Commit Verlauf

Autor SHA1 Nachricht Datum
  Richard Levitte 4579924b7e Cleanse memory using the new OPENSSL_cleanse() function. vor 22 Jahren
  Ben Laurie 54a656ef08 Security fixes brought forward from 0.9.7. vor 22 Jahren
  Geoff Thorpe e0db2eed8d Correct and enhance the behaviour of "internal" session caching as it vor 22 Jahren
  Bodo Möller 5574e0ed41 get rid of OpenSSLDie vor 22 Jahren
  Lutz Jänicke c046fffa16 OpenSSL Security Advisory [30 July 2002] vor 22 Jahren
  Lutz Jänicke acfe628b6e Make removal from session cache more robust. vor 22 Jahren
  Geoff Thorpe 79aa04ef27 Make the necessary changes to work with the recent "ex_data" overhaul. vor 23 Jahren
  Geoff Thorpe b7727ee616 The indexes returned by ***_get_ex_new_index() functions are used when vor 23 Jahren
  Richard Levitte c2a3358b60 Whoops, my fault, a backslash got converted to a slash... vor 23 Jahren
  Richard Levitte 882e891284 More Kerberos SSL changes from Jeffrey Altman <jaltman@columbia.edu> vor 23 Jahren
  Geoff Thorpe f85c9904c6 Fix an oversight - when checking a potential session ID for conflicts with vor 23 Jahren
  Geoff Thorpe dc644fe229 This change allows a callback to be used to override the generation of vor 23 Jahren
  Geoff Thorpe 3c91484052 Move all the existing function pointer casts associated with LHASH's two vor 24 Jahren
  Geoff Thorpe 385d81380c First step in tidying up the LHASH code. The callback prototypes (and vor 24 Jahren
  Lutz Jänicke 0dd2254d76 Store verify_result with sessions to avoid potential security hole. vor 24 Jahren
  Richard Levitte 26a3a48d65 There have been a number of complaints from a number of sources that names vor 24 Jahren
  Ulf Möller 9d1a01be8f Source code cleanups: Use void * rather than char * in lhash, vor 25 Jahren
  Bodo Möller 52732b38da Some comments added, and slight code clean-ups. vor 25 Jahren
  Dr. Stephen Henson dd9d233e2a vor 25 Jahren
  Ulf Möller e7f97e2d22 Check RAND_bytes() return value or use RAND_pseudo_bytes(). vor 25 Jahren
  Bodo Möller 45fd4dbb84 Fix SSL_CTX_add_session: When two SSL_SESSIONs have the same ID, vor 25 Jahren
  Bodo Möller 1088e27ca8 Restore traditional SSL_get_session behaviour so that s_client and s_server vor 25 Jahren
  Bodo Möller b1fe6ca175 Store verify_result with sessions to avoid potential security hole. vor 25 Jahren
  Mark J. Cox b7cfcfb7f8 This corrects the reference count handling in SSL_get_session. vor 25 Jahren
  Bodo Möller b1c4fe3625 Don't mix real tabs with tabs expanded as 8 spaces -- that's vor 25 Jahren
  Bodo Möller bdc98ffba9 Don't use NULL-pointer :-/ vor 25 Jahren
  Bodo Möller 1dfad80565 Comment about bug. vor 25 Jahren
  Bodo Möller 8876bc0548 Let ssl_get_prev_session reliably work in multi-threaded settings. vor 25 Jahren
  Bodo Möller 9a193d8825 Avoid memory hole when we don't like the session proposed by the client vor 25 Jahren
  Bodo Möller 673eadec2c Additional, more descriptive error message for rejection of a session ID vor 25 Jahren