- a972b78 Add APIs to query a list of possible strings for TLS features by David Benjamin · 1 year, 11 months ago
- 4d30888 Add a more general mechanism for deprecating TLS ciphers by David Benjamin · 2 years ago
- 1b724a6 Align Kyber names with draft-tls-westerbaan-xyber768d00 by David Benjamin · 1 year, 11 months ago
- 2f6409e Support WPA 3.1 "enterprise" mode. by Adam Langley · 2 years ago
- de2d610 Remove TLS_RSA_WITH_NULL_SHA by David Benjamin · 2 years ago
- 3e91d37 Clarify in ssl.h documentation not to use the verify callback by David Benjamin · 2 years ago
- 4ae4fb7 Drop CECPQ2 support. by Adam Langley · 2 years ago
- 8cacbd9 Add functions to allow the mocking of AES hw support for testing. by Bob Beck · 2 years ago
- bf1b792 Remove SSL_CIPHER_get_rfc_name by David Benjamin · 2 years ago
- d897027 Update X25519+Kyber ID. by Adam Langley · 2 years ago
- fc07738 Add stubs for hybrid Kyber768 with X25519 or P-256. by Adam Langley · 2 years, 3 months ago
- 05b360d Remove hmac.h include from ssl.h. by Piotr Sikora · 2 years, 2 months ago
- a614d46 Add SSL_was_key_usage_invalid. by David Benjamin · 2 years, 4 months ago
- 7ac94aa More -Wshorten-64-to-32 fixes. by David Benjamin · 2 years, 5 months ago
- 19d6ec9 Check for TLS 1.3 in SSL_generate_key_block. by David Benjamin · 2 years, 6 months ago
- 80eb814 Remove the experimental in-place record APIs. by David Benjamin · 2 years, 6 months ago
- e8e6cac Add the "groups" variants of SSL_CTX_set1_curves_list. by David Benjamin · 2 years, 7 months ago
- 10fef97 Prefer established session properties mid renegotiation. by David Benjamin · 2 years, 7 months ago
- 4a6c8fd Support handshake hints for TLS 1.2 full handshakes. by David Benjamin · 2 years, 8 months ago
- 5697a92 Add SSL_CTX_get_num_tickets. by David Benjamin · 2 years, 8 months ago
- 955ef79 Rewrite SSL_add_file_cert_subjects_to_stack by David Benjamin · 2 years, 10 months ago
- 451ea3c Add SSL_[CTX_]_set_compliance_policy. by Adam Langley · 2 years, 11 months ago
- 3f180b8 Implement SSL_CTX_set_num_tickets. by David Benjamin · 2 years, 11 months ago
- 123eaae Record ClientHelloInner values in msg_callback. by David Benjamin · 3 years, 2 months ago
- 7198d11 Explicitly reject self-referential ech_outer_extensions. by David Benjamin · 3 years, 2 months ago
- 7e2a957 Document |SSL_set1_host| return values. by Adam Langley · 3 years, 4 months ago
- 7e7e6b6 Add |SSL_set1_host| and |SSL_set_hostflags|. by Adam Langley · 3 years, 4 months ago
- b3ed071 Add SSL_has_pending. by David Benjamin · 3 years, 5 months ago
- c2827d3 Add a function to express the desired record version protocol. by Adam Langley · 3 years, 6 months ago
- cfafcd4 Deduplicate d2i and i2d documentation. by David Benjamin · 3 years, 6 months ago
- 45c8be9 Forward-declare SSL_CLIENT_HELLO. by David Benjamin · 3 years, 6 months ago
- 62c4f15 Clarify that TLS sessions are not application sessions. by David Benjamin · 3 years, 7 months ago
- 18b6836 Update to draft-ietf-tls-esni-13. by David Benjamin · 3 years, 9 months ago
- 37a3c70 Reword SSL_get0_ech_name_override documentation. by David Benjamin · 3 years, 7 months ago
- 07b365f Remove SSL_set_verify_result. by David Benjamin · 3 years, 7 months ago
- 6191cc9 Document that SSL_PRIVATE_KEY_METHOD should configure signing prefs. by David Benjamin · 3 years, 9 months ago
- ba423c9 Implement ClientHelloOuter handshakes. by David Benjamin · 3 years, 10 months ago
- e9c5d72 Add an option to permute ClientHello extension order. by David Benjamin · 3 years, 10 months ago
- 83a4993 Add most of an ECH client implementation. by David Benjamin · 3 years, 10 months ago
- 24545c5 Add a basic API to make ECHConfigs. by David Benjamin · 3 years, 10 months ago
- c890ae5 Make ECH server APIs take EVP_HPKE_KEY. by David Benjamin · 3 years, 10 months ago
- c3b373b Rename SSL_ECH_SERVER_CONFIG_LIST to SSL_ECH_KEYS. by David Benjamin · 3 years, 10 months ago
- 3a036c7 Add SSL_ech_accepted API and ech_is_required alerts. by David Benjamin · 3 years, 10 months ago
- b587911 Remove the Channel ID callback. by David Benjamin · 3 years, 11 months ago
- 8acec00 Manage Channel ID handshake state better. by David Benjamin · 3 years, 11 months ago
- a1d3bfb Cite an RFC over 9000 (draft-ietf-quic-tls is now RFC 9001). by David Benjamin · 3 years, 10 months ago
- 3675eb3 GREASE is now RFC 8701. by David Benjamin · 3 years, 11 months ago
- b778b9c Const-correct SSL_get_srtp_profiles. by David Benjamin · 3 years, 10 months ago
- 49ee62f Update the ECH GREASE size selection. by David Benjamin · 3 years, 10 months ago
