Jean-Paul Calderone | aa9c797 | 2008-09-07 21:27:49 -0400 | [diff] [blame^] | 1 | 2008-09-07 Jean-Paul Calderone <exarkun@twistedmatrix.com> |
| 2 | |
| 3 | * src/ssl/context.c: Add a capath parameter to |
| 4 | Context.load_verify_locations to allow Python code to specify |
| 5 | either or both arguments to the underlying |
| 6 | SSL_CTX_load_verify_locations API. |
| 7 | * src/ssl/context.c: Add Context.set_default_verify_paths, a wrapper |
| 8 | around SSL_CTX_set_default_verify_paths. |
| 9 | |
Jean-Paul Calderone | 828c9cb | 2008-04-26 18:06:54 -0400 | [diff] [blame] | 10 | 2008-04-26 Jean-Paul Calderone <exarkun@twistedmatrix.com> |
| 11 | |
Jean-Paul Calderone | 5ef8651 | 2008-04-26 19:06:28 -0400 | [diff] [blame] | 12 | * src/ssl/context.c: Change global_passphrase_callback and |
| 13 | global_info_callback so that they acquire the GIL before |
| 14 | invoking any CPython APIs and do not release it until after they |
| 15 | are finished invoking all of them (based heavily on on patch |
| 16 | from Dan Williams). |
Jean-Paul Calderone | aea5d90 | 2008-04-26 19:53:39 -0400 | [diff] [blame] | 17 | * src/ssl/crypto.c: Initialize OpenSSL thread support so that it |
| 18 | is valid to use OpenSSL APIs from more than one thread (based on |
| 19 | patch from Dan Williams). |
Jean-Paul Calderone | 828c9cb | 2008-04-26 18:06:54 -0400 | [diff] [blame] | 20 | * test/test_crypto.py: Add tests for load_privatekey and |
| 21 | dump_privatekey when a passphrase or a passphrase callback is |
| 22 | supplied. |
Jean-Paul Calderone | 5ef8651 | 2008-04-26 19:06:28 -0400 | [diff] [blame] | 23 | * test/test_ssl.py: Add tests for Context.set_passwd_cb and |
| 24 | Context.set_info_callback. |
Jean-Paul Calderone | 828c9cb | 2008-04-26 18:06:54 -0400 | [diff] [blame] | 25 | |
Jean-Paul Calderone | e53ccf7 | 2008-04-11 11:40:39 -0400 | [diff] [blame] | 26 | 2008-04-11 Jean-Paul Calderone <exarkun@twistedmatrix.com> |
| 27 | |
| 28 | * Release 0.7 |
| 29 | |
Jean-Paul Calderone | c54cc18 | 2008-03-26 21:11:07 -0400 | [diff] [blame] | 30 | 2008-03-26 Jean-Paul Calderone <exarkun@twistedmatrix.com> |
| 31 | |
| 32 | * src/crypto/x509name.c: Add X509Name.get_components |
| 33 | |
Jean-Paul Calderone | 9ab16c0 | 2008-03-25 15:22:47 -0400 | [diff] [blame] | 34 | 2008-03-25 Jean-Paul Calderone <exarkun@twistedmatrix.com> |
| 35 | |
| 36 | * src/crypto/x509name.c: Add hash and der methods to X509Name. |
Jean-Paul Calderone | c821543 | 2008-03-25 15:34:21 -0400 | [diff] [blame] | 37 | * src/crypto/x509.c: Fix a bug in X509.get_notBefore and |
| 38 | X509.get_notAfter preventing UTCTIME format timestamps from |
| 39 | working. |
Jean-Paul Calderone | 9ab16c0 | 2008-03-25 15:22:47 -0400 | [diff] [blame] | 40 | |
Jean-Paul Calderone | 3de9f62 | 2008-03-12 14:12:19 -0400 | [diff] [blame] | 41 | 2008-03-12 Jean-Paul Calderone <exarkun@twistedmatrix.com> |
| 42 | |
| 43 | * Fix coding problems in examples/. Remove keys and certificates |
| 44 | and add a note about how to generate new ones. |
| 45 | |
Jean-Paul Calderone | 525ef80 | 2008-03-09 20:39:42 -0400 | [diff] [blame] | 46 | 2008-03-09 Jean-Paul Calderone <exarkun@twistedmatrix.com> |
| 47 | |
| 48 | * src/crypto/x509.c: Add getters and setters for the notBefore and |
| 49 | notAfter attributes of X509s. |
Jean-Paul Calderone | ac0d95f | 2008-03-10 00:00:42 -0400 | [diff] [blame] | 50 | * src/crypto/pkey.h, src/crypto/pkey.c, src/crypto/x509req.c, |
