Manuel Pégourié-Gonnard
|
e5b0fc1847
|
Make malloc-init script a bit happier
|
2014-11-13 12:42:12 +01:00 |
|
Manuel Pégourié-Gonnard
|
5924f9f810
|
Add script to find malloc() not followed by init
|
2014-11-13 12:42:12 +01:00 |
|
Manuel Pégourié-Gonnard
|
f631bbc1da
|
Make x509_string_cmp() iterative
|
2014-11-13 12:42:06 +01:00 |
|
Manuel Pégourié-Gonnard
|
8a5e3d4a40
|
Forbid repeated X.509 extensions
|
2014-11-12 18:13:58 +01:00 |
|
Manuel Pégourié-Gonnard
|
d681443f69
|
Fix potential stack overflow
|
2014-11-12 01:25:31 +01:00 |
|
Manuel Pégourié-Gonnard
|
b134060f90
|
Fix memory leak with crafted X.509 certs
|
2014-11-12 00:01:52 +01:00 |
|
Manuel Pégourié-Gonnard
|
0369a5291b
|
Fix uninitialised pointer dereference
|
2014-11-12 00:01:52 +01:00 |
|
Manuel Pégourié-Gonnard
|
e9271e6835
|
Add a MemSan Cmake build type
Detects uninitialised memory reads. Available only with Clang on Linux x86_64
for now. Experimental but seems usable enough.
|
2014-11-12 00:01:52 +01:00 |
|
Manuel Pégourié-Gonnard
|
49aa99e653
|
Fix exit codes in cert_app
|
2014-11-12 00:01:52 +01:00 |
|
Manuel Pégourié-Gonnard
|
e959979621
|
Fix ECDSA sign buffer size
|
2014-11-12 00:01:52 +01:00 |
|
Manuel Pégourié-Gonnard
|
b31b61b9e8
|
Fix potential undefined behaviour in Camellia
|
2014-11-12 00:01:51 +01:00 |
|
Manuel Pégourié-Gonnard
|
d6197a37e0
|
Detect undefined behaviours too in ASan builds
|
2014-11-12 00:01:51 +01:00 |
|
Manuel Pégourié-Gonnard
|
54f6e562e6
|
Fix CFLAGS with cmake and gcc
|
2014-11-12 00:01:51 +01:00 |
|
Manuel Pégourié-Gonnard
|
de17125875
|
Update ChangeLog for pk_check_pair() & Co
|
2014-11-12 00:01:51 +01:00 |
|
Manuel Pégourié-Gonnard
|
7c13d69cb5
|
Fix dependency issues
|
2014-11-12 00:01:34 +01:00 |
|
Manuel Pégourié-Gonnard
|
a1efcb084f
|
Implement pk_check_pair() for RSA-alt
|
2014-11-08 18:00:22 +01:00 |
|
Manuel Pégourié-Gonnard
|
27e3edbe2c
|
Check key/cert pair in ssl_set_own_cert()
|
2014-11-06 18:25:51 +01:00 |
|
Manuel Pégourié-Gonnard
|
70bdadf54b
|
Add pk_check_pair()
|
2014-11-06 18:25:51 +01:00 |
|
Manuel Pégourié-Gonnard
|
30668d688d
|
Add ecp_check_pub_priv()
|
2014-11-06 18:25:51 +01:00 |
|
Manuel Pégourié-Gonnard
|
2f8d1f9fc3
|
Add rsa_check_pub_priv()
|
2014-11-06 18:25:51 +01:00 |
|
Manuel Pégourié-Gonnard
|
e10e06d863
|
Blind RSA operations even without CRT
|
2014-11-06 18:25:44 +01:00 |
|
Manuel Pégourié-Gonnard
|
d056ce0e3e
|
Use seq_num as AEAD nonce by default
|
2014-11-06 18:23:49 +01:00 |
|
Manuel Pégourié-Gonnard
|
9d7821d774
|
Fix warning in reduced config
|
2014-11-06 01:19:52 +01:00 |
|
Manuel Pégourié-Gonnard
|
b3c6a97b31
|
Update Changelog for session-hash
|
2014-11-05 16:00:50 +01:00 |
|
Manuel Pégourié-Gonnard
|
c122ae7612
|
Update Changelog for EtM
|
