Simon Arlott
d6acb43769
openssl: don't allow certificates outside the validity period
2016-04-27 22:03:49 +01:00
Aaron Jones
b1f0549361
[openssl] support ECDHE on more than one curve when possible
2016-04-27 16:17:33 +00:00
Simon Arlott
0346918701
add mkfingerprint program
2016-04-26 20:49:03 +01:00
Simon Arlott
e1f16ce22e
openssl: accept more certificate verify errors as valid
2016-04-25 20:38:39 +01:00
Simon Arlott
5ad62c80ee
librb: remove socklen parameter from rb_connect_tcp
2016-04-24 17:11:20 +01:00
Simon Arlott
cf430c1a40
ssld: Add new certfp_methods spki_sha256 and spki_sha512
...
These operate on the SubjectPublicKeyInfo of the certificate, which does
change unless the private key is changed. This allows the fingerprint to
stay constant even if the certificate is reissued.
(The same fingerprint is also used by DANE)
2016-04-23 22:51:05 +01:00
Matt Ullman
c056dba233
Remove the rest of the SVN id tags
2016-03-23 20:13:12 -04:00
Elizabeth Myers
3a1f645bed
misc solaris fixes
2016-03-23 12:04:46 -05:00
Elizabeth Myers
fe037171d6
Change all leftover libratbox stuff to librb.
2016-03-06 03:49:27 -06:00
William Pitcock
c83f2f5e12
rename libratbox to librb, since its pretty modified anyway
2016-03-06 02:30:20 -06:00