1. 4366476 MINOR: ssl: remove duplicate ssl_methods in struct bind_conf by Emmanuel Hocdet · Wed Aug 09 18:26:20 2017 +0200
  2. 585744b REORG/MEDIUM: connection: introduce the notion of connection handle by Willy Tarreau · Thu Aug 24 14:31:19 2017 +0200
  3. 1596929 BUILD: ssl: replace SSL_CTX_get0_privatekey for openssl < 1.0.2 by Emmanuel Hocdet · Fri Aug 11 10:56:00 2017 +0200
  4. aa0d637 MINOR: ssl: allow to start without certificate if strict-sni is set by Emmanuel Hocdet · Wed Aug 09 11:24:25 2017 +0200
  5. 48a8332 BUG/MEDIUM: ssl: Fix regression about certificates generation by Christopher Faulet · Fri Jul 28 16:56:09 2017 +0200
  6. 174dfe5 MINOR: ssl: add "no-ca-names" parameter for bind by Emmanuel Hocdet · Fri Jul 28 15:01:05 2017 +0200
  7. 71d058c MINOR: ssl: add a new error codes for wrong server certificates by Willy Tarreau · Wed Jul 26 20:09:56 2017 +0200
  8. ad92a9a BUG/MINOR: ssl: make use of the name in SNI before verifyhost by Willy Tarreau · Fri Jul 28 11:38:41 2017 +0200
  9. 96c7b8d BUG/MINOR: ssl: Fix check against SNI during server certificate verification by Christopher Faulet · Wed Jul 26 11:50:01 2017 +0200
  10. f80bc24 MINOR: ssl: remove an unecessary SSL_OP_NO_* dependancy by Emmanuel Hocdet · Wed Jul 12 14:25:38 2017 +0200
  11. 23877ab BUG/MINOR: ssl: remove haproxy SSLv3 support when ssl lib have no SSLv3 by Emmanuel Hocdet · Wed Jul 12 12:53:02 2017 +0200
  12. 7784f17 OPTIM: ssl: don't consider a small ssl_read() as an indication of end of buffer by Willy Tarreau · Tue Jul 11 14:38:39 2017 +0200
  13. 2ab8867 MINOR: ssl: compare server certificate names to the SNI on outgoing connections by Willy Tarreau · Wed Jul 05 18:23:03 2017 +0200
  14. 8743f7e MINOR: ssl: add a get_alpn() method to ssl_sock by Willy Tarreau · Sun Dec 04 18:44:29 2016 +0100
  15. 1e59fcc BUG/MINOR: ssl: Be sure that SSLv3 connection methods exist for openssl < 1.1.0 by Christopher Faulet · Thu Jun 08 22:18:52 2017 +0200
  16. bbc1654 BUG/MINOR: ssl: do not call directly the conn_fd_handler from async_fd_handler by Emeric Brun · Fri Jun 02 15:54:06 2017 +0000
  17. b5e42a8 BUG/MAJOR: ssl: buffer overflow using offloaded ciphering on async engine by Emeric Brun · Tue Jun 06 12:35:14 2017 +0000
  18. ce9e01c BUG/MAJOR: ssl: fix segfault on connection close using async engines. by Emeric Brun · Wed May 31 10:02:53 2017 +0000
  19. bd695fe MEDIUM: ssl: disable SSLv3 per default for bind by Emmanuel Hocdet · Mon May 15 15:53:41 2017 +0200
  20. df701a2 MINOR: ssl: support ssl-min-ver and ssl-max-ver with crt-list by Emmanuel Hocdet · Thu May 18 12:46:50 2017 +0200
  21. 4aa615f MEDIUM: ssl: ctx_set_version/ssl_set_version func for methodVersions table by Emmanuel Hocdet · Thu May 18 12:33:19 2017 +0200
  22. ecb0e23 REORG: ssl: move defines and methodVersions table upper by Emmanuel Hocdet · Thu May 18 11:56:58 2017 +0200
  23. 9ac143b BUILD: ssl: fix build with OPENSSL_NO_ENGINE by Emmanuel Hocdet · Mon May 29 14:36:20 2017 +0200
  24. 2c32d8f MINOR: boringssl: basic support for OCSP Stapling by Emmanuel Hocdet · Mon May 22 14:58:00 2017 +0200
  25. 3854e01 MEDIUM: ssl: handle multiple async engines by Emeric Brun · Wed May 17 20:42:48 2017 +0200
