| Commit message (Collapse) | Author | Age | Files | Lines |
|
|
|
|
| |
certificate so need to match its subject with the certificate IDs in the
response.
|
| |
|
|
|
|
| |
properly and supports several flags.
|
|
|
|
|
| |
Note that all *_it variables are suddenly non-existant according to
libeay.num. This is a bug that will be corrected. Please be patient.
|
| |
|
|
|
|
| |
or serial number.
|
|
|
|
|
|
| |
prototype hack. This unfortunately means that
every ASN1_*_END construct cannot have a
trailing ;
|
|
|
|
|
|
|
|
| |
change the way ASN1 modules are exported.
Still needs a bit of work for example the hack which a
dummy function prototype to avoid compilers warning about
multiple ;s.
|
|
|
|
|
|
|
|
| |
and make all files the depend on it include it without prefixing it
with openssl/.
This means that all Makefiles will have $(TOP) as one of the include
directories.
|
|
|
|
| |
lots of silly warnings from the compiler.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
| |
sure they are available in opensslconf.h, by giving them names starting
with "OPENSSL_" to avoid conflicts with other packages and by making
sure e_os2.h will cover all platform-specific cases together with
opensslconf.h.
I've checked fairly well that nothing breaks with this (apart from
external software that will adapt if they have used something like
NO_KRB5), but I can't guarantee it completely, so a review of this
change would be a good thing.
|
|
|
|
| |
Doesn't handle SSL URLs yet.
|
| |
|
|
|
|
|
| |
inversed. Corrected. Hopefully, this will make it work without
dumping core.
|
|
|
|
|
|
|
|
|
|
| |
Update Rijndael source to v3.0
Add AES OIDs.
Change most references of Rijndael to AES.
Add new draft AES ciphersuites.
|
|
|
|
| |
request to response.
|
| |
|
|
|
|
|
|
|
|
| |
Add protoype for OCSP_response_create().
Add OCSP_request_sign() and OCSP_basic_sign()
private key and certificate checks and make
OCSP_NOCERTS consistent with PKCS7_NOCERTS
|
|
|
|
|
|
| |
Delete obsolete OCSP functions.
Largely untested at present...
|
| |
|
| |
|
|
|
|
|
|
|
| |
of status info. Check nonce values. Option to disable
verify. Update usage message.
Rename status to string functions and make them global.
|
|
|
|
| |
accordance with RFC2560.
|
|
|
|
| |
it just supports a "trusted OCSP global root CA".
|
|
|
|
|
|
|
|
| |
OCSP requests. It can also query reponders and parse or
print out responses.
Still needs some more work: OCSP response checks and
of course documentation.
|
| |
|
|
|
|
|
|
|
|
|
|
|
| |
invalid format in OCSP request signatures.
Add spaces to OCSP HTTP header.
Change X509_NAME_set() there's no reason
why it should return an error if the
destination points to NULL... though it
should if the destination is NULL.
|
|
|
|
|
|
|
|
|
|
| |
but will verify the signatures on a response
and locate the signers certifcate.
Still needs to implement a proper OCSP certificate
verify.
Fix warning in RAND_egd().
|
|
|
|
| |
Fix bug in OCSP_find_status().
|
|
|
|
|
|
|
|
| |
and subject to addition, modifcation or deletion.
Add two OCSP nonce utility functions.
Fix typo in status code name.
|
|
|
|
|
|
| |
application needs.
Add OCSP library name to error code.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
Remove extensions argument from various functions
because it is not needed with the new extension
code.
New function OCSP_cert_to_id() to convert a pair
of certificates into an OCSP_CERTID.
New simple OCSP HTTP function. This is rather primitive
but just about adequate to send OCSP requests and
parse the response.
Fix typo in CRL distribution points extension.
Fix ASN1 code so it adds a final null to constructed
strings.
|
| |
|
|
|
|
|
|
|
|
|
|
| |
currently OpenSSL itself wont compile with this set
because some old style stuff remains.
Change old functions X509_sign(), X509_verify() etc
to use new item based functions.
Replace OCSP function declarations with DECLARE macros.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
Win32 but it is getting there...
Update mkdef.pl to handle ASN1_ANY and fix headers.
Stop various VC++ warnings.
Include some fixes from "Peter 'Luna' Runestig"
<peter@runestig.com>
Remove external declaration for des_set_weak_key_flag:
it doesn't exist.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
Don't try to print request certificates if signature is not present.
Remove unnecessary test for certificates being NULL.
Fix typos in printed output.
Tidy up output.
Fix for typo in OCSP_SERVICELOC ASN1 template.
Also give a bit more info in CHANGES about the ASN1 revision.
|
|
|
|
| |
obsolete code. Delete some redundant files.
|
|
|
|
| |
are all raw print only extensions at present.
|
|
|
|
|
|
| |
This is a little unusual because it can contain no
structure i.e. the extension OCTET STRING content
octets do not contain a DER encoded structure.
|
|
|
|
|
|
|
|
|
| |
from the print routines.
Reorganisation of OCSP code: initial print routines in ocsp_prn.c. Doesn't
work fully because OCSP extensions aren't reimplemented yet.
Implement some ASN1 functions needed to compile OCSP code.
|
| |
|
| |
|
| |
|
|
|
|
| |
Caught by Jeffrey Altman <jaltman@columbia.edu>
|
| |
|
| |
|
| |
|
|
|