- ae1c1a4 Document filesystem-based X509_STORE APIs by David Benjamin · 1 year, 3 months ago
- 5d88014 Deprecate and simplify SSL_CTX_check_private_key by David Benjamin · 1 year, 1 month ago
- 48b0edf Update delegated credentials to the final RFC by David Benjamin · 1 year, 2 months ago
- 0568c2c Rewrite the warning about X509_AUX by David Benjamin · 1 year, 3 months ago
- 10605c0 Minor formatting fixes by David Benjamin · 1 year, 2 months ago
- fbb4133 Add SSL_get0_chain method by Gabriel Redner · 1 year, 2 months ago
- b6e0eba Warn more explicitly not to use the callback in SSL_set_verify by David Benjamin · 1 year, 3 months ago
- a942d57 Support lists and code blocks in doc.go by David Benjamin · 1 year, 4 months ago
- b251d81 Change certificate depth limit to match OpenSSL and document by David Benjamin · 1 year, 4 months ago
- 9e40481 Document functions that export verification internals by David Benjamin · 1 year, 4 months ago
- 3309ca6 Add ALPS codepoint supports for split handshake by Victor Tan · 1 year, 6 months ago
- 558960d Add support for the new ALPS codepoint by Victor Tan · 1 year, 9 months ago
- 6ca4938 Update the warnings on split handshakes and handshake hints by David Benjamin · 1 year, 7 months ago
- 7cb91d2 Reflect OPENSSL_NO_SOCK and OPENSSL_NO_POSIX_IO into headers by David Benjamin · 1 year, 9 months ago
- 0ffd365 Use a stub fopen implementation when OPENSSL_NO_FILESYSTEM is set by David Benjamin · 1 year, 8 months ago
- 5ba5db1 Support Android's "baremetal" target by David Benjamin · 1 year, 9 months ago
- 70be012 Use constant curve-specific groups whenever possible by David Benjamin · 2 years, 2 months ago
- 4e88a35 Make the curve compat APIs into real functions by David Benjamin · 1 year, 9 months ago
- 556a973f Add SSL_CIPHER_get_handshake_digest by David Benjamin · 1 year, 10 months ago
- 28c2409 Define TLSEXT_nid_unknown by David Benjamin · 1 year, 10 months ago
- 6cf9820 Align NIDs vs group IDs in TLS group APIs by David Benjamin · 1 year, 10 months ago
- 335523a Align remaining TLS ECDH APIs on "group" terminology by David Benjamin · 1 year, 10 months ago
- 2da5ba9 Align on using the "group" over "curve" for ECDH in TLS by David Benjamin · 1 year, 10 months ago
- 4631ccc Remove SSL_CIPHER_get_value by David Benjamin · 1 year, 10 months ago
- a972b78 Add APIs to query a list of possible strings for TLS features by David Benjamin · 1 year, 11 months ago
- 4d30888 Add a more general mechanism for deprecating TLS ciphers by David Benjamin · 2 years ago
- 1b724a6 Align Kyber names with draft-tls-westerbaan-xyber768d00 by David Benjamin · 1 year, 11 months ago
- 2f6409e Support WPA 3.1 "enterprise" mode. by Adam Langley · 2 years ago
- de2d610 Remove TLS_RSA_WITH_NULL_SHA by David Benjamin · 2 years ago
- 3e91d37 Clarify in ssl.h documentation not to use the verify callback by David Benjamin · 2 years ago
- 4ae4fb7 Drop CECPQ2 support. by Adam Langley · 2 years ago
- 8cacbd9 Add functions to allow the mocking of AES hw support for testing. by Bob Beck · 2 years ago
- bf1b792 Remove SSL_CIPHER_get_rfc_name by David Benjamin · 2 years ago
