<feed xmlns='http://www.w3.org/2005/Atom'>
<title>delta/curl.git/docs/CIPHERS.md, branch bagder/ftp-over-httpsproxy</title>
<subtitle>github.com: bagder/curl.git
</subtitle>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/curl.git/'/>
<entry>
<title>CIPHERS.md: Explain Schannel error SEC_E_ALGORITHM_MISMATCH</title>
<updated>2019-07-17T05:08:23+00:00</updated>
<author>
<name>georgeok</name>
<email>giorgos.n.oikonomou@gmail.com</email>
</author>
<published>2019-07-10T11:34:17+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/curl.git/commit/?id=fea0120312f0e6a74b9dcc2a194c76c87c727ffe'/>
<id>fea0120312f0e6a74b9dcc2a194c76c87c727ffe</id>
<content type='text'>
If the SSL backend is Schannel and the user specifies an Schannel CALG_
that is not supported by the protocol or the server then curl returns
CURLE_SSL_CONNECT_ERROR (35) SEC_E_ALGORITHM_MISMATCH.

Fixes https://github.com/curl/curl/issues/3389
Closes https://github.com/curl/curl/pull/4106
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
If the SSL backend is Schannel and the user specifies an Schannel CALG_
that is not supported by the protocol or the server then curl returns
CURLE_SSL_CONNECT_ERROR (35) SEC_E_ALGORITHM_MISMATCH.

Fixes https://github.com/curl/curl/issues/3389
Closes https://github.com/curl/curl/pull/4106
</pre>
</div>
</content>
</entry>
<entry>
<title>tls13-docs: mention it is only for OpenSSL &gt;= 1.1.1</title>
<updated>2019-06-02T14:15:45+00:00</updated>
<author>
<name>Daniel Stenberg</name>
<email>daniel@haxx.se</email>
</author>
<published>2019-05-27T06:01:18+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/curl.git/commit/?id=7e590b3ecd2d4c061d8e001b25b869460bbdc560'/>
<id>7e590b3ecd2d4c061d8e001b25b869460bbdc560</id>
<content type='text'>
Reported-by: Jay Satiro
Co-authored-by: Jay Satiro
Fixes #3938
Closes #3946
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Reported-by: Jay Satiro
Co-authored-by: Jay Satiro
Fixes #3938
Closes #3946
</pre>
</div>
</content>
</entry>
<entry>
<title>nss: allow to specify TLS 1.3 ciphers if supported by NSS</title>
<updated>2019-05-27T07:04:09+00:00</updated>
<author>
<name>Hubert Kario</name>
<email>hkario@redhat.com</email>
</author>
<published>2019-05-17T17:15:24+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/curl.git/commit/?id=319ae9075efba769c9d5e98e827bb325ad0fcb6f'/>
<id>319ae9075efba769c9d5e98e827bb325ad0fcb6f</id>
<content type='text'>
Closes #3916
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Closes #3916
</pre>
</div>
</content>
</entry>
<entry>
<title>docs: Markdown and misc improvements [ci skip]</title>
<updated>2019-05-16T22:11:27+00:00</updated>
<author>
<name>Viktor Szakats</name>
<email>commit@vszakats.net</email>
</author>
<published>2019-05-16T22:11:27+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/curl.git/commit/?id=f3e0f071b14fcb46a453f69bdf4e062bcaacf362'/>
<id>f3e0f071b14fcb46a453f69bdf4e062bcaacf362</id>
<content type='text'>
Approved-by: Daniel Stenberg
Closes #3896
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Approved-by: Daniel Stenberg
Closes #3896
</pre>
</div>
</content>
</entry>
<entry>
<title>schannel: support CALG_ECDH_EPHEM algorithm</title>
<updated>2019-02-25T06:38:35+00:00</updated>
<author>
<name>georgeok</name>
<email>giorgos.n.oikonomou@gmail.com</email>
</author>
<published>2019-02-24T18:20:57+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/curl.git/commit/?id=531b7ad43a7804d6fdaece570fc39b954373a4a9'/>
<id>531b7ad43a7804d6fdaece570fc39b954373a4a9</id>
<content type='text'>
Add support for Ephemeral elliptic curve Diffie-Hellman key exchange
algorithm option when selecting ciphers. This became available on the
Win10 SDK.

Closes https://github.com/curl/curl/pull/3608
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Add support for Ephemeral elliptic curve Diffie-Hellman key exchange
algorithm option when selecting ciphers. This became available on the
Win10 SDK.

