e95d20dcb8
This CL removes the last of the EVP_CIPHER codepath in ssl/. The dead code is intentionally not pruned for ease of review, except in DTLS-only code where adding new logic to support both, only to remove half, would be cumbersome. Fixes made: - dtls1_retransmit_state is taught to retain aead_write_ctx rather than enc_write_ctx. - d1_pkt.c reserves space for the variable-length nonce when echoed into the packet. - dtls1_do_write sizes the MTU based on EVP_AEAD max overhead. - tls1_change_cipher_state_cipher should not free AEAD write contexts in DTLS. This matches the (rather confused) ownership for the EVP_CIPHER contexts. I've added a TODO to resolve this craziness. A follow-up CL will remove all the resultant dead code. Change-Id: I644557f4db53bbfb182950823ab96d5e4c908866 Reviewed-on: https://boringssl-review.googlesource.com/2699 Reviewed-by: Adam Langley <agl@google.com> |
||
---|---|---|
crypto | ||
doc | ||
include/openssl | ||
ssl | ||
tool | ||
util | ||
.clang-format | ||
.gitignore | ||
BUILDING | ||
CMakeLists.txt | ||
codereview.settings |