- 90f0f05 Integrate TLS 1.2 sigalg and cipher suite selection by David Benjamin · 1 year, 2 months ago
- 48b0edf Update delegated credentials to the final RFC by David Benjamin · 1 year, 2 months ago
- dd68e4b Add OPENSSL_zalloc by David Benjamin · 1 year, 6 months ago
- 558960d Add support for the new ALPS codepoint by Victor Tan · 1 year, 9 months ago
- 9404a0b runner: Check that the shim HRRs echo the session ID by David Benjamin · 1 year, 7 months ago
- e4f6067 Use a callable type for ScopedFILE in settings_writer.cc by David Benjamin · 1 year, 8 months ago
- a4f8755 Fix error handling in bssl_shim socket object by David Benjamin · 1 year, 9 months ago
- a36ac0a Use std::make_unique when possible by David Benjamin · 1 year, 9 months ago
- 8f4daaf Resolve an old TODO in TestState::Deserialize by David Benjamin · 1 year, 9 months ago
- fa6ab4f Remove remnants of malloc.cc by David Benjamin · 1 year, 9 months ago
- 286ea21 Replace byteBuilder and byteReader with cryptobyte by David Benjamin · 1 year, 9 months ago
- 50ee095 Use a single TCP server port in runner by David Benjamin · 1 year, 10 months ago
- f4d1d79 Simplify shimProcess accept and wait by David Benjamin · 1 year, 10 months ago
- 73dcd47 Turn SocketCloser in bssl_shim into a proper owning type by David Benjamin · 1 year, 10 months ago
- e33257f Pass IPv6 vs IPv4 down to the shim by David Benjamin · 1 year, 10 months ago
- e1b8685 Log failure to create SSL objects in handshakers by David Benjamin · 1 year, 10 months ago
- 6cf9820 Align NIDs vs group IDs in TLS group APIs by David Benjamin · 1 year, 10 months ago
- 335523a Align remaining TLS ECDH APIs on "group" terminology by David Benjamin · 1 year, 10 months ago
- 2da5ba9 Align on using the "group" over "curve" for ECDH in TLS by David Benjamin · 1 year, 10 months ago
- 7e56051 Miscellaneous size_t truncation fixes by David Benjamin · 1 year, 10 months ago
- b0251b1 Disable TLS_RSA_WITH_3DES_EDE_CBC_SHA by default by David Benjamin · 2 years ago
- a972b78 Add APIs to query a list of possible strings for TLS features by David Benjamin · 1 year, 11 months ago
- b1c6f45 Add back support for TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 by Adam Langley · 1 year, 11 months ago
- 1b724a6 Align Kyber names with draft-tls-westerbaan-xyber768d00 by David Benjamin · 1 year, 11 months ago
- 77b6f25 Replace interface{} with any by David Benjamin · 1 year, 11 months ago
- b811a6c Add Kyber to runner tests by Adam Langley · 1 year, 11 months ago
- 2f6409e Support WPA 3.1 "enterprise" mode. by Adam Langley · 2 years ago
- a02b743 runner: Remove an unnecessary use of AllCurves by David Benjamin · 1 year, 11 months ago
- edf7662 Allow passing extra flags to BoGo shim by Roland Shoemaker · 1 year, 11 months ago
- de2d610 Remove TLS_RSA_WITH_NULL_SHA by David Benjamin · 2 years ago
- cee2dbb Default SSL_set_enforce_rsa_key_usage to enabled. by David Benjamin · 2 years ago
- 4ae4fb7 Drop CECPQ2 support. by Adam Langley · 2 years ago
- 8cacbd9 Add functions to allow the mocking of AES hw support for testing. by Bob Beck · 2 years ago
- a438519 Fix miscellaneous size_t truncations by David Benjamin · 2 years ago
- fe7a067 Run `go fmt` in `ssl/test/runner`. by Adam Langley · 2 years ago
- 08b1f38 Use KEM terminology in TLS ECDHE and key_share abstractions by David Benjamin · 2 years, 1 month ago
- 8c75ed0 Remove global_target from build. by David Benjamin · 2 years, 2 months ago
- 0e68520 Specify -Iinclude with the crypto target. by David Benjamin · 2 years, 2 months ago
- 582904f Move malloc failure testing into OPENSSL_malloc by David Benjamin · 2 years, 2 months ago
- 00c70b8 Add locale independent implementations of isalpha, isalnum, isdigit, by Bob Beck · 2 years, 2 months ago
- f86a63c Introduce a locale-independent version of isdigit by Bob Beck · 2 years, 2 months ago
- 1e97ce3 Don't send two post-quantum initial key shares. by Adam Langley · 2 years, 2 months ago
- 05b360d Remove hmac.h include from ssl.h. by Piotr Sikora · 2 years, 2 months ago
- 3251ca1 Simplify MSVC warning configuration by David Benjamin · 2 years, 3 months ago
- ec6425ca Drop the preference for 256-bit ciphers with CECPQ2. by Adam Langley · 2 years, 3 months ago
- a614d46 Add SSL_was_key_usage_invalid. by David Benjamin · 2 years, 4 months ago
- 02f7705 Add int casts to BIO_ctrl calls where appropriate. by David Benjamin · 2 years, 4 months ago
- 3a1b730 Don't allow the caller to configure invalid signature algorithms. by David Benjamin · 2 years, 4 months ago
- e8f57ca Never accidentally use SSL_SIGN_RSA_PKCS1_MD5_SHA1 at TLS 1.2. by David Benjamin · 2 years, 4 months ago
- 5511fa8 Migrate io/ioutil uses to new APIs. by David Benjamin · 2 years, 5 months ago
