Commit History

Autor SHA1 Mensaxe Data
  Viktor Dukhovni 55a6250f1e Skip CN DNS name constraint checks when not needed %!s(int64=6) %!d(string=hai) anos
  Matt Caswell 6ec5fce25e Update copyright year %!s(int64=6) %!d(string=hai) anos
  FdaSilvaYY 7fcdbd839c X509: add more error codes on malloc or sk_TYP_push failure %!s(int64=6) %!d(string=hai) anos
  Pauli f32b0abe26 Remove unnecessary #include <openssl/lhash.h> directives. %!s(int64=7) %!d(string=hai) anos
  David Benjamin 8545051c36 Guard against DoS in name constraints handling. %!s(int64=7) %!d(string=hai) anos
  Rich Salz 176db6dc51 Use "" not <> for internal/ includes %!s(int64=7) %!d(string=hai) anos
  Pauli a1df06b363 This has been added to avoid the situation where some host ctype.h functions %!s(int64=7) %!d(string=hai) anos
  Matt Caswell 24664a3bf5 Remove OPENSSL_assert() from crypto/x509 %!s(int64=7) %!d(string=hai) anos
  Dr. Stephen Henson c3c8823c87 Use X509_get_signature_info() when checking security levels. %!s(int64=7) %!d(string=hai) anos
  Emilia Kasper 80770da39e X509 time: tighten validation per RFC 5280 %!s(int64=7) %!d(string=hai) anos
  Viktor Dukhovni c53f7355b9 Restore last-resort expired untrusted intermediate issuers %!s(int64=8) %!d(string=hai) anos
  Viktor Dukhovni 4a7b3a7b4d Un-delete still documented X509_STORE_CTX_set_verify %!s(int64=8) %!d(string=hai) anos
  Matt Caswell 8b7c51a0e4 Add some sanity checks when checking CRL scores %!s(int64=8) %!d(string=hai) anos
  Dr. Stephen Henson 568ce3a583 Constify certificate and CRL time routines. %!s(int64=8) %!d(string=hai) anos
  klemens 6025001707 spelling fixes, just comments and readme. %!s(int64=8) %!d(string=hai) anos
  Richard Levitte 790555d675 Don't check any revocation info on proxy certificates %!s(int64=8) %!d(string=hai) anos
  Dr. Stephen Henson e032117db2 Fix CRL time comparison. %!s(int64=8) %!d(string=hai) anos
  Dr. Stephen Henson fc9d1ef39c Remove current_method from X509_STORE_CTX %!s(int64=8) %!d(string=hai) anos
  Richard Levitte 0a5fe2eb94 Add setter and getter for X509_STORE's check_policy %!s(int64=8) %!d(string=hai) anos
  Richard Levitte 1060a50b6d Add getters / setters for the X509_STORE_CTX and X509_STORE functions %!s(int64=8) %!d(string=hai) anos
  Dr. Stephen Henson 626aa24849 Use newest CRL. %!s(int64=8) %!d(string=hai) anos
  Viktor Dukhovni 5ae4ceb92c Perform DANE-EE(3) name checks by default %!s(int64=8) %!d(string=hai) anos
  Dr. Stephen Henson 5bd5dcd496 Add nameConstraints commonName checking. %!s(int64=8) %!d(string=hai) anos
  Richard Levitte 8e21938ce3 Remove the envvar hack to enable proxy cert processing %!s(int64=8) %!d(string=hai) anos
  FdaSilvaYY 02e112a885 Whitespace cleanup in crypto %!s(int64=8) %!d(string=hai) anos
  Richard Levitte ed17c7c146 Fix proxy certificate pathlength verification %!s(int64=8) %!d(string=hai) anos
  Richard Levitte c8223538cb Check that the subject name in a proxy cert complies to RFC 3820 %!s(int64=8) %!d(string=hai) anos
  Viktor Dukhovni f3e235ed6f Ensure verify error is set when X509_verify_cert() fails %!s(int64=8) %!d(string=hai) anos
  Rich Salz 6ddbb4cd92 X509_STORE_CTX accessors. %!s(int64=8) %!d(string=hai) anos
  Rich Salz b1322259d9 Copyright consolidation 09/10 %!s(int64=8) %!d(string=hai) anos