1. 3ac0939 Fix spelling of Identifier by Bob Beck · 1 year ago
  2. 4fa4804 Don't dereference hs->credential on TLS 1.2 PSK ciphers by David Benjamin · 1 year ago
  3. a792f88 Fix a number of cases overwriting certificates, keys, etc. with SSL_CREDENTIAL by David Benjamin · 1 year ago
  4. 5a3faaa Remove an unused runner/shim flag in SSL tests by David Benjamin · 1 year, 1 month ago
  5. 05c285d Only negotiate ECDHE curves and sigalgs once by David Benjamin · 1 year, 1 month ago
  6. 91a3f26 Add an SSL_CREDENTIAL API for ECDSA/RSA and delegated credentials by David Benjamin · 1 year, 1 month ago
  7. 1a118bb Rename CRYPTO_get_ex_new_index to CRYPTO_get_ex_new_index_ex by David Benjamin · 1 year, 1 month ago
  8. 860db9e Remove unused group_id parameter in TLS 1.3 cipher suite selection by David Benjamin · 1 year, 1 month ago
  9. 9280f15 Check ECDSA curves in TLS 1.2 servers by David Benjamin · 1 year, 1 month ago
  10. 60c2867 Check client certificate types in TLS <= 1.2 by David Benjamin · 1 year, 1 month ago
  11. 69eec38 runner: Add a test for hint mismatch due to public key by David Benjamin · 1 year, 1 month ago
  12. 6651948 runner: Configure all relevant fields from the Credential type by David Benjamin · 1 year, 1 month ago
  13. f191838 runner: Rename CertificateChain to Credential by David Benjamin · 1 year, 1 month ago
  14. fc1f521 Align CRYPTO_get_ex_new_index with the public API's calling convention by David Benjamin · 1 year, 1 month ago
  15. f4ac688 Make bssl_shim's setup logic infallible by David Benjamin · 1 year, 1 month ago
  16. ad91495 Slightly simplify ssl_x509.cc by David Benjamin · 1 year, 1 month ago
  17. c9a9d8d Forbid RSA delegated credentials by David Benjamin · 1 year, 1 month ago
  18. efad2bf Fix delegated credential signature algorithm handling by David Benjamin · 1 year, 1 month ago
  19. 9f376b0 Make DelegatedCredentials-KeyMismatch test less confusing by David Benjamin · 1 year, 1 month ago
  20. 8037383 Use slices.Contains in ssl/test/runner by David Benjamin · 1 year, 1 month ago
  21. 88a537f Fold ssl_add_cert_chain into its caller by David Benjamin · 1 year, 1 month ago
  22. e3af771 runner: Remove the ability to configure multiple certificates by David Benjamin · 1 year, 1 month ago
  23. 1e8461c runner: Use go:embed by David Benjamin · 1 year, 1 month ago
  24. df3b58e Generate certs on the fly in runner, pass trusted cert to shim by Roland Shoemaker · 1 year, 7 months ago
  25. a6e2be4 Add tests for what happens when no certificate is configured by David Benjamin · 1 year, 1 month ago
  26. ec2a08d Introduce a test helper for asserting on the error by David Benjamin · 1 year, 1 month ago
  27. 85c5d96 Make an include/openssl/experimental. Move kyber to it for now. by Bob Beck · 1 year, 1 month ago
  28. 5d88014 Deprecate and simplify SSL_CTX_check_private_key by David Benjamin · 1 year, 1 month ago
  29. 6db6604 Use std::copy instead of OPENSSL_memcpy for the internal bssl::Array::CopyFrom by David Benjamin · 1 year, 1 month ago
  30. cadebfd Consistently open files in binary mode on Windows by David Benjamin · 1 year, 2 months ago
  31. 0ff377a Add some utilities for testing temporary files by David Benjamin · 1 year, 2 months ago
  32. c06c4d5 Remove redundant piece of DC state by David Benjamin · 1 year, 1 month ago
