2015-01-07 |
Kaspar Brand | Add support for extracting subjectAltName entries of...
|
commit | commitdiff | tree |
2014-10-04 |
Kaspar Brand | Move OCSP stapling information from a per-certificate...
|
commit | commitdiff | tree |
2014-04-21 |
Kaspar Brand | in 2.4.x as of r1588496
|
commit | commitdiff | tree |
2014-04-21 |
Kaspar Brand | ssl_stapling_init_cert: do not return success when...
|
commit | commitdiff | tree |
2014-04-21 |
Kaspar Brand | ssl_callback_TmpDH: for OpenSSL 1.0.2 and later, set...
|
commit | commitdiff | tree |
2014-04-18 |
Kaspar Brand | Also clear the error queue before calling SSL_CTX_use_certif...
|
commit | commitdiff | tree |
2014-04-18 |
Kaspar Brand | Merge r1585090 from trunk:
|
commit | commitdiff | tree |
2014-04-09 |
Kaspar Brand | Reverse the order when merging global and vhost-level...
|
commit | commitdiff | tree |
2014-04-09 |
Kaspar Brand | Only read "active" values from the key_files array...
|
commit | commitdiff | tree |
2014-04-05 |
Kaspar Brand | Bring SNI behavior into better conformance with RFC...
|
commit | commitdiff | tree |
2014-04-05 |
Kaspar Brand | Update SSLPassPhraseDialog directive docs to properly...
|
commit | commitdiff | tree |
2014-02-06 |
Kaspar Brand | update APLOGNO for r1564760
|
commit | commitdiff | tree |
2014-02-05 |
Kaspar Brand | With OpenSSL 1.0.2 or later, enable OCSP stapling in...
|
commit | commitdiff | tree |
2014-02-01 |
Kaspar Brand | enable auto curve selection for ephemeral ECDH keys
|
commit | commitdiff | tree |
2014-02-01 |
Kaspar Brand | Followup fix for r1553824:
|
commit | commitdiff | tree |
2014-01-06 |
Kaspar Brand | Backport r1421323, r1534754, r1546693, r1555464 from...
|
commit | commitdiff | tree |
2014-01-05 |
Kaspar Brand | make the ppcb_arg initialization a bit more uniform...
|
commit | commitdiff | tree |
2014-01-05 |
Kaspar Brand | update transformations for SSLOpenSSLConfCmd
|
commit | commitdiff | tree |
2014-01-05 |
Kaspar Brand | More finishing touches for SSLOpenSSLConfCmd:
|
commit | commitdiff | tree |
2014-01-05 |
Kaspar Brand | Remove per-certificate chain handling code (obsoleted by
|
commit | commitdiff | tree |
2013-12-28 |
Kaspar Brand | update transformation
|
commit | commitdiff | tree |
2013-12-28 |
Kaspar Brand | Remove the hardcoded algorithm-type dependency for...
|
commit | commitdiff | tree |
2013-12-01 |
Kaspar Brand | SGC became dead in January 2000, effectively
|
commit | commitdiff | tree |
2013-12-01 |
Kaspar Brand | Throw away the myCtxVar{Set,Get} abomination and introduce
|
commit | commitdiff | tree |
2013-11-30 |
Kaspar Brand | Tweaks for SSLOpenSSLConfCmd:
|
commit | commitdiff | tree |
2013-11-30 |
Kaspar Brand | Axe dead code: It wouldn't have been needed ever since...
|
commit | commitdiff | tree |
2013-11-30 |
Kaspar Brand | Remove obsolete TODOs for mod_ssl:
|
commit | commitdiff | tree |
2013-11-23 |
Kaspar Brand | Followup to r1544774: do not ignore failures from ssl_server...
