- 971b330 Use the same Deleter across all bssl::UniquePtr<T>. by David Benjamin · 2 years, 2 months ago
- 1e97ce3 Don't send two post-quantum initial key shares. by Adam Langley · 2 years, 2 months ago
- fc07738 Add stubs for hybrid Kyber768 with X25519 or P-256. by Adam Langley · 2 years, 3 months ago
- df8a55b Const-correct sk_FOO_deep_copy's copy callback. by David Benjamin · 2 years, 3 months ago
- 05b360d Remove hmac.h include from ssl.h. by Piotr Sikora · 2 years, 2 months ago
- 3251ca1 Simplify MSVC warning configuration by David Benjamin · 2 years, 2 months ago
- ec6425ca Drop the preference for 256-bit ciphers with CECPQ2. by Adam Langley · 2 years, 3 months ago
- a614d46 Add SSL_was_key_usage_invalid. by David Benjamin · 2 years, 4 months ago
- c7b255e Add NO_CHECK_TIME to SSLTest.ECHBuiltinVerifier too by David Benjamin · 2 years, 4 months ago
- 28f96c2 Fix timebomb by disabling time check in this test by Bob Beck · 2 years, 4 months ago
- 02f7705 Add int casts to BIO_ctrl calls where appropriate. by David Benjamin · 2 years, 4 months ago
- 3a1b730 Don't allow the caller to configure invalid signature algorithms. by David Benjamin · 2 years, 4 months ago
- e8f57ca Never accidentally use SSL_SIGN_RSA_PKCS1_MD5_SHA1 at TLS 1.2. by David Benjamin · 2 years, 4 months ago
- 5511fa8 Migrate io/ioutil uses to new APIs. by David Benjamin · 2 years, 4 months ago
- a1dffbf Define CBS/CBB tags as uint32_t with a typedef. by David Benjamin · 2 years, 5 months ago
- 7ac94aa More -Wshorten-64-to-32 fixes. by David Benjamin · 2 years, 5 months ago
- 1045897 Allow using the TLS exporter in more cases. by Nick Harper · 2 years, 5 months ago
- 4b35543 Revert "Default SSL_set_enforce_rsa_key_usage to enabled." by David Benjamin · 2 years, 5 months ago
- 9d64d8d Miscellaneous -Wshorten-64-to-32 fixes. by David Benjamin · 2 years, 7 months ago
- 19d6ec9 Check for TLS 1.3 in SSL_generate_key_block. by David Benjamin · 2 years, 6 months ago
- 64393b5 Default SSL_set_enforce_rsa_key_usage to enabled. by David Benjamin · 2 years, 6 months ago
- 80eb814 Remove the experimental in-place record APIs. by David Benjamin · 2 years, 6 months ago
- 32013e8 Maintain the sequence number as a uint64_t. by David Benjamin · 2 years, 6 months ago
- 46af243 Use Array<uint8_t> in DTLS1_OUTGOING_MESSAGE. by David Benjamin · 2 years, 7 months ago
- 361e3e0 Move the DTLS cookie to SSL_HANDSHAKE. by David Benjamin · 2 years, 7 months ago
- 7b2795a Replace even more ad-hoc bytes/integer conversions. by David Benjamin · 2 years, 7 months ago
- 9f426b6 Specify all library install destinations by Don · 2 years, 7 months ago
- e8e6cac Add the "groups" variants of SSL_CTX_set1_curves_list. by David Benjamin · 2 years, 7 months ago
- 10fef97 Prefer established session properties mid renegotiation. by David Benjamin · 2 years, 7 months ago
- ebd8b89 Track SSL_ERROR_ZERO_RETURN explicitly. by David Benjamin · 2 years, 8 months ago
- 401137f Add a test for SSL_CTX_set_quiet_shutdown. by David Benjamin · 2 years, 8 months ago
- adaa322 Add handshake hints for TLS 1.2 session tickets. by David Benjamin · 2 years, 8 months ago
