Andreas Steffen
288ee54875
libimcv: No need to load AIK pubkey if AIK certificate is available
2016-08-31 16:12:55 +02:00
Tobias Brunner
f883cd6df6
swanctl: Document how DH groups in CHILD_SA proposals are applied
...
References #1039 .
2016-08-31 11:47:25 +02:00
Tobias Brunner
fe4ed4578f
padlock: Use builtin bswap32() to fix compilation on FreeBSD
...
Fixes #591 .
2016-08-31 10:52:55 +02:00
Thomas Egerer
c6b9a3a485
proposal: Use proper list to get function pointer when adding custom parser
...
Signed-off-by: Thomas Egerer <[email protected] >
2016-08-29 16:02:07 +02:00
Tobias Brunner
dc5b05ea18
android: Add missing xof.c file
...
Fixes #2093 .
2016-08-29 10:42:00 +02:00
Tobias Brunner
831425491c
xof: Add header to dev headers
2016-08-29 10:40:59 +02:00
Thomas Egerer
8456d6f5a8
ikev1: Don't require AH mapping for integrity algorithm when generating proposal
...
Signed-off-by: Thomas Egerer <[email protected] >
2016-08-25 13:34:36 +02:00
Andreas Steffen
d125941802
libtpmtss: TCTI finalization call changed
2016-08-25 13:22:51 +02:00
Tobias Brunner
09d8215d3f
pki: Allow to load CRLs from files in --verify
2016-08-25 11:07:35 +02:00
Tobias Brunner
17ecc104fb
ikev1: Ignore the last two bytes of the Cisco Unity vendor ID
...
These seem to indicate the major and minor version of the protocol, like
e.g. for the DPD vendor ID. Some implementations seem to send versions
other than 1.0 so we just ignore these for now when checking for known
vendor IDs.
Fixes #2088 .
2016-08-24 17:46:05 +02:00
Tobias Brunner
603a1d3c8f
utils: Fix definition of BYTE_ORDER with MinGW
2016-08-24 10:40:57 +02:00
Tobias Brunner
22b839e6e9
ikev1: Accept more than one certificate payload in aggressive mode
...
Fixes #2085 .
2016-08-17 10:30:39 +02:00
Andreas Steffen
3bca51e430
unit-tests: Removed unused variable
2016-08-11 17:01:33 +02:00
Andreas Steffen
1342bd3386
unit-tests: Created newhope unit-tests
2016-08-10 14:22:00 +02:00
Andreas Steffen
393688aea0
Created newhope plugin implementing the New Hope key exchange algorithm
2016-08-10 14:22:00 +02:00
Andreas Steffen
1fddb0b92e
xof: Added ChaCha20 stream as XOF
2016-08-06 12:09:05 +02:00
Andreas Steffen
8993cb556e
utils: Defined uletoh16() and htole16()
2016-08-06 12:09:05 +02:00
Andreas Steffen
b8070e2c85
integrity-test: Added ntru_param_sets to read-only segment
2016-07-29 12:36:15 +02:00
Andreas Steffen
17e4ca6ac9
integrity-test: Added bliss_param_sets to read-only segment
2016-07-29 12:36:15 +02:00
Andreas Steffen
7256c68da0
integrity-test: check code and ro segments of libnttfft
2016-07-29 12:36:15 +02:00
Andreas Steffen
d305f251a5
Created libnttfft
...
This makes Number Theoretic Transforms (NTT) based on the efficient
Fast-Fourier-Transform (FFT) available to multiple plugins.
2016-07-29 12:36:15 +02:00
Andreas Steffen
65f2ecb86d
Share twiddle factors table between 512 and 1024 point FFT
2016-07-29 12:36:14 +02:00
Andreas Steffen
68075fb7a7
Implemented FFT with n = 1024 and q = 11289 using Montgomery arithmetic
2016-07-29 12:36:14 +02:00
Andreas Steffen
a7d626118f
bliss: Implemented FFT with fast Montgomery arithmetic
2016-07-29 12:36:14 +02:00
Andreas Steffen
5ff88c9622
xof: Implemented SHAKE128 and SHAKE256 Extended Output Functions
2016-07-29 12:36:14 +02:00
Andreas Steffen
04208ac5d4
xof: Defined Extended Output Functions
2016-07-29 12:36:14 +02:00
Andreas Steffen
7f65a8c271
vici: Increased various string buffers to BUF_LEN (512 bytes)
2016-07-29 12:34:40 +02:00
Andreas Steffen
fa1865094d
integrity-test: Added charon-systemd
2016-07-29 12:33:32 +02:00
Andreas Steffen
eda8907b90
Added SHA-3 signature OIDs
2016-07-26 13:34:45 +02:00
Tobias Brunner
a6d7aed78a
libcharon: Add exchange_tests to .gitignore
2016-07-25 14:01:26 +02:00
Andreas Steffen
5ce749bcfc
unit-tests: Decreased loop count of FFT speed test to 10'000
2016-07-22 21:27:42 +02:00
Andreas Steffen
10ebb3c914
unit-tests: Added bliss_fft_speed test
2016-07-22 11:58:10 +02:00
Andreas Steffen
0274163674
libtpmtss: Use pkconfig to configure TSS 2.0 includes and libraries
2016-07-20 11:26:07 +02:00
Tobias Brunner
60d0f52fd6
ike1: Flush active queue when queueing a delete of the IKE_SA
...