  26. fa6c7ee MAJOR: ssl: add openssl async mode support by Grant Zhang · Sat Jan 14 01:42:15 2017 +0000
  27. 872f9c2 MEDIUM: ssl: add basic support for OpenSSL crypto engine by Grant Zhang · Sat Jan 21 01:10:18 2017 +0000
  28. abd3233 MEDIUM: ssl: ssl-min-ver and ssl-max-ver compatibility. by Emmanuel Hocdet · Fri May 05 18:06:12 2017 +0200
  29. e1c722b MEDIUM: ssl: add ssl-min-ver and ssl-max-ver parameters for bind and server by Emmanuel Hocdet · Fri Mar 31 15:02:54 2017 +0200
  30. 50e25e1 MINOR: ssl: show methods supported by openssl by Emmanuel Hocdet · Fri Mar 24 15:20:03 2017 +0100
  31. 42fb980 MINOR: ssl: support TLSv1.3 for bind and server by Emmanuel Hocdet · Thu Mar 30 19:29:39 2017 +0200
  32. b4e9ba4 MEDIUM: ssl: calculate the real min/max TLS version and find holes by Emmanuel Hocdet · Thu Mar 30 19:25:07 2017 +0200
  33. 5db33cb MEDIUM: ssl: ssl_methods implementation is reworked and factored for min/max tlsxx by Emmanuel Hocdet · Thu Mar 30 19:19:37 2017 +0200
  34. 6cb2d1e MEDIUM: ssl: revert ssl/tls version settings relative to default-server. by Emmanuel Hocdet · Thu Mar 30 14:43:31 2017 +0200
  35. 53ae85c MINOR: ssl: add prefer-client-ciphers by Lukas Tribus · Thu May 04 15:45:40 2017 +0000
  36. fa5c5c8 BUG/MINOR: ssl: fix warnings about methods for opensslv1.1. by Emeric Brun · Fri Apr 28 16:19:51 2017 +0200
  37. 9a146de MINOR: server: Make 'default-server' support 'sni' keyword. by Frédéric Lécaille · Mon Mar 20 14:54:41 2017 +0100
  38. bcaf1d7 MINOR: server: Make 'default-server' support 'ciphers' keyword. by Frédéric Lécaille · Wed Mar 15 16:20:02 2017 +0100
  39. 5e57643 MINOR: server: Make 'default-server' support 'ca-file', 'crl-file' and 'crt' settings. by Frédéric Lécaille · Tue Mar 14 15:52:04 2017 +0100
  40. 273f321 MINOR: server: Make 'default-server' support 'verifyhost' setting. by Frédéric Lécaille · Mon Mar 13 15:52:01 2017 +0100
  41. 7c8cd58 MINOR: server: Make 'default-server' support 'verify' keyword. by Frédéric Lécaille · Mon Mar 13 13:41:16 2017 +0100
  42. 18388c9 CLEANUP: server: code alignement. by Frédéric Lécaille · Mon Mar 13 13:10:59 2017 +0100
  43. e892c4c MINOR: server: Make 'default-server' support 'send-proxy-v2-ssl*' keywords. by Frédéric Lécaille · Mon Mar 13 12:08:01 2017 +0100
  44. e381d76 MINOR: server: Make 'default-server' support 'ssl' keyword. by Frédéric Lécaille · Mon Mar 13 11:54:17 2017 +0100
  45. 2cfcdbe MINOR: server: Make 'default-server' support 'no-ssl*' and 'no-tlsv*' keywords. by Frédéric Lécaille · Mon Mar 13 11:32:20 2017 +0100
  46. ec16f03 CLEANUP: server: code alignement. by Frédéric Lécaille · Mon Mar 13 11:02:01 2017 +0100
  47. 9698092 MINOR: server: Make 'default-server' support 'force-sslv3' and 'force-tlsv1[0-2]' keywords. by Frédéric Lécaille · Mon Mar 13 10:54:52 2017 +0100
  48. 340ae60 MINOR: server: Make 'default-server' support 'check-ssl' keyword. by Frédéric Lécaille · Mon Mar 13 10:38:04 2017 +0100
  49. a52bb15 BUILD: ssl: simplify SSL_CTX_set_ecdh_auto compatibility by Emmanuel Hocdet · Mon Mar 20 11:11:49 2017 +0100
