Gitiles
Code Review
Sign In
git01.mediatek.com
/
haproxy
/
0ed1e896398c18b294507d384670f41fb2676fe7
/
src
/
ssl_sock.c
f6715e7
BUG/MEDIUM: ssl: Revamp the way early data are handled.
by Olivier Houchard
· Thu Dec 19 15:02:39 2019 +0100
e82c1d4
BUG/MEDIUM: ssl: Don't set the max early data we can receive too early.
by Olivier Houchard
· Tue Dec 17 15:39:54 2019 +0100
5b8a865
BUILD/MINOR: ssl: shut up a build warning about format truncation
by Willy Tarreau
· Tue Oct 29 10:48:50 2019 +0100
cc957c3
BUG/MINOR: ssl: certificate choice can be unexpected with openssl >= 1.1.1
by Emmanuel Hocdet
· Wed Nov 06 16:05:34 2019 +0100
d13e925
BUG/MINOR: ssl: fix curve setup with LibreSSL
by Lukas Tribus
· Sun Nov 24 18:20:40 2019 +0100
27c21cd
BUILD/MINOR: ssl: fix compiler warning about useless statement
by Eric Salama
· Wed Nov 20 11:33:40 2019 +0100
26b7b80
BUG/MINOR: ssl: fix crt-list neg filter for openssl < 1.1.1
by Emmanuel Hocdet
· Mon Nov 04 15:49:46 2019 +0100
7b34de3
BUG/MINOR: ssl: fix memcpy overlap without consequences.
by Emeric Brun
· Tue Oct 08 18:27:37 2019 +0200
2bbc80d
BUG/MINOR: ssl: Fix fd leak on error path when a TLS ticket keys file is parsed
by Christopher Faulet
· Mon Oct 21 09:55:49 2019 +0200
d6de151
BUG/MEDIUM: ssl: 'tune.ssl.default-dh-param' value ignored with openssl > 1.1.1
by Emeric Brun
· Thu Oct 17 14:53:03 2019 +0200
cfc1afe
CLEANUP: ssl: make ssl_sock_load_dh_params handle errcode/warn
by Emeric Brun
· Thu Oct 17 13:27:40 2019 +0200
394701d
CLEANUP: ssl: make ssl_sock_put_ckch_into_ctx handle errcode/warn
by Emeric Brun
· Thu Oct 17 13:25:14 2019 +0200
b131c87
CLEANUP: ssl: make ssl_sock_load_cert*() return real error codes
by Willy Tarreau
· Wed Oct 16 16:42:19 2019 +0200
c33d83d
BUILD: ssl: wrong #ifdef for SSL engines code
by William Lallemand
· Mon Oct 14 14:14:59 2019 +0200
4801c70
BUG/MINOR: ssl: abort on sni_keytypes allocation failure
by William Lallemand
· Fri Oct 04 17:36:55 2019 +0200
e92c030
BUG/MINOR: ssl: free the sni_keytype nodes
by William Lallemand
· Fri Oct 04 17:24:39 2019 +0200
24e292c
BUG/MINOR: ssl: abort on sni allocation failure
by William Lallemand
· Thu Oct 03 23:46:33 2019 +0200
4517b0c
BUG/MINOR: ssl: always check for ssl connection before getting its XPRT context
by Christopher Faulet
· Tue Sep 10 10:12:03 2019 +0200
87cfd66
BUG/MAJOR: ssl: ssl_sock was not fully initialized.
by Emeric Brun
· Fri Sep 06 15:36:02 2019 +0200
bb8643c
MINOR: ssl: ssl_fc_has_early should work for BoringSSL
by Emmanuel Hocdet
· Wed Aug 07 14:44:49 2019 +0200
510fce5
BUG/MINOR: ssl: fix 0-RTT for BoringSSL
by Emmanuel Hocdet
· Mon Aug 05 18:04:16 2019 +0200
5db881f
BUG/MINOR: ssl: revert empty handshake detection in OpenSSL <= 1.0.2
by Lukas Tribus
· Mon Jul 08 14:29:15 2019 +0200
aa2ecea
BUG/MEDIUM: ssl: Don't attempt to set alpn if we're not using SSL.
by Olivier Houchard
· Fri Jun 28 14:10:33 2019 +0200
a37eb6a
BUG/MEDIUM: ssl: Don't do anything in ssl_subscribe if we have no ctx.
