1. 90f0f05 Integrate TLS 1.2 sigalg and cipher suite selection by David Benjamin · 1 year, 2 months ago
  2. 48b0edf Update delegated credentials to the final RFC by David Benjamin · 1 year, 2 months ago
  3. dd68e4b Add OPENSSL_zalloc by David Benjamin · 1 year, 6 months ago
  4. 558960d Add support for the new ALPS codepoint by Victor Tan · 1 year, 9 months ago
  5. 9404a0b runner: Check that the shim HRRs echo the session ID by David Benjamin · 1 year, 7 months ago
  6. e4f6067 Use a callable type for ScopedFILE in settings_writer.cc by David Benjamin · 1 year, 8 months ago
  7. a4f8755 Fix error handling in bssl_shim socket object by David Benjamin · 1 year, 9 months ago
  8. a36ac0a Use std::make_unique when possible by David Benjamin · 1 year, 9 months ago
  9. 8f4daaf Resolve an old TODO in TestState::Deserialize by David Benjamin · 1 year, 9 months ago
  10. fa6ab4f Remove remnants of malloc.cc by David Benjamin · 1 year, 9 months ago
  11. 286ea21 Replace byteBuilder and byteReader with cryptobyte by David Benjamin · 1 year, 9 months ago
  12. 50ee095 Use a single TCP server port in runner by David Benjamin · 1 year, 10 months ago
  13. f4d1d79 Simplify shimProcess accept and wait by David Benjamin · 1 year, 10 months ago
  14. 73dcd47 Turn SocketCloser in bssl_shim into a proper owning type by David Benjamin · 1 year, 10 months ago
  15. e33257f Pass IPv6 vs IPv4 down to the shim by David Benjamin · 1 year, 10 months ago
  16. e1b8685 Log failure to create SSL objects in handshakers by David Benjamin · 1 year, 10 months ago
  17. 6cf9820 Align NIDs vs group IDs in TLS group APIs by David Benjamin · 1 year, 10 months ago
  18. 335523a Align remaining TLS ECDH APIs on "group" terminology by David Benjamin · 1 year, 10 months ago
  19. 2da5ba9 Align on using the "group" over "curve" for ECDH in TLS by David Benjamin · 1 year, 10 months ago
  20. 7e56051 Miscellaneous size_t truncation fixes by David Benjamin · 1 year, 10 months ago
  21. b0251b1 Disable TLS_RSA_WITH_3DES_EDE_CBC_SHA by default by David Benjamin · 2 years ago
  22. a972b78 Add APIs to query a list of possible strings for TLS features by David Benjamin · 1 year, 11 months ago
  23. b1c6f45 Add back support for TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 by Adam Langley · 1 year, 11 months ago
  24. 1b724a6 Align Kyber names with draft-tls-westerbaan-xyber768d00 by David Benjamin · 1 year, 11 months ago
  25. 77b6f25 Replace interface{} with any by David Benjamin · 1 year, 11 months ago
  26. b811a6c Add Kyber to runner tests by Adam Langley · 1 year, 11 months ago
  27. 2f6409e Support WPA 3.1 "enterprise" mode. by Adam Langley · 2 years ago
  28. a02b743 runner: Remove an unnecessary use of AllCurves by David Benjamin · 1 year, 11 months ago
  29. edf7662 Allow passing extra flags to BoGo shim by Roland Shoemaker · 1 year, 11 months ago
  30. de2d610 Remove TLS_RSA_WITH_NULL_SHA by David Benjamin · 2 years ago
  31. cee2dbb Default SSL_set_enforce_rsa_key_usage to enabled. by David Benjamin · 2 years ago
  32. 4ae4fb7 Drop CECPQ2 support. by Adam Langley · 2 years ago
  33. 8cacbd9 Add functions to allow the mocking of AES hw support for testing. by Bob Beck · 2 years ago
  34. a438519 Fix miscellaneous size_t truncations by David Benjamin · 2 years ago