| 51 | src/crypto/x509.c: Track the initialized and public/private state |
| 52 | of EVP_PKEY structures underlying the crypto_PKeyObj type and |
| 53 | reject X509Req signature operations on keys not suitable for the |
| 54 | task. |
Jean-Paul Calderone | 525ef80 | 2008-03-09 20:39:42 -0400 | [diff] [blame] | 55 | |
Jean-Paul Calderone | da92ccc | 2008-03-06 23:48:12 -0500 | [diff] [blame] | 56 | 2008-03-06 Jean-Paul Calderone <exarkun@twistedmatrix.com> |
| 57 | |
| 58 | * src/crypto/x509name.c: Fix tp_compare so it only returns -1, 0, or |
| 59 | 1. This eliminates a RuntimeWarning emitted by Python. |
| 60 | * src/crypto/x509req.c: Fix reference counting for X509Name returned |
| 61 | by X509Req.get_subject. This removes a segfault when the subject |
| 62 | name outlives the request object. |
| 63 | * src/crypto/x509.c: Change get_serial_number and set_serial_number |
| 64 | to accept Python longs. |
| 65 | * doc/pyOpenSSL.tex: A number of minor corrections. |
| 66 | |
Jean-Paul Calderone | 7df40db | 2008-03-03 15:12:42 -0500 | [diff] [blame] | 67 | 2008-03-03 Jean-Paul Calderone <exarkun@twistedmatrix.com> |
| 68 | |
| 69 | * src/crypto/crypto.c: Expose X509_verify_cert_error_string. (patch |
| 70 | from Victor Stinner) |
| 71 | |
Jean-Paul Calderone | 12ea9a0 | 2008-02-22 12:24:39 -0500 | [diff] [blame] | 72 | 2008-02-22 Jean-Paul Calderone <exarkun@twistedmatrix.com> |
| 73 | |
| 74 | * src/ssl/connection.c src/ssl/context.c src/ssl/ssl.c: Fix |
| 75 | compilation on Windows. (patch from Michael Schneider) |
| 76 | |
Jean-Paul Calderone | 72b8f0f | 2008-02-21 23:57:40 -0500 | [diff] [blame] | 77 | 2008-02-21 Jean-Paul Calderone <exarkun@twistedmatrix.com> |
| 78 | |
| 79 | * src/ssl/connection.c: Expose SSL_get_shutdown and |
| 80 | SSL_set_shutdown. (patch from James Knight) |
| 81 | * src/ssl/ssl.c: Expose SSL_SENT_SHUTDOWN and SSL_RECEIVED_SHUTDOWN. |
| 82 | (patch from James Knight) |
| 83 | |
Jean-Paul Calderone | 779db6b | 2008-02-19 21:00:37 -0500 | [diff] [blame] | 84 | 2008-02-19 Jean-Paul Calderone <exarkun@twistedmatrix.com> |
| 85 | |
| 86 | * src/ssl/context.c: Expose SSL_CTX_add_extra_chain_cert. |
| 87 | * src/crypto/x509name.c: Fix memory leaks in __getattr__ and |
| 88 | __setattr_ implementations. |
Jean-Paul Calderone | 19555b9 | 2008-02-19 22:29:57 -0500 | [diff] [blame] | 89 | * src/crypto/x509.c: Fix memory leak in X509.get_pubkey(). |
| 90 | * leakcheck/: An attempt at a systematic approach to leak |
| 91 | elimination. |
Jean-Paul Calderone | 779db6b | 2008-02-19 21:00:37 -0500 | [diff] [blame] | 92 | |
Jean-Paul Calderone | 897bc25 | 2008-02-18 20:50:23 -0500 | [diff] [blame] | 93 | 2004-08-13 Martin Sjögren <msjogren@gmail.com> |
| 94 | |
| 95 | * Released version 0.6. |
| 96 | |
| 97 | 2004-08-11 Martin Sjögren <msjogren@gmail.com> |
| 98 | |
| 99 | * doc/pyOpenSSL.tex: Updates to the docs. |
| 100 | |
| 101 | 2004-08-10 Martin Sjögren <msjogren@gmail.com> |
| 102 | |
| 103 | * src/crypto/x509.c: Add X509.add_extensions based on a patch |
| 104 | from Han S. Lee. |
| 105 | * src/ssl/ssl.c: Add more SSL_OP_ constants. Patch from Mihai |
| 106 | Ibanescu. |
| 107 | |
| 108 | 2004-08-09 Martin Sjögren <msjogren@gmail.com> |
| 109 | |
| 110 | * setup.py src/crypto/: Add support for Netscape SPKI extensions |
| 111 | based on a patch from Tollef Fog Heen. |
| 112 | * src/crypto/crypto.c: Add support for python passphrase callbacks |
| 113 | based on a patch from Robert Olson. |
| 114 | |
