Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | | let the compiler figure out these values | Paul Kehrer | 2015-12-01 | 1 | -3/+4 | |
| | | ||||||
* | | fix a warning in cffi | Paul Kehrer | 2015-12-01 | 2 | -1/+8 | |
|/ | | | | | cffi doesn't want to guess the type, so we'll deopaque the enum and strip the values out of the lib if EC is unavailable | |||||
* | Add support for 160 bit ARC4 keys | Ehren Kret | 2015-11-28 | 1 | -1/+1 | |
| | ||||||
* | Add more CRYPTO_EX_DATA functions | Christian Heimes | 2015-11-20 | 3 | -0/+20 | |
| | | | | | | | | The patch adds a couple of additional functions to create, store and retrieve ex_data on SSL, SSL_CTX and X509 objects. It also adds the missing get_ex_new_index function for X509_STORE_CTX. Signed-off-by: Christian Heimes <cheimes@redhat.com> | |||||
* | add tbsCertList and signature interfaces to CRLs | Erik Trauschke | 2015-11-19 | 3 | -0/+30 | |
| | ||||||
* | RHEL 6.4 and below don't even claim to be 1.0.0 final... | Paul Kehrer | 2015-11-12 | 1 | -1/+1 | |
| | ||||||
* | whoops | Paul Kehrer | 2015-11-12 | 1 | -0/+1 | |
| | ||||||
* | reorganize and rename | Paul Kehrer | 2015-11-12 | 2 | -11/+11 | |
| | ||||||
* | these functions were added in 1.0.0, while CMS was added in 0.9.8h | Paul Kehrer | 2015-11-12 | 2 | -0/+15 | |
| | | | | | We didn't catch this in our CI because all our 0.9.8 targets have CMS disabled or are older than 0.9.8h | |||||
* | Include the full OpenSSL error in the exception message | Alex Gaynor | 2015-11-08 | 1 | -1/+1 | |
| | ||||||
* | Merge pull request #2467 from reaperhulk/fix-version-check | Alex Gaynor | 2015-11-04 | 1 | -2/+2 | |
|\ | | | | | these flags were actually added in 1.0.2beta2, not before that. | |||||
| * | these flags were actually added in 1.0.2beta2, not before that. | Paul Kehrer | 2015-11-05 | 1 | -2/+2 | |
| | | ||||||
* | | remove malloc_debug_init as it has occasionally caused compile issues | Paul Kehrer | 2015-11-05 | 1 | -1/+0 | |
|/ | | | | We also don't use it in our backend (and neither does pyOpenSSL) | |||||
* | rename tbs_certificate to tbs_certificate_bytes, add a comment | Paul Kehrer | 2015-11-03 | 2 | -2/+3 | |
| | ||||||
* | add support for Certificate signature and tbs_certificate | Paul Kehrer | 2015-11-03 | 4 | -1/+29 | |
| | ||||||
* | Provide more aggressive language about dropping 2.6 | Alex Gaynor | 2015-11-01 | 1 | -1/+2 | |
| | ||||||
* | flake8 | Alex Gaynor | 2015-11-01 | 1 | -2/+2 | |
| | ||||||
* | corrected a few typos in comments | Alex Gaynor | 2015-11-01 | 1 | -3/+3 | |
| | ||||||
* | Merge pull request #2455 from alex/different-curves | Paul Kehrer | 2015-10-29 | 1 | -0/+5 | |
|\ | | | | | Error cleanly if the public and private keys to an ECDH key exchange … | |||||
| * | please flake8 | Alex Gaynor | 2015-10-29 | 1 | -1/+1 | |
| | | ||||||
| * | Error cleanly if the public and private keys to an ECDH key exchange are on ↵ | Alex Gaynor | 2015-10-28 | 1 | -0/+5 | |
| | | | | | | | | different curves | |||||
* | | oh right pep8 is a thing | Paul Kehrer | 2015-10-29 | 1 | -3/+0 | |
| | | ||||||
* | | do the deprecation dance for the twelfth release | Paul Kehrer | 2015-10-29 | 2 | -13/+1 | |
|/ | ||||||
* | reopen master for development on the twelfth release | Paul Kehrer | 2015-10-29 | 1 | -1/+1 | |
| | ||||||
* | bump version and update changelog for eleventh release (1.1) | Paul Kehrer | 2015-10-29 | 1 | -1/+1 | |
| | | | | Add some missing changelog entries | |||||
* | add ellipticcurvepublicnumbers repr | Paul Kehrer | 2015-10-28 | 1 | -0/+6 | |
| | ||||||
* | Merge pull request #2447 from reaperhulk/encode-decode-point | Alex Gaynor | 2015-10-27 | 2 | -2/+30 | |