|
commit | commitdiff | tree |
2013-11-23 |
Kaspar Brand | Remove SSLPKCS7CertificateFile support:
|
commit | commitdiff | tree |
2013-11-23 |
Kaspar Brand | Address a todo listed in
|
commit | commitdiff | tree |
2013-10-01 |
Kaspar Brand | add attribution
|
commit | commitdiff | tree |
2013-10-01 |
Kaspar Brand | PR 55616 (add missing APLOGNO), part 2
|
commit | commitdiff | tree |
2013-10-01 |
Kaspar Brand | PR 55616 (add missing APLOGNO), part 1
|
commit | commitdiff | tree |
2013-09-29 |
Kaspar Brand | update transformations for mod_ssl and ssl_faq
|
commit | commitdiff | tree |
2013-09-29 |
Kaspar Brand | Improve ephemeral key handling (companion to r1526168):
|
commit | commitdiff | tree |
2013-09-29 |
Kaspar Brand | Increase minimum required OpenSSL version to 0.9.8a...
|
commit | commitdiff | tree |
2013-09-29 |
Kaspar Brand | Follow-up fixes for r1526168:
|
commit | commitdiff | tree |
2013-09-25 |
Kaspar Brand | meanwhile in 2.4.6 and 2.2.25, respectively
|
commit | commitdiff | tree |
2013-09-25 |
Kaspar Brand | Streamline ephemeral key handling:
|
commit | commitdiff | tree |
2013-08-04 |
Kaspar Brand | Fix logging of SSL session cache timeout value (at...
|
commit | commitdiff | tree |
2013-08-01 |
Kaspar Brand | RFC 6961 (TLS Multiple Certificate Status Extension)
|
commit | commitdiff | tree |
2013-04-15 |
Kaspar Brand | revert r1352596, for the reasons explained in
|
commit | commitdiff | tree |
2013-04-13 |
Kaspar Brand | Extend check for encrypted private keys: with OpenSSL...
|
commit | commitdiff | tree |
2013-01-05 |
Kaspar Brand | mod_ssl/ab: only use "--static" for pkg-config when...
|
commit | commitdiff | tree |
2013-01-03 |
Kaspar Brand | Improve pkg-config usage for mod_ssl/ab:
|
commit | commitdiff | tree |
2012-12-26 |
Kaspar Brand | transformations
|
commit | commitdiff | tree |
2012-12-26 |
Kaspar Brand | mod_ssl: add support for subjectAltName-based host...
|
commit | commitdiff | tree |
2012-10-07 |
Kaspar Brand | Allow forced setting of TLS1.1 and TLS1.2 protocols...
|
commit | commitdiff | tree |
2012-09-19 |
Kaspar Brand | switch back to MOD_SSL_LDADD, as suggested by jorton
|
commit | commitdiff | tree |
2012-09-16 |
Kaspar Brand | Spin off module-specific build options into separate...
|
commit | commitdiff | tree |
2012-09-16 |
Kaspar Brand | revert r1385214, as I inadvertently left out acinclude.m4.
|
commit | commitdiff | tree |
2012-09-16 |
Kaspar Brand | Spin off module-specific build options into separate...
|
commit | commitdiff | tree |
2012-09-16 |
Kaspar Brand | revert r1358167, in preparation of the next commit
|
commit | commitdiff | tree |
2012-02-28 |
Kaspar Brand | properly free the GENERAL_NAMEs, as pointed out in...
|
commit | commitdiff | tree |
2012-02-12 |
Kaspar Brand | Fix regression introduced in r1222917: in ssl_find_vhost...
|
commit | commitdiff | tree |
2012-01-08 |
Kaspar Brand | fix signedness issue with SSL_X509_NAME_to_string(...
|
commit | commitdiff | tree |
2011-12-30 |
Kaspar Brand | Fix another case of #ifdef-within-a-macro (which was...
|
commit | commitdiff | tree |
2011-12-24 |
Kaspar Brand | add missing #ifdef in ssl_cmd_protocol_parse (should...
|
commit | commitdiff | tree |
2011-12-24 |
Kaspar Brand | update transformations
|
commit | commitdiff | tree |
2011-12-24 |
Kaspar Brand | SSLProtocol: allow explicit control of TLSv1.1 and...