  50. 8d71049 BUG/MEDIUM: ssl: Clear OpenSSL error stack after trying to parse OCSP file by Janusz Dziemidowicz · Wed Mar 08 16:59:41 2017 +0100
  51. e380474 MINOR: ssl: improved cipherlist captures by Emmanuel Hocdet · Wed Mar 08 11:07:10 2017 +0100
  52. aaee750 BUG/MINOR: ssl: fix cipherlist captures with sustainable SSL calls by Emmanuel Hocdet · Tue Mar 07 18:34:58 2017 +0100
  53. f6b37c6 BUG/MEDIUM: ssl: in bind line, ssl-options after 'crt' are ignored. by Emmanuel Hocdet · Mon Mar 06 15:34:44 2017 +0100
  54. 4608ed9 MEDIUM: ssl: remove ssl-options from crt-list by Emmanuel Hocdet · Fri Jan 20 13:06:27 2017 +0100
  55. 5bf7732 MEDIUM: ssl: add new sample-fetch which captures the cipherlist by Thierry FOURNIER · Sat Feb 25 12:45:22 2017 +0100
  56. cc6c2a2 BUILD: ssl: fix build with -DOPENSSL_NO_DH by Emmanuel Hocdet · Fri Mar 03 17:04:14 2017 +0100
  57. 4de1ff1 MINOR: ssl: removes SSL_CTX_set_ssl_version call and cleanup CTX creation. by Emmanuel Hocdet · Fri Mar 03 12:21:32 2017 +0100
  58. d385060 BUG/MEDIUM: ssl: switchctx should not return SSL_TLSEXT_ERR_ALERT_WARNING by Emmanuel Hocdet · Fri Mar 03 15:21:26 2017 +0100
  59. 530141f BUG/MEDIUM: ssl: fix verify/ca-file per certificate by Emmanuel Hocdet · Wed Mar 01 18:54:56 2017 +0100
  60. 0594211 MEDIUM: boringssl: support native multi-cert selection without bundling by Emmanuel Hocdet · Mon Feb 20 16:11:50 2017 +0100
  61. e3cc3a3 BUG/MAJOR: ssl: fix a regression in ssl_sock_shutw() by Willy Tarreau · Mon Feb 13 11:12:29 2017 +0100
  62. e3e326d BUILD: ssl: kill a build warning introduced by BoringSSL compatibility by Willy Tarreau · Thu Jan 19 17:25:20 2017 +0100
  63. fdec789 BUILD: ssl: fix to build (again) with boringssl by Emmanuel Hocdet · Fri Jan 13 17:48:18 2017 +0100
  64. e7f2b73 MINOR: ssl: add curve suite for ECDHE negotiation by Emmanuel Hocdet · Mon Jan 09 16:15:54 2017 +0100
  65. 9826329 MAJOR: ssl: bind configuration per certificat by Emmanuel Hocdet · Thu Dec 29 18:26:15 2016 +0100
  66. 3eb5b3f MINOR: ssl: don't show prefer-server-ciphers output by Lukas Tribus · Wed Jan 11 22:47:18 2017 +0000
  67. 405ff31 BUG/MINOR: ssl: assert on SSL_set_shutdown with BoringSSL by Emmanuel Hocdet · Sun Jan 08 14:07:39 2017 +0100
  68. b7a4c34 BUG/MINOR: ssl: EVP_PKEY must be freed after X509_get_pubkey usage by Emmanuel Hocdet · Fri Jan 06 12:57:46 2017 +0100
  69. 119a408 BUG/MEDIUM: ssl: for a handshake when server-side SNI changes by Willy Tarreau · Thu Dec 22 21:58:38 2016 +0100
  70. ef93460 CLEANUP: ssl: move most ssl-specific global settings to ssl_sock.c by Willy Tarreau · Thu Dec 22 23:12:01 2016 +0100
  71. d1c5750 CLEANUP: ssl: move tlskeys_finalize_config() to a post_check callback by Willy Tarreau · Thu Dec 22 22:46:15 2016 +0100
  72. 17d4538 MINOR: ssl_sock: implement and use prepare_srv()/destroy_srv() by Willy Tarreau · Thu Dec 22 21:16:08 2016 +0100
  73. d9f5cca CLEANUP: connection: unexport raw_sock and ssl_sock by Willy Tarreau · Thu Dec 22 21:08:52 2016 +0100
  74. 13e1410 MINOR: connection: add a minimal transport layer registration system by Willy Tarreau · Thu Dec 22 20:25:26 2016 +0100
  75. 795cdab MINOR: ssl_sock: implement ssl_sock_destroy_bind_conf() by Willy Tarreau · Thu Dec 22 17:30:54 2016 +0100
