aboutsummaryrefslogtreecommitdiff
path: root/openssl/src/ssl/mod.rs
Commit message (Collapse)AuthorAgeFilesLines
* Callback cleanupSteven Fackler2016-10-181-27/+16
|
* Don't ignore errors in NPN/ALPN logicSteven Fackler2016-10-181-5/+18
| | | | Closes #479
* Implement new feature setupSteven Fackler2016-10-171-27/+18
| | | | | | | | The basic idea here is that there is a feature for each supported OpenSSL version. Enabling multiple features represents support for multiple OpenSSL versions, but it's then up to you to check which version you link against (probably by depending on openssl-sys and making a build script similar to what openssl does).
* Fix algorithm fieldSteven Fackler2016-10-161-2/+1
|
* ssl error handling cleanupSteven Fackler2016-10-161-88/+82
|
* Fix set_read_ahead signatureSteven Fackler2016-10-151-2/+2
|
* De-enumify SslMethodSteven Fackler2016-10-151-28/+45
|
* Handle OPENSSL_NO_COMPSteven Fackler2016-10-141-0/+10
| | | | Closes #459
* Enable hostname verification on 1.0.2Steven Fackler2016-10-141-3/+3
|
* Support hostname verificationSteven Fackler2016-10-141-0/+12
| | | | Closes #206
* CleanupSteven Fackler2016-10-131-2/+0
|
* Clean up featuresSteven Fackler2016-10-131-10/+12
|
* Flag off dtls and mask ssl_opsSteven Fackler2016-10-131-13/+3
| | | | Also un-feature gate npn as it ships with 1.0.1
* Add remaining SSL_OP constantsSteven Fackler2016-10-121-0/+5
|
* Add support for OpenSSL 1.1.0Alex Crichton2016-10-121-156/+194
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit is relatively major refactoring of the `openssl-sys` crate as well as the `openssl` crate itself. The end goal here was to support OpenSSL 1.1.0, and lots of other various tweaks happened along the way. The major new features are: * OpenSSL 1.1.0 is supported * OpenSSL 0.9.8 is no longer supported (aka all OSX users by default) * All FFI bindings are verified with the `ctest` crate (same way as the `libc` crate) * CI matrixes are vastly expanded to include 32/64 of all platforms, more OpenSSL version coverage, as well as ARM coverage on Linux * The `c_helpers` module is completely removed along with the `gcc` dependency. * The `openssl-sys` build script was completely rewritten * Now uses `OPENSSL_DIR` to find the installation, not include/lib env vars. * Better error messages for mismatched versions. * Better error messages for failing to find OpenSSL on a platform (more can be done here) * Probing of OpenSSL build-time configuration to inform the API of the `*-sys` crate. * Many Cargo features have been removed as they're now enabled by default. As this is a breaking change to both the `openssl` and `openssl-sys` crates this will necessitate a major version bump of both. There's still a few more API questions remaining but let's hash that out on a PR! Closes #452
* Fix SslContext::add_extra_chain_certSteven Fackler2016-08-171-3/+8
| | | | | | | | | SSL_CTX_add_extra_chain_cert assumes ownership of the certificate, so the method really needs to take an X509 by value. Work around this by manually cloning the cert. This method has been around for over a year but I'm guessing nobody actually used it since it produces a nice double free into segfault!
* PKCS #12 supportSteven Fackler2016-08-141-1/+1
|
* Mangle c helper functionsSteven Fackler2016-08-131-1/+1
| | | | | | | We want to make sure that multiple openssl versions can coexist in the same dependency tree. Closes #438
* Little tweaksSteven Fackler2016-08-101-3/+6
|
* Method renamesSteven Fackler2016-08-101-3/+3
|
* More API cleanupSteven Fackler2016-08-101-1/+1
|
* Make c_helpers optionalSteven Fackler2016-08-091-108/+137
|
* Remove rust_SSL_cloneSteven Fackler2016-08-091-59/+94
|
* Move init to crate rootSteven Fackler2016-08-071-7/+2
|
* Clean up asn1timeSteven Fackler2016-08-061-33/+37
|
* Fix pkey method safetySteven Fackler2016-08-051-1/+1
|
* Clean up x509Steven Fackler2016-08-051-6/+6
|
* Move SSL_CTX_set_ecdh_auto to -sysSteven Fackler2016-08-041-1/+1
|
* Mvoe SSL_CTX_add_extra_chain_cert to -sysSteven Fackler2016-08-041-3/+2
|
* Move SSL_CTX_set_tmp_dh to -sysSteven Fackler2016-08-041-1/+1
|
* Move SSL_CTX_set_read_ahead to -sysSteven Fackler2016-08-041-1/+1
|
* Move SSL_CTX_set_tlsext_servername_callback to -sysSteven Fackler2016-08-041-1/+1
|
* Move SSL_set_tlsext_host_name to -sysSteven Fackler2016-08-041-1/+1
|
* Stop once-ing init wrapperSteven Fackler2016-08-041-3/+2
| | | | The underlying function already once-s itself
* Support basic SSL options without C shimsSteven Fackler2016-08-041-51/+31
|
* Define SSL_CTX_set_mode in openssl-sysSteven Fackler2016-08-021-1/+1
|
* Merge pull request #432 from alexcrichton/mid-handshakeSteven Fackler2016-07-311-8/+112
|\ | | | | Add MidHandshakeSslStream
| * Add MidHandshakeSslStreamAlex Crichton2016-07-311-8/+112
| | | | | | | | | | | | Allows recognizing when a stream is still in handshake mode and can gracefully transition when ready. The blocking usage of the API should still be the same, just helps nonblocking implementations!
* | Fix build with dtlsSteven Fackler2016-07-311-2/+2
|/
* Merge remote-tracking branch 'origin/master' into breaksSteven Fackler2016-07-311-11/+28
|\
| * Set SSL_MODE_ACCEPT_MOVING_WRITE_BUFFER flagShaun Taheri2016-07-241-1/+1
| |
| * Set auto retrySteven Fackler2016-07-011-1/+8
| | | | | | | | | | | | SSL_read returns a WANT_READ after a renegotiation by default which ends up bubbling up as a weird BUG error. Tell OpenSSL to just do the read again.
| * RustfmtSteven Fackler2016-05-161-15/+30
| |
* | Fix a few mutable types for `self` parameters.Corey Farwell2016-06-021-3/+3
| |
* | Remove AsRaw{Fd, Socket} implsSteven Fackler2016-05-031-18/+0
| | | | | | | | | | An SslStream can't really act as a raw socket since you'd skip the whole TLS layer
* | Remove silly internal error enumSteven Fackler2016-05-031-44/+9
| |
* | Drop MaybeSslStreamSteven Fackler2016-05-031-61/+0
| | | | | | | | It should be inlined into crates that depend on it.
* | Drop is_dtls methods on SslMethodSteven Fackler2016-05-031-26/+6
| |
* | Clean up SNI APIsSteven Fackler2016-05-031-73/+30
| |
* | Move SslContext::set_verify to a closure based APISteven Fackler2016-05-031-67/+14
| |