2014-11-05 16:00:50 +01:00 |
|
Manuel Pégourié-Gonnard
|
769c6b6351
|
Make session-hash depend on TLS versions
|
2014-11-05 16:00:50 +01:00 |
|
Manuel Pégourié-Gonnard
|
1a03473576
|
Keep EtM state across renegotiations
|
2014-11-05 16:00:50 +01:00 |
|
Manuel Pégourié-Gonnard
|
b575b54cb9
|
Forbid extended master secret with SSLv3
|
2014-11-05 16:00:50 +01:00 |
|
Manuel Pégourié-Gonnard
|
169dd6a514
|
Adjust minimum length for EtM
|
2014-11-05 16:00:50 +01:00 |
|
Manuel Pégourié-Gonnard
|
dd4592774b
|
compat.sh: allow git version of gnutls
|
2014-11-05 16:00:50 +01:00 |
|
Manuel Pégourié-Gonnard
|
78e745fc0a
|
Don't send back EtM extension if not using CBC
|
2014-11-05 16:00:50 +01:00 |
|
Manuel Pégourié-Gonnard
|
08558e5b46
|
Fix for the RFC erratum
|
2014-11-05 16:00:50 +01:00 |
|
Manuel Pégourié-Gonnard
|
313d796e80
|
Implement EtM
|
2014-11-05 16:00:50 +01:00 |
|
Manuel Pégourié-Gonnard
|
0098e7dc70
|
Preparation for EtM
|
2014-11-05 16:00:50 +01:00 |
|
Manuel Pégourié-Gonnard
|
699cafaea2
|
Implement initial negotiation of EtM
Not implemented yet:
- actually using EtM
- conditions on renegotiation
|
2014-11-05 16:00:50 +01:00 |
|
Manuel Pégourié-Gonnard
|
178f9d6e19
|
Update Changelog for FALLBACK_SCSV
|
2014-11-05 16:00:49 +01:00 |
|
Manuel Pégourié-Gonnard
|
85a4178f82
|
compat.sh: make options a bit more robust
|
2014-11-05 16:00:49 +01:00 |
|
Manuel Pégourié-Gonnard
|
01b2699198
|
Implement FALLBACK_SCSV server-side
|
2014-11-05 16:00:49 +01:00 |
|
Manuel Pégourié-Gonnard
|
ada3030485
|
Implement extended master secret
|
2014-11-05 16:00:49 +01:00 |
|
Manuel Pégourié-Gonnard
|
1cbd39dbeb
|
Implement FALLBACK_SCSV client-side
|
2014-11-05 16:00:49 +01:00 |
|
Manuel Pégourié-Gonnard
|
367381fddd
|
Add negotiation of Extended Master Secret
(But not the actual thing yet.)
|
2014-11-05 16:00:49 +01:00 |
|
Paul Bakker
|
a6c5ea2c43
|
Include 1.2.12 release information in ChangeLog
|
2014-10-24 16:26:29 +02:00 |
|
Paul Bakker
|
82788fb63b
|
Fix minor style issues
|
2014-10-20 13:59:19 +02:00 |
|
Paul Bakker
|
9eac4f7c4e
|
Prepare for release 1.3.9
|
2014-10-20 13:56:15 +02:00 |
|
Paul Bakker
|
b082bb50de
|
Fix typos in ChangeLog
|
2014-10-20 13:37:51 +02:00 |
|
Manuel Pégourié-Gonnard
|
f7cdbc0e87
|
Fix potential bad read of length
|
2014-10-17 17:02:10 +02:00 |
|
Manuel Pégourié-Gonnard
|
ef9a6aec51
|
Allow comparing name with mismatched encodings
|
2014-10-17 12:42:31 +02:00 |
|
Manuel Pégourié-Gonnard
|
9c911da68f
|
Add tests for X.509 name encoding mismatch
|
2014-10-17 12:42:31 +02:00 |
|
Manuel Pégourié-Gonnard
|
88421246d8
|
Rename a function
|
2014-10-17 12:42:30 +02:00 |
|
Manuel Pégourié-Gonnard
|
43c3b28ca6
|
Fix memory leak with crafted ClientHello
|
2014-10-17 12:42:11 +02:00 |
|