- d897027 Update X25519+Kyber ID. by Adam Langley · 2 years ago
- fc07738 Add stubs for hybrid Kyber768 with X25519 or P-256. by Adam Langley · 2 years, 3 months ago
- 05b360d Remove hmac.h include from ssl.h. by Piotr Sikora · 2 years, 3 months ago
- a614d46 Add SSL_was_key_usage_invalid. by David Benjamin · 2 years, 4 months ago
- 7ac94aa More -Wshorten-64-to-32 fixes. by David Benjamin · 2 years, 5 months ago
- 19d6ec9 Check for TLS 1.3 in SSL_generate_key_block. by David Benjamin · 2 years, 6 months ago
- 80eb814 Remove the experimental in-place record APIs. by David Benjamin · 2 years, 6 months ago
- e8e6cac Add the "groups" variants of SSL_CTX_set1_curves_list. by David Benjamin · 2 years, 7 months ago
- 10fef97 Prefer established session properties mid renegotiation. by David Benjamin · 2 years, 7 months ago
- 4a6c8fd Support handshake hints for TLS 1.2 full handshakes. by David Benjamin · 2 years, 8 months ago
- 5697a92 Add SSL_CTX_get_num_tickets. by David Benjamin · 2 years, 8 months ago
- 955ef79 Rewrite SSL_add_file_cert_subjects_to_stack by David Benjamin · 2 years, 10 months ago
- 451ea3c Add SSL_[CTX_]_set_compliance_policy. by Adam Langley · 2 years, 11 months ago
- 3f180b8 Implement SSL_CTX_set_num_tickets. by David Benjamin · 2 years, 11 months ago
- 123eaae Record ClientHelloInner values in msg_callback. by David Benjamin · 3 years, 2 months ago
- 7198d11 Explicitly reject self-referential ech_outer_extensions. by David Benjamin · 3 years, 2 months ago
- 7e2a957 Document |SSL_set1_host| return values. by Adam Langley · 3 years, 4 months ago
- 7e7e6b6 Add |SSL_set1_host| and |SSL_set_hostflags|. by Adam Langley · 3 years, 4 months ago
- b3ed071 Add SSL_has_pending. by David Benjamin · 3 years, 5 months ago
- c2827d3 Add a function to express the desired record version protocol. by Adam Langley · 3 years, 6 months ago
- cfafcd4 Deduplicate d2i and i2d documentation. by David Benjamin · 3 years, 6 months ago
- 45c8be9 Forward-declare SSL_CLIENT_HELLO. by David Benjamin · 3 years, 6 months ago
- 62c4f15 Clarify that TLS sessions are not application sessions. by David Benjamin · 3 years, 7 months ago
- 18b6836 Update to draft-ietf-tls-esni-13. by David Benjamin · 3 years, 10 months ago
- 37a3c70 Reword SSL_get0_ech_name_override documentation. by David Benjamin · 3 years, 7 months ago
- 07b365f Remove SSL_set_verify_result. by David Benjamin · 3 years, 7 months ago
- 6191cc9 Document that SSL_PRIVATE_KEY_METHOD should configure signing prefs. by David Benjamin · 3 years, 9 months ago
- ba423c9 Implement ClientHelloOuter handshakes. by David Benjamin · 3 years, 10 months ago
- e9c5d72 Add an option to permute ClientHello extension order. by David Benjamin · 3 years, 10 months ago
- 83a4993 Add most of an ECH client implementation. by David Benjamin · 3 years, 11 months ago
- 24545c5 Add a basic API to make ECHConfigs. by David Benjamin · 3 years, 10 months ago
- c890ae5 Make ECH server APIs take EVP_HPKE_KEY. by David Benjamin · 3 years, 10 months ago
- c3b373b Rename SSL_ECH_SERVER_CONFIG_LIST to SSL_ECH_KEYS. by David Benjamin · 3 years, 10 months ago
- 3a036c7 Add SSL_ech_accepted API and ech_is_required alerts. by David Benjamin · 3 years, 10 months ago