|\ | | | | | add support for encoding/decoding elliptic curve points | |||||
| * | address review feedback | Paul Kehrer | 2015-10-28 | 1 | -5/+2 | |
| | | ||||||
| * | modify approach to use EllipticCurvePublicNumbers methods | Paul Kehrer | 2015-10-27 | 2 | -34/+28 | |
| | | ||||||
| * | remove support for null points, improve docs | Paul Kehrer | 2015-10-27 | 1 | -4/+4 | |
| | | ||||||
| * | add support for encoding/decoding elliptic curve points | Paul Kehrer | 2015-10-26 | 2 | -2/+39 | |
| | | | | | | | | Based on the work of @ronf in #2346. | |||||
* | | Merge pull request #2435 from reaperhulk/fix-2407 | Alex Gaynor | 2015-10-27 | 1 | -6/+8 | |
|\ \ | | | | | | | encode countryName with PrintableString | |||||
| * | | update comment to include a bit more detail | Paul Kehrer | 2015-10-27 | 1 | -2/+2 | |
| | | | ||||||
| * | | encode countryName with PrintableString | Paul Kehrer | 2015-10-20 | 1 | -6/+8 | |
| | | | | | | | | | | | | | | | | | | | | | This commit adds a dependency on asn1crypto for testing purposes to parse the certificate and confirm that countryName is encoded with PrintableString while other fields are UTF8String. This is a test only dep. | |||||
* | | | Merge pull request #2446 from reaperhulk/init-locks | Alex Gaynor | 2015-10-26 | 2 | -2/+8 | |
|\ \ \ | |_|/ |/| | | move lock initialization to during binding import | |||||
| * | | modify sadness prose | Paul Kehrer | 2015-10-27 | 1 | -3/+5 | |
| | | | ||||||
| * | | expand comment | Paul Kehrer | 2015-10-24 | 1 | -1/+3 | |
| | | | ||||||
| * | | move lock initialization to during binding import | Paul Kehrer | 2015-10-24 | 2 | -2/+4 | |
| | | | | | | | | | | | | | | | | | | | | | | | | Previously we attempted to register our openssl locks only if the backend was initialized, but we should really just do it immediately. Consumers like PyOpenSSL already call init_static_locks after importing the binding and if a library wants to replace the locks with something else they can do so themselves. | |||||
* | | | Merge pull request #2220 from reaperhulk/encode-cp | Alex Gaynor | 2015-10-24 | 1 | -0/+90 | |
|\ \ \ | |/ / |/| | | support encoding certificate policies in CertificateBuilder | |||||
| * | | use new ExtensionOID | Paul Kehrer | 2015-10-24 | 1 | -1/+1 | |
| | | | ||||||
| * | | one more assert | Paul Kehrer | 2015-10-24 | 1 | -1/+1 | |
| | | | ||||||
| * | | convert asserts to openssl_assert | Paul Kehrer | 2015-10-24 | 1 | -10/+10 | |
| | | | ||||||
| * | | support encoding certificate policies in CertificateBuilder | Paul Kehrer | 2015-10-24 | 1 | -0/+90 | |
| | | | ||||||
* | | | Merge pull request #2293 from reaperhulk/idempotent-engine-add | Alex Gaynor | 2015-10-24 | 2 | -6/+9 | |
|\ \ \ | |/ / |/| | | idempotent engine add | |||||
| * | | address review comments | Paul Kehrer | 2015-10-24 | 1 | -5/+2 | |
| | | | ||||||
| * | | make engine addition idempotent | Paul Kehrer | 2015-10-21 | 2 | -5/+11 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Threading issues keep cropping up. ENGINE_add already acquires a lock at the C layer via CRYPTO_w_lock (provided you have registered the locking callbacks) so let's try to use that. As part of this we'll try to init the openssl locks, but of course there's potentially a race there as well. Clearly this isn't the real fix but it might improve the situation while we try to determine what to do. | |||||
* | | | Fixed #2444 -- added an __hash__ to x509 Names | Alex Gaynor | 2015-10-24 | 1 | -0/+8 | |
| | | | ||||||
* | | | update a comment | Paul Kehrer | 2015-10-22 | 1 | -2/+3 | |
| | | | ||||||
* | | | pep8! | Paul Kehrer | 2015-10-21 | 1 | -1/+1 | |
| | | | ||||||
* | | | AES keywrap support | Paul Kehrer | 2015-10-21 | 2 | -1/+85 | |
|/ / |