- d89ec68 Remove draft tokbind implementation. by David Benjamin · 3 years, 11 months ago
- 71a3b82 Check for resumption identifiers in SSL_SESSION_is_resumable. by David Benjamin · 3 years, 11 months ago
- 9b2cdb7 Add SSL_can_release_private_key. by David Benjamin · 4 years ago
- b571e77 Add experimental handshake hints API. by David Benjamin · 4 years ago
- 12a3e7e Check for invalid ALPN inputs in SSL_(CTX_)set_alpn_protos. by David Benjamin · 4 years ago
- 00e434d Add ECH server (draft-ietf-tls-esni-09). by Daniel McArdle · 4 years, 1 month ago
- e5fe31c Revert "Implement rsa_pkcs1_sha256_legacy." by David Benjamin · 4 years ago
- a3437c0 Implement rsa_pkcs1_sha256_legacy. by David Benjamin · 4 years, 1 month ago
- a1d1a67 Remove some remnants of TLS 1.3 downgrade carveouts. by David Benjamin · 4 years, 1 month ago
- c02c19e Honor SSL_TLSEXT_ERR_ALERT_FATAL in the ALPN callback. by David Benjamin · 4 years, 2 months ago
- 595cdc2 doc: fix SSL_set0_rbio by Yuchen Dai · 4 years, 2 months ago
- 3d8b8c3 Add support for the new QUIC TLS extension codepoint by David Schinazi · 4 years, 3 months ago
- 92c48be Update ECH GREASE to draft-ietf-tls-esni-09 by Dan McArdle · 4 years, 3 months ago
- ca058c0 Revert "Add support for the new QUIC TLS extension codepoint" by Adam Langley · 4 years, 3 months ago
- 7ba96a6 Add support for the new QUIC TLS extension codepoint by David Schinazi · 4 years, 4 months ago
- 1920c6f Implement GREASE for ECH (draft-ietf-tls-esni-08). by Dan McArdle · 5 years ago
- 41a1430 draft-ietf-tls-certificate-compression is now RFC 8879. by David Benjamin · 4 years, 4 months ago
- 5351c8b Rename the master_key field in SSL_SESSION to secret. by David Benjamin · 4 years, 4 months ago
- 0a6bfa3 Always check the TLS 1.3 downgrade signal. by David Benjamin · 4 years, 4 months ago
- fa9796e Add SSL_early_data_reason_string. by David Benjamin · 4 years, 5 months ago
- 51607f1 Implement draft-vvv-tls-alps-01. by Steven Valdez · 4 years, 8 months ago
- 3743aaf Add SSL_CIPHER_get_protocol_id. by David Benjamin · 4 years, 6 months ago
- dcd6e44 Support delegated credentials verison 06 by Watson Ladd · 4 years, 8 months ago
- 74161f4 Enforce presence of ALPN when QUIC is in use. by Nick Harper · 4 years, 8 months ago
- 7d3a24d Fix the naming of alert error codes. by David Benjamin · 4 years, 8 months ago
- cac9392 Disallow TLS 1.3 compatibility mode in QUIC. by Nick Harper · 5 years ago
- 5fa22ed Avoid relying on SSL_get_session's behavior during the handshake. by David Benjamin · 4 years, 9 months ago
- 53a17f5 Add a |SSL_process_tls13_new_session_ticket|. by Adam Langley · 4 years, 10 months ago
- 8519432 Modify how QUIC 0-RTT go/no-go decision is made. by Nick Harper · 4 years, 10 months ago
- 8f12996 Fix docs link for SSL_CTX_load_verify_locations by Anna Sarai Rosenberg · 4 years, 11 months ago
- 7c52299 Restrict when 0-RTT will be accepted in QUIC. by Nick Harper · 5 years ago
- f9e0cda Add SSL_SESSION_copy_without_early_data. by David Benjamin · 5 years ago
- 72cff81 Require QUIC method with Transport Parameters and vice versa by Nick Harper · 5 years ago
- 964256d Add |SSL_CTX_get0_chain|. by Adam Langley · 5 years ago
- 1e85905 Revise QUIC encryption secret APIs. by David Benjamin · 5 years ago
- 754d4c9 Fix client handling of 0-RTT rejects with cipher mismatch. by David Benjamin · 5 years ago
- f9cc26f Require handshake flights end at record boundaries. by David Benjamin · 5 years ago
- 1766935 Remove SSL_CTX_set_ed25519_enabled. by David Benjamin · 5 years ago
- f0a815c Add SSL_set_verify_algorithm_prefs. by David Benjamin · 5 years ago
- 10165d8 Add SSL_AD_NO_APPLICATION_PROTOCOL by David Schinazi · 5 years ago
- f249840 Remove SSL_CTX_set_rsa_pss_rsae_certs_enabled. by David Benjamin · 5 years ago
- e0d95ad Remove post-quantum experiment signal extension. by David Benjamin · 5 years ago
- b11902a HelloRetryRequest getter by Kris Kwiatkowski · 6 years ago
- 3ab3b12 Add compatibility functions for sigalgs by Shelley Vohr · 5 years ago
- 7f02881 Drop CECPQ2b code. by Adam Langley · 5 years ago fips-android-20191020
- 12049fd Add |SSL_get_min_proto_version| and |SSL_get_max_proto_version| by Alessandro Ghedini · 5 years ago
- 0e7dbd5 Add an option for explicit renegotiations. by David Benjamin · 6 years ago
- 0bb4345 Mark ssl_early_data_reason_t values stable. by David Benjamin · 6 years ago
- 04a89c8 Add |SSL_CIPHER_get_value| to get the IANA number of a cipher suite. by Adam Langley · 6 years ago
- d634357 Add initial support for 0-RTT with QUIC. by David Benjamin · 6 years ago
- bd2a8d6 Add a function to convert SSL_ERROR_* values to strings. by David Benjamin · 6 years ago