- 92de0b5 Reject bad ASN.1 templates with implicitly-tagged CHOICEs. by David Benjamin · 4 years, 4 months ago
- 1920c6f Implement GREASE for ECH (draft-ietf-tls-esni-08). by Dan McArdle · 5 years ago
- 225961d Const-correct GENERAL_NAME_cmp. by David Benjamin · 4 years, 4 months ago
- aa4ecb4 Fix EDIPartyName parsing and GENERAL_NAME_cmp. by David Benjamin · 4 years, 5 months ago
- 455b78d PWCT failures should clear the generated key. by Adam Langley · 4 years, 4 months ago
- 3094902 Get closer to Ed25519 boundary conditions. by David Benjamin · 4 years, 4 months ago
- 5763899 Update FIPS.md to include latest FIPS certificate. by Adam Langley · 4 years, 4 months ago
- eb57cc1 aesv8-armx.pl: avoid 32-bit lane assignment in CTR mode by David Benjamin · 4 years, 4 months ago
- f8047e2 Improve sk_dup. by Aaron zhang · 4 years, 4 months ago
- 1bec252 Poly1305: Use |size_t|; assert |poly1305_state| is large enough. by Brian Smith · 4 years, 4 months ago
- 9dae0ac Add digest.h to self_check.c by Adam Langley · 4 years, 4 months ago
- 8846533 Add FIPS self test for the TLS KDF. by Adam Langley · 4 years, 4 months ago
- 53bbb18 Const-correct and document more X509 functions. by David Benjamin · 4 years, 5 months ago
- 354e1e9 Add APIs for checking ASN.1 INTEGERs. by David Benjamin · 4 years, 7 months ago
- 43f3756 Remove some unnecessary pointer casts. by David Benjamin · 4 years, 5 months ago
- 2361677 Document the basic ASN1_STRING functions. by David Benjamin · 4 years, 5 months ago
- 2e5f38a Rearrange ASN1_STRING_copy slightly. by David Benjamin · 4 years, 5 months ago
- c509ee3 Switch M_ASN1_TIME macros within the library. by David Benjamin · 4 years, 5 months ago
- c6ffcde Unwind M_ASN1_* macros for primitive types. by David Benjamin · 4 years, 5 months ago
- 9bdec29 Remove ASN1_STRING_FLAG_NDEF. by David Benjamin · 4 years, 7 months ago
- e4da107 Unexport internal crypto/asn1 functions. by David Benjamin · 4 years, 9 months ago
- 9e282c9 Unwind some old ASN.1 ifdefs. by David Benjamin · 4 years, 9 months ago
- 3de5949 Unwind ASN1_PRIMITIVE_FUNCS. by David Benjamin · 4 years, 9 months ago
- 45858ae Unwind ASN1_TFLG_NDEF. by David Benjamin · 4 years, 9 months ago
- 75a05d1 Unwind ASN1_ITYPE_COMPAT. by David Benjamin · 4 years, 9 months ago
- cf1c925 Unwind ASN1_AFLG_BROKEN. by David Benjamin · 4 years, 9 months ago
- a93545c Const-correct various X509 string parameters. by David Benjamin · 4 years, 5 months ago
- 352351b Remove sk_new_null call. by David Benjamin · 4 years, 7 months ago
- 17e530c Fix x509_rsa_ctx_to_pss when saltlen is md_size. by David Benjamin · 4 years, 5 months ago
- 8591d53 Document the X509V3_get_d2i family of functions. by David Benjamin · 4 years, 5 months ago
- 6dcce80 Add functions for manipulating X.509 TBS structures. by David Benjamin · 4 years, 5 months ago
- 7c4a3f7 Add ECDSA verify KAT to FIPS self-tests. by Adam Langley · 4 years, 5 months ago
- 83a3f46 Add AES-GCM AEADs with internal nonce generation. by Adam Langley · 4 years, 5 months ago
- d5b2b17 Define a constant for the standard GCM nonce length. by Adam Langley · 4 years, 5 months ago