by Olivier Houchard
· Mon Jun 24 18:57:39 2019 +0200
965e84e
BUG/MEDIUM: ssl: Make sure we initiate the handshake after using early data.
by Olivier Houchard
· Sat Jun 15 20:59:30 2019 +0200
3c39a7d
CLEANUP: connection: rename the wait_event.task field to .tasklet
by Willy Tarreau
· Fri Jun 14 14:42:29 2019 +0200
9faebe3
MEDIUM: tools: improve time format error detection
by Willy Tarreau
· Fri Jun 07 19:00:37 2019 +0200
81284e6
BUG/MEDIUM: ssl: Don't forget to initialize ctx->send_recv and ctx->recv_wait.
by Olivier Houchard
· Thu Jun 06 13:21:23 2019 +0200
03abf2d
MEDIUM: connections: Remove CONN_FL_SOCK*
by Olivier Houchard
· Tue May 28 10:12:02 2019 +0200
2e05548
MINOR: connections: Add a new xprt method, add_xprt().
by Olivier Houchard
· Mon May 27 19:50:12 2019 +0200
5149b59
MINOR: connections: Add a new xprt method, remove_xprt.
by Olivier Houchard
· Thu May 23 17:47:36 2019 +0200
000694c
MINOR: ssl: Make ssl_sock_handshake() static.
by Olivier Houchard
· Thu May 23 14:45:12 2019 +0200
ea8dd94
MEDIUM: ssl: Handle subscribe by itself.
by Olivier Houchard
· Mon May 20 14:02:16 2019 +0200
6567466
MINOR: SSL: add client/server random sample fetches
by Patrick Hemmer
· Tue Jun 04 08:13:03 2019 -0400
839af57
CLEANUP: ssl: remove unneeded defined(OPENSSL_IS_BORINGSSL)
by Emmanuel Hocdet
· Tue May 14 16:27:35 2019 +0200
692c1d0
MINOR: ssl: Don't forget to call the close method of the underlying xprt.
by Olivier Houchard
· Thu May 23 18:41:47 2019 +0200
19afb27
MINOR: ssl: Make sure the underlying xprt's init method doesn't fail.
by Olivier Houchard
· Thu May 23 18:24:07 2019 +0200
0590f44
BUILD: ssl: fix latest LibreSSL reg-test error
by Ilya Shipitsin
· Sat May 25 19:30:50 2019 +0500
e242f3d
BUG/MINOR: ssl_sock: Fix memory leak when disabling compression
by Ilya Shipitsin
· Sat May 25 03:38:14 2019 +0500
7e1770b
BUG/MAJOR: ssl: segfault upon an heartbeat request
by William Lallemand
· Mon May 13 14:31:34 2019 +0200
295d614
CLEANUP: ssl: move all BIO_* definitions to openssl-compat
by Willy Tarreau
· Sat May 11 17:34:03 2019 +0200
11b1671
CLEANUP: ssl: remove ifdef around SSL_CTX_get_extra_chain_certs()
by Willy Tarreau
· Sat May 11 17:02:04 2019 +0200
366a698
CLEANUP: ssl: move the SSL_OP_* and SSL_MODE_* definitions to openssl-compat
by Willy Tarreau
· Sat May 11 17:09:44 2019 +0200
8d164dc
CLEANUP: ssl: never include openssl/*.h outside of openssl-compat.h anymore
by Willy Tarreau
· Fri May 10 09:35:00 2019 +0200
9356dac
REORG: ssl: move some OpenSSL defines from ssl_sock to openssl-compat
by Willy Tarreau
· Fri May 10 09:22:53 2019 +0200
5599456
REORG: ssl: move openssl-compat from proto to common
by Willy Tarreau
· Thu May 09 14:52:44 2019 +0200
df17e0e
BUILD: ssl: fix libressl build again after aes-gcm-enc
by Willy Tarreau
· Fri May 10 09:16:53 2019 +0200
86a394e
MINOR: ssl: enable aes_gcm_dec on LibreSSL
by Willy Tarreau
· Thu May 09 14:15:32 2019 +0200
5db847a
CLEANUP: ssl: remove 57 occurrences of useless tests on LIBRESSL_VERSION_NUMBER
by Willy Tarreau
· Thu May 09 14:13:35 2019 +0200
1d158ab
BUILD: ssl: make libressl use its own version numbers
by Willy Tarreau
· Thu May 09 13:41:45 2019 +0200
9a1ab08
CLEANUP: ssl-sock: use HA_OPENSSL_VERSION_NUMBER instead of OPENSSL_VERSION_NUMBER
by Willy Tarreau
· Thu May 09 13:26:41 2019 +0200
4cd2af4
BUG/MEDIUM: ssl: Don't attempt to use early data with libressl.
