Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | consolidate the windows specific header trickery we need to do | Paul Kehrer | 2016-01-18 | 2 | -9/+8 |
| | |||||
* | Merge pull request #2646 from reaperhulk/static-callbacks | Alex Gaynor | 2016-01-08 | 2 | -0/+51 |
|\ | | | | | Static callbacks | ||||
| * | remove the callbacks we don't use in cryptography | Paul Kehrer | 2016-01-07 | 1 | -61/+0 |
| | | |||||
| * | Port callbacks to new static callback | Christian Heimes | 2016-01-07 | 2 | -0/+112 |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | cffi 1.4.0 will introduce a new API to create static callbacks. Contrary to the old callback API, static callbacks no longer depend on libffi's dynamic code generation for closures. Static code has some benefits over dynamic generation. For example the code is faster. Also it doesn't need writeable and executable memory mappings, which makes it compatible with SELinux's deny execmem policy. The branch depends on PR #2488. https://bitbucket.org/cffi/cffi/issues/232/static-callbacks Closes: #2477 Signed-off-by: Christian Heimes <cheimes@redhat.com> | ||||
* | | use EVP_PKEY_id where we can | Paul Kehrer | 2016-01-07 | 1 | -2/+7 |
| | | |||||
* | | add Cryptography_EVP_PKEY_id | Paul Kehrer | 2016-01-07 | 1 | -0/+6 |
| | | |||||
* | | opaque EVP_PKEY since EVP_PKEY_id exists | Paul Kehrer | 2016-01-07 | 1 | -4/+1 |
|/ | |||||
* | convert other extra_link_args calls | Paul Kehrer | 2016-01-01 | 2 | -6/+4 |
| | |||||
* | don't add the NXCOMPAT and DYNAMICBASE flags if the compiler isn't msvc | Paul Kehrer | 2016-01-01 | 2 | -8/+25 |
| | |||||
* | RSA_R_OAEP_DECODING_ERROR is pretty ubiquitous | Paul Kehrer | 2015-12-27 | 1 | -8/+0 |
| | |||||
* | Add support for RSA_R_OAEP_DECODING_ERROR error flag. | Christopher Grebs | 2015-12-27 | 1 | -0/+9 |
| | |||||
* | Simplify code slightly by adding a new binding | Alex Gaynor | 2015-12-26 | 1 | -0/+2 |
| | |||||
* | new asn1 bindings needed for #2582 | Paul Kehrer | 2015-12-26 | 1 | -0/+3 |
| | |||||
* | X509_REVOKED_dup isn't available everywhere, we get to define our own | Paul Kehrer | 2015-12-25 | 1 | -1/+10 |
| | |||||
* | support revoked certificates in CertificateRevocationListBuilder | Paul Kehrer | 2015-12-25 | 1 | -0/+1 |
| | |||||
* | a different approach to refactoring the x509 extension addition | Paul Kehrer | 2015-12-24 | 1 | -0/+1 |
| | |||||
* | Add PEM_write_bio_DHparams binding | evilaliv3 | 2015-12-24 | 1 | -0/+1 |
| | |||||
* | add binding for setting the revocation date of an X509_REVOKED | Paul Kehrer | 2015-12-23 | 1 | -0/+2 |
| | |||||
* | Remove spaces. | Cory Benfield | 2015-12-23 | 1 | -1/+1 |
| | |||||
* | Add binding for CommonCrypto SecTrustCopyAnchorCertificates | Cory Benfield | 2015-12-23 | 2 | -0/+23 |
| | |||||
* | Comment lingering SSLv2 symbol. | Cory Benfield | 2015-12-14 | 1 | -0/+4 |
| | |||||
* | Remove SSLv2 bindings. | Cory Benfield | 2015-12-14 | 1 | -16/+1 |
| | | | | | | | | | This commit removes bindings that allow users to set SSLv2 handshake methods. These are regarded as unnecessary and out-of-date: see #2527. This commit does leave in a few options that refer to SSLv2 in order to avoid breaking deployments that rely on them, and in order to allow users to continue to request that SSLv2 not be enabled at all in their OpenSSL. | ||||
* | Merge pull request #2515 from reaperhulk/sigbus | Alex Gaynor | 2015-12-09 | 1 | -16/+0 |
|\ | | | | | remove the bindings for these x86_64 specific EC functions | ||||
| * | remove the bindings for these x86_64 specific EC functions | Paul Kehrer | 2015-12-09 | 1 | -16/+0 |
| | | | | | | | | | | | | | | | | We have no need to invoke them directly and their presence triggers a bug related to Fedora 23's hobbling of openssl EC functions (uugh) This also fixes the SIGBUS issue in #2503, although that is more appropriately resolved via header fixes for universal libraries on OS X. | ||||
