openssl/doc/ssl
Dr. Stephen Henson ce325c60c7 Only allow ephemeral RSA keys in export ciphersuites.
OpenSSL clients would tolerate temporary RSA keys in non-export
ciphersuites. It also had an option SSL_OP_EPHEMERAL_RSA which
enabled this server side. Remove both options as they are a
protocol violation.

Thanks to Karthikeyan Bhargavan for reporting this issue.
(CVE-2015-0204)
Reviewed-by: Matt Caswell <matt@openssl.org>
2015-01-06 02:06:39 +00:00
..
d2i_SSL_SESSION.pod Close a whole bunch of documentation-related tickets: 2014-07-02 22:42:40 -04:00
SSL_accept.pod Remove MS SGC 2015-01-02 22:56:54 +00:00
SSL_alert_type_string.pod
SSL_CIPHER_get_name.pod Remove SSLv2 support 2014-12-04 11:55:03 +01:00
SSL_clear.pod POD: Fix item numbering 2013-10-22 07:38:25 +01:00
SSL_COMP_add_compression_method.pod POD: Fix item numbering 2013-10-22 07:38:25 +01:00
SSL_CONF_cmd_argv.pod Close a whole bunch of documentation-related tickets: 2014-07-02 22:42:40 -04:00
SSL_CONF_cmd.pod Remove SSLv2 support 2014-12-04 11:55:03 +01:00
SSL_CONF_CTX_new.pod
SSL_CONF_CTX_set1_prefix.pod
SSL_CONF_CTX_set_flags.pod
SSL_CONF_CTX_set_ssl_ctx.pod Close a whole bunch of documentation-related tickets: 2014-07-02 22:42:40 -04:00
SSL_connect.pod POD: Fix item numbering 2013-10-22 07:38:25 +01:00
SSL_CTX_add1_chain_cert.pod Update chain building function. 2014-03-27 14:24:40 +00:00
SSL_CTX_add_extra_chain_cert.pod Clarify docs. 2014-06-27 16:39:11 +01:00
SSL_CTX_add_session.pod Close a whole bunch of documentation-related tickets: 2014-07-02 22:42:40 -04:00
SSL_CTX_ctrl.pod
SSL_CTX_flush_sessions.pod
SSL_CTX_free.pod
SSL_CTX_get_ex_new_index.pod
SSL_CTX_get_verify_mode.pod
SSL_CTX_load_verify_locations.pod POD: Fix item numbering 2013-10-22 07:38:25 +01:00
SSL_CTX_new.pod Remove SSLv2 support 2014-12-04 11:55:03 +01:00
SSL_CTX_sess_number.pod
SSL_CTX_sess_set_cache_size.pod RT468: SSL_CTX_sess_set_cache_size wrong 2014-09-08 11:26:03 -04:00
SSL_CTX_sess_set_get_cb.pod
SSL_CTX_sessions.pod
SSL_CTX_set1_curves.pod Clarify the return values for SSL_get_shared_curve. 2014-12-05 18:31:21 +01:00
SSL_CTX_set1_verify_cert_store.pod POD: Fix list termination 2013-10-22 07:38:25 +01:00
SSL_CTX_set_cert_cb.pod Close a whole bunch of documentation-related tickets: 2014-07-02 22:42:40 -04:00
SSL_CTX_set_cert_store.pod
SSL_CTX_set_cert_verify_callback.pod
SSL_CTX_set_cipher_list.pod Remove SSLv2 support 2014-12-04 11:55:03 +01:00
SSL_CTX_set_client_CA_list.pod Close a whole bunch of documentation-related tickets: 2014-07-02 22:42:40 -04:00
SSL_CTX_set_client_cert_cb.pod Close a whole bunch of documentation-related tickets: 2014-07-02 22:42:40 -04:00
SSL_CTX_set_custom_cli_ext.pod Custom extension documentation. 2014-08-28 17:06:53 +01:00
SSL_CTX_set_default_passwd_cb.pod
SSL_CTX_set_generate_session_id.pod Remove SSLv2 support 2014-12-04 11:55:03 +01:00
SSL_CTX_set_info_callback.pod Fix RT 3193 2014-07-01 12:44:32 -04:00
SSL_CTX_set_max_cert_list.pod RT3239: Extra comma in NAME lines of two manpages 2014-08-12 15:59:18 -04:00
