- 3ac0939 Fix spelling of Identifier by Bob Beck · 1 year ago
- 4fa4804 Don't dereference hs->credential on TLS 1.2 PSK ciphers by David Benjamin · 1 year ago
- a792f88 Fix a number of cases overwriting certificates, keys, etc. with SSL_CREDENTIAL by David Benjamin · 1 year ago
- 5a3faaa Remove an unused runner/shim flag in SSL tests by David Benjamin · 1 year, 1 month ago
- 05c285d Only negotiate ECDHE curves and sigalgs once by David Benjamin · 1 year, 1 month ago
- 91a3f26 Add an SSL_CREDENTIAL API for ECDSA/RSA and delegated credentials by David Benjamin · 1 year, 1 month ago
- 1a118bb Rename CRYPTO_get_ex_new_index to CRYPTO_get_ex_new_index_ex by David Benjamin · 1 year, 1 month ago
- 860db9e Remove unused group_id parameter in TLS 1.3 cipher suite selection by David Benjamin · 1 year, 1 month ago
- 9280f15 Check ECDSA curves in TLS 1.2 servers by David Benjamin · 1 year, 1 month ago
- 60c2867 Check client certificate types in TLS <= 1.2 by David Benjamin · 1 year, 1 month ago
- 69eec38 runner: Add a test for hint mismatch due to public key by David Benjamin · 1 year, 1 month ago
- 6651948 runner: Configure all relevant fields from the Credential type by David Benjamin · 1 year, 1 month ago
- f191838 runner: Rename CertificateChain to Credential by David Benjamin · 1 year, 1 month ago
- fc1f521 Align CRYPTO_get_ex_new_index with the public API's calling convention by David Benjamin · 1 year, 1 month ago
- f4ac688 Make bssl_shim's setup logic infallible by David Benjamin · 1 year, 1 month ago
- ad91495 Slightly simplify ssl_x509.cc by David Benjamin · 1 year, 1 month ago
- c9a9d8d Forbid RSA delegated credentials by David Benjamin · 1 year, 1 month ago
- efad2bf Fix delegated credential signature algorithm handling by David Benjamin · 1 year, 1 month ago
- 9f376b0 Make DelegatedCredentials-KeyMismatch test less confusing by David Benjamin · 1 year, 1 month ago
- 8037383 Use slices.Contains in ssl/test/runner by David Benjamin · 1 year, 1 month ago
- 88a537f Fold ssl_add_cert_chain into its caller by David Benjamin · 1 year, 1 month ago
- e3af771 runner: Remove the ability to configure multiple certificates by David Benjamin · 1 year, 1 month ago
- 1e8461c runner: Use go:embed by David Benjamin · 1 year, 1 month ago
- df3b58e Generate certs on the fly in runner, pass trusted cert to shim by Roland Shoemaker · 1 year, 7 months ago
- a6e2be4 Add tests for what happens when no certificate is configured by David Benjamin · 1 year, 1 month ago
- ec2a08d Introduce a test helper for asserting on the error by David Benjamin · 1 year, 1 month ago
- 85c5d96 Make an include/openssl/experimental. Move kyber to it for now. by Bob Beck · 1 year, 1 month ago
- 5d88014 Deprecate and simplify SSL_CTX_check_private_key by David Benjamin · 1 year, 1 month ago
- 6db6604 Use std::copy instead of OPENSSL_memcpy for the internal bssl::Array::CopyFrom by David Benjamin · 1 year, 1 month ago
- cadebfd Consistently open files in binary mode on Windows by David Benjamin · 1 year, 2 months ago
- 0ff377a Add some utilities for testing temporary files by David Benjamin · 1 year, 2 months ago
- c06c4d5 Remove redundant piece of DC state by David Benjamin · 1 year, 1 month ago
- 4fe29eb Test an unusual split between context and connection configuration by David Benjamin · 1 year, 1 month ago
- 281053e Remove some impossible null checks by David Benjamin · 1 year, 1 month ago
- 1bd6e92 Remove some indirection in SSL_certs_clear by David Benjamin · 1 year, 1 month ago
- fbf10f0 Make an internal RefCounted base class for libssl by David Benjamin · 1 year, 1 month ago
- 90f0f05 Integrate TLS 1.2 sigalg and cipher suite selection by David Benjamin · 1 year, 1 month ago
- 48b0edf Update delegated credentials to the final RFC by David Benjamin · 1 year, 1 month ago
- c528061 Allow a C++ runtime dependency in libssl by David Benjamin · 1 year, 1 month ago
- 10605c0 Minor formatting fixes by David Benjamin · 1 year, 1 month ago
- fbb4133 Add SSL_get0_chain method by Gabriel Redner · 1 year, 1 month ago
- 07cd196 Always use a 32-byte shared secret for Kyber by David Benjamin · 1 year, 4 months ago
- 58906ea Merge <openssl/x509v3.h> into <openssl/x509.h> by David Benjamin · 1 year, 4 months ago
- 3309ca6 Add ALPS codepoint supports for split handshake by Victor Tan · 1 year, 6 months ago
- dd68e4b Add OPENSSL_zalloc by David Benjamin · 1 year, 6 months ago
- 558960d Add support for the new ALPS codepoint by Victor Tan · 1 year, 9 months ago
- 9404a0b runner: Check that the shim HRRs echo the session ID by David Benjamin · 1 year, 7 months ago
- e4f6067 Use a callable type for ScopedFILE in settings_writer.cc by David Benjamin · 1 year, 7 months ago
- 20a0647 Mark all of bssl::Span as constexpr by David Benjamin · 1 year, 8 months ago