| 115 | 2004-08-03 Martin Sjögren <msjogren@gmail.com> |
| 116 | |
| 117 | * src/ssl/context.c: Applied patch from Frederic Peters to add |
| 118 | Context.use_certificate_chain_file. |
| 119 | * src/crypto/x509.c: Applid patch from Tollef Fog Heen to add |
| 120 | X509.subject_name_hash and X509.digest. |
| 121 | |
| 122 | 2004-08-02 Martin Sjögren <msjogren@gmail.com> |
| 123 | |
| 124 | * src/crypto/crypto.c src/ssl/ssl.c: Applied patch from Bastian |
| 125 | Kleineidam to fix full names of exceptions. |
| 126 | |
| 127 | 2004-07-19 Martin Sjögren <msjogren@gmail.com> |
| 128 | |
| 129 | * doc/pyOpenSSL.tex: Fix the errors regarding X509Name's field names. |
Jean-Paul Calderone | 828c9cb | 2008-04-26 18:06:54 -0400 | [diff] [blame] | 130 | |
Jean-Paul Calderone | 897bc25 | 2008-02-18 20:50:23 -0500 | [diff] [blame] | 131 | 2004-07-18 Martin Sjögren <msjogren@gmail.com> |
| 132 | |
| 133 | * examples/certgen.py: Fixed wrong attributes in doc string, thanks |
| 134 | Remy. (SFbug#913315) |
| 135 | * __init__.py, setup.py, version.py: Add __version__, as suggested by |
| 136 | Ronald Oussoren in SFbug#888729. |
| 137 | * examples/proxy.py: Fix typos, thanks Mihai Ibanescu. (SFpatch#895820) |
| 138 | |
| 139 | 2003-01-09 Martin Sjögren <martin@strakt.com> |
| 140 | |
| 141 | * Use cyclic GC protocol in SSL.Connection, SSL.Context, crypto.PKCS12 |
| 142 | and crypto.X509Name. |
| 143 | |
| 144 | 2002-12-02 Martin Sjögren <martin@strakt.com> |
| 145 | |
| 146 | * tsafe.py: Add some missing methods. |
| 147 | |
| 148 | 2002-10-06 Martin Sjögren <martin@strakt.com> |
| 149 | |
| 150 | * __init__.py: Import tsafe too! |
| 151 | |
| 152 | 2002-10-05 Martin Sjögren <martin@strakt.com> |
| 153 | |
| 154 | * src/crypto/x509name.c: Use unicode strings instead of ordinary |
| 155 | strings in getattr/setattr. Note that plain ascii strings should |
| 156 | still work. |
| 157 | |
| 158 | 2002-09-17 Martin Sjögren <martin@strakt.com> |
| 159 | |
| 160 | * Released version 0.5.1. |
| 161 | |
| 162 | 2002-09-09 Martin Sjögren <martin@strakt.com> |
| 163 | |
| 164 | * setup.cfg: Fixed build requirements for rpms. |
| 165 | |
| 166 | 2002-09-07 Martin Sjögren <martin@strakt.com> |
| 167 | |
| 168 | * src/ssl/connection.c: Fix sendall() method. It segfaulted because |
| 169 | it was too generous about giving away the GIL. |
| 170 | * Added SecureXMLRPCServer example, contributed by Michal Wallace. |
| 171 | |
| 172 | 2002-09-06 Martin Sjögren <martin@strakt.com> |
| 173 | |
| 174 | * setup.cfg: Updated the build requirements. |
| 175 | * src/ssl/connection.c: Fix includes for AIX. |
| 176 | |
| 177 | 2002-09-04 Anders Hammarquist <iko@strakt.com> |
| 178 | |
| 179 | * Added type checks in all the other places where we expect |
| 180 | specific types of objects passed. |
| 181 | |
| 182 | 2002-09-04 Martin Sjögren <martin@strakt.com> |
| 183 | |
| 184 | * src/crypto/crypto.c: Added an explicit type check in the dump_* |
| 185 | functions, so that they won't die when e.g. None is passed in. |
| 186 | |
| 187 | 2002-08-25 Martin Sjögren <martin@strakt.com> |
| 188 | |
| 189 | * doc/pyOpenSSL.tex: Docs for PKCS12. |
| 190 | |
| 191 | 2002-08-24 Martin Sjögren <martin@strakt.com> |
| 192 | |
| 193 | * src/crypto: Added basic PKCS12 support, thanks to Mark Welch |
| 194 | <mark@collab.net> |
| 195 | |
| 196 | 2002-08-16 Martin Sjögren <martin@strakt.com> |
| 197 | |
| 198 | * D'oh! Fixes for python 1.5 and python 2.1. |
| 199 | |