SSL_CTX_set_mode.pod Fix and improve SSL_MODE_SEND_FALLBACK_SCSV documentation. 2014-10-21 22:43:08 +02:00
SSL_CTX_set_msg_callback.pod Fixed error in args for SSL_set_msg_callback and SSL_set_msg_callback_arg 2014-05-25 23:45:12 +01:00
SSL_CTX_set_options.pod Only allow ephemeral RSA keys in export ciphersuites. 2015-01-06 02:06:39 +00:00
SSL_CTX_set_psk_client_callback.pod
SSL_CTX_set_quiet_shutdown.pod
SSL_CTX_set_security_level.pod Close a whole bunch of documentation-related tickets: 2014-07-02 22:42:40 -04:00
SSL_CTX_set_session_cache_mode.pod
SSL_CTX_set_session_id_context.pod POD: Fix item numbering 2013-10-22 07:38:25 +01:00
SSL_CTX_set_ssl_version.pod POD: Fix item numbering 2013-10-22 07:38:25 +01:00
SSL_CTX_set_timeout.pod
SSL_CTX_set_tlsext_ticket_key_cb.pod Fixed error in pod files with latest versions of pod2man 2014-07-06 00:03:13 +01:00
SSL_CTX_set_tmp_dh_callback.pod RT1744: SSL_CTX_set_dump_dh() doc feedback 2014-08-26 13:47:23 -04:00
SSL_CTX_set_tmp_rsa_callback.pod Only allow ephemeral RSA keys in export ciphersuites. 2015-01-06 02:06:39 +00:00
SSL_CTX_set_verify.pod Close a whole bunch of documentation-related tickets: 2014-07-02 22:42:40 -04:00
SSL_CTX_use_certificate.pod Use algorithm specific chains for certificates. 2014-01-03 22:39:49 +00:00
SSL_CTX_use_psk_identity_hint.pod RT2518: fix pod2man errors 2014-09-08 11:18:30 -04:00
SSL_CTX_use_serverinfo.pod typo 2014-01-10 23:00:50 +00:00
SSL_do_handshake.pod Remove MS SGC 2015-01-02 22:56:54 +00:00
SSL_free.pod
SSL_get_ciphers.pod
SSL_get_client_CA_list.pod
SSL_get_current_cipher.pod
SSL_get_default_timeout.pod Remove SSLv2 support 2014-12-04 11:55:03 +01:00
SSL_get_error.pod
SSL_get_ex_data_X509_STORE_CTX_idx.pod
SSL_get_ex_new_index.pod
SSL_get_fd.pod
SSL_get_peer_cert_chain.pod typo in SSL_get_peer_cert_chain docs 2014-05-01 13:40:01 +02:00
SSL_get_peer_certificate.pod
SSL_get_psk_identity.pod
SSL_get_rbio.pod
SSL_get_session.pod
SSL_get_SSL_CTX.pod
SSL_get_verify_result.pod
SSL_get_version.pod Remove SSLv2 support 2014-12-04 11:55:03 +01:00
SSL_library_init.pod
SSL_load_client_CA_file.pod
SSL_new.pod Remove SSLv2 support 2014-12-04 11:55:03 +01:00
SSL_pending.pod
SSL_read.pod POD: Fix item numbering 2013-10-22 07:38:25 +01:00
SSL_rstate_string.pod
SSL_SESSION_free.pod
SSL_SESSION_get_ex_new_index.pod
SSL_SESSION_get_time.pod
SSL_session_reused.pod POD: Fix item numbering 2013-10-22 07:38:25 +01:00
SSL_set_bio.pod
SSL_set_connect_state.pod
SSL_set_fd.pod POD: Fix item numbering 2013-10-22 07:38:25 +01:00
SSL_set_session.pod POD: Fix item numbering 2013-10-22 07:38:25 +01:00
SSL_set_shutdown.pod Fix additional pod errors with numbered items. 2014-02-14 22:30:26 +00:00
SSL_set_verify_result.pod
SSL_shutdown.pod Remove SSLv2 support 2014-12-04 11:55:03 +01:00
SSL_state_string.pod
SSL_want.pod
SSL_write.pod POD: Fix item numbering 2013-10-22 07:38:25 +01:00
ssl.pod Remove SSLv2 support 2014-12-04 11:55:03 +01:00