boringssl/include/openssl
David Benjamin b6a0a518a3 Simplify version configuration.
OpenSSL's SSL_OP_NO_* flags allow discontinuous version ranges. This is a
nuisance for two reasons. First it makes it unnecessarily difficult to answer
"are any versions below TLS 1.3 enabled?". Second the protocol does not allow
discontinuous version ranges on the client anyway. OpenSSL instead picks the
first continous range of enabled versions on the client, but not the server.

This is bizarrely inconsistent. It also doesn't quite do this as the
ClientHello sending logic does this, but not the ServerHello processing logic.
So we actually break some invariants slightly. The logic is also cumbersome in
DTLS which kindly inverts the comparison logic.

First, switch min_version/max_version's storage to normalized versions. Next
replace all the ad-hoc version-related functions with a single
ssl_get_version_range function. Client and server now consistently pick a
contiguous range of versions. Note this is a slight behavior change for
servers. Version-range-sensitive logic is rewritten to use this new function.

BUG=66

Change-Id: Iad0d64f2b7a917603fc7da54c9fc6656c5fbdb24
Reviewed-on: https://boringssl-review.googlesource.com/8513
Reviewed-by: David Benjamin <davidben@google.com>
2016-06-30 21:56:01 +00:00
..
aead.h Require in == out for in-place encryption. 2016-06-09 19:49:03 +00:00
aes.h
arm_arch.h
asn1_mac.h
asn1.h Remove ASN.1 BIOs. 2016-06-14 17:39:30 +00:00
asn1t.h Remove ASN.1 print hooks. 2016-06-14 17:38:31 +00:00
base64.h Replace base64 decoding. 2016-05-26 17:59:10 +00:00
base.h Wrap MSVC-only warning pragmas in a macro. 2016-06-09 21:29:36 +00:00
bio.h Test both synchronous and asynchronous DTLS retransmit. 2016-06-08 18:11:41 +00:00
blowfish.h
bn.h Handle BN_mod_word failures. 2016-06-23 21:25:18 +00:00
buf.h Add BUF_MEM_reserve. 2016-05-18 19:09:06 +00:00
buffer.h
bytestring.h Add CBB_add_u32. 2016-06-27 20:12:54 +00:00
cast.h
chacha.h Require in == out for in-place encryption. 2016-06-09 19:49:03 +00:00
cipher.h Switch all 'num' parameters in crypto/modes to unsigned. 2016-04-19 17:56:25 +00:00
cmac.h
conf.h Fix the shared library build. 2016-03-09 20:13:41 +00:00
cpu.h Make CRYPTO_is_NEON_capable aware of the buggy CPU. 2016-04-28 16:42:21 +00:00
crypto.h Add CRYPTO_has_asm. 2016-05-17 19:03:31 +00:00
curve25519.h Tweak X25519 documentation. 2016-04-14 14:20:56 +00:00
des.h
dh.h Reimplement PKCS #3 DH parameter parsing with crypto/bytestring. 2016-05-09 19:36:41 +00:00
digest.h Add |EVP_dss1| as an alias for |EVP_sha1| in decrepit. 2016-05-20 15:31:52 +00:00
dsa.h Compute kinv in DSA with Fermat's Little Theorem. 2016-06-20 17:16:18 +00:00
dtls1.h
ec_key.h Drop support for engines-provided signature verification. 2016-04-18 20:40:17 +00:00
ec.h Always use Fermat's Little Theorem in ecdsa_sign_setup. 2016-06-20 17:11:42 +00:00
ecdh.h
ecdsa.h Update comments to better document in-place semantics. 2016-01-19 17:01:37 +00:00
engine.h
err.h
evp.h Fix the name of OPENSSL_add_all_algorithms_conf. 2016-06-15 21:29:50 +00:00
ex_data.h
hkdf.h Separating HKDF into HKDFExtract and HKDFExpand. 2016-05-20 15:17:17 +00:00
hmac.h Reimplement PKCS#12 key derivation. 2016-04-19 18:16:38 +00:00
lhash_macros.h
lhash.h
md4.h
md5.h
mem.h Add CRYPTO_[malloc|free|realloc] as aliases for the OPENSSL_𝑥 names. 2016-03-10 17:44:23 +00:00
newhope.h Add missing newline in newhope.h. 2016-06-03 22:01:13 +00:00
nid.h Elliptic curve + post-quantum key exchange 2016-05-19 22:19:14 +00:00
obj_mac.h Rename obj_mac.h to nid.h and make it a multiply-includable header. 2016-03-31 20:45:35 +00:00
obj.h Make OBJ_NAME_do_all more OpenSSL-compatible. 2016-06-27 21:42:27 +00:00
objects.h
opensslconf.h
opensslv.h
ossl_typ.h
pem.h Include crypto.h from pem.h. 2016-05-20 15:31:26 +00:00
pkcs7.h
pkcs8.h
pkcs12.h
poly1305.h Revert "Enable upstream's Poly1305 code." 2016-03-29 22:47:11 +00:00
rand.h
rc4.h
ripemd.h Add RIPEMD160 support in decrepit. 2016-03-09 19:37:14 +00:00
rsa.h Do RSA blinding unless |e| is NULL and specifically requested not to. 2016-05-04 23:14:08 +00:00
safestack.h
sha.h Revert md_len removal from SHA256_CTX and SHA512_CTX. 2016-04-27 19:01:23 +00:00
srtp.h
ssl3.h Remove a/b parameters to send_change_cipher_spec. 2016-06-29 18:50:47 +00:00
ssl.h Simplify version configuration. 2016-06-30 21:56:01 +00:00
stack_macros.h Fix stack macro const-ness. 2016-05-13 18:24:57 +00:00
stack.h
thread.h Add missing 'does nothing' comments for consistency. 2016-06-28 20:40:45 +00:00
time_support.h Include time.h in time_support.h. 2016-03-17 17:27:27 +00:00
tls1.h Cleaning up internal use of Signature Algorithms. 2016-06-29 21:22:25 +00:00
type_check.h
x509_vfy.h Unwind X509_LU_RETRY and fix a lot of type confusion. 2016-06-16 16:24:44 +00:00
x509.h Add checks to X509_NAME_oneline() 2016-05-03 16:34:59 +00:00
x509v3.h Add missing prototypes. 2016-03-20 16:43:50 +00:00