1. 92de0b5 Reject bad ASN.1 templates with implicitly-tagged CHOICEs. by David Benjamin · 4 years, 4 months ago
  2. 1920c6f Implement GREASE for ECH (draft-ietf-tls-esni-08). by Dan McArdle · 5 years ago
  3. 225961d Const-correct GENERAL_NAME_cmp. by David Benjamin · 4 years, 4 months ago
  4. aa4ecb4 Fix EDIPartyName parsing and GENERAL_NAME_cmp. by David Benjamin · 4 years, 5 months ago
  5. 455b78d PWCT failures should clear the generated key. by Adam Langley · 4 years, 4 months ago
  6. 3094902 Get closer to Ed25519 boundary conditions. by David Benjamin · 4 years, 4 months ago
  7. 5763899 Update FIPS.md to include latest FIPS certificate. by Adam Langley · 4 years, 4 months ago
  8. eb57cc1 aesv8-armx.pl: avoid 32-bit lane assignment in CTR mode by David Benjamin · 4 years, 4 months ago
  9. f8047e2 Improve sk_dup. by Aaron zhang · 4 years, 4 months ago
  10. 1bec252 Poly1305: Use |size_t|; assert |poly1305_state| is large enough. by Brian Smith · 4 years, 4 months ago
  11. 9dae0ac Add digest.h to self_check.c by Adam Langley · 4 years, 4 months ago
  12. 8846533 Add FIPS self test for the TLS KDF. by Adam Langley · 4 years, 4 months ago
  13. 53bbb18 Const-correct and document more X509 functions. by David Benjamin · 4 years, 5 months ago
  14. 354e1e9 Add APIs for checking ASN.1 INTEGERs. by David Benjamin · 4 years, 7 months ago
  15. 43f3756 Remove some unnecessary pointer casts. by David Benjamin · 4 years, 5 months ago
  16. 2361677 Document the basic ASN1_STRING functions. by David Benjamin · 4 years, 5 months ago
  17. 2e5f38a Rearrange ASN1_STRING_copy slightly. by David Benjamin · 4 years, 5 months ago
  18. c509ee3 Switch M_ASN1_TIME macros within the library. by David Benjamin · 4 years, 5 months ago
  19. c6ffcde Unwind M_ASN1_* macros for primitive types. by David Benjamin · 4 years, 5 months ago
  20. 9bdec29 Remove ASN1_STRING_FLAG_NDEF. by David Benjamin · 4 years, 7 months ago
  21. e4da107 Unexport internal crypto/asn1 functions. by David Benjamin · 4 years, 9 months ago
  22. 9e282c9 Unwind some old ASN.1 ifdefs. by David Benjamin · 4 years, 9 months ago
  23. 3de5949 Unwind ASN1_PRIMITIVE_FUNCS. by David Benjamin · 4 years, 9 months ago
  24. 45858ae Unwind ASN1_TFLG_NDEF. by David Benjamin · 4 years, 9 months ago
  25. 75a05d1 Unwind ASN1_ITYPE_COMPAT. by David Benjamin · 4 years, 9 months ago
  26. cf1c925 Unwind ASN1_AFLG_BROKEN. by David Benjamin · 4 years, 9 months ago
  27. a93545c Const-correct various X509 string parameters. by David Benjamin · 4 years, 5 months ago
  28. 352351b Remove sk_new_null call. by David Benjamin · 4 years, 7 months ago
  29. 17e530c Fix x509_rsa_ctx_to_pss when saltlen is md_size. by David Benjamin · 4 years, 5 months ago
  30. 8591d53 Document the X509V3_get_d2i family of functions. by David Benjamin · 4 years, 5 months ago
  31. 6dcce80 Add functions for manipulating X.509 TBS structures. by David Benjamin · 4 years, 5 months ago
  32. 7c4a3f7 Add ECDSA verify KAT to FIPS self-tests. by Adam Langley · 4 years, 5 months ago
  33. 83a3f46 Add AES-GCM AEADs with internal nonce generation. by Adam Langley · 4 years, 5 months ago
  34. d5b2b17 Define a constant for the standard GCM nonce length. by Adam Langley · 4 years, 5 months ago