* | | expose tbs_certrequest_bytes and signature on CertificateSigningRequest | Paul Kehrer | 2015-12-03 | 1 | -0/+4 |
| | | |||||
* | | Merge pull request #2504 from reaperhulk/encode-name-constraints | Alex Gaynor | 2015-12-03 | 1 | -0/+12 |
|\ \ | | | | | | | implement support for encoding name constraints | ||||
| * | | implement support for encoding name constraints | Paul Kehrer | 2015-12-02 | 1 | -0/+12 |
| |/ | |||||
* | | shouldn't need values here | Paul Kehrer | 2015-12-01 | 1 | -3/+3 |
| | | |||||
* | | if EC isn't present we need to declare this enum | Paul Kehrer | 2015-12-01 | 1 | -1/+5 |
| | | |||||
* | | let the compiler figure out these values | Paul Kehrer | 2015-12-01 | 1 | -3/+4 |
| | | |||||
* | | fix a warning in cffi | Paul Kehrer | 2015-12-01 | 1 | -1/+5 |
|/ | | | | | cffi doesn't want to guess the type, so we'll deopaque the enum and strip the values out of the lib if EC is unavailable | ||||
* | Add more CRYPTO_EX_DATA functions | Christian Heimes | 2015-11-20 | 3 | -0/+20 |
| | | | | | | | | The patch adds a couple of additional functions to create, store and retrieve ex_data on SSL, SSL_CTX and X509 objects. It also adds the missing get_ex_new_index function for X509_STORE_CTX. Signed-off-by: Christian Heimes <cheimes@redhat.com> | ||||
* | add tbsCertList and signature interfaces to CRLs | Erik Trauschke | 2015-11-19 | 1 | -0/+3 |
| | |||||
* | RHEL 6.4 and below don't even claim to be 1.0.0 final... | Paul Kehrer | 2015-11-12 | 1 | -1/+1 |
| | |||||
* | whoops | Paul Kehrer | 2015-11-12 | 1 | -0/+1 |
| | |||||
* | reorganize and rename | Paul Kehrer | 2015-11-12 | 1 | -10/+10 |
| | |||||
* | these functions were added in 1.0.0, while CMS was added in 0.9.8h | Paul Kehrer | 2015-11-12 | 1 | -0/+10 |
| | | | | | We didn't catch this in our CI because all our 0.9.8 targets have CMS disabled or are older than 0.9.8h | ||||
* | Merge pull request #2467 from reaperhulk/fix-version-check | Alex Gaynor | 2015-11-04 | 1 | -2/+2 |
|\ | | | | | these flags were actually added in 1.0.2beta2, not before that. | ||||
| * | these flags were actually added in 1.0.2beta2, not before that. | Paul Kehrer | 2015-11-05 | 1 | -2/+2 |
| | | |||||
* | | remove malloc_debug_init as it has occasionally caused compile issues | Paul Kehrer | 2015-11-05 | 1 | -1/+0 |
|/ | | | | We also don't use it in our backend (and neither does pyOpenSSL) | ||||
* | add support for Certificate signature and tbs_certificate | Paul Kehrer | 2015-11-03 | 2 | -1/+3 |
| | |||||
* | make engine addition idempotent | Paul Kehrer | 2015-10-21 | 1 | -0/+2 |
| | | | | | | | | | | | Threading issues keep cropping up. ENGINE_add already acquires a lock at the C layer via CRYPTO_w_lock (provided you have registered the locking callbacks) so let's try to use that. As part of this we'll try to init the openssl locks, but of course there's potentially a race there as well. Clearly this isn't the real fix but it might improve the situation while we try to determine what to do. | ||||
* | Remove long comments and workarounds, use new cffi syntax | Alex Gaynor | 2015-10-21 | 2 | -36/+2 |
| | |||||
* | add binding for d2i_GENERAL_NAMES() | Erik Trauschke | 2015-10-15 | 1 | -0/+2 |
| | |||||
* | extend pkcs7 openssl bindings | Dominic Chen | 2015-10-13 | 2 | -2/+32 |
| | |||||
* | rename env var to CRYPTOGRAPHY_OSX_NO_LINK_FLAGS | Paul Kehrer | 2015-08-31 | 1 | -1/+1 |
| | |||||
* | no need for None | Paul Kehrer | 2015-08-29 | 1 | -1/+1 |
| | |||||
* | add support for static linking of the openssl backend on OS X | Paul Kehrer | 2015-08-29 | 1 | -3/+16 |
| | |||||
* | Removed SSL_renegotiate_abbreviated binding | kjav | 2015-08-28 | 1 | -1/+0 |
| | | | As this is not supported in OpenSSL < 1.01 | ||||
* | Added bindings for SSL_renegotiate_<pending/abbreviated> | kjav | 2015-08-28 | 1 | -0/+2 |
| |