1. 467d322 Add FIPS-compliant key generation that calls check_fips for RSA and EC. by Steven Valdez · 8 years ago
  2. 208e239 Move OPENSSL_ASAN to base.h. by Adam Langley · 8 years ago
  3. 48b6b8f Add SSL_CIPHER_has_SHA384_HMAC. by Alessandro Ghedini · 8 years ago
  4. 1d59f6e Add a flag to toggle the buggy RSA parser. by David Benjamin · 8 years ago
  5. 93731d9 Remove old SSL min/max version functions. by David Benjamin · 8 years ago
  6. 4249481 Add EVP_AEAD_CTX_[new|free] and UniquePtr support. by Adam Langley · 8 years ago
  7. 61ae41f Use a minimal totient when generating RSA keys. by David Benjamin · 8 years ago
  8. 073391f Detach encrypt and keygen hooks from RSA_METHOD. by David Benjamin · 8 years ago
  9. 79d18bc Add crypto/rsa-level RSA-PSS functions. by David Benjamin · 8 years ago
  10. 8ee0d14 Fix comment typo. by David Benjamin · 8 years ago
  11. 9187101 Add an OPENSSL_ia32cap_get() function for C code. by David Benjamin · 8 years ago
  12. a684152 Downgrade BN_kronecker to bn_jacobi and unexport. by David Benjamin · 8 years ago
  13. 0d5bf8d Document ERR_error_string_n standalone. by David Benjamin · 8 years ago
  14. 1d134ee Add aes-(128|256)-gcm-fips-testonly mode for FIPS compatibility. by Steven Valdez · 8 years ago
  15. 8ebc9ea Update BN_enhanced_miller_rabin_primality_test to enforce preconditions and accept BN_prime_checks. by Steven Valdez · 8 years ago
  16. fc674c8 Unexport bn_correct_top and bn_wexpand. by David Benjamin · 8 years ago
  17. 378a08a Add PKCS7_get_raw_certificates. by David Benjamin · 8 years ago
  18. 6fdea2a Move PKCS#7 functions into their own directory. by David Benjamin · 8 years ago
  19. de254b4 Enforce max_early_data_size on the server. by Alessandro Ghedini · 8 years ago
  20. fc9f10f Implement Enhanced Miller-Rabin primality test for FIPS. by Steven Valdez · 8 years ago
  21. 2c45fa0 Convert bytestring_test to GTest. by David Benjamin · 8 years ago
  22. 71c21b4 Add SSL_CTX_set_verify_algorithm_prefs. by David Benjamin · 8 years ago
  23. 730d69e Add CTR-DRBG. by Adam Langley · 8 years ago
  24. b15143f Fix check_fips for public keys and synchronize the EC and RSA versions. by Steven Valdez · 8 years ago
  25. 400d0b7 Add PWCT for RSA and ECDSA for FIPS 140-2. by Steven Valdez · 8 years ago
  26. 82b2b85 Unwind multiprime RSA support. by David Benjamin · 8 years ago
  27. d403be9 Ensure consumers set up include paths properly. by David Benjamin · 8 years ago
  28. d0b9882 Add RSA_check_fips to support public key validation checks. by Steven Valdez · 8 years ago
  29. 7e06de5 Really remove DHE ciphersuites from TLS. by Matthew Braithwaite · 8 years ago
  30. a533449 Add support for 3DES-ECB. by Adam Langley · 8 years ago
  31. 4a2cc28 Unwind RSA_generate_multi_prime_key. by David Benjamin · 8 years ago
  32. 3cfeb95 Disable SSLv3 by default. by David Benjamin · 8 years ago
  33. fd49993 First part of the FIPS module. by Adam Langley · 8 years ago
  34. 6952211 Support Ed25519 in TLS. by David Benjamin · 8 years ago
  35. d69d94e Teach crypto/x509 how to verify an Ed25519 signature. by David Benjamin · 8 years ago
  36. 417830d Support EVP_PKEY_{sign,verify}_message with Ed25519. by David Benjamin · 8 years ago
  37. 05bb1c5 Implement draft-ietf-curdle-pkix-04's serialization. by David Benjamin · 8 years ago
  38. a232a71 Deprecate SSL_PRIVATE_KEY_METHOD type and max_signature_len. by David Benjamin · 8 years ago
  39. 7c83fda Add message-based EVP_PKEY APIs. by David Benjamin · 8 years ago
  40. 3e0b2ce Prune some dead constants. by David Benjamin · 8 years ago
  41. c8ff30c Add an option to allow unknown ALPN protocols. by David Benjamin · 8 years ago chromium-3071
  42. b18cb6a Make the POWER hardware capability value a global in crypto.c. by Adam Langley · 8 years ago
  43. 67bb45f Support enabling early data on SSL by Alessandro Ghedini · 8 years ago
  44. 7e9949c Import additional test vectors from RFC 8032. by David Benjamin · 8 years ago
  45. 17eeb98 Unwind the rest of EVP_PKEY_supports_digest. by David Benjamin · 8 years ago
  46. 764ab98 Support and test P-224 certificates. by Adam Langley · 8 years ago
  47. fc2d78d Document server 0-RTT behavior. by David Benjamin · 8 years ago
  48. 2a07072 Prevent Channel ID and Custom Extensions on 0-RTT. by Steven Valdez · 8 years ago
  49. 02084ea Decouple PKCS8_encrypt and PKCS8_decrypt's core from crypto/asn1. by David Benjamin · 8 years ago
  50. f466cdb size_t the RSA padding add functions. by David Benjamin · 8 years ago
