1. a972b78 Add APIs to query a list of possible strings for TLS features by David Benjamin · 1 year, 11 months ago
  2. 4d30888 Add a more general mechanism for deprecating TLS ciphers by David Benjamin · 2 years ago
  3. 1b724a6 Align Kyber names with draft-tls-westerbaan-xyber768d00 by David Benjamin · 1 year, 11 months ago
  4. 2f6409e Support WPA 3.1 "enterprise" mode. by Adam Langley · 2 years ago
  5. de2d610 Remove TLS_RSA_WITH_NULL_SHA by David Benjamin · 2 years ago
  6. 3e91d37 Clarify in ssl.h documentation not to use the verify callback by David Benjamin · 2 years ago
  7. 4ae4fb7 Drop CECPQ2 support. by Adam Langley · 2 years ago
  8. 8cacbd9 Add functions to allow the mocking of AES hw support for testing. by Bob Beck · 2 years ago
  9. bf1b792 Remove SSL_CIPHER_get_rfc_name by David Benjamin · 2 years ago
  10. d897027 Update X25519+Kyber ID. by Adam Langley · 2 years ago
  11. fc07738 Add stubs for hybrid Kyber768 with X25519 or P-256. by Adam Langley · 2 years, 3 months ago
  12. 05b360d Remove hmac.h include from ssl.h. by Piotr Sikora · 2 years, 2 months ago
  13. a614d46 Add SSL_was_key_usage_invalid. by David Benjamin · 2 years, 4 months ago
  14. 7ac94aa More -Wshorten-64-to-32 fixes. by David Benjamin · 2 years, 5 months ago
  15. 19d6ec9 Check for TLS 1.3 in SSL_generate_key_block. by David Benjamin · 2 years, 6 months ago
  16. 80eb814 Remove the experimental in-place record APIs. by David Benjamin · 2 years, 6 months ago
  17. e8e6cac Add the "groups" variants of SSL_CTX_set1_curves_list. by David Benjamin · 2 years, 7 months ago
  18. 10fef97 Prefer established session properties mid renegotiation. by David Benjamin · 2 years, 7 months ago
  19. 4a6c8fd Support handshake hints for TLS 1.2 full handshakes. by David Benjamin · 2 years, 8 months ago
  20. 5697a92 Add SSL_CTX_get_num_tickets. by David Benjamin · 2 years, 8 months ago
  21. 955ef79 Rewrite SSL_add_file_cert_subjects_to_stack by David Benjamin · 2 years, 10 months ago
  22. 451ea3c Add SSL_[CTX_]_set_compliance_policy. by Adam Langley · 2 years, 11 months ago
  23. 3f180b8 Implement SSL_CTX_set_num_tickets. by David Benjamin · 2 years, 11 months ago
  24. 123eaae Record ClientHelloInner values in msg_callback. by David Benjamin · 3 years, 2 months ago
  25. 7198d11 Explicitly reject self-referential ech_outer_extensions. by David Benjamin · 3 years, 2 months ago
  26. 7e2a957 Document |SSL_set1_host| return values. by Adam Langley · 3 years, 4 months ago
  27. 7e7e6b6 Add |SSL_set1_host| and |SSL_set_hostflags|. by Adam Langley · 3 years, 4 months ago
  28. b3ed071 Add SSL_has_pending. by David Benjamin · 3 years, 5 months ago
  29. c2827d3 Add a function to express the desired record version protocol. by Adam Langley · 3 years, 6 months ago
  30. cfafcd4 Deduplicate d2i and i2d documentation. by David Benjamin · 3 years, 6 months ago
  31. 45c8be9 Forward-declare SSL_CLIENT_HELLO. by David Benjamin · 3 years, 6 months ago
  32. 62c4f15 Clarify that TLS sessions are not application sessions. by David Benjamin · 3 years, 7 months ago
  33. 18b6836 Update to draft-ietf-tls-esni-13. by David Benjamin · 3 years, 9 months ago