| 200 | 2002-08-15 Martin Sjögren <martin@strakt.com> |
| 201 | |
| 202 | * Version 0.5. Yay! |
| 203 | |
| 204 | 2002-07-25 Martin Sjögren <martin@strakt.com> |
| 205 | |
| 206 | * src/ssl/context.c: Added set_options method. |
| 207 | * src/ssl/ssl.c: Added constants for Context.set_options method. |
| 208 | |
| 209 | 2002-07-23 Martin Sjögren <martin@strakt.com> |
| 210 | |
| 211 | * Updated docs |
| 212 | * src/ssl/connection.c: Changed the get_cipher_list method to actually |
| 213 | return a list! WARNING: This change makes the API incompatible with |
| 214 | earlier versions! |
| 215 | |
| 216 | 2002-07-15 Martin Sjögren <martin@strakt.com> |
| 217 | |
| 218 | * src/ssl/connection.[ch]: Removed the fileno method, it uses the |
| 219 | transport object's fileno instead. |
| 220 | |
| 221 | 2002-07-09 Martin Sjögren <martin@strakt.com> |
| 222 | |
| 223 | * src/crypto/x509.c src/crypto/x509name.c: Fixed segfault bug where |
| 224 | you used an X509Name after its X509 had been destroyed. |
| 225 | * src/crypto/crypto.[ch] src/crypto/x509req.c src/crypto/x509ext.[ch]: |
| 226 | Added X509 Extension support. Thanks to maas-Maarten Zeeman |
| 227 | <maas@awanim.com> |
| 228 | * src/crypto/pkey.c: Added bits() and type() methods. |
| 229 | |
| 230 | 2002-07-08 Martin Sjögren <martin@strakt.com> |
| 231 | |
| 232 | * src/ssl/connection.c: Moved the contents of setup_ssl into the |
| 233 | constructor, thereby fixing some segfault bugs :) |
| 234 | * src/ssl/connection.c: Added connect_ex and sendall methods. |
| 235 | * src/crypto/x509name.c: Cleaned up comparisons and NID lookup. |
| 236 | Thank you Maas-Maarten Zeeman <maas@awanim.com> |
| 237 | * src/rand/rand.c: Fix RAND_screen import. |
| 238 | * src/crypto/crypto.c src/crypto/pkcs7.[ch]: Added PKCS7 management, |
| 239 | courtesy of Maas-Maarten Zeeman <maas@awanim.com> |
| 240 | * src/crypto/x509req.c: Added verify method. |
| 241 | |
| 242 | 2002-06-17 Martin Sjögren <martin@strakt.com> |
| 243 | |
| 244 | * rpm/, setup.cfg: Added improved RPM-building stuff, thanks to |
| 245 | Mihai Ibanescu <misa@redhat.com> |
| 246 | |
| 247 | 2002-06-14 Martin Sjögren <martin@strakt.com> |
| 248 | |
| 249 | * examples/proxy.py: Example code for using OpenSSL through a proxy |
| 250 | contributed by Mihai Ibanescu <misa@redhat.com> |
| 251 | * Updated installation instruction and added them to the TeX manual. |
| 252 | |
| 253 | 2002-06-13 Martin Sjögren <martin@strakt.com> |
| 254 | |
| 255 | * src/ssl/context.c: Changed global_verify_callback so that it uses |
| 256 | PyObject_IsTrue instead of requring ints. |
| 257 | * Added pymemcompat.h to make the memory management uniform and |
| 258 | backwards-compatible. |
| 259 | * src/util.h: Added conditional definition of PyModule_AddObject and |
| 260 | PyModule_AddIntConstant |
| 261 | * src/ssl/connection.c: Socket methods are no longer explicitly |
| 262 | wrapped. fileno() is the only method the transport layer object HAS |
| 263 | to support, but if you want to use connect, accept or sock_shutdown, |
| 264 | then the transport layer object has to supply connect, accept |
| 265 | and shutdown respectively. |
| 266 | |
| 267 | 2002-06-12 Martin Sjögren <martin@strakt.com> |
| 268 | |
| 269 | * Changed comments to docstrings that are visible in Python. |
| 270 | * src/ssl/connection.c: Added set_connect_state and set_accept_state |
| 271 | methods. Thanks to Mark Welch <mark@collab.net> for this. |
| 272 | |