  35. 1a751ee Add test for X25519-containing certificate. by Adam Langley · 4 years, 5 months ago
  36. 0782715 Add raw redeem API. by Steven Valdez · 4 years, 6 months ago
  37. b67732a aarch64: Remove some flavour conditionals by Tamas Petz · 4 years, 5 months ago
  38. c583dbe Have fewer opaque booleans in aead_test.cc by Adam Langley · 4 years, 5 months ago
  39. 80e3f95 Support 4096-bit keys in FIPS mode. by Adam Langley · 4 years, 5 months ago
  40. 40f4942 Reland "Check AlgorithmIdentifier parameters for RSA and ECDSA signatures."" by David Benjamin · 4 years, 5 months ago
  41. 043fba2 Clear some reported gcc -Wshadow warnings. by David Benjamin · 4 years, 5 months ago
  42. e9fce74 Const-correct X509V3_extensions_print. by David Benjamin · 4 years, 5 months ago
  43. 51607f1 Implement draft-vvv-tls-alps-01. by Steven Valdez · 4 years, 8 months ago
  44. 3989c99 Fix crash when flushing an SSL BIO. by David Benjamin · 4 years, 6 months ago
  45. f2b2ef8 Update TrustTokenV2 to use VOPRFs and assemble RR. by Steven Valdez · 4 years, 6 months ago
  46. 51b4281 Include rodata subsections in FIPS-shared build. by Adam Langley · 4 years, 6 months ago
  47. 991835d Switch x509_test.cc to use C++ raw string literals. by David Benjamin · 4 years, 6 months ago
  48. 723faad Fix some malloc error handling. by David Benjamin · 4 years, 6 months ago
  49. 9bf1634 Move Trusty workaround to the OPENSSL_LINUX define. by David Benjamin · 4 years, 6 months ago
  50. 6b6b66b Disable fork detection on Trusty. by Pete Bentley · 4 years, 6 months ago
  51. 5850a01 Disable check that X.509 extensions implies v3. by Adam Langley · 4 years, 6 months ago
  52. b13e7b5 Silence some clang warnings on macOS and iOS CQ bots. by David Benjamin · 4 years, 6 months ago
  53. cefbf9c Const-correct X509_get0_extensions. by David Benjamin · 4 years, 6 months ago
  54. 9adcb0a Add TrustTokenV2. by Steven Valdez · 4 years, 7 months ago
  55. ee4af9e Add X509_get_pathlen and X509_REVOKED_get0_extensions. by David Benjamin · 4 years, 7 months ago
  56. 5eeaf30 Add some accommodations for FreeRDP by Adam Langley · 4 years, 6 months ago
  57. ca3f243 Require non-NULL store in X509_STORE_CTX_init. by David Benjamin · 4 years, 7 months ago
  58. 6d70353 Const-correct X509V3_CONF_METHOD. by David Benjamin · 4 years, 7 months ago
  59. 6247347 Avoid unions in X509_NAME logic. by David Benjamin · 4 years, 7 months ago
  60. 49e9f67 Bump OPENSSL_VERSION_NUMBER to 1.1.1. by David Benjamin · 4 years, 7 months ago
  61. 6ad3b46 Remove ASN1_STRING_length_set. by David Benjamin · 4 years, 7 months ago
  62. 6a263ce Revert "Check AlgorithmIdentifier parameters for RSA and ECDSA signatures." by Adam Langley · 4 years, 7 months ago
  63. bc24805 Implement PSK variants of HPKE setup functions. by Daniel McArdle · 4 years, 7 months ago
  64. 4ef5de0 Document a few more functions in x509.h. by David Benjamin · 4 years, 7 months ago
  65. 298d8be Add subject key ID and authority key ID accessors. by David Benjamin · 4 years, 7 months ago
  66. 1c58648 Remove sxnet and pkey_usage_period extensions. by David Benjamin · 4 years, 9 months ago
  67. 125a38f Const-correct various X509 functions. by David Benjamin · 4 years, 7 months ago