- 1a751ee Add test for X25519-containing certificate. by Adam Langley · 4 years, 5 months ago
- 0782715 Add raw redeem API. by Steven Valdez · 4 years, 6 months ago
- b67732a aarch64: Remove some flavour conditionals by Tamas Petz · 4 years, 5 months ago
- c583dbe Have fewer opaque booleans in aead_test.cc by Adam Langley · 4 years, 5 months ago
- 80e3f95 Support 4096-bit keys in FIPS mode. by Adam Langley · 4 years, 5 months ago
- 40f4942 Reland "Check AlgorithmIdentifier parameters for RSA and ECDSA signatures."" by David Benjamin · 4 years, 5 months ago
- 043fba2 Clear some reported gcc -Wshadow warnings. by David Benjamin · 4 years, 5 months ago
- e9fce74 Const-correct X509V3_extensions_print. by David Benjamin · 4 years, 5 months ago
- 51607f1 Implement draft-vvv-tls-alps-01. by Steven Valdez · 4 years, 8 months ago
- 3989c99 Fix crash when flushing an SSL BIO. by David Benjamin · 4 years, 6 months ago
- f2b2ef8 Update TrustTokenV2 to use VOPRFs and assemble RR. by Steven Valdez · 4 years, 6 months ago
- 51b4281 Include rodata subsections in FIPS-shared build. by Adam Langley · 4 years, 6 months ago
- 991835d Switch x509_test.cc to use C++ raw string literals. by David Benjamin · 4 years, 6 months ago
- 723faad Fix some malloc error handling. by David Benjamin · 4 years, 6 months ago
- 9bf1634 Move Trusty workaround to the OPENSSL_LINUX define. by David Benjamin · 4 years, 6 months ago
- 6b6b66b Disable fork detection on Trusty. by Pete Bentley · 4 years, 6 months ago
- 5850a01 Disable check that X.509 extensions implies v3. by Adam Langley · 4 years, 6 months ago
- b13e7b5 Silence some clang warnings on macOS and iOS CQ bots. by David Benjamin · 4 years, 6 months ago
- cefbf9c Const-correct X509_get0_extensions. by David Benjamin · 4 years, 6 months ago
- 9adcb0a Add TrustTokenV2. by Steven Valdez · 4 years, 7 months ago
- ee4af9e Add X509_get_pathlen and X509_REVOKED_get0_extensions. by David Benjamin · 4 years, 7 months ago
- 5eeaf30 Add some accommodations for FreeRDP by Adam Langley · 4 years, 6 months ago
- ca3f243 Require non-NULL store in X509_STORE_CTX_init. by David Benjamin · 4 years, 7 months ago
- 6d70353 Const-correct X509V3_CONF_METHOD. by David Benjamin · 4 years, 7 months ago
- 6247347 Avoid unions in X509_NAME logic. by David Benjamin · 4 years, 7 months ago
- 49e9f67 Bump OPENSSL_VERSION_NUMBER to 1.1.1. by David Benjamin · 4 years, 7 months ago
- 6ad3b46 Remove ASN1_STRING_length_set. by David Benjamin · 4 years, 7 months ago
- 6a263ce Revert "Check AlgorithmIdentifier parameters for RSA and ECDSA signatures." by Adam Langley · 4 years, 7 months ago
- bc24805 Implement PSK variants of HPKE setup functions. by Daniel McArdle · 4 years, 7 months ago
- 4ef5de0 Document a few more functions in x509.h. by David Benjamin · 4 years, 7 months ago
- 298d8be Add subject key ID and authority key ID accessors. by David Benjamin · 4 years, 7 months ago
- 1c58648 Remove sxnet and pkey_usage_period extensions. by David Benjamin · 4 years, 9 months ago
- 125a38f Const-correct various X509 functions. by David Benjamin · 4 years, 7 months ago