|
commit | commitdiff | tree |
2011-12-24 |
Kaspar Brand | Set OPENSSL_NO_SSL_INTERN when compiling against OpenSSL...
|
commit | commitdiff | tree |
2011-12-24 |
Kaspar Brand | REMOTE_ADDR is now r->useragent_ip, which is not/never...
|
commit | commitdiff | tree |
2011-12-12 |
Kaspar Brand | logging adjustments:
|
commit | commitdiff | tree |
2011-12-12 |
Kaspar Brand | Streamline TLS session ticket key handling (added in...
|
commit | commitdiff | tree |
2011-12-07 |
Kaspar Brand | Adjust the OpenSSL session id context for SNI configurations...
|
commit | commitdiff | tree |
2011-11-18 |
Kaspar Brand | update transformations
|
commit | commitdiff | tree |
2011-11-18 |
Kaspar Brand | Change the SSLCipherSuite default to a shorter, whitelist
|
commit | commitdiff | tree |
2011-11-18 |
Kaspar Brand | drop SSLv2 support (set SSL_OP_NO_SSLv2 for any new...
|
commit | commitdiff | tree |
2011-10-04 |
Kaspar Brand | Add SSLCARevocationCheck directive to default mod_ssl...
|
commit | commitdiff | tree |
2011-10-04 |
Kaspar Brand | fix indentation
|
commit | commitdiff | tree |
2011-09-28 |
Kaspar Brand | In ssl_check_public_cert(), also take dNSNames in the...
|
commit | commitdiff | tree |
2011-09-26 |
Kaspar Brand | replace another occurence of X509_NAME_oneline by SSL_X509_N...
|
commit | commitdiff | tree |
2011-09-25 |
Kaspar Brand | enable the SNI extension for proxy connections
|
commit | commitdiff | tree |
2011-09-21 |
Kaspar Brand | Bring error messages for TLS stapling related options...
|
commit | commitdiff | tree |
2011-09-21 |
Kaspar Brand | update transformations
|
commit | commitdiff | tree |
2011-09-21 |
Kaspar Brand | mod_ssl:
|
commit | commitdiff | tree |
2011-09-19 |
Kaspar Brand | Add ssl_log_xerror() and ssl_log_rxerror(), modeled...
|
commit | commitdiff | tree |
2011-09-14 |
Kaspar Brand | Properly fill in the SSL_{CLIENT,SERVER}_V_{START,END...
|
commit | commitdiff | tree |
2011-09-14 |
Kaspar Brand | ssl_callback_proxy_cert(): take advantage of ssl_log_cxerror()
|
commit | commitdiff | tree |
2011-09-07 |
Kaspar Brand | ssl_var_lookup_ssl_cert_dn_oneline(): properly deal...
|
commit | commitdiff | tree |
2011-09-04 |
Kaspar Brand | we might also see GeneralizedTimes in certs nowadays
|
commit | commitdiff | tree |
2011-09-04 |
Kaspar Brand | Revamp CRL checking for client and remote servers:
|
commit | commitdiff | tree |
2011-08-28 |
Kaspar Brand | Better safe than sorry: with OpenSSL 1.0, X509_STORE_CTX_get...
|
commit | commitdiff | tree |
2011-08-28 |
Kaspar Brand | Fix the default OCSP responder timeout for client cert
|
commit | commitdiff | tree |
2011-08-15 |
Kaspar Brand | Improve ssl_log_cxerror():
|
commit | commitdiff | tree |
2011-08-14 |
Kaspar Brand | Enforce OpenSSL 0.9.7 or later at compile time (#error...
|
commit | commitdiff | tree |
2011-08-07 |
Kaspar Brand | Enforce OpenSSL 0.9.7 as a minimum requirement in configure...
|
commit | commitdiff | tree |
2011-08-07 |
Kaspar Brand | Remove the ssl_toolkit_compat layer, which is no longer...
|
commit | commitdiff | tree |
2011-08-07 |
Kaspar Brand | Drop support for the RSA BSAFE SSL-C toolkit from configure,
|
commit | commitdiff | tree |
|