by Olivier Houchard
· Mon May 06 15:18:27 2019 +0200
54832b9
BUILD: enable several LibreSSL hacks, including
by Ilya Shipitsin
· Sun May 05 23:27:54 2019 +0500
010941f
BUG/MEDIUM: ssl: Use the early_data API the right way.
by Olivier Houchard
· Fri May 03 20:56:19 2019 +0200
b51937e
BUG/MEDIUM: ssl: Don't pretend we can retry a recv/send if we got a shutr/w.
by Olivier Houchard
· Wed May 01 17:24:36 2019 +0200
a28454e
BUG/MEDIUM: ssl: Return -1 on recv/send if we got EAGAIN.
by Olivier Houchard
· Wed Apr 24 12:04:36 2019 +0200
d0e095c
MINOR: ssl/cli: async fd io-handlers printable on show fd
by Emeric Brun
· Fri Apr 19 17:15:28 2019 +0200
66a7b33
BUILD/medium: ssl: Fix build with OpenSSL < 1.1.0
by Olivier Houchard
· Thu Apr 18 15:58:15 2019 +0200
a8955d5
MEDIUM: ssl: provide our own BIO.
by Olivier Houchard
· Sun Apr 07 22:00:38 2019 +0200
e179d0e
MEDIUM: connections: Provide a xprt_ctx for each xprt method.
by Olivier Houchard
· Thu Mar 21 18:27:17 2019 +0100
df35784
MEDIUM: ssl: provide its own subscribe/unsubscribe function.
by Olivier Houchard
· Thu Mar 21 16:30:07 2019 +0100
7b5fd1e
MEDIUM: connections: Move some fields from struct connection to ssl_sock_ctx.
by Olivier Houchard
· Thu Feb 28 18:10:45 2019 +0100
66ab498
MEDIUM: ssl: Give ssl_sock its own context.
by Olivier Houchard
· Tue Feb 26 18:37:15 2019 +0100
0e492e2
BUILD: address a few cases of "static <type> inline foo()"
by Willy Tarreau
· Mon Apr 15 21:25:03 2019 +0200
2b4edfb
MINOR: ssl: Activate aes_gcm_dec converter for BoringSSL
by Emmanuel Hocdet
· Mon Apr 01 18:24:38 2019 +0200
c31499d
MINOR: ssl: Add aes_gcm_dec converter
by Nenad Merdanovic
· Sat Mar 23 11:00:32 2019 +0100
bc34cd1
BUG/MEDIUM: ssl: ability to set TLS 1.3 ciphers using ssl-default-server-ciphersuites
by Pierre Cheynier
· Thu Mar 21 16:15:47 2019 +0000
2be5a4c
MEDIUM: ssl: Use the new _HA_ATOMIC_* macros.
by Olivier Houchard
· Fri Mar 08 18:54:43 2019 +0100
1aabc93
BUG/MINOR: ssl: fix warning about ssl-min/max-ver support
by Lukas Tribus
· Tue Mar 05 23:14:32 2019 +0100
526894f
BUG/MEDIUM: ssl: Fix handling of TLS 1.3 KeyUpdate messages
by Dirkjan Bussink
· Mon Jan 21 09:35:03 2019 -0800
f24502b
BUG/MEDIUM: connections: Add the CO_FL_CONNECTED flag if a send succeeded.
by Olivier Houchard
· Thu Jan 17 19:09:11 2019 +0100
9e75477
MINOR: ssl: add support of aes256 bits ticket keys on file and cli.
by Emeric Brun
· Thu Jan 10 17:51:55 2019 +0100
09852f7
BUG/MEDIUM: ssl: missing allocation failure checks loading tls key file
by Emeric Brun
· Thu Jan 10 10:51:13 2019 +0100
51088ce
BUG/MEDIUM: ssl: Disable anti-replay protection and set max data with 0RTT.
by Olivier Houchard
· Wed Jan 02 18:46:41 2019 +0100
9215014
MEDIUM: checks: Add check-alpn.
