Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | add OpenSSH serialization for ed25519 keys (#4808) (#4811) | bernhl | 2019-03-17 | 2 | -0/+18 | |
| | | | | | | * add OpenSSH serialization for ed25519 keys (#4808) * address review comments | |||||
* | poly1305 support (#4802) | Paul Kehrer | 2019-03-09 | 9 | -0/+334 | |
| | | | | | | | | | | | | | | | | | | | | * poly1305 support * some more tests * have I mentioned how bad the spellchecker is? * doc improvements * EVP_PKEY_new_raw_private_key copies the key but that's not documented Let's assume that might change and be very defensive * review feedback * add a test that fails on a tag of the correct length but wrong value * docs improvements | |||||
* | Improve deprecation warning to specify the release (#4804) | Josh Soref | 2019-03-08 | 1 | -2/+2 | |
| | ||||||
* | remove maccontext (#4803) | Paul Kehrer | 2019-03-07 | 9 | -88/+21 | |
| | ||||||
* | add poly1305 test vectors from rfc 7539 (#4800) | Paul Kehrer | 2019-03-07 | 2 | -0/+61 | |
| | ||||||
* | add poly1305 NID/EVP, and EVP_DigestSign{Update,Final} for incremental (#4799) | Paul Kehrer | 2019-03-07 | 3 | -0/+25 | |
| | ||||||
* | Add PEP 517 to pyproject.toml (#4783) | Paul Ganssle | 2019-02-28 | 1 | -2/+5 | |
| | | | | | This puts a new minimum on the PEP 518 requirement for `setuptools` because older versions of setuptools' PEP 517 backend will fail to include `setup.py` in an sdist. | |||||
* | Reopen master for 2.7 (#4788) | Alex Gaynor | 2019-02-28 | 3 | -2/+7 | |
| | ||||||
* | 2.6.1 release with fixed wheels (#4792) | Alex Gaynor | 2019-02-28 | 3 | -2/+10 | |
| | ||||||
* | Don't use pep517 when building our wheel (#4790) | Alex Gaynor | 2019-02-28 | 1 | -3/+3 | |
| | | | Refs #4789, https://github.com/pypa/pip/issues/6304 | |||||
* | bump version and update changelog for 2.6 release (#4787) | Paul Kehrer | 2019-02-27 | 3 | -8/+8 | |
| | | | | | | * bump version and update changelog for 2.6 release * 1.1.1b wheels for 2.6 | |||||
* | support ed25519 openssh public keys (#4785) | Paul Kehrer | 2019-02-27 | 7 | -15/+62 | |
| | | | | | | * support ed25519 openssh public keys * don't need this check | |||||
* | ed448 support (#4610) | Paul Kehrer | 2019-02-27 | 8 | -0/+716 | |
| | | | | | | | | * ed448 support * move the changelog entry * flake8 | |||||
* | homebrew switched from --build-bottle to --build-from-source (#4786) | Paul Kehrer | 2019-02-27 | 1 | -1/+1 | |
| | ||||||
* | ed25519 support (#4114) | Paul Kehrer | 2019-02-26 | 11 | -0/+782 | |
| | | | | | | * ed25519 support * review feedback | |||||
* | remove unused x509 bindings (#4776) | Paul Kehrer | 2019-02-26 | 1 | -87/+1 | |
| | ||||||
* | update travis builders to newer versions of openssl (#4784) | Paul Kehrer | 2019-02-26 | 1 | -4/+4 | |
| | ||||||
* | remove unused locking functions (#4780) | Paul Kehrer | 2019-02-26 | 2 | -29/+2 | |
| | | | | | | | | * remove unused locking functions we do all this in C when necessary * oops, need this | |||||
* | remove unused DH bindings (#4779) | Paul Kehrer | 2019-02-26 | 1 | -7/+0 | |
| | ||||||
* | remove unused PEM bindings (#4778) | Paul Kehrer | 2019-02-26 | 1 | -10/+0 | |
| | ||||||
* | how about we have less NIDs (#4777) | Paul Kehrer | 2019-02-26 | 1 | -204/+0 | |
| | | | | | | * how about we have less NIDs * pyopenssl needs these two NIDs still | |||||
* | strip out unused EVP functions (#4775) | Paul Kehrer | 2019-02-26 | 1 | -51/+0 | |
| | ||||||
* | Remove unused constant binding from ecdh.py (#4774) | Alex Gaynor | 2019-02-26 | 1 | -3/+0 | |
| | ||||||
* | Remove unused constant from ec.py bindings (#4773) | Alex Gaynor | 2019-02-26 | 1 | -3/+0 | |
| | ||||||
* | Remove unused bindings from aes.py (#4772) | Alex Gaynor | 2019-02-26 | 1 | -7/+1 | |
| | ||||||
* | Removed unused constant from bindings (#4771) | Alex Gaynor | 2019-02-26 | 1 | -2/+0 | |
| | ||||||
* | Polish off removal of unused engine bindings (#4769) | Alex Gaynor | 2019-02-25 | 2 | -15/+0 | |
| | ||||||
* | reduce our engine bindings even more (#4768) | Paul Kehrer | 2019-02-25 | 6 | -110/+47 | |
| | ||||||
* | support NO_ENGINE (#4763) | Paul Kehrer | 2019-02-25 | 11 | -18/+155 | |
| | | | | | | | | * support OPENSSL_NO_ENGINE * support some new openssl config args * sigh | |||||
* | Remove a bunch of unused engine bindings (#4766) | Alex Gaynor | 2019-02-25 | 1 | -61/+0 | |
| | ||||||