  51. 3cb047e Decouple PKCS#12 hash lookup from the OID table. by David Benjamin · 8 years ago
  52. 2d85062 Add Data-less Zero-RTT support. by Steven Valdez · 8 years ago
  53. 57e81e6 Name |select_certificate_cb| return values by Alessandro Ghedini · 8 years ago
  54. 2d05568 Fix out-of-memory condition in conf. by David Benjamin · 8 years ago
  55. 8c64679 Remove BIGNUM and CBIGNUM crypto/asn1 types. by David Benjamin · 8 years ago
  56. eb30288 Remove crypto/asn1 LONG and ZLONG. by David Benjamin · 8 years ago
  57. edb7299 Fix typo in the |ssl_ticket_aead_success| documentation by Alessandro Ghedini · 8 years ago
  58. 438229a Correct a typo in ASN.1 type name. by Victor Vasiliev · 8 years ago
  59. 48e1d18 Restore SSL_CTX_set_ecdh_auto compatibility hook. by David Benjamin · 8 years ago
  60. 4c341d0 Support asynchronous ticket decryption with TLS 1.0–1.2. by Adam Langley · 8 years ago
  61. be49706 Rename initial_ctx to session_ctx. by David Benjamin · 8 years ago
  62. 6ad20dc Move error-on-empty-cipherlist into ssl_create_cipher_list(). by Matthew Braithwaite · 8 years ago
  63. d04ca95 Add |SSL[_CTX]_set_chain_and_key|. by Adam Langley · 8 years ago
  64. 35ac5b7 Export server-side ticket_age skew. by David Benjamin · 8 years ago
  65. fe36672 Allow users of the |CRYPTO_BUFFER|-based methods to verify certs after the handshake. by Adam Langley · 8 years ago
  66. 8ebeabf Add SSL_CTX_get_ciphers. by David Benjamin · 8 years ago
  67. f29c429 Remove support for old-style SSL_PRIVATE_KEY_METHOD types. by David Benjamin · 8 years ago
  68. f465461 Add SSL_get0_peer_certificates. by David Benjamin · 8 years ago
  69. 924a352 Remove experimental TLS 1.3 short record header extension. by Steven Valdez · 8 years ago
  70. d6c22ee Add |SSL_get0_server_requested_CAs|. by Adam Langley · 8 years ago
  71. a58baaf Forbid the server certificate from changing on renego. by David Benjamin · 8 years ago
  72. ad8f5e1 Don't use long for timestamps. by David Benjamin · 8 years ago
  73. 11c8289 Remove support for blocking DTLS timeout handling. by David Benjamin · 8 years ago
  74. 39425b0 Add |TLS_with_buffers_method|. by Adam Langley · 8 years ago
  75. 34b4c82 Hold CA names as |CRYPTO_BUFFER|s. by Adam Langley · 8 years ago
  76. adec772 Remove SSL_CIPHER_has_MD5_HMAC. by David Benjamin · 8 years ago
  77. de5c325 Fix SSL_write doc comment by Michel Lespinasse · 8 years ago
  78. a57dcfb Add new cipherlist-setting APIs that reject nonsense. by Matthew Braithwaite · 8 years ago
  79. c4796c9 ECDSA: const EC_KEY* arguments where possible. by Matthew Braithwaite · 8 years ago
  80. 699e55b Unexport time_support.h. by David Benjamin · 8 years ago
  81. c92f29d Remove freelist_max_len. by David Benjamin · 8 years ago
  82. 3e8b782 Remove "raw" versions of PKCS8_encrypt and PKCS8_decrypt. by David Benjamin · 8 years ago
  83. 5960a90 Move sid_ctx from SSL/SSL_CTX to CERT. by David Benjamin · 8 years ago
  84. 26e1ff3 Remove some unnecessary return values. by David Benjamin · 8 years ago
  85. 27a9e6a Adding ALPN to session. by Steven Valdez · 8 years ago
  86. 83a3212 Move SCT lists and OCSP responses to CERT. by David Benjamin · 8 years ago
  87. 16b1b1d Simplify state and info_callback management. by David Benjamin · 8 years ago
  88. 77458a4 Avoid transitioning into SSL_ST_OK and back out. by David Benjamin · 8 years ago
  89. 9e766d7 Unexport the handshake's internal state. by David Benjamin · 8 years ago
  90. 46db7af Remove |X509| things from SSL_SESSION. by Adam Langley · 8 years ago
  91. 908ac19 Moving transcript and PRF functions to SSL_TRANSCRIPT. by Steven Valdez · 8 years ago
  92. b987355 Add BN_is_pow2, BN_mod_pow2, and BN_nnmod_pow2. by Rob Sloan · 8 years ago
  93. 3509dac Add |X509_METHOD| and, using it, move many functions to ssl_x509.c. by Adam Langley · 8 years ago
  94. dc8c1d9 Remove some dead state constants. by David Benjamin · 8 years ago
  95. 8df6766 Support setting per-connection SCT list by Alessandro Ghedini · 8 years ago
  96. 33fe4a0 Remove support for setting per-connection default session timeout by Alessandro Ghedini · 8 years ago
  97. 3f2611a Hide SSL struct. by David Benjamin · 8 years ago
  98. 58966a4 Remove legacy ChaCha20-Poly1305 cipher name aliases. by David Benjamin · 8 years ago
  99. 2056f63 Recommend ex_data for SSL_CTX_set_cert_verify_callback. by David Benjamin · 8 years ago
  100. bdcfd13 Move the SSL BIO into ssl/ from decrepit/. by Adam Langley · 8 years ago