  35. fe7a067 Run `go fmt` in `ssl/test/runner`. by Adam Langley · 2 years ago
  36. 08b1f38 Use KEM terminology in TLS ECDHE and key_share abstractions by David Benjamin · 2 years, 1 month ago
  37. 8c75ed0 Remove global_target from build. by David Benjamin · 2 years, 2 months ago
  38. 0e68520 Specify -Iinclude with the crypto target. by David Benjamin · 2 years, 2 months ago
  39. 582904f Move malloc failure testing into OPENSSL_malloc by David Benjamin · 2 years, 2 months ago
  40. 00c70b8 Add locale independent implementations of isalpha, isalnum, isdigit, by Bob Beck · 2 years, 2 months ago
  41. f86a63c Introduce a locale-independent version of isdigit by Bob Beck · 2 years, 2 months ago
  42. 1e97ce3 Don't send two post-quantum initial key shares. by Adam Langley · 2 years, 2 months ago
  43. 05b360d Remove hmac.h include from ssl.h. by Piotr Sikora · 2 years, 2 months ago
  44. 3251ca1 Simplify MSVC warning configuration by David Benjamin · 2 years, 3 months ago
  45. ec6425ca Drop the preference for 256-bit ciphers with CECPQ2. by Adam Langley · 2 years, 3 months ago
  46. a614d46 Add SSL_was_key_usage_invalid. by David Benjamin · 2 years, 4 months ago
  47. 02f7705 Add int casts to BIO_ctrl calls where appropriate. by David Benjamin · 2 years, 4 months ago
  48. 3a1b730 Don't allow the caller to configure invalid signature algorithms. by David Benjamin · 2 years, 4 months ago
  49. e8f57ca Never accidentally use SSL_SIGN_RSA_PKCS1_MD5_SHA1 at TLS 1.2. by David Benjamin · 2 years, 4 months ago
  50. 5511fa8 Migrate io/ioutil uses to new APIs. by David Benjamin · 2 years, 5 months ago
  51. 4b35543 Revert "Default SSL_set_enforce_rsa_key_usage to enabled." by David Benjamin · 2 years, 5 months ago
  52. 9d64d8d Miscellaneous -Wshorten-64-to-32 fixes. by David Benjamin · 2 years, 7 months ago
  53. 64393b5 Default SSL_set_enforce_rsa_key_usage to enabled. by David Benjamin · 2 years, 6 months ago
  54. 361e3e0 Move the DTLS cookie to SSL_HANDSHAKE. by David Benjamin · 2 years, 7 months ago
  55. adaa322 Add handshake hints for TLS 1.2 session tickets. by David Benjamin · 2 years, 8 months ago
  56. 4a6c8fd Support handshake hints for TLS 1.2 full handshakes. by David Benjamin · 2 years, 8 months ago
  57. 451ea3c Add SSL_[CTX_]_set_compliance_policy. by Adam Langley · 2 years, 11 months ago
  58. c76da9d HPKE is now RFC 9180. by David Benjamin · 3 years, 1 month ago
  59. 5112b45 Support Bazel's test-sharding protocol. by Adam Langley · 3 years, 2 months ago
  60. 123eaae Record ClientHelloInner values in msg_callback. by David Benjamin · 3 years, 2 months ago
  61. 7198d11 Explicitly reject self-referential ech_outer_extensions. by David Benjamin · 3 years, 2 months ago
  62. 0f4454c Condition split handshake tests on Linux in CMake. by David Benjamin · 3 years, 2 months ago
  63. d7936c2 Use uint16_t in TestConfig and enable -Wformat-signedness. by David Benjamin · 3 years, 3 months ago
  64. 203b92b Reorder flags to match TestConfig struct. by David Benjamin · 3 years, 3 months ago
  65. 8ed06e0 Rewrite bssl_shim command-line parser. by David Benjamin · 3 years, 3 months ago
  66. 4f1fae3 Fix the easy -Wformat-signedness errors. by David Benjamin · 3 years, 4 months ago
  67. ea57bcb Update HPKE test vectors. by David Benjamin · 3 years, 4 months ago