By aborting the active task we don't have to wait for potential
retransmits if the other peer does not respond to the current task.
Since IKEv1 has no sequential message IDs and INFORMATIONALs are no real
exchanges this should not be a problem.
Fixes #1537
References #429 , #1410
Closes strongswan/strongswan#48
2016-07-19 11:48:17 +02:00
Tobias Brunner
1fafc56b95
Fixed some typos, courtesy of codespell
2016-07-04 12:18:51 +02:00
Andreas Steffen
37ffa99cf2
imcv: Added EFI HCRTM event
2016-06-30 16:20:10 +02:00
Tobias Brunner
a8d6501036
aikgen: Fix computation of key ID of the AIK public key
...
We don't have direct access to the modulus and exponent of the key anymore.
2016-06-30 12:56:41 +02:00
Tobias Brunner
c05d49632f
libtpmtss: Define missing Doxygen group and fix some comments
2016-06-30 12:12:31 +02:00
Tobias Brunner
a23bde26bd
libimcv: Fix Doxygen comment
2016-06-30 12:12:26 +02:00
Thomas Egerer
40bb4677f7
ikev1: Add support for extended sequence numbers
...
Signed-off-by: Thomas Egerer <[email protected] >
2016-06-29 11:16:48 +02:00
Tobias Brunner
7c81219bb8
plugin-loader: Allow selective modification of the default plugin list
...
This change allows selectively modifying the default plugin list by setting
the `load` setting of individual plugins (e.g. to disable them or to change
their priority) without enabling charon.load_modular and having to configure
a section and a load statement for every plugin.
2016-06-29 11:16:48 +02:00
Tobias Brunner
505c318701
leak-detective: Try to properly free allocations after deinitialization
...
If a function we whitelist allocates memory while leak detective is enabled
but only frees it after LD has already been disabled, free() will get called
with invalid pointers (not pointing to the actually allocated memory by LD),
which will cause checks in the C library to fail and the program to crash.
This tries to detect such cases and calling free with the correct pointer.
2016-06-29 11:09:38 +02:00
Tobias Brunner
c1410cb045
openssl: Whitelist OPENSSL_init_crypto() and others in leak detective
...
Lots of static data is allocated in this function, which isn't freed until
the library is unloaded (we can't call OPENSSL_cleanup() as initialization
would fail when calling it again later). When enabling the leak
detective the test runner eventually crashes as all the data allocated during
initialization has an invalid size when freed after leak detective has been
unloaded.
2016-06-29 11:09:38 +02:00
Tobias Brunner
fedec33f5a
openssl: Update GCM/crypter API to OpenSSL 1.1.0
2016-06-29 11:09:38 +02:00
Tobias Brunner
97b1a27f43
openssl: Update HMAC API to OpenSSL 1.1.0
2016-06-29 11:09:38 +02:00
Tobias Brunner
cd08eb84cb
openssl: Don't use deprecated RAND_pseudo_bytes()
2016-06-29 11:09:38 +02:00
Tobias Brunner
985d7b1c67
openssl: Update PKCS#12 API to OpenSSL 1.1.0
2016-06-29 11:09:37 +02:00
Tobias Brunner
a9f388e368
openssl: Update PKCS#7 API to OpenSSL 1.1.0
2016-06-29 11:09:37 +02:00
Tobias Brunner
989ba4b6cd
openssl: Update CRL API to OpenSSL 1.1.0
...
There is currently no way to compare the outer and inner algorithms
encoded in a parsed CRL. X509_CRL_verify() does not seem to check that
either, though (unlike X509_verify()).
2016-06-29 11:09:37 +02:00
Tobias Brunner
08d7e1f190
openssl: Update x509 API to OpenSSL 1.1.0
2016-06-29 11:09:37 +02:00