about summary refs log tree commit diff
path: root/include/compat/netinet/in.h (unfollow)
Commit message (Collapse)Author
2020-07-31tls: Call SSL_CTX_set_default_verify_paths by defaultJune McEnroe
This removes the hard dependency on a CA bundle file existing in the default path (which seems to not be the case on Debian, for example), but results in a subtle behaviour change: if the CA bundle file does not exist, the CA directory will be used instead, rather than failing hard. I believe the only reason libtls insists on loading a CA bundle file itself is so that it can be sandboxed afterwards, given that a file is loaded all at once while a directory is only loaded as needed. If the default CA bundle file exists, SSL_CTX_set_default_verify_paths will still immediately load it, so sandboxing will still work. If it doesn't exist, then the CA directory will be used, which will work well for unsandboxed applications, but will likely fail during verification as it tries to search the directory. Either way, if the CA bundle file does not exist, a sandboxed application will not work. Enabling the use of the CA directory, however, will allow more unsandboxed applications to work. Finally, to restore the original behaviour, an application can call tls_config_set_ca_file(3) with the path returned by tls_default_ca_cert_file(3).
2020-07-31tls_config: Replace constant with X509_get_default_cert_file()June McEnroe
2020-07-31tls_internal: Replace default ciphers with compatJune McEnroe
2020-07-31tls: Implement load_verify_memJune McEnroe
Based on crypto/x509/by_mem.c
2020-07-31tls: Implement use_certificate_chain_memJune McEnroe
Based on ssl/ssl_rsa.c.
2020-07-31tls: Use SSL_CTX_get0_param and X509_STORE_get0_paramJune McEnroe
2020-07-31tls_server: Remove SSL_OP_NO_CLIENT_RENEGOTIATIONJune McEnroe
This is a LibreSSL-specific option.
2020-07-31tls_ocsp: Use X509_STORE_CTX_new and X509_OBJECT_newJune McEnroe
2020-07-31tls_ocsp: Use ASN1_TIME_to_tmJune McEnroe
2020-07-31tls_conninfo: Implement time_tm_clamp_notafterJune McEnroe
From crypto/asn1/a_time_tm.c
2020-07-31tls_conninfo: Use ASN1_TIME_to_tmJune McEnroe
2020-07-31tls_verify: Use ASN1_STRING_get0_dataJune McEnroe
2020-07-31tls_bio_cb: Use public BIO interfacesJune McEnroe
2020-07-30tls_server: #include <string.h>June McEnroe
2020-07-30tls_client: #include <string.h>June McEnroe
2020-07-30tls_util: #include <string.h>June McEnroe
2020-07-30tls_config: #include <string.h>June McEnroe
2020-07-30tls: #include <string.h>June McEnroe
2020-07-30Import LibreSSL 3.2.0June McEnroe