- 95d8eaa Make X509_set_not{Before,After} functions rather than macros. by David Benjamin · 4 years, 7 months ago
- 48cb69f Add X509_get0_uids from OpenSSL 1.1.0. by David Benjamin · 4 years, 7 months ago
- 9372f38 Bound RSA and DSA key sizes better. by David Benjamin · 4 years, 8 months ago
- c947efa Add set1 versions of X509 timestamp setters. by David Benjamin · 4 years, 7 months ago
- 430ccd6 Update HPKE implementation and test vectors to draft-irtf-cfrg-hpke-05. by Daniel McArdle · 4 years, 8 months ago
- d3a5b87 Handle NULL arguments in some i2d_* functions. by Adam Langley · 4 years, 8 months ago
- a0b49d6 aarch64: support BTI and pointer authentication in assembly by Tamas Petz · 4 years, 10 months ago
- 74161f4 Enforce presence of ALPN when QUIC is in use. by Nick Harper · 4 years, 8 months ago
- 7d3a24d Fix the naming of alert error codes. by David Benjamin · 4 years, 8 months ago
- db129f3 Add X509_SIG_get0 and X509_SIG_getm. by David Benjamin · 4 years, 8 months ago
- 8b601c8 Implement HPKE. by Daniel McArdle · 4 years, 9 months ago
- cac9392 Disallow TLS 1.3 compatibility mode in QUIC. by Nick Harper · 5 years ago
- 83b74c6 Add details of 20190808 FIPS certification. by Adam Langley · 4 years, 9 months ago
- 8f88b27 Link to ws2_32 more consistently. by David Benjamin · 4 years, 9 months ago
- de19612 Allow explicitly-encoded X.509v1 versions for now. by David Benjamin · 4 years, 9 months ago
- eda849d Opaquify PKCS8_PRIV_KEY_INFO. by David Benjamin · 4 years, 9 months ago
- 5d7c2f8 Implement i2d_PUBKEY and friends without crypto/asn1. by David Benjamin · 4 years, 9 months ago
- d0637e9 Remove TRUST_TOKEN_experiment_v0. by Steven Valdez · 4 years, 10 months ago
- 25638f0 Remove x509->name. by David Benjamin · 4 years, 9 months ago
- 939d426 Maybe build for AArch64 Windows. by Adam Langley · 4 years, 9 months ago
- e2abade sha1-x86_64: fix CFI. by Adam Langley · 4 years, 9 months ago
- 5d74463 Use |crypto_word_t| and |size_t| more consistently in ECC scalar recoding. by Brian Smith · 4 years, 10 months ago
- 7361ee4 Enable shaext path for sha1. by Ilya Tokar · 4 years, 9 months ago
- 430a742 Const-correct various functions in crypto/asn1. by David Benjamin · 4 years, 9 months ago
- 33f8d33 Convert X.509 accessor macros to proper functions. by David Benjamin · 4 years, 9 months ago
- 9dd9d4f Check AlgorithmIdentifier parameters for RSA and ECDSA signatures. by David Benjamin · 4 years, 9 months ago
- dd86e75 Check the X.509 version when parsing. by David Benjamin · 4 years, 10 months ago
- fd86eaa Fix x509v3_cache_extensions error-handling. by David Benjamin · 4 years, 10 months ago
- 5ddc5b1 Move crypto/x509 test data into its own directory. by David Benjamin · 4 years, 10 months ago
- 7f90eda Add “Z Computation” KAT. by Adam Langley · 4 years, 10 months ago
- 0313b59 Let memory hooks override the size prefix. by Adam Langley · 4 years, 10 months ago
- 251b516 Assert md_size > 0. by David Benjamin · 4 years, 10 months ago
- 2309f64 Use ctr32 optimizations for AES_ctr128_encrypt. by David Benjamin · 4 years, 10 months ago