmp_mock_srv.c Convert all {NAME}err() in crypto/ to their corresponding ERR_raise() call 2020-11-13 09:35:02 +01:00
cmp_mock_srv.h Rename OPENSSL_CTX prefix to OSSL_LIB_CTX 2020-10-15 11:59:53 +01:00
cmp.c APPS: Adapt load_key() and load_pubkey() for the engine: loader 2020-12-02 20:19:31 +01:00
cms.c APPS: Remove the format argument where it's not used 2020-10-26 09:43:39 +01:00
crl2p7.c Fix stacks of OPENSSL_STRING, OPENSSL_CSTRING and OPENSSL_BLOCK 2020-09-13 11:10:39 +01:00
crl.c APPS: Remove the format argument where it's not used 2020-10-26 09:43:39 +01:00
ct_log_list.cnf
dgst.c openssl dgst: add option to specify output length for XOF 2020-12-02 16:46:46 +01:00
dhparam.c Fix no-dsa 2020-12-04 07:49:24 +01:00
dsa512.pem
dsa1024.pem
dsa-ca.pem
dsa-pca.pem
dsa.c load_key_certs_crls(): Restore output of fatal errors 2020-09-24 14:34:56 +02:00
dsap.pem
dsaparam.c Remove -C from dhparam,dsaparam,ecparam 2020-11-13 14:45:22 +01:00
ec.c load_key_certs_crls(): Restore output of fatal errors 2020-09-24 14:34:56 +02:00
ecparam.c Deprecate EC_POINT_bn2point and EC_POINT_point2bn. 2020-12-07 17:15:39 +10:00
enc.c Specific the engine pointer 2020-07-22 10:37:49 +03:00
engine.c Fix stacks of OPENSSL_STRING, OPENSSL_CSTRING and OPENSSL_BLOCK 2020-09-13 11:10:39 +01:00
errstr.c
fipsinstall.c Rename EVP_MAC_size() to EVP_MAC_CTX_get_mac_size(). 2020-10-22 20:47:02 +10:00
gendsa.c
genpkey.c Remove deprecation warning suppression from genpkey 2020-11-25 16:45:03 +00:00
genrsa.c Deprecate RSA harder 2020-11-18 23:38:34 +01:00
info.c
insta.ca.crt openssl-cmp.pod.in: Update and extend example using Insta Demo CA 2020-08-04 12:11:46 +02:00
kdf.c Fix stacks of OPENSSL_STRING, OPENSSL_CSTRING and OPENSSL_BLOCK 2020-09-13 11:10:39 +01:00
list.c list: add a -provider-info option. 2020-10-16 10:33:38 +10:00
mac.c Fix stacks of OPENSSL_STRING, OPENSSL_CSTRING and OPENSSL_BLOCK 2020-09-13 11:10:39 +01:00
nseq.c Fix safestack issues in x509.h 2020-09-13 11:09:45 +01:00
ocsp.c APPS: Remove the format argument where it's not used 2020-10-26 09:43:39 +01:00
openssl-vms.cnf Check the configuration file by default 2020-11-05 20:45:20 +03:00
openssl.c APPS: Add OSSL_STORE loader for engine keys 2020-12-02 20:19:31 +01:00
openssl.cnf Check the configuration file by default 2020-11-05 20:45:20 +03:00
passwd.c apps/passwd: remove the -crypt option. 2020-11-12 08:35:47 +10:00
pca-cert.srl
pca-key.pem
pca-req.pem
pkcs7.c Rename OPENSSL_CTX prefix to OSSL_LIB_CTX 2020-10-15 11:59:53 +01:00
pkcs8.c
pkcs12.c apps/pkcs12.c: Improve user guidance, re-ordering no-export vs. export options 2020-12-03 12:38:41 +01:00
pkey.c Use OSSL_STORE for load_{,pub}key() and load_cert() in apps/lib/apps.c 2020-05-15 20:20:08 +02:00
pkeyparam.c
pkeyutl.c APPS: Remove the format argument where it's not used 2020-10-26 09:43:39 +01:00
prime.c
privkey.pem
progs.pl
rand.c
rehash.c Fix stacks of OPENSSL_STRING, OPENSSL_CSTRING and OPENSSL_BLOCK 2020-09-13 11:10:39 +01:00
req.c apps/{ca,req,x509}.c: Improve diag and doc mostly on X.509 extensions, fix multiple instances 2020-12-10 15:19:55 +01:00
req.pem
rsa8192.pem Fix rsa8192.pem 2020-05-13 06:28:36 +02:00
rsa.c Adapt everything else to the updated OSSL_ENCODER_CTX_new_by_EVP_PKEY() 2020-12-02 13:37:20 +01:00
rsautl.c Deprecate RSA harder 2020-11-18 23:38:34 +01:00
s512-key.pem
s512-req.pem
s1024key.pem
s1024req.pem
s_client.c APPS: Remove the format argument where it's not used 2020-10-26 09:43:39 +01:00
s_server.c Minor cleanup of error output for various apps 2020-11-19 11:36:02 +01:00
s_time.c s_time: check return values better 2020-09-09 18:01:05 +10:00
server2.pem
server.pem
server.srl
sess_id.c
smime.c APPS: Remove the format argument where it's not used 2020-10-26 09:43:39 +01:00
speed.c apps/speed.c: Rename misleading 'rsa_count' variable to 'op_count' 2020-12-04 16:20:53 +01:00
spkac.c Use OSSL_STORE for load_{,pub}key() and load_cert() in apps/lib/apps.c 2020-05-15 20:20:08 +02:00
srp.c
storeutl.c apps/storeutl: Add error output in case of parse/decryption/mac errors in input files 2020-11-19 11:36:02 +01:00
testCA.pem
testdsa.h
testrsa.h
timeouts.h
ts.c Rename OPENSSL_CTX prefix to OSSL_LIB_CTX 2020-10-15 11:59:53 +01:00
tsget.in
verify.c apps/verify:c: Enable output of multiple verification errors due to -x509_strict 2020-12-04 16:24:28 +01:00
version.c NonStop port updates for 3.0.0. 2020-09-12 20:32:11 +02:00
vms_decc_init.c
x509.c apps/{ca,req,x509}.c: Improve diag and doc mostly on X.509 extensions, fix multiple instances 2020-12-10 15:19:55 +01:00