- b587911 Remove the Channel ID callback. by David Benjamin · 3 years, 11 months ago
- 8acec00 Manage Channel ID handshake state better. by David Benjamin · 3 years, 11 months ago
- a1d3bfb Cite an RFC over 9000 (draft-ietf-quic-tls is now RFC 9001). by David Benjamin · 3 years, 10 months ago
- 3675eb3 GREASE is now RFC 8701. by David Benjamin · 3 years, 11 months ago
- b778b9c Const-correct SSL_get_srtp_profiles. by David Benjamin · 3 years, 11 months ago
- 49ee62f Update the ECH GREASE size selection. by David Benjamin · 3 years, 11 months ago
- d89ec68 Remove draft tokbind implementation. by David Benjamin · 3 years, 11 months ago
- 71a3b82 Check for resumption identifiers in SSL_SESSION_is_resumable. by David Benjamin · 3 years, 11 months ago
- 9b2cdb7 Add SSL_can_release_private_key. by David Benjamin · 4 years ago
- b571e77 Add experimental handshake hints API. by David Benjamin · 4 years ago
- 12a3e7e Check for invalid ALPN inputs in SSL_(CTX_)set_alpn_protos. by David Benjamin · 4 years ago
- 00e434d Add ECH server (draft-ietf-tls-esni-09). by Daniel McArdle · 4 years, 1 month ago
- e5fe31c Revert "Implement rsa_pkcs1_sha256_legacy." by David Benjamin · 4 years ago
- a3437c0 Implement rsa_pkcs1_sha256_legacy. by David Benjamin · 4 years, 1 month ago
- a1d1a67 Remove some remnants of TLS 1.3 downgrade carveouts. by David Benjamin · 4 years, 1 month ago
- c02c19e Honor SSL_TLSEXT_ERR_ALERT_FATAL in the ALPN callback. by David Benjamin · 4 years, 2 months ago
- 595cdc2 doc: fix SSL_set0_rbio by Yuchen Dai · 4 years, 3 months ago
- 3d8b8c3 Add support for the new QUIC TLS extension codepoint by David Schinazi · 4 years, 3 months ago
- 92c48be Update ECH GREASE to draft-ietf-tls-esni-09 by Dan McArdle · 4 years, 3 months ago
- ca058c0 Revert "Add support for the new QUIC TLS extension codepoint" by Adam Langley · 4 years, 4 months ago
- 7ba96a6 Add support for the new QUIC TLS extension codepoint by David Schinazi · 4 years, 4 months ago
- 1920c6f Implement GREASE for ECH (draft-ietf-tls-esni-08). by Dan McArdle · 5 years ago
- 41a1430 draft-ietf-tls-certificate-compression is now RFC 8879. by David Benjamin · 4 years, 4 months ago
- 5351c8b Rename the master_key field in SSL_SESSION to secret. by David Benjamin · 4 years, 4 months ago
- 0a6bfa3 Always check the TLS 1.3 downgrade signal. by David Benjamin · 4 years, 4 months ago
- fa9796e Add SSL_early_data_reason_string. by David Benjamin · 4 years, 5 months ago
- 51607f1 Implement draft-vvv-tls-alps-01. by Steven Valdez · 4 years, 8 months ago
- 3743aaf Add SSL_CIPHER_get_protocol_id. by David Benjamin · 4 years, 6 months ago
- dcd6e44 Support delegated credentials verison 06 by Watson Ladd · 4 years, 8 months ago
- 74161f4 Enforce presence of ALPN when QUIC is in use. by Nick Harper · 4 years, 8 months ago
- 7d3a24d Fix the naming of alert error codes. by David Benjamin · 4 years, 8 months ago
- cac9392 Disallow TLS 1.3 compatibility mode in QUIC. by Nick Harper · 5 years ago
- 5fa22ed Avoid relying on SSL_get_session's behavior during the handshake. by David Benjamin · 4 years, 9 months ago