  33. 4fe29eb Test an unusual split between context and connection configuration by David Benjamin · 1 year, 1 month ago
  34. 281053e Remove some impossible null checks by David Benjamin · 1 year, 1 month ago
  35. 1bd6e92 Remove some indirection in SSL_certs_clear by David Benjamin · 1 year, 1 month ago
  36. fbf10f0 Make an internal RefCounted base class for libssl by David Benjamin · 1 year, 1 month ago
  37. 90f0f05 Integrate TLS 1.2 sigalg and cipher suite selection by David Benjamin · 1 year, 1 month ago
  38. 48b0edf Update delegated credentials to the final RFC by David Benjamin · 1 year, 1 month ago
  39. c528061 Allow a C++ runtime dependency in libssl by David Benjamin · 1 year, 1 month ago
  40. 10605c0 Minor formatting fixes by David Benjamin · 1 year, 1 month ago
  41. fbb4133 Add SSL_get0_chain method by Gabriel Redner · 1 year, 1 month ago
  42. 07cd196 Always use a 32-byte shared secret for Kyber by David Benjamin · 1 year, 4 months ago
  43. 58906ea Merge <openssl/x509v3.h> into <openssl/x509.h> by David Benjamin · 1 year, 4 months ago
  44. 3309ca6 Add ALPS codepoint supports for split handshake by Victor Tan · 1 year, 6 months ago
  45. dd68e4b Add OPENSSL_zalloc by David Benjamin · 1 year, 6 months ago
  46. 558960d Add support for the new ALPS codepoint by Victor Tan · 1 year, 9 months ago
  47. 9404a0b runner: Check that the shim HRRs echo the session ID by David Benjamin · 1 year, 7 months ago
  48. e4f6067 Use a callable type for ScopedFILE in settings_writer.cc by David Benjamin · 1 year, 7 months ago
  49. 20a0647 Mark all of bssl::Span as constexpr by David Benjamin · 1 year, 8 months ago
  50. 7cb91d2 Reflect OPENSSL_NO_SOCK and OPENSSL_NO_POSIX_IO into headers by David Benjamin · 1 year, 8 months ago
  51. 0ffd365 Use a stub fopen implementation when OPENSSL_NO_FILESYSTEM is set by David Benjamin · 1 year, 8 months ago
  52. 5ba5db1 Support Android's "baremetal" target by David Benjamin · 1 year, 8 months ago
  53. 23d6e4c Replace BIO_snprintf with snprintf within the library by David Benjamin · 1 year, 8 months ago
  54. a4f8755 Fix error handling in bssl_shim socket object by David Benjamin · 1 year, 8 months ago
  55. 70be012 Use constant curve-specific groups whenever possible by David Benjamin · 2 years, 1 month ago
  56. a36ac0a Use std::make_unique when possible by David Benjamin · 1 year, 9 months ago
  57. 8f4daaf Resolve an old TODO in TestState::Deserialize by David Benjamin · 1 year, 9 months ago
  58. fa6ab4f Remove remnants of malloc.cc by David Benjamin · 1 year, 9 months ago
  59. 197b571 Use sources.cmake for test binaries by David Benjamin · 1 year, 9 months ago
  60. 286ea21 Replace byteBuilder and byteReader with cryptobyte by David Benjamin · 1 year, 9 months ago
  61. 4e88a35 Make the curve compat APIs into real functions by David Benjamin · 1 year, 9 months ago
  62. 50ee095 Use a single TCP server port in runner by David Benjamin · 1 year, 9 months ago
  63. f4d1d79 Simplify shimProcess accept and wait by David Benjamin · 1 year, 9 months ago
  64. 73dcd47 Turn SocketCloser in bssl_shim into a proper owning type by David Benjamin · 1 year, 9 months ago
  65. e33257f Pass IPv6 vs IPv4 down to the shim by David Benjamin · 1 year, 9 months ago
  66. e1b8685 Log failure to create SSL objects in handshakers by David Benjamin · 1 year, 9 months ago