- 4da5a94 Fix SSL_load_client_CA_file when given an empty file. by David Benjamin · 2 years, 8 months ago
- b7d6320 Replace OPENSSL_STATIC_ASSERT with static_assert. by David Benjamin · 2 years, 8 months ago
- 5cb597e Test that close_notify state does not impair SSL_ERROR_SYSCALL. by David Benjamin · 2 years, 8 months ago
- 4bd32a8 Convert more of the SSL write path to size_t and Spans. by David Benjamin · 3 years, 11 months ago
- 4a6c8fd Support handshake hints for TLS 1.2 full handshakes. by David Benjamin · 2 years, 8 months ago
- b95c7e5 Fix up book-keeping between the write buffer and pending writes. by David Benjamin · 2 years, 8 months ago
- 64bf8c5 Fix an edge case in SSL_write's retry mechanism. by David Benjamin · 2 years, 8 months ago
- 5697a92 Add SSL_CTX_get_num_tickets. by David Benjamin · 2 years, 8 months ago
- a6981a3 More alignment with OpenSSL on TLS 1.3 cipher suite constants. by Bob Beck · 2 years, 8 months ago
- dfddbc4 Align with OpenSSL on TLS 1.3 cipher suite constants. by David Benjamin · 2 years, 8 months ago
- 955ef79 Rewrite SSL_add_file_cert_subjects_to_stack by David Benjamin · 2 years, 10 months ago
- 451ea3c Add SSL_[CTX_]_set_compliance_policy. by Adam Langley · 2 years, 10 months ago
- 3f180b8 Implement SSL_CTX_set_num_tickets. by David Benjamin · 2 years, 11 months ago
- 48f7947 Fix build for older CMake versions. by Daniel Thornburgh · 2 years, 11 months ago
- 493d5cb Try to require C++14. by David Benjamin · 3 years ago
- 2fc6d38 Add CMake install rules. by Daniel Thornburgh · 3 years ago
- 2144076 Remove VS 2015 support. by David Benjamin · 3 years ago
- c76da9d HPKE is now RFC 9180. by David Benjamin · 3 years, 1 month ago
- 5112b45 Support Bazel's test-sharding protocol. by Adam Langley · 3 years, 2 months ago
- 123eaae Record ClientHelloInner values in msg_callback. by David Benjamin · 3 years, 2 months ago
- 44425dd Fold ssl_decode_client_hello_inner into ssl_client_hello_decrypt. by David Benjamin · 3 years, 2 months ago
- 7198d11 Explicitly reject self-referential ech_outer_extensions. by David Benjamin · 3 years, 2 months ago
- 0f4454c Condition split handshake tests on Linux in CMake. by David Benjamin · 3 years, 2 months ago
- 50e7ea5 LSC: Apply clang-tidy's modernize-use-bool-literals to boringssl by Anton Bikineev · 3 years, 2 months ago
- d7936c2 Use uint16_t in TestConfig and enable -Wformat-signedness. by David Benjamin · 3 years, 3 months ago
- 203b92b Reorder flags to match TestConfig struct. by David Benjamin · 3 years, 3 months ago
- 8ed06e0 Rewrite bssl_shim command-line parser. by David Benjamin · 3 years, 3 months ago
- 4f1fae3 Fix the easy -Wformat-signedness errors. by David Benjamin · 3 years, 3 months ago
- c3c540b Remove non-standard X.509 DNS wildcard matching. by David Benjamin · 3 years, 4 months ago
- 7e7e6b6 Add |SSL_set1_host| and |SSL_set_hostflags|. by Adam Langley · 3 years, 4 months ago
- b3ed071 Add SSL_has_pending. by David Benjamin · 3 years, 4 months ago
- ea57bcb Update HPKE test vectors. by David Benjamin · 3 years, 4 months ago
- 69030a0 Match OPENSSL_EXPORT in ssl/internal.h friend declarations. by David Benjamin · 3 years, 5 months ago