| 273 | 2002-06-11 Martin Sjögren <martin@strakt.com> |
| 274 | |
| 275 | * src/ssl/connection.c: accept and connect now use SSL_set_accept_state |
| 276 | and SSL_set_connect_state respectively, instead of SSL_accept and |
| 277 | SSL_connect. |
| 278 | * src/ssl/connection.c: Added want_read and want_write methods. |
| 279 | |
| 280 | 2002-06-05 Martin Sjögren <martin@strakt.com> |
| 281 | |
| 282 | * src/ssl/connection.c: Added error messages for windows. The code is |
| 283 | copied from Python's socketmodule.c. Ick. |
| 284 | * src/ssl/connection.c: Changed the parameters to the SysCallError. It |
| 285 | always has a tuple (number, string) now, even though the number |
| 286 | might not always be useful. |
| 287 | |
| 288 | 2002-04-05 Martin Sjögren <md9ms@mdstud.chalmers.se> |
| 289 | |
| 290 | * Worked more on the Debian packaging, hopefully the packages |
| 291 | are getting into the main Debian archive soon. |
| 292 | |
| 293 | 2002-01-10 Martin Sjögren <martin@strakt.com> |
| 294 | |
| 295 | * Worked some more on the Debian packaging, it's turning out real |
| 296 | nice. |
| 297 | * Changed format on this file, I'm going to try to be a bit more |
| 298 | verbose about my changes, and this format makes it easier. |
| 299 | |
| 300 | 2002-01-08 Martin Sjögren <martin@strakt.com> |
| 301 | |
| 302 | * Version 0.4.1 |
| 303 | * Added some example code |
| 304 | * Added the thread safe Connection object in the 'tsafe' submodule |
| 305 | * New Debian packaging |
| 306 | |
| 307 | 2001-08-09 Martin Sjögren <martin@strakt.com> |
| 308 | |
| 309 | * Version 0.4 |
| 310 | * Added a compare function for X509Name structures. |
| 311 | * Moved the submodules to separate .so files, with tiny C APIs so they |
| 312 | can communicate |
| 313 | * Skeletal OpenSSL/__init__.py |
| 314 | * Removed the err submodule, use crypto.Error and SSL.Error instead |
| 315 | |
| 316 | 2001-08-06 Martin Sjögren <martin@strakt.com> |
| 317 | |
| 318 | * Version 0.3 |
| 319 | * Added more types for dealing with certificates (X509Store, X509Req, |
| 320 | PKey) |
| 321 | * Functionality to load private keys, certificates and certificate |
| 322 | requests from memory buffers, and store them too |
| 323 | * X509 and X509Name objects can now be modified as well, very neat when |
| 324 | creating certificates ;) |
| 325 | * Added SSL_MODE_AUTO_RETRY to smooth things for blocking sockets |
| 326 | * Added a sock_shutdown() method to the Connection type |
| 327 | * I don't understand why, but I can't use Py_InitModule() to create |
| 328 | submodules in Python 2.0, the interpreter segfaults on the cleanup |
| 329 | process when I do. I added a conditional compile on the version |
| 330 | number, falling back to my own routine. It would of course be nice to |
| 331 | investigate what is happening, but I don't have the time to do so |
| 332 | * Do INCREF on the type objects before inserting them in the |
| 333 | dictionary, so they will never reach refcount 0 (they are, after all, |
| 334 | statically allocated) |
| 335 | |
| 336 | 2001-07-30 Martin Sjögren <martin@strakt.com> |
| 337 | |
| 338 | * Version 0.2 |
| 339 | * Lots of tweaking and comments in the code |
| 340 | * Now uses distutils instead of the stupid Setup file |
| 341 | * Hacked doc/tools/mkhowto, html generation should now work |
| 342 | |
| 343 | 2001-07-16 Martin Sjögren <martin@strakt.com> |
| 344 | |
| 345 | * Initial release (0.1, don't expect much from this one :-) |
| 346 | |