- 7cb91d2 Reflect OPENSSL_NO_SOCK and OPENSSL_NO_POSIX_IO into headers by David Benjamin · 1 year, 8 months ago
- 0ffd365 Use a stub fopen implementation when OPENSSL_NO_FILESYSTEM is set by David Benjamin · 1 year, 8 months ago
- 5ba5db1 Support Android's "baremetal" target by David Benjamin · 1 year, 8 months ago
- 23d6e4c Replace BIO_snprintf with snprintf within the library by David Benjamin · 1 year, 8 months ago
- a4f8755 Fix error handling in bssl_shim socket object by David Benjamin · 1 year, 8 months ago
- 70be012 Use constant curve-specific groups whenever possible by David Benjamin · 2 years, 1 month ago
- a36ac0a Use std::make_unique when possible by David Benjamin · 1 year, 9 months ago
- 8f4daaf Resolve an old TODO in TestState::Deserialize by David Benjamin · 1 year, 9 months ago
- fa6ab4f Remove remnants of malloc.cc by David Benjamin · 1 year, 9 months ago
- 197b571 Use sources.cmake for test binaries by David Benjamin · 1 year, 9 months ago
- 286ea21 Replace byteBuilder and byteReader with cryptobyte by David Benjamin · 1 year, 9 months ago
- 4e88a35 Make the curve compat APIs into real functions by David Benjamin · 1 year, 9 months ago
- 50ee095 Use a single TCP server port in runner by David Benjamin · 1 year, 9 months ago
- f4d1d79 Simplify shimProcess accept and wait by David Benjamin · 1 year, 9 months ago
- 73dcd47 Turn SocketCloser in bssl_shim into a proper owning type by David Benjamin · 1 year, 9 months ago
- e33257f Pass IPv6 vs IPv4 down to the shim by David Benjamin · 1 year, 9 months ago
- e1b8685 Log failure to create SSL objects in handshakers by David Benjamin · 1 year, 9 months ago
- 556a973f Add SSL_CIPHER_get_handshake_digest by David Benjamin · 1 year, 10 months ago
- 6cf9820 Align NIDs vs group IDs in TLS group APIs by David Benjamin · 1 year, 10 months ago
- 335523a Align remaining TLS ECDH APIs on "group" terminology by David Benjamin · 1 year, 10 months ago
- 2da5ba9 Align on using the "group" over "curve" for ECDH in TLS by David Benjamin · 1 year, 10 months ago
- 4631ccc Remove SSL_CIPHER_get_value by David Benjamin · 1 year, 10 months ago
- 7e56051 Miscellaneous size_t truncation fixes by David Benjamin · 1 year, 10 months ago
- b0251b1 Disable TLS_RSA_WITH_3DES_EDE_CBC_SHA by default by David Benjamin · 1 year, 11 months ago
- 2eaf070 Add a thread test for ex_data by David Benjamin · 1 year, 11 months ago
- c215ce7 Use a helper function to implement get_all_foo_names functions. by Adam Langley · 1 year, 11 months ago
- a972b78 Add APIs to query a list of possible strings for TLS features by David Benjamin · 1 year, 11 months ago
- b1c6f45 Add back support for TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 by Adam Langley · 1 year, 11 months ago
- 4d30888 Add a more general mechanism for deprecating TLS ciphers by David Benjamin · 1 year, 11 months ago
- 1b724a6 Align Kyber names with draft-tls-westerbaan-xyber768d00 by David Benjamin · 1 year, 11 months ago
- 77b6f25 Replace interface{} with any by David Benjamin · 1 year, 11 months ago
- b811a6c Add Kyber to runner tests by Adam Langley · 1 year, 11 months ago
- 2f6409e Support WPA 3.1 "enterprise" mode. by Adam Langley · 2 years ago
- a02b743 runner: Remove an unnecessary use of AllCurves by David Benjamin · 1 year, 11 months ago
- d42c4e4 Specify the TLS cipher order more straightforwardly by David Benjamin · 1 year, 11 months ago
- edf7662 Allow passing extra flags to BoGo shim by Roland Shoemaker · 1 year, 11 months ago
- de2d610 Remove TLS_RSA_WITH_NULL_SHA by David Benjamin · 1 year, 11 months ago
- cee2dbb Default SSL_set_enforce_rsa_key_usage to enabled. by David Benjamin · 2 years ago
- 480344d Move TLS 1.3 KDF functions into the FIPS module. by Adam Langley · 2 years ago
- 4ae4fb7 Drop CECPQ2 support. by Adam Langley · 2 years ago
- 8cacbd9 Add functions to allow the mocking of AES hw support for testing. by Bob Beck · 2 years ago
- a438519 Fix miscellaneous size_t truncations by David Benjamin · 2 years ago
- bf1b792 Remove SSL_CIPHER_get_rfc_name by David Benjamin · 2 years ago
- fe7a067 Run `go fmt` in `ssl/test/runner`. by Adam Langley · 2 years ago
- 44a389a Tidy up some lengths in SSL_SESSION by David Benjamin · 2 years, 4 months ago
- 6e723e5 Convert a few more ints to bools in libssl. by David Benjamin · 2 years ago
- 58472cc Adding a C implementation of Kyber. by Sophie Schmieg · 2 years, 1 month ago
- af0739f Const-correct sk_FOO_cmp_func by David Benjamin · 2 years, 2 months ago
- 08b1f38 Use KEM terminology in TLS ECDHE and key_share abstractions by David Benjamin · 2 years, 1 month ago
- 9cbff81 Simplify ECKeyShare slightly. by David Benjamin · 2 years, 2 months ago
- a5dcf35 Move the ASN.1-based SSLKeyShare serialization to handoff.cc. by David Benjamin · 2 years, 2 months ago