Sign in
boringssl
/
boringssl.git
/
0de64a749b344ce16367bc6514a7d4549bba8c6c
/
ssl
04a89c8
Add |SSL_CIPHER_get_value| to get the IANA number of a cipher suite.
by Adam Langley
· 6 years ago
b82f945
Use the Go 1.13 standard library ed25519.
by David Benjamin
· 6 years ago
3b62960
Move the config->async check into RetryAsync.
by David Benjamin
· 6 years ago
d0b9794
Clear *out in ReadHandshakeData's empty case.
by David Benjamin
· 6 years ago
d634357
Add initial support for 0-RTT with QUIC.
by David Benjamin
· 6 years ago
95dd54e
Have some more fun with spans.
by David Benjamin
· 6 years ago
f350351
Align 0-RTT and resumption state machines slightly
by David Benjamin
· 6 years ago
bd2a8d6
Add a function to convert SSL_ERROR_* values to strings.
by David Benjamin
· 6 years ago
f492830
Fold SSL_want constants into SSL_get_error constants.
by David Benjamin
· 6 years ago
e530ea3
Use spans for the various TLS 1.3 secrets.
by David Benjamin
· 6 years ago
b244e3a
Switch another low-level function to spans.
by David Benjamin
· 6 years ago
79b8b3a
Switch tls13_enc.cc to spans.
by David Benjamin
· 6 years ago
9806ae0
Check the second ClientHello's PSK binder on resumption.
by David Benjamin
· 6 years ago
8c98bac
Remove stale TODO.
by David Benjamin
· 6 years ago
fd863b6
Add a QUIC test for HelloRetryRequest.
by David Benjamin
· 6 years ago
ee4888c
Make alert_dispatch into a bool.
by David Benjamin
· 6 years ago
bc42402
Trim some more per-connection memory.
by David Benjamin
· 6 years ago
94b2871
Remove SSL_export_early_keying_material.
by David Benjamin
· 6 years ago
ef0183c
Make SSL_get_servername work in the early callback.
by David Benjamin
· 6 years ago
4dfd5af
Only bypass the signature verification itself in fuzzer mode.
by David Benjamin
· 6 years ago
9f5c419
Move the PQ-experiment signal to SSL_CTX.
by Adam Langley
· 6 years ago
b9e2b8a
Name cipher suite tests in runner by IETF names.
by David Benjamin
· 6 years ago
a86c698
Add post-quantum experiment signal extension.
by Adam Langley
· 6 years ago
0fc4979
Fix shim error message endings.
by Adam Langley
· 6 years ago
3c8ae0f
Implements SIKE/p434
by Kris Kwiatkowski
· 6 years ago
d6f9c35
Factor out TLS cipher selection to ssl_choose_tls_cipher.
by Steven Valdez
· 6 years ago
629f321
Add an API to record use of delegated credential
by Watson Ladd
· 6 years ago
d59682c
Fix runner tests with Go 1.13.
by David Benjamin
· 6 years ago
5b89336
Replace addc64,subc64,mul64 in SIKE Go code with functions from math/bits
by Kris Kwiatkowski
· 6 years ago
c0b4c72
Eliminate some superfluous conditions in SIKE Go code.
by Adam Langley
· 6 years ago
567e463
Fix various typos.
by Adam Langley
· 6 years ago
78c88c9
Integrate SIKE with TLS key exchange.
by Kris Kwiatkowski
· 6 years ago
6676b9a
Convert ecdsa_p224_key.pem to PKCS#8.
by David Benjamin
· 6 years ago
5274cea
Always store early data tickets.
by Steven Valdez
· 6 years ago
b29e1e1
Save and restore errors when ignoring ssl_send_alert result.
by David Benjamin
· 6 years ago
b19b79d
Make expect/expected flag and variable names match.
by David Benjamin
· 6 years ago
0ad8d57
clang-format Flag arrays in test_config.cc.
by David Benjamin
· 6 years ago
262fd6a
Rename remnants of ticket_early_data_info.
by David Benjamin
· 6 years ago
6433a91
Enforce the ticket_age parameter for 0-RTT.
by David Benjamin
· 6 years ago
6477012
Add SSL_get_early_data_reason.
by David Benjamin
· 6 years ago
572edbf
Remove implicit -on-resume for -expect-early-data-accept.
by David Benjamin
· 6 years ago
ffe384c
Fix spelling in comments.
by Adam Langley
· 6 years ago
1b878e7
Check for errors when setting up X509_STORE_CTX.
by David Benjamin
· 6 years ago
1e77ef4
Convert a few more things from int to bool.
by David Benjamin
· 6 years ago
85eef29
Compute the delegated credentials length prefix with CBB.
by David Benjamin
· 6 years ago
a486c6c
Convert the rest of ssl_test to GTest.
by David Benjamin
· 6 years ago
777a239
Hold off flushing NewSessionTicket until write.
by Steven Valdez
· 6 years ago
7540cc2
Predeclare enums in base.h
by Adam Langley
· 6 years ago
c9827e0
Output a ClientHello during handoff.
by Adam Langley
· 6 years ago
be7006a
Update third_party/googletest.
by David Benjamin
· 6 years ago
be9953a
nit: Update references to draft-ietf-tls-subcerts.