  67. 556a973f Add SSL_CIPHER_get_handshake_digest by David Benjamin · 1 year, 10 months ago
  68. 6cf9820 Align NIDs vs group IDs in TLS group APIs by David Benjamin · 1 year, 10 months ago
  69. 335523a Align remaining TLS ECDH APIs on "group" terminology by David Benjamin · 1 year, 10 months ago
  70. 2da5ba9 Align on using the "group" over "curve" for ECDH in TLS by David Benjamin · 1 year, 10 months ago
  71. 4631ccc Remove SSL_CIPHER_get_value by David Benjamin · 1 year, 10 months ago
  72. 7e56051 Miscellaneous size_t truncation fixes by David Benjamin · 1 year, 10 months ago
  73. b0251b1 Disable TLS_RSA_WITH_3DES_EDE_CBC_SHA by default by David Benjamin · 1 year, 11 months ago
  74. 2eaf070 Add a thread test for ex_data by David Benjamin · 1 year, 11 months ago
  75. c215ce7 Use a helper function to implement get_all_foo_names functions. by Adam Langley · 1 year, 11 months ago
  76. a972b78 Add APIs to query a list of possible strings for TLS features by David Benjamin · 1 year, 11 months ago
  77. b1c6f45 Add back support for TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 by Adam Langley · 1 year, 11 months ago
  78. 4d30888 Add a more general mechanism for deprecating TLS ciphers by David Benjamin · 1 year, 11 months ago
  79. 1b724a6 Align Kyber names with draft-tls-westerbaan-xyber768d00 by David Benjamin · 1 year, 11 months ago
  80. 77b6f25 Replace interface{} with any by David Benjamin · 1 year, 11 months ago
  81. b811a6c Add Kyber to runner tests by Adam Langley · 1 year, 11 months ago
  82. 2f6409e Support WPA 3.1 "enterprise" mode. by Adam Langley · 2 years ago
  83. a02b743 runner: Remove an unnecessary use of AllCurves by David Benjamin · 1 year, 11 months ago
  84. d42c4e4 Specify the TLS cipher order more straightforwardly by David Benjamin · 1 year, 11 months ago
  85. edf7662 Allow passing extra flags to BoGo shim by Roland Shoemaker · 1 year, 11 months ago
  86. de2d610 Remove TLS_RSA_WITH_NULL_SHA by David Benjamin · 1 year, 11 months ago
  87. cee2dbb Default SSL_set_enforce_rsa_key_usage to enabled. by David Benjamin · 2 years ago
  88. 480344d Move TLS 1.3 KDF functions into the FIPS module. by Adam Langley · 2 years ago
  89. 4ae4fb7 Drop CECPQ2 support. by Adam Langley · 2 years ago
  90. 8cacbd9 Add functions to allow the mocking of AES hw support for testing. by Bob Beck · 2 years ago
  91. a438519 Fix miscellaneous size_t truncations by David Benjamin · 2 years ago
  92. bf1b792 Remove SSL_CIPHER_get_rfc_name by David Benjamin · 2 years ago
  93. fe7a067 Run `go fmt` in `ssl/test/runner`. by Adam Langley · 2 years ago
  94. 44a389a Tidy up some lengths in SSL_SESSION by David Benjamin · 2 years, 4 months ago
  95. 6e723e5 Convert a few more ints to bools in libssl. by David Benjamin · 2 years ago
  96. 58472cc Adding a C implementation of Kyber. by Sophie Schmieg · 2 years, 1 month ago
  97. af0739f Const-correct sk_FOO_cmp_func by David Benjamin · 2 years, 2 months ago
  98. 08b1f38 Use KEM terminology in TLS ECDHE and key_share abstractions by David Benjamin · 2 years, 1 month ago
  99. 9cbff81 Simplify ECKeyShare slightly. by David Benjamin · 2 years, 2 months ago
  100. a5dcf35 Move the ASN.1-based SSLKeyShare serialization to handoff.cc. by David Benjamin · 2 years, 2 months ago