  68. 95d8eaa Make X509_set_not{Before,After} functions rather than macros. by David Benjamin · 4 years, 7 months ago
  69. 48cb69f Add X509_get0_uids from OpenSSL 1.1.0. by David Benjamin · 4 years, 7 months ago
  70. 9372f38 Bound RSA and DSA key sizes better. by David Benjamin · 4 years, 8 months ago
  71. c947efa Add set1 versions of X509 timestamp setters. by David Benjamin · 4 years, 7 months ago
  72. 430ccd6 Update HPKE implementation and test vectors to draft-irtf-cfrg-hpke-05. by Daniel McArdle · 4 years, 8 months ago
  73. d3a5b87 Handle NULL arguments in some i2d_* functions. by Adam Langley · 4 years, 8 months ago
  74. a0b49d6 aarch64: support BTI and pointer authentication in assembly by Tamas Petz · 4 years, 10 months ago
  75. 74161f4 Enforce presence of ALPN when QUIC is in use. by Nick Harper · 4 years, 8 months ago
  76. 7d3a24d Fix the naming of alert error codes. by David Benjamin · 4 years, 8 months ago
  77. db129f3 Add X509_SIG_get0 and X509_SIG_getm. by David Benjamin · 4 years, 8 months ago
  78. 8b601c8 Implement HPKE. by Daniel McArdle · 4 years, 9 months ago
  79. cac9392 Disallow TLS 1.3 compatibility mode in QUIC. by Nick Harper · 5 years ago
  80. 83b74c6 Add details of 20190808 FIPS certification. by Adam Langley · 4 years, 9 months ago
  81. 8f88b27 Link to ws2_32 more consistently. by David Benjamin · 4 years, 9 months ago
  82. de19612 Allow explicitly-encoded X.509v1 versions for now. by David Benjamin · 4 years, 9 months ago
  83. eda849d Opaquify PKCS8_PRIV_KEY_INFO. by David Benjamin · 4 years, 9 months ago
  84. 5d7c2f8 Implement i2d_PUBKEY and friends without crypto/asn1. by David Benjamin · 4 years, 9 months ago
  85. d0637e9 Remove TRUST_TOKEN_experiment_v0. by Steven Valdez · 4 years, 10 months ago
  86. 25638f0 Remove x509->name. by David Benjamin · 4 years, 9 months ago
  87. 939d426 Maybe build for AArch64 Windows. by Adam Langley · 4 years, 9 months ago
  88. e2abade sha1-x86_64: fix CFI. by Adam Langley · 4 years, 9 months ago
  89. 5d74463 Use |crypto_word_t| and |size_t| more consistently in ECC scalar recoding. by Brian Smith · 4 years, 10 months ago
  90. 7361ee4 Enable shaext path for sha1. by Ilya Tokar · 4 years, 9 months ago
  91. 430a742 Const-correct various functions in crypto/asn1. by David Benjamin · 4 years, 9 months ago
  92. 33f8d33 Convert X.509 accessor macros to proper functions. by David Benjamin · 4 years, 9 months ago
  93. 9dd9d4f Check AlgorithmIdentifier parameters for RSA and ECDSA signatures. by David Benjamin · 4 years, 9 months ago
  94. dd86e75 Check the X.509 version when parsing. by David Benjamin · 4 years, 10 months ago
  95. fd86eaa Fix x509v3_cache_extensions error-handling. by David Benjamin · 4 years, 10 months ago
  96. 5ddc5b1 Move crypto/x509 test data into its own directory. by David Benjamin · 4 years, 10 months ago
  97. 7f90eda Add “Z Computation” KAT. by Adam Langley · 4 years, 10 months ago
  98. 0313b59 Let memory hooks override the size prefix. by Adam Langley · 4 years, 10 months ago
  99. 251b516 Assert md_size > 0. by David Benjamin · 4 years, 10 months ago
  100. 2309f64 Use ctr32 optimizations for AES_ctr128_encrypt. by David Benjamin · 4 years, 10 months ago