  76. 55d3791 MEDIUM: ssl_sock: implement ssl_sock_prepare_bind_conf() by Willy Tarreau · Wed Dec 21 23:38:39 2016 +0100
  77. 0320934 MEDIUM: ssl: remote the proxy argument from most functions by Willy Tarreau · Thu Dec 22 17:08:28 2016 +0100
  78. 71a8c7c MINOR: listener: move the transport layer pointer to the bind_conf by Willy Tarreau · Wed Dec 21 22:04:54 2016 +0100
  79. 94ff03a BUG/MEDIUM: ssl: avoid double free when releasing bind_confs by Willy Tarreau · Thu Dec 22 17:57:46 2016 +0100
  80. 30fd4bd BUG/MEDIUM: ssl: properly reset the reused_sess during a forced handshake by Willy Tarreau · Thu Dec 22 21:54:21 2016 +0100
  81. 14e36a1 MEDIUM: cfgparse: move ssl-dh-param-file parsing to ssl_sock by Willy Tarreau · Wed Dec 21 23:28:13 2016 +0100
  82. f22e968 MINOR: cfgparse: move parsing of ssl-default-{bind,server}-ciphers to ssl_sock by Willy Tarreau · Wed Dec 21 23:23:19 2016 +0100
  83. 0bea58d MEDIUM: cfgparse: move maxsslconn parsing to ssl_sock by Willy Tarreau · Wed Dec 21 23:17:25 2016 +0100
  84. 9ceda38 MEDIUM: cfgparse: move all tune.ssl.* keywords to ssl_sock by Willy Tarreau · Wed Dec 21 23:13:03 2016 +0100
  85. 8c3b0fd MINOR: cfgparse: move parsing of "ca-base" and "crt-base" to ssl_sock by Willy Tarreau · Wed Dec 21 22:44:46 2016 +0100
  86. c2c0b61 CLEANUP: ssl: use the build options list to report the SSL details by Willy Tarreau · Wed Dec 21 19:23:20 2016 +0100
  87. f5f26e8 MINOR: appctx/cli: remove the "tlskeys" entry from the appctx union by Willy Tarreau · Fri Dec 16 18:47:27 2016 +0100
  88. 578b169 BUILD/MEDIUM: Fixing the build using LibreSSL by Luca Pizzamiglio · Mon Dec 12 10:56:56 2016 +0100
  89. 3067bfa BUG/MEDIUM: cli: fix "show stat resolvers" and "show tls-keys" by Willy Tarreau · Mon Dec 05 14:50:15 2016 +0100
  90. 30e5e18 CLEANUP: cli: remove assignments to st0 and st2 in keyword parsers by Willy Tarreau · Thu Nov 24 16:45:53 2016 +0100
  91. 3b6e547 CLEANUP: cli: rename STAT_CLI_* to CLI_ST_* by Willy Tarreau · Thu Nov 24 15:53:53 2016 +0100
  92. 32af203 REORG: cli: move ssl CLI functions to ssl_sock.c by William Lallemand · Sat Oct 29 18:09:35 2016 +0200
  93. 8e0bb0a MINOR: connection: add names for transport and data layers by Willy Tarreau · Thu Nov 24 16:58:12 2016 +0100
  94. ff13c06 CLEANUP: ssl: Fix bind keywords name in comments by Bertrand Jacquin · Sun Nov 13 16:37:11 2016 +0000
  95. 5424ee0 BUG/MINOR: ssl: Print correct filename when error occurs reading OCSP by Bertrand Jacquin · Sun Nov 13 16:37:14 2016 +0000
  96. 3342309 BUG/MEDIUM: ssl: Store certificate filename in a variable by Bertrand Jacquin · Sun Nov 13 16:37:13 2016 +0000
  97. 1866d6d MEDIUM: ssl: Add support for OpenSSL 1.1.0 by Dirkjan Bussink · Mon Aug 29 13:26:37 2016 +0200
  98. 07c3d78 BUG/MINOR: ssl: prevent multiple entries for the same certificate by Thierry FOURNIER / OZON.IO · Thu Oct 06 10:56:48 2016 +0200
  99. 7a3bd3b BUG/MINOR: ssl: Check malloc return code by Thierry FOURNIER / OZON.IO · Thu Oct 06 10:35:29 2016 +0200
  100. d44ea3f BUILD/CLEANUP: ssl: Check BIO_reset() return code by Thierry FOURNIER / OZON.IO · Fri Oct 14 00:49:21 2016 +0200