  34. 37a3c70 Reword SSL_get0_ech_name_override documentation. by David Benjamin · 3 years, 7 months ago
  35. 07b365f Remove SSL_set_verify_result. by David Benjamin · 3 years, 7 months ago
  36. 6191cc9 Document that SSL_PRIVATE_KEY_METHOD should configure signing prefs. by David Benjamin · 3 years, 9 months ago
  37. ba423c9 Implement ClientHelloOuter handshakes. by David Benjamin · 3 years, 10 months ago
  38. e9c5d72 Add an option to permute ClientHello extension order. by David Benjamin · 3 years, 10 months ago
  39. 83a4993 Add most of an ECH client implementation. by David Benjamin · 3 years, 10 months ago
  40. 24545c5 Add a basic API to make ECHConfigs. by David Benjamin · 3 years, 10 months ago
  41. c890ae5 Make ECH server APIs take EVP_HPKE_KEY. by David Benjamin · 3 years, 10 months ago
  42. c3b373b Rename SSL_ECH_SERVER_CONFIG_LIST to SSL_ECH_KEYS. by David Benjamin · 3 years, 10 months ago
  43. 3a036c7 Add SSL_ech_accepted API and ech_is_required alerts. by David Benjamin · 3 years, 10 months ago
  44. b587911 Remove the Channel ID callback. by David Benjamin · 3 years, 11 months ago
  45. 8acec00 Manage Channel ID handshake state better. by David Benjamin · 3 years, 11 months ago
  46. a1d3bfb Cite an RFC over 9000 (draft-ietf-quic-tls is now RFC 9001). by David Benjamin · 3 years, 10 months ago
  47. 3675eb3 GREASE is now RFC 8701. by David Benjamin · 3 years, 11 months ago
  48. b778b9c Const-correct SSL_get_srtp_profiles. by David Benjamin · 3 years, 10 months ago
  49. 49ee62f Update the ECH GREASE size selection. by David Benjamin · 3 years, 10 months ago
  50. d89ec68 Remove draft tokbind implementation. by David Benjamin · 3 years, 11 months ago
  51. 71a3b82 Check for resumption identifiers in SSL_SESSION_is_resumable. by David Benjamin · 3 years, 11 months ago
  52. 9b2cdb7 Add SSL_can_release_private_key. by David Benjamin · 4 years ago
  53. b571e77 Add experimental handshake hints API. by David Benjamin · 4 years ago
  54. 12a3e7e Check for invalid ALPN inputs in SSL_(CTX_)set_alpn_protos. by David Benjamin · 4 years ago
  55. 00e434d Add ECH server (draft-ietf-tls-esni-09). by Daniel McArdle · 4 years, 1 month ago
  56. e5fe31c Revert "Implement rsa_pkcs1_sha256_legacy." by David Benjamin · 4 years ago
  57. a3437c0 Implement rsa_pkcs1_sha256_legacy. by David Benjamin · 4 years, 1 month ago
  58. a1d1a67 Remove some remnants of TLS 1.3 downgrade carveouts. by David Benjamin · 4 years, 1 month ago
  59. c02c19e Honor SSL_TLSEXT_ERR_ALERT_FATAL in the ALPN callback. by David Benjamin · 4 years, 2 months ago
  60. 595cdc2 doc: fix SSL_set0_rbio by Yuchen Dai · 4 years, 2 months ago
  61. 3d8b8c3 Add support for the new QUIC TLS extension codepoint by David Schinazi · 4 years, 3 months ago
  62. 92c48be Update ECH GREASE to draft-ietf-tls-esni-09 by Dan McArdle · 4 years, 3 months ago
  63. ca058c0 Revert "Add support for the new QUIC TLS extension codepoint" by Adam Langley · 4 years, 3 months ago
  64. 7ba96a6 Add support for the new QUIC TLS extension codepoint by David Schinazi · 4 years, 4 months ago
  65. 1920c6f Implement GREASE for ECH (draft-ietf-tls-esni-08). by Dan McArdle · 5 years ago
  66. 41a1430 draft-ietf-tls-certificate-compression is now RFC 8879. by David Benjamin · 4 years, 4 months ago