  68. 27a3328 Fix the TLS fuzzers for ECH draft-13. by David Benjamin · 3 years, 7 months ago
  69. 19fe794 Fix calculation of draft-13 ECH confirmation signal. by David Benjamin · 3 years, 7 months ago
  70. 18b6836 Update to draft-ietf-tls-esni-13. by David Benjamin · 3 years, 9 months ago
  71. dddb60e Make most of crypto/x509 opaque. by David Benjamin · 3 years, 8 months ago
  72. e2cb423 Deduplicate our three ServerHello parsers. by David Benjamin · 3 years, 9 months ago
  73. 8648c53 Refer to RFCs consistently. by David Benjamin · 3 years, 7 months ago
  74. 16c3e3a runner: Test session IDs over 32 bytes. by David Benjamin · 3 years, 9 months ago
  75. ad5db96 Handle the server case in SSL_get0_ech_name_override. by David Benjamin · 3 years, 9 months ago
  76. 5514476 Update hpke_test.go. by Adam Langley · 3 years, 9 months ago
  77. ba423c9 Implement ClientHelloOuter handshakes. by David Benjamin · 3 years, 10 months ago
  78. ca7ef8c runner: Add a convenience function for base64 flags. by David Benjamin · 3 years, 10 months ago
  79. afa867b runner: Test that clients actually use renewed tickets. by David Benjamin · 3 years, 10 months ago
  80. 5d224a5 runner: Clean up test logic. by David Benjamin · 3 years, 9 months ago
  81. c41a3a9 runner: Fix process exit timeout. by David Benjamin · 3 years, 9 months ago
  82. 9cbe737 Validate ECH public names. by David Benjamin · 3 years, 10 months ago
  83. e9c5d72 Add an option to permute ClientHello extension order. by David Benjamin · 3 years, 10 months ago
  84. 5358cb5 runner: Check the test name against the protocol being tested. by David Benjamin · 3 years, 10 months ago
  85. 83a4993 Add most of an ECH client implementation. by David Benjamin · 3 years, 10 months ago
  86. c890ae5 Make ECH server APIs take EVP_HPKE_KEY. by David Benjamin · 3 years, 10 months ago
  87. c3b373b Rename SSL_ECH_SERVER_CONFIG_LIST to SSL_ECH_KEYS. by David Benjamin · 3 years, 10 months ago
  88. 0724e3d runner: Self-check tests more accurately and earlier. by David Benjamin · 3 years, 10 months ago
  89. 26f186b Implement a handshake hint for certificate compression. by David Benjamin · 3 years, 10 months ago
  90. 7fffa46 runner: Implement ECH server for testing. by David Benjamin · 3 years, 10 months ago
  91. 1f54fd9 runner: Parse the status_request extension more strictly. by David Benjamin · 3 years, 10 months ago
  92. 00bccd6 runner: Make echIsInner a boolean. by David Benjamin · 3 years, 10 months ago
  93. 1241228 runner: Revise ECHConfig type in preparation for client implementation by David Benjamin · 3 years, 10 months ago
  94. 88df13d Fix ECH-Server-RepeatedConfigID test. by David Benjamin · 3 years, 10 months ago
  95. 3a036c7 Add SSL_ech_accepted API and ech_is_required alerts. by David Benjamin · 3 years, 10 months ago
  96. 5b7ec83 Reject the ECH extension in TLS 1.2 ServerHello. by David Benjamin · 3 years, 10 months ago
  97. b587911 Remove the Channel ID callback. by David Benjamin · 3 years, 11 months ago
  98. bc4c91a DTLS-SRTP is only defined for DTLS. by David Benjamin · 3 years, 11 months ago
  99. a1d3bfb Cite an RFC over 9000 (draft-ietf-quic-tls is now RFC 9001). by David Benjamin · 3 years, 10 months ago
  100. 3dd9864 Test ECH server with unique and repeated config IDs. by Dan McArdle · 3 years, 10 months ago