* | why did we have these variables (#4764) | Paul Kehrer | 2019-02-24 | 3 | -10/+8 | |
| | ||||||
* | add an EC OID to curve dictionary mapping (#4759) | Paul Kehrer | 2019-02-20 | 4 | -1/+57 | |
| | | | | | | | | | | * add an EC OID to curve dictionary mapping * oid_to_curve function * changelog and docs fix * rename to get_curve_for_oid | |||||
* | encode the package version in the shared object (#4756) | Paul Kehrer | 2019-02-20 | 3 | -1/+42 | |
| | | | | | | | | | | * encode the package version in the shared object * review feedback * move into build_ffi so the symbol is in all shared objects * review feedback | |||||
* | add ed25519 PKCS8 and subjectPublicKeyInfo vectors (#4719) | Paul Kehrer | 2019-02-20 | 7 | -0/+19 | |
| | | | | | | * add ed25519 PKCS8 and subjectPublicKeyInfo vectors * line length fix | |||||
* | add ed448 PKCS8 and subjectPublicKeyInfo vectors (#4718) | Paul Kehrer | 2019-02-20 | 7 | -0/+21 | |
| | ||||||
* | full state or province name (#4758) | itinerarium | 2019-02-20 | 1 | -2/+2 | |
| | | | | | | | CA -> California 6.3.5 of ITU-T X.520 (10/2016) provides a spelled out sample state. In other contexts, hints generally suggest the "full name" of a state or province. A spelled out state in the sample code might be more consistent with general usage. | |||||
* | Simplify string formatting (#4757) | Alex Gaynor | 2019-02-20 | 32 | -89/+89 | |
| | ||||||
* | update the thread link (#4748) | Paul Kehrer | 2019-02-03 | 1 | -10/+9 | |
| | | | | | | | | * update the thread link linkcheck doing its job! * update our locking information | |||||
* | concede to digicert's garbage CDN (#4747) | Paul Kehrer | 2019-02-03 | 1 | -1/+1 | |
| | | | Which, despite supporting HTTPS, is non-deterministically providing 404s and DigiCert has asserted that http is the only "supported" protocol. | |||||
* | Also suggest cryptopals to learn crypo (#4745) | Alex Gaynor | 2019-02-03 | 1 | -1/+3 | |
| | ||||||
* | Rename [wheel] section to [bdist_wheel] as the former is legacy (#4743) | Jon Dufresne | 2019-02-03 | 1 | -1/+1 | |
| | | | | | | | For additional details, see: https://github.com/pypa/wheel/blob/3dc261abc98a5e43bc7fcf5783d080aaf8f9f0cf/wheel/bdist_wheel.py#L127-L133 http://pythonwheels.com/ | |||||
* | Fixes for the latest pep8-naming (#4744) | Alex Gaynor | 2019-02-02 | 12 | -60/+60 | |
| | ||||||
* | Run wycheproof RSA tests on LibreSSL>=2.8 (#4737) | Alex Gaynor | 2019-01-24 | 2 | -7/+16 | |
| | | | | | | | | * Run wycheproof RSA tests on LibreSSL>=2.8 * Define it this way * These are errors on libressl | |||||
* | Fixes #4734 -- Deal with deprecated things (#4736) | Alex Gaynor | 2019-01-23 | 10 | -79/+26 | |
| | | | | | | | | | | * Fixes #4734 -- Deal with deprecated things - Make year based aliases of PersistentlyDeprecated so we can easily assess age - Removed encode/decode rfc6979 signature - Removed Certificate.serial * Unused import | |||||
* | Use O_CLOEXEC when it's available (#4733) | Alex Gaynor | 2019-01-23 | 1 | -10/+16 | |
| | | | | | | | | * Use O_CLOEXEC when it's available * Don't have two vars with the same name * A normal person would be emberassed | |||||
* | pypy 5.4+ (#4732) | Paul Kehrer | 2019-01-22 | 1 | -1/+1 | |
| | ||||||
* | reopen master for 2.6 work (#4730) | Paul Kehrer | 2019-01-22 | 3 | -2/+10 | |
| | ||||||
* | changelog and version bump for 2.5 (#4729) | Paul Kehrer | 2019-01-22 | 3 | -6/+6 | |
| | ||||||
* | allow asn1 times of 1950-01-01 and later. (#4728) | Paul Kehrer | 2019-01-22 | 5 | -28/+57 | |
| | | | | | | | | * allow asn1 times of 1950-01-01 and later. * add a test * pretty up the test | |||||
* | allow 32-bit platforms to encode certs with dates > unix epoch (#4727) | Paul Kehrer | 2019-01-21 | 2 | -23/+19 | |
| | | | | | | | | | | | | | | | | | Previously we used unix timestamps, but now we are switching to using ASN1_TIME_set_string and automatically formatting the string based on the year. The rule is as follows: Per RFC 5280 (section 4.1.2.5.), the valid input time strings should be encoded with the following rules: 1. UTC: YYMMDDHHMMSSZ, if YY < 50 (20YY) --> UTC: YYMMDDHHMMSSZ 2. UTC: YYMMDDHHMMSSZ, if YY >= 50 (19YY) --> UTC: YYMMDDHHMMSSZ 3. G'd: YYYYMMDDHHMMSSZ, if YYYY >= 2050 --> G'd: YYYYMMDDHHMMSSZ 4. G'd: YYYYMMDDHHMMSSZ, if YYYY < 2050 --> UTC: YYMMDDHHMMSSZ Notably, Dates < 1950 are not valid UTCTime. At the moment we still reject dates < Jan 1, 1970 in all cases but a followup PR can fix that. |