- c2827d3 Add a function to express the desired record version protocol. by Adam Langley · 3 years, 5 months ago
- 7a4df8e Tidy up SSLTest.SetVersion. by David Benjamin · 3 years, 5 months ago
- c31a8a6 Fold x509_vfy.h into x509.h. by David Benjamin · 3 years, 6 months ago
- 27a3328 Fix the TLS fuzzers for ECH draft-13. by David Benjamin · 3 years, 6 months ago
- 0fa3030 Update comment for ECH draft-13. by David Benjamin · 3 years, 7 months ago
- 1a668b3 Switch to the new, simpler WHATWG URL formulation. by David Benjamin · 3 years, 7 months ago
- 19fe794 Fix calculation of draft-13 ECH confirmation signal. by David Benjamin · 3 years, 7 months ago
- 18b6836 Update to draft-ietf-tls-esni-13. by David Benjamin · 3 years, 9 months ago
- 07b365f Remove SSL_set_verify_result. by David Benjamin · 3 years, 7 months ago
- dddb60e Make most of crypto/x509 opaque. by David Benjamin · 3 years, 8 months ago
- d55f450 Avoid re-hashing the transcript multiple times. by David Benjamin · 3 years, 8 months ago
- a75027b Make ssl_parse_extensions a little easier to use. by David Benjamin · 3 years, 8 months ago
- e2cb423 Deduplicate our three ServerHello parsers. by David Benjamin · 3 years, 9 months ago
- 9545062 Add a CBB_add_zeros helper. by David Benjamin · 3 years, 8 months ago
- 8648c53 Refer to RFCs consistently. by David Benjamin · 3 years, 7 months ago
- 16c3e3a runner: Test session IDs over 32 bytes. by David Benjamin · 3 years, 9 months ago
- 05ce773 Process the TLS 1.3 cipher suite in one place. by David Benjamin · 3 years, 9 months ago
- 006f20a Add Span::first() and Span::last(). by David Benjamin · 3 years, 9 months ago
- 69ec7c8 Fix some error returns from SSL_read and SSL_write. by David Benjamin · 3 years, 8 months ago
- 7153013 hrss: use less stack space. by Adam Langley · 3 years, 9 months ago
- b86dcfe Switch another malloc to bssl::Array. by David Benjamin · 3 years, 9 months ago
- ad5db96 Handle the server case in SSL_get0_ech_name_override. by David Benjamin · 3 years, 9 months ago
- 5514476 Update hpke_test.go. by Adam Langley · 3 years, 9 months ago
- ba423c9 Implement ClientHelloOuter handshakes. by David Benjamin · 3 years, 9 months ago
- ca7ef8c runner: Add a convenience function for base64 flags. by David Benjamin · 3 years, 9 months ago
- a10017c Reduce bouncing on the cache lock in ssl_update_cache. by David Benjamin · 3 years, 9 months ago
- 10a76ac Only clear not_resumable after the handshake. by David Benjamin · 3 years, 9 months ago
- afa867b runner: Test that clients actually use renewed tickets. by David Benjamin · 3 years, 9 months ago
- 5d224a5 runner: Clean up test logic. by David Benjamin · 3 years, 9 months ago
- c41a3a9 runner: Fix process exit timeout. by David Benjamin · 3 years, 9 months ago
- 7f85116 Unexport almost all of LHASH. by David Benjamin · 3 years, 9 months ago
- ec552ca Rename t1_lib.cc to extensions.cc. by David Benjamin · 3 years, 9 months ago
- 9cbe737 Validate ECH public names. by David Benjamin · 3 years, 9 months ago
- 9734e44 More reliably report handshake errors through SSL_write. by David Benjamin · 3 years, 9 months ago
- e9c5d72 Add an option to permute ClientHello extension order. by David Benjamin · 3 years, 10 months ago