- 6f41595 Start maintaining an AUTHORS file by David Benjamin · 4 months ago
- ca420da Support sending KeyUpdate in DTLS 1.3 by David Benjamin · 4 months ago
- 484c334 Rework how DTLS ACKs and retransmits are flushed by David Benjamin · 4 months ago
- 7ad6554 Add SSL_is_quic API by David Benjamin · 4 months ago
- 391bd56 Implement receiving KeyUpdates in DTLS 1.3 by David Benjamin · 4 months ago
- 61725ea clang-format all of ssl by Bob Beck · 4 months ago
- fb5b271 Support resumption in DTLS 1.3. by Nick Harper · 5 months ago
- efff877 Improve handling of DTLS 1.3 post-handshake messages. by Nick Harper · 6 months ago
- 0f55aa8 Use InplaceVector for the various handshake derivations by David Benjamin · 6 months ago
- e1d209d Send a consistent alert when the peer sends a bad signature algorithm by David Benjamin · 11 months ago
- 05c285d Only negotiate ECDHE curves and sigalgs once by David Benjamin · 1 year, 1 month ago
- 91a3f26 Add an SSL_CREDENTIAL API for ECDSA/RSA and delegated credentials by David Benjamin · 1 year, 2 months ago
- 44a389a Tidy up some lengths in SSL_SESSION by David Benjamin · 2 years, 4 months ago
- dcabfe2 Make OPENSSL_malloc push ERR_R_MALLOC_FAILURE on failure. by Bob Beck · 2 years, 2 months ago
- 4a6c8fd Support handshake hints for TLS 1.2 full handshakes. by David Benjamin · 2 years, 8 months ago
- 50e7ea5 LSC: Apply clang-tidy's modernize-use-bool-literals to boringssl by Anton Bikineev · 3 years, 2 months ago
- a75027b Make ssl_parse_extensions a little easier to use. by David Benjamin · 3 years, 8 months ago
- 26f186b Implement a handshake hint for certificate compression. by David Benjamin · 3 years, 10 months ago
- b571e77 Add experimental handshake hints API. by David Benjamin · 4 years ago
- c4ec14c Switch ssl_parse_extensions to bool and Span. by David Benjamin · 4 years, 6 months ago
- ebad508 Switch verify sigalg pref functions to SSL_HANDSHAKE. by David Benjamin · 5 years ago
- 8fe1584 Switch cert_compression_algs to GrowableArray. by David Benjamin · 5 years ago
- e530ea3 Use spans for the various TLS 1.3 secrets. by David Benjamin · 6 years ago
- 4dfd5af Only bypass the signature verification itself in fuzzer mode. by David Benjamin · 6 years ago
- 629f321 Add an API to record use of delegated credential by Watson Ladd · 6 years ago
- 85eef29 Compute the delegated credentials length prefix with CBB. by David Benjamin · 6 years ago
- d7266ec Enforce key usage for RSA keys in TLS 1.2. by Jesse Selover · 6 years ago
- 6c1b376 Implement server support for delegated credentials. by Christopher Patton · 7 years ago
- 3cbb029 Allow configuring QUIC method per-connection by Alessandro Ghedini · 6 years ago
- 9cde848 Use handshake parameters to decide if cert/key are available by Christopher Patton · 7 years ago
- ba9ad66 Add |SSL_key_update|. by Adam Langley · 6 years ago
- 6965d25 Work around a JDK 11 TLS 1.3 bug. by David Benjamin · 6 years ago
- c8e0f90 Add an interface for QUIC integration. by Steven Valdez · 7 years ago
- 8c7c635 Support symbol prefixes by Joshua Liebow-Feeser · 7 years ago
- 12f5878 Some more bools. by David Benjamin · 7 years ago
- a130ce0 Update TLS 1.3 citations for the final RFC. by David Benjamin · 7 years ago
- f1af129 Implement TLS 1.3 anti-downgrade signal. by Steven Valdez · 7 years ago
- 35b4a12 Namespace CertCompressionAlg and use more scopers. by David Benjamin · 7 years ago
- e0afc85 Send an alert if we fail to pick a signature algorithm. by Adam Langley · 7 years ago
- 0ce090a A bunch more scopers. by David Benjamin · 7 years ago
- 8596795 Drop C++ from certificate compression API. by Adam Langley · 7 years ago
- bfdd1a9 Give SSL_SESSION a destructor. by David Benjamin · 7 years ago
- 0080d83 Implement the client side of certificate compression. by Adam Langley · 7 years ago
- a307cb7 Preliminary support for compressed certificates. by Adam Langley · 7 years ago
- b7bc80a SSL_CONFIG: new struct for sheddable handshake configuration. by Matthew Braithwaite · 7 years ago
- e325c3f Give CERT a destructor. by David Benjamin · 7 years ago
- 6df6540 Add a draft TLS 1.3 anti-downgrade signal. by David Benjamin · 7 years ago
- 964b237 Implement PR 1091 (TLS 1.3 draft '22'). by Steven Valdez · 7 years ago
- 75a1f23 Have a bit more fun with Span. by David Benjamin · 7 years ago
- d1e3ce1 Rename ssl3_send_alert and ssl3_protocol_version. by David Benjamin · 7 years ago