  67. 5351c8b Rename the master_key field in SSL_SESSION to secret. by David Benjamin · 4 years, 4 months ago
  68. 0a6bfa3 Always check the TLS 1.3 downgrade signal. by David Benjamin · 4 years, 4 months ago
  69. fa9796e Add SSL_early_data_reason_string. by David Benjamin · 4 years, 5 months ago
  70. 51607f1 Implement draft-vvv-tls-alps-01. by Steven Valdez · 4 years, 8 months ago
  71. 3743aaf Add SSL_CIPHER_get_protocol_id. by David Benjamin · 4 years, 6 months ago
  72. dcd6e44 Support delegated credentials verison 06 by Watson Ladd · 4 years, 8 months ago
  73. 74161f4 Enforce presence of ALPN when QUIC is in use. by Nick Harper · 4 years, 8 months ago
  74. 7d3a24d Fix the naming of alert error codes. by David Benjamin · 4 years, 8 months ago
  75. cac9392 Disallow TLS 1.3 compatibility mode in QUIC. by Nick Harper · 5 years ago
  76. 5fa22ed Avoid relying on SSL_get_session's behavior during the handshake. by David Benjamin · 4 years, 9 months ago
  77. 53a17f5 Add a |SSL_process_tls13_new_session_ticket|. by Adam Langley · 4 years, 10 months ago
  78. 8519432 Modify how QUIC 0-RTT go/no-go decision is made. by Nick Harper · 4 years, 10 months ago
  79. 8f12996 Fix docs link for SSL_CTX_load_verify_locations by Anna Sarai Rosenberg · 4 years, 11 months ago
  80. 7c52299 Restrict when 0-RTT will be accepted in QUIC. by Nick Harper · 5 years ago
  81. f9e0cda Add SSL_SESSION_copy_without_early_data. by David Benjamin · 5 years ago
  82. 72cff81 Require QUIC method with Transport Parameters and vice versa by Nick Harper · 5 years ago
  83. 964256d Add |SSL_CTX_get0_chain|. by Adam Langley · 5 years ago
  84. 1e85905 Revise QUIC encryption secret APIs. by David Benjamin · 5 years ago
  85. 754d4c9 Fix client handling of 0-RTT rejects with cipher mismatch. by David Benjamin · 5 years ago
  86. f9cc26f Require handshake flights end at record boundaries. by David Benjamin · 5 years ago
  87. 1766935 Remove SSL_CTX_set_ed25519_enabled. by David Benjamin · 5 years ago
  88. f0a815c Add SSL_set_verify_algorithm_prefs. by David Benjamin · 5 years ago
  89. 10165d8 Add SSL_AD_NO_APPLICATION_PROTOCOL by David Schinazi · 5 years ago
  90. f249840 Remove SSL_CTX_set_rsa_pss_rsae_certs_enabled. by David Benjamin · 5 years ago
  91. e0d95ad Remove post-quantum experiment signal extension. by David Benjamin · 5 years ago
  92. b11902a HelloRetryRequest getter by Kris Kwiatkowski · 6 years ago
  93. 3ab3b12 Add compatibility functions for sigalgs by Shelley Vohr · 5 years ago
  94. 7f02881 Drop CECPQ2b code. by Adam Langley · 5 years ago fips-android-20191020
  95. 12049fd Add |SSL_get_min_proto_version| and |SSL_get_max_proto_version| by Alessandro Ghedini · 5 years ago
  96. 0e7dbd5 Add an option for explicit renegotiations. by David Benjamin · 6 years ago
  97. 0bb4345 Mark ssl_early_data_reason_t values stable. by David Benjamin · 6 years ago
  98. 04a89c8 Add |SSL_CIPHER_get_value| to get the IANA number of a cipher suite. by Adam Langley · 6 years ago
  99. d634357 Add initial support for 0-RTT with QUIC. by David Benjamin · 6 years ago
  100. bd2a8d6 Add a function to convert SSL_ERROR_* values to strings. by David Benjamin · 6 years ago