by Christopher Patton
· 6 years ago
a4af5f8
Support get versions with get_{min,max}_proto_version for context
by Nitish Sakhawalkar
· 6 years ago
3390fd8
Correct outdated comments
by Watson Ladd
· 6 years ago
f9c8d30
Remove SSL_get_structure_sizes.
by David Benjamin
· 6 years ago
f109f20
Clear out a bunch of -Wextra-semi warnings.
by David Benjamin
· 6 years ago
2f213f6
Update delegated credentials to draft-03
by Watson Ladd
· 6 years ago
2d38b83
Remove separate default group list for servers.
by Adam Langley
· 6 years ago
fcc1ad7
Enable all curves (inc CECPQ2) during fuzzing.
by Adam Langley
· 6 years ago
20a9b40
runner: Don't generate an RSA key on startup.
by David Benjamin
· 6 years ago
d7266ec
Enforce key usage for RSA keys in TLS 1.2.
by Jesse Selover
· 6 years ago
73308b6
Avoid SCT/OCSP extensions in SH on {Omit|Empty}Extensions
by Filippo Valsorda
· 6 years ago
6c1b376
Implement server support for delegated credentials.
by Christopher Patton
· 7 years ago
9801a07
Tweak some slightly fragile tests.
by Adam Langley
· 6 years ago
4bfab5d
Make 256-bit ciphers a preference for CECPQ2, not a requirement.
by Adam Langley
· 6 years ago
fa81cc6
Update comments around JDK11 workaround.
by David Benjamin
· 6 years ago
14c611c
Don't pass NULL,0 to qsort.
by David Benjamin
· 6 years ago
823effe
Revert "Fix protos_len size in SSL_set_alpn_protos and SSL_CTX_set_alpn_protos"
by Adam Langley
· 6 years ago
3cbb029
Allow configuring QUIC method per-connection
by Alessandro Ghedini
· 6 years ago
b84674b
Delete the variants/draft code.
by Steven Valdez
· 7 years ago
35771ff
Fix protos_len size in SSL_set_alpn_protos and SSL_CTX_set_alpn_protos
by Raul Tambre
· 6 years ago
9cde848
Use handshake parameters to decide if cert/key are available
by Christopher Patton
· 7 years ago
17d553d
Add a CFI tester to CHECK_ABI.
by David Benjamin
· 6 years ago
2cc6f44
Use same HKDF label as TLS 1.3 for QUIC as per draft-ietf-quic-tls-17
by Alessandro Ghedini
· 6 years ago
ba9ad66
Add |SSL_key_update|.
by Adam Langley
· 6 years ago
9700b44
HRSS: omit reconstruction of ciphertext.
by Adam Langley
· 6 years ago
a6a049a
Add start of infrastructure for checking constant-time properties.
by Adam Langley
· 6 years ago
4cce955
Fix thread-safety bug in SSL_get_peer_cert_chain.
by David Benjamin
· 6 years ago
200fe67
Remove HRSS confirmation hash.
by Adam Langley
· 6 years ago
d6e1f23
Add |SSL_export_traffic_secrets|.
by Adam Langley
· 6 years ago
43cc9c6
Do not allow AES_128_GCM_SHA256 with CECPQ2.
by David Benjamin
· 6 years ago
7b93593
Add initial HRSS support.
by Adam Langley
· 6 years ago
602f466
Forbid empty CertificateRequestsupported_signature_algorithms in TLS 1.2.
by David Benjamin
· 6 years ago
e6ad7a0
Drop some explicit SSLKeyShare destructors.
by Adam Langley
· 6 years ago
278b312
Validate ClientHellos in tests some more.
by David Benjamin
· 6 years ago
9113e09
Satisfy golint.
by David Benjamin
· 6 years ago
6965d25
Work around a JDK 11 TLS 1.3 bug.
by David Benjamin
· 6 years ago
c65a1f4
go fmt
by Adam Langley
· 6 years ago
ce61710
Move JSON test results code into a common module.
by David Benjamin
· 6 years ago
f241a59
In 0RTT mode, reverify the server certificate before sending early data.
by Jesse Selover
· 6 years ago
e6eef1c
Add post-handshake support for the QUIC API.
by Steven Valdez
· 6 years ago
ce45588
Speculatively remove __STDC_*_MACROS.
by David Benjamin
· 6 years ago
7d10ab5
Abstract hs_buf a little.
by David Benjamin
· 6 years ago
384d0ea
Make SSL_get_current_cipher valid during QUIC callbacks.
by Steven Valdez
· 6 years ago
c65eb2c
Serialize SSL curve list in handoff and check it on application.
by Matthew Braithwaite
· 6 years ago
d2ed382
Serialize SSL configuration in handoff and check it on application.
by Matthew Braithwaite
· 7 years ago
cc9d935
Buffer up QUIC data within a level internally.
by David Benjamin
· 6 years ago
c8e0f90
Add an interface for QUIC integration.
by Steven Valdez
· 7 years ago
c0c9001
Implement SSL_get_tlsext_status_type
by Jeremy Apthorp
· 6 years ago
1eff948
Use proper functions for lh_*.
by David Benjamin
· 7 years ago
2d98d49
Add a per-SSL TLS 1.3 downgrade enforcement option and improve tests.
by David Benjamin
· 6 years ago
Next »