- 74795b3 More miscellaneous bools. by David Benjamin · 8 years ago
- 046bc1f SSL3_STATE ints to bools. by David Benjamin · 8 years ago
- c11ea942 Convert comments in ssl. by David Benjamin · 8 years ago
- 4d71a9a Migrate TLS 1.2 and below state machines to the new style. by Steven Valdez · 8 years ago
- 8fc2dc0 Put SCTs and OCSP responses in CRYPTO_BUFFERs. by David Benjamin · 8 years ago
- 7934f08 Replace init_msg/init_num with a get_message hook. by David Benjamin · 8 years ago
- 9bbdf58 Remove expect and received flight hooks. by David Benjamin · 8 years ago
- 6e9321f Add a bssl::PushToStack helper. by David Benjamin · 8 years ago
- e664a53 Return null from SSL_get0_peer_certificates if unauthenticated. by David Benjamin · 8 years ago
- 6dc8bf6 Convert SSL_TRANSCRIPT to C++. by David Benjamin · 8 years ago
- 31b0c9b Add a bunch of scopers. by David Benjamin · 8 years ago
- e39ac8f Switch BORINGSSL_INTERNAL_CXX_TYPES in favor of subclassing games. by David Benjamin · 8 years ago
- 1386aad Switch various things to scopers. by David Benjamin · 8 years ago
- 86e95b8 Move libssl's internals into the bssl namespace. by David Benjamin · 8 years ago
- 3a1dd46 Add async certificate verification callback. by David Benjamin · 8 years ago
- 11d11d6 Fix and/or annotate all switch fall-throughs. by Adam Langley · 8 years ago
- 81678aa Switch t1_lib, tls_record, and tls13_both to C++. by David Benjamin · 8 years ago[Renamed (95%) from ssl/tls13_both.c]
- 520e122 Implement experimental alternate encoding of TLS 1.3. by Steven Valdez · 8 years ago
- 4414874 Simplify ssl_private_key_* state machine points. by David Benjamin · 8 years ago
- 8d606e3 Clear out f_err pattern from handshake_client.c. by David Benjamin · 8 years ago
- e831a81 Adding support for sending early data on the client. by Steven Valdez · 8 years ago
- bbba939 Acknowledge KeyUpdate messages. by David Benjamin · 8 years ago
- a232a71 Deprecate SSL_PRIVATE_KEY_METHOD type and max_signature_len. by David Benjamin · 8 years ago
- 681eb6a Adding support for receiving early data on the server. by Steven Valdez · 8 years ago
- 794cc59 Send half-RTT tickets when negotiating 0-RTT. by David Benjamin · 8 years ago
- 2d85062 Add Data-less Zero-RTT support. by Steven Valdez · 8 years ago
- 707af29 Support asynchronous ticket decryption with TLS 1.3. by David Benjamin · 8 years ago
- ab1d28e Trim x509.h includes. by David Benjamin · 8 years ago
- 2a3b343 Move X509-related verification code into ssl_x509.c. by Adam Langley · 8 years ago
- 45738dd Move new_cipher and new_session to SSL_HANDSHAKE. by David Benjamin · 8 years ago
- 83a3212 Move SCT lists and OCSP responses to CERT. by David Benjamin · 8 years ago
- 46db7af Remove |X509| things from SSL_SESSION. by Adam Langley · 8 years ago
- 908ac19 Moving transcript and PRF functions to SSL_TRANSCRIPT. by Steven Valdez · 8 years ago
- c68e5b9 Establish that the default value of an out-arg for alerts is SSL_AD_DECODE_ERROR. by Adam Langley · 8 years ago
- 8df6766 Support setting per-connection SCT list by Alessandro Ghedini · 8 years ago
- f71036e Remove ssl_hash_message_t from ssl_get_message. by David Benjamin · 8 years ago
- 276b7e8 Move optional message type checks out of ssl_get_message. by David Benjamin · 8 years ago
- 3a2b47a Don't use |X509| objects in |CERT|, by default. by Adam Langley · 8 years ago
- 0f24bed Rename tls13_prepare_* to tls13_add_*. by David Benjamin · 8 years ago
- 25ac251 Remove write_message from TLS 1.3 handshakes. by David Benjamin · 8 years ago
- daf207a Don't use the buffer BIO in TLS. by David Benjamin · 8 years ago
- 8d5f9da Abstract away BIO_flush calls in the handshake. by David Benjamin · 8 years ago
- 08b65f4 Enabling 0-RTT on new Session Tickets. by Steven Valdez · 8 years ago
- a4b9198 Make TLS 1.3 check ECDSA KeyUsage and add test. by Adam Langley · 8 years ago
- 0c29425 Don't use |X509_get_pubkey| in TLS 1.3 code either. by Adam Langley · 8 years ago
- f1050fd Preserve the peer signature algorithm across resumes. by David Benjamin · 8 years ago
- d519bf6 Add |SSL_CTX_set0_buffer_pool|. by Adam Langley · 8 years ago
- 68e7124 Hold certificates in an SSL_SESSION as CRYPTO_BUFFERSs as well. by Adam Langley · 8 years ago
- 364f7a6 Push the difference in chain semantics to the edge. by Adam Langley · 8 years ago
- c0fc7a1 Revert "Add |SSL_CTX_set0_buffer_pool|." and "Hold certificates in an SSL_SESSION as CRYPTO_BUFFERSs as well." by Adam Langley · 8 years ago