- 4b35543 Revert "Default SSL_set_enforce_rsa_key_usage to enabled." by David Benjamin · 2 years, 5 months ago
- 9d64d8d Miscellaneous -Wshorten-64-to-32 fixes. by David Benjamin · 2 years, 7 months ago
- 64393b5 Default SSL_set_enforce_rsa_key_usage to enabled. by David Benjamin · 2 years, 6 months ago
- 361e3e0 Move the DTLS cookie to SSL_HANDSHAKE. by David Benjamin · 2 years, 7 months ago
- adaa322 Add handshake hints for TLS 1.2 session tickets. by David Benjamin · 2 years, 8 months ago
- 4a6c8fd Support handshake hints for TLS 1.2 full handshakes. by David Benjamin · 2 years, 8 months ago
- 451ea3c Add SSL_[CTX_]_set_compliance_policy. by Adam Langley · 2 years, 11 months ago
- c76da9d HPKE is now RFC 9180. by David Benjamin · 3 years, 1 month ago
- 5112b45 Support Bazel's test-sharding protocol. by Adam Langley · 3 years, 2 months ago
- 123eaae Record ClientHelloInner values in msg_callback. by David Benjamin · 3 years, 2 months ago
- 7198d11 Explicitly reject self-referential ech_outer_extensions. by David Benjamin · 3 years, 2 months ago
- 0f4454c Condition split handshake tests on Linux in CMake. by David Benjamin · 3 years, 2 months ago
- d7936c2 Use uint16_t in TestConfig and enable -Wformat-signedness. by David Benjamin · 3 years, 3 months ago
- 203b92b Reorder flags to match TestConfig struct. by David Benjamin · 3 years, 3 months ago
- 8ed06e0 Rewrite bssl_shim command-line parser. by David Benjamin · 3 years, 3 months ago
- 4f1fae3 Fix the easy -Wformat-signedness errors. by David Benjamin · 3 years, 4 months ago
- ea57bcb Update HPKE test vectors. by David Benjamin · 3 years, 4 months ago
- 27a3328 Fix the TLS fuzzers for ECH draft-13. by David Benjamin · 3 years, 7 months ago
- 19fe794 Fix calculation of draft-13 ECH confirmation signal. by David Benjamin · 3 years, 7 months ago
- 18b6836 Update to draft-ietf-tls-esni-13. by David Benjamin · 3 years, 9 months ago
- dddb60e Make most of crypto/x509 opaque. by David Benjamin · 3 years, 8 months ago
- e2cb423 Deduplicate our three ServerHello parsers. by David Benjamin · 3 years, 9 months ago
- 8648c53 Refer to RFCs consistently. by David Benjamin · 3 years, 7 months ago
- 16c3e3a runner: Test session IDs over 32 bytes. by David Benjamin · 3 years, 9 months ago
- ad5db96 Handle the server case in SSL_get0_ech_name_override. by David Benjamin · 3 years, 9 months ago
- 5514476 Update hpke_test.go. by Adam Langley · 3 years, 9 months ago
- ba423c9 Implement ClientHelloOuter handshakes. by David Benjamin · 3 years, 10 months ago
- ca7ef8c runner: Add a convenience function for base64 flags. by David Benjamin · 3 years, 10 months ago
- afa867b runner: Test that clients actually use renewed tickets. by David Benjamin · 3 years, 10 months ago
- 5d224a5 runner: Clean up test logic. by David Benjamin · 3 years, 9 months ago
- c41a3a9 runner: Fix process exit timeout. by David Benjamin · 3 years, 9 months ago
- 9cbe737 Validate ECH public names. by David Benjamin · 3 years, 10 months ago
- e9c5d72 Add an option to permute ClientHello extension order. by David Benjamin · 3 years, 10 months ago
- 5358cb5 runner: Check the test name against the protocol being tested. by David Benjamin · 3 years, 10 months ago
- 83a4993 Add most of an ECH client implementation. by David Benjamin · 3 years, 10 months ago
- c890ae5 Make ECH server APIs take EVP_HPKE_KEY. by David Benjamin · 3 years, 10 months ago
- c3b373b Rename SSL_ECH_SERVER_CONFIG_LIST to SSL_ECH_KEYS. by David Benjamin · 3 years, 10 months ago
- 0724e3d runner: Self-check tests more accurately and earlier. by David Benjamin · 3 years, 10 months ago
- 26f186b Implement a handshake hint for certificate compression. by David Benjamin · 3 years, 10 months ago
- 7fffa46 runner: Implement ECH server for testing. by David Benjamin · 3 years, 10 months ago
- 1f54fd9 runner: Parse the status_request extension more strictly. by David Benjamin · 3 years, 10 months ago
- 00bccd6 runner: Make echIsInner a boolean. by David Benjamin · 3 years, 10 months ago
- 1241228 runner: Revise ECHConfig type in preparation for client implementation by David Benjamin · 3 years, 10 months ago
- 88df13d Fix ECH-Server-RepeatedConfigID test. by David Benjamin · 3 years, 10 months ago
- 3a036c7 Add SSL_ech_accepted API and ech_is_required alerts. by David Benjamin · 3 years, 10 months ago
- 5b7ec83 Reject the ECH extension in TLS 1.2 ServerHello. by David Benjamin · 3 years, 10 months ago
- b587911 Remove the Channel ID callback. by David Benjamin · 3 years, 11 months ago
- bc4c91a DTLS-SRTP is only defined for DTLS. by David Benjamin · 3 years, 11 months ago
- a1d3bfb Cite an RFC over 9000 (draft-ietf-quic-tls is now RFC 9001). by David Benjamin · 3 years, 10 months ago
- 3dd9864 Test ECH server with unique and repeated config IDs. by Dan McArdle · 3 years, 10 months ago