83a321231b
Recent changes added SSL-level setters to these APIs. Unfortunately, this has the side effect of breaking SSL_set_SSL_CTX, which is how SNI is typically handled. SSL_set_SSL_CTX is kind of a weird function in that it's very sensitive to which of the hodge-podge of config styles is in use. I previously listed out all the config styles here, but it was long and unhelpful. (I counted up to 7.) Of the various SSL_set_SSL_CTX-visible config styles, the sanest seems to be to move it to CERT. In this case, it's actually quite reasonable since they're very certificate-related. Later we may wish to think about whether we can cut down all 7 kinds of config styles because this is kinda nuts. I'm wondering we should do CERT => SSL_CONFIG, move everything there, and make that be the same structure that is dropped post-handshake (supposing the caller has disavowed SSL_clear and renego). Fruit for later thought. (Note though that comes with a behavior change for all the existing config.) Change-Id: I9aa47d8bd37bf2847869e0b577739d4d579ee4ae Reviewed-on: https://boringssl-review.googlesource.com/13864 Reviewed-by: Martin Kreichgauer <martinkr@google.com> Reviewed-by: David Benjamin <davidben@google.com> Commit-Queue: David Benjamin <davidben@google.com> CQ-Verified: CQ bot account: commit-bot@chromium.org <commit-bot@chromium.org> |
||
---|---|---|
.. | ||
aead.h | ||
aes.h | ||
arm_arch.h | ||
asn1_mac.h | ||
asn1.h | ||
asn1t.h | ||
base64.h | ||
base.h | ||
bio.h | ||
blowfish.h | ||
bn.h | ||
buf.h | ||
buffer.h | ||
bytestring.h | ||
cast.h | ||
chacha.h | ||
cipher.h | ||
cmac.h | ||
conf.h | ||
cpu.h | ||
crypto.h | ||
curve25519.h | ||
des.h | ||
dh.h | ||
digest.h | ||
dsa.h | ||
dtls1.h | ||
ec_key.h | ||
ec.h | ||
ecdh.h | ||
ecdsa.h | ||
engine.h | ||
err.h | ||
evp.h | ||
ex_data.h | ||
hkdf.h | ||
hmac.h | ||
lhash_macros.h | ||
lhash.h | ||
md4.h | ||
md5.h | ||
mem.h | ||
nid.h | ||
obj_mac.h | ||
obj.h | ||
objects.h | ||
opensslconf.h | ||
opensslv.h | ||
ossl_typ.h | ||
pem.h | ||
pkcs7.h | ||
pkcs8.h | ||
pkcs12.h | ||
poly1305.h | ||
pool.h | ||
rand.h | ||
rc4.h | ||
ripemd.h | ||
rsa.h | ||
safestack.h | ||
sha.h | ||
srtp.h | ||
ssl3.h | ||
ssl.h | ||
stack_macros.h | ||
stack.h | ||
thread.h | ||
time_support.h | ||
tls1.h | ||
type_check.h | ||
x509_vfy.h | ||
x509.h | ||
x509v3.h |