by Olivier Houchard
· Fri Dec 21 19:47:01 2018 +0100
ab28a32
MINOR: ssl: Add ssl_sock_set_alpn().
by Olivier Houchard
· Fri Dec 21 19:45:40 2018 +0100
6818595
BUILD: ssl: Fix compilation without deprecated OpenSSL 1.1 APIs
by Rosen Penev
· Fri Dec 14 08:47:02 2018 -0800
e0f24ee
MINOR: connection: realign empty buffers in muxes, not transport layers
by Willy Tarreau
· Fri Dec 14 10:51:23 2018 +0100
e064a80
BUG/MINOR: fix ssl_fc_alpn and actually add ssl_bc_alpn
by Jérôme Magnin
· Mon Dec 03 22:21:04 2018 +0100
6be139f
BUG/MINOR: ssl: ssl_sock_parse_clienthello ignores session id
by Baptiste Assmann
· Wed Nov 28 15:20:25 2018 +0100
7706b85
MINOR: ssl: free ctx when libssl doesn't support NPN
by Lukas Tribus
· Mon Nov 26 22:57:17 2018 +0100
8071338
MINOR: initcall: apply initcall to all register_build_opts() calls
by Willy Tarreau
· Mon Nov 26 10:19:54 2018 +0100
86abe44
MEDIUM: init: use self-initializing spinlocks and rwlocks
by Willy Tarreau
· Sun Nov 25 20:12:18 2018 +0100
0108d90
MEDIUM: init: convert all trivial registration calls to initcalls
by Willy Tarreau
· Sun Nov 25 19:14:37 2018 +0100
da95fd9
BUILD/MINOR: ssl: fix build with non-alpn/non-npn libssl
by Lukas Tribus
· Sun Nov 25 13:21:27 2018 +0100
6b77f49
MEDIUM: ssl: Add ssl_bc_alpn and ssl_bc_npn sample fetches.
by Olivier Houchard
· Thu Nov 22 18:18:29 2018 +0100
c756600
MINOR: server: Add "alpn" and "npn" keywords.
by Olivier Houchard
· Tue Nov 20 23:33:50 2018 +0100
017b3da
CLEANUP: fix typos in the ssl_sock subsystem
by Joseph Herlant
· Thu Nov 15 09:07:59 2018 -0800
db39843
MINOR: stream-int: replace si_cant_put() with si_rx_room_{blk,rdy}()
by Willy Tarreau
· Thu Nov 15 11:08:52 2018 +0100
0cd3bd6
MINOR: stream-int: rename si_applet_{want|stop|cant}_{get|put}
by Willy Tarreau
· Tue Nov 06 18:46:37 2018 +0100
4c8aa11
BUG/MINOR: ssl: Wrong usage of shctx_init().
by Frédéric Lécaille
· Thu Oct 25 20:22:46 2018 +0200
b7838af
MINOR: shctx: Add a maximum object size parameter.
by Frédéric Lécaille
· Mon Oct 22 16:21:39 2018 +0200
0bec807
MINOR: shctx: Shared objects block by block allocation.
by Frédéric Lécaille
· Mon Oct 22 17:55:57 2018 +0200
a882552
BUILD: ssl: fix another null-deref warning in ssl_sock_switchctx_cbk()
by Willy Tarreau
· Mon Oct 15 13:20:07 2018 +0200
b729077
BUILD: ssl: fix null-deref warning in ssl_fc_cipherlist_str sample fetch
by Willy Tarreau
· Mon Oct 15 11:01:59 2018 +0200
83a0cd8
MINOR: connections: Introduce an unsubscribe method.
by Olivier Houchard
· Fri Sep 28 17:57:58 2018 +0200
7ad43e7
BUG/MEDIUM: Cur/CumSslConns counters not threadsafe.
by Emeric Brun
· Wed Oct 10 14:51:02 2018 +0200
415150f
MEDIUM: ssl: add support for ciphersuites option for TLSv1.3
by Dirkjan Bussink
· Fri Sep 14 11:14:21 2018 +0200
747ca61
MINOR: ssl: generate-certificates for BoringSSL
by Emmanuel Hocdet
· Mon Oct 01 18:45:19 2018 +0200
a9b8402
MINOR: ssl: cleanup old openssl API call
by Emmanuel Hocdet
· Mon Oct 01 18:41:36 2018 +0200
Next »