Closes https://github.com/curl/curl/pull/3608
</pre>
</div>
</content>
</entry>
<entry>
<title>docs/CIPHERS: fix the TLS 1.3 cipher names</title>
<updated>2018-10-27T08:46:36+00:00</updated>
<author>
<name>Daniel Stenberg</name>
<email>daniel@haxx.se</email>
</author>
<published>2018-10-26T11:33:34+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/curl.git/commit/?id=067992baa7fc616086237a8f917beaf0e05a4d7d'/>
<id>067992baa7fc616086237a8f917beaf0e05a4d7d</id>
<content type='text'>
... picked straight from the OpenSSL man page:
https://www.openssl.org/docs/manmaster/man3/SSL_CTX_set_ciphersuites.html

Reported-by: Ricky-Tigg on github
Bug: #3178
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
... picked straight from the OpenSSL man page:
https://www.openssl.org/docs/manmaster/man3/SSL_CTX_set_ciphersuites.html

Reported-by: Ricky-Tigg on github
Bug: #3178
</pre>
</div>
</content>
</entry>
<entry>
<title>CIPHERS.md: Mention the options used to set TLS 1.3 ciphers</title>
<updated>2018-10-23T07:37:37+00:00</updated>
<author>
<name>Jay Satiro</name>
<email>raysatiro@yahoo.com</email>
</author>
<published>2018-10-23T04:49:12+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/curl.git/commit/?id=a023dfa19abd581f9645d218519ec8843564eb47'/>
<id>a023dfa19abd581f9645d218519ec8843564eb47</id>
<content type='text'>
Closes https://github.com/curl/curl/pull/3159
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Closes https://github.com/curl/curl/pull/3159
</pre>
</div>
</content>
</entry>
<entry>
<title>docs/CIPHERS: mention the colon separation for OpenSSL</title>
<updated>2018-10-02T11:55:36+00:00</updated>
<author>
<name>Daniel Stenberg</name>
<email>daniel@haxx.se</email>
</author>
<published>2018-10-02T11:55:36+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/curl.git/commit/?id=835a2fe694214341b601b2439082a30a24cc9da9'/>
<id>835a2fe694214341b601b2439082a30a24cc9da9</id>
<content type='text'>
Bug: #3077
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Bug: #3077
</pre>
</div>
</content>
</entry>
<entry>
<title>schannel: support selecting ciphers</title>
<updated>2018-06-12T10:08:40+00:00</updated>
<author>
<name>Robert Prag</name>
<email>Robert_Prag@symantec.com</email>
</author>
<published>2018-06-02T00:17:40+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/curl.git/commit/?id=9aefbff30d280c60fc9d8cc3e0b2f19fc70a2f28'/>
<id>9aefbff30d280c60fc9d8cc3e0b2f19fc70a2f28</id>
<content type='text'>
Given the contstraints of SChannel, I'm exposing these as the algorithms
themselves instead; while replicating the ciphersuite as specified by
OpenSSL would have been preferable, I found no way in the SChannel API
to do so.

To use this from the commandline, you need to pass the names of contants
defining the desired algorithms. For example, curl --ciphers
"CALG_SHA1:CALG_RSA_SIGN:CALG_RSA_KEYX:CALG_AES_128:CALG_DH_EPHEM"
https://github.com The specific names come from wincrypt.h

Closes #2630
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Given the contstraints of SChannel, I'm exposing these as the algorithms
themselves instead; while replicating the ciphersuite as specified by
OpenSSL would have been preferable, I found no way in the SChannel API
to do so.

To use this from the commandline, you need to pass the names of contants
defining the desired algorithms. For example, curl --ciphers
"CALG_SHA1:CALG_RSA_SIGN:CALG_RSA_KEYX:CALG_AES_128:CALG_DH_EPHEM"
https://github.com The specific names come from wincrypt.h

Closes #2630
</pre>
</div>
</content>
</entry>
<entry>
<title>setopt: add TLS 1.3 ciphersuites</title>
<updated>2018-05-29T14:12:52+00:00</updated>
<author>
<name>Daniel Stenberg</name>
<email>daniel@haxx.se</email>
</author>
<published>2018-05-29T14:12:52+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/curl.git/commit/?id=050c93c46f5bc880897152419200e60da56b46e0'/>
<id>050c93c46f5bc880897152419200e60da56b46e0</id>
<content type='text'>
Adds CURLOPT_TLS13_CIPHERS and CURLOPT_PROXY_TLS13_CIPHERS.

curl: added --tls13-ciphers and --proxy-tls13-ciphers

Fixes #2435
Reported-by: zzq1015 on github
Closes #2607
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Adds CURLOPT_TLS13_CIPHERS and CURLOPT_PROXY_TLS13_CIPHERS.

curl: added --tls13-ciphers and --proxy-tls13-ciphers

Fixes #2435
Reported-by: zzq1015 on github
Closes #2607
</pre>
</div>
</content>
</entry>
</feed>
