Martin Willi
|
7b3814f75d
|
remove spaces before tabs at the beginning of lines (^( )+\t)
|
2009-09-04 15:02:11 +02:00 |
|
Martin Willi
|
b9b8a98f47
|
remove spaces within tabs (\t( )+\t)
|
2009-09-04 15:00:19 +02:00 |
|
Martin Willi
|
323f9f990f
|
replaces four spaces by tabs, where appropriate
|
2009-09-04 14:50:23 +02:00 |
|
Martin Willi
|
7daf5226b7
|
removed trailing spaces ([[:space:]]+$)
|
2009-09-04 13:46:09 +02:00 |
|
Martin Willi
|
dd2b6f3073
|
fixed memleak in rekey collissions
|
2009-09-03 18:09:29 +02:00 |
|
Martin Willi
|
72e2faf291
|
Convert empty CREATE_CHILD_SA exchange to an INFORMATIONAL
|
2009-09-03 17:32:41 +02:00 |
|
Martin Willi
|
9beb83868f
|
Use get_notify() to look up single notifies
|
2009-09-03 17:32:01 +02:00 |
|
Martin Willi
|
3e15f99189
|
accept octet strings in is_asn1() check
|
2009-09-03 15:35:05 +02:00 |
|
Martin Willi
|
d176994235
|
Use recursive source address lookup if we get a gateway only
|
2009-09-03 14:46:39 +02:00 |
|
Martin Willi
|
12a230ddb4
|
Complain about rw(un)lock errors
|
2009-09-03 14:46:28 +02:00 |
|
Martin Willi
|
8fb4edc4ff
|
handle plugin loading failures
|
2009-09-01 16:20:45 +02:00 |
|
Martin Willi
|
d6a45127dc
|
plugins marked with a '!' are handled as critical: cancel if loading fails
|
2009-09-01 16:08:28 +02:00 |
|
Martin Willi
|
9412bbfa7c
|
use subjectPublicKeyInfo hash for CA certificate lookup
|
2009-09-01 14:06:44 +02:00 |
|
Martin Willi
|
8f68b72424
|
sql/rw-rsa and sql/rw-rsa-keyid scenarios require the pubkey plugin
|
2009-09-01 11:34:09 +02:00 |
|
Martin Willi
|
ad31f98a74
|
fixed certificate_t enum names
|
2009-09-01 11:28:05 +02:00 |
|
Martin Willi
|
6180a55852
|
use time_monotonic() instead of time() for statistics and time difference calculations
|
2009-08-31 18:00:28 +02:00 |
|
Martin Willi
|
de5784452b
|
use time_monotonic() instead of gettimeofday() for time difference calculations
|
2009-08-31 15:25:03 +02:00 |
|
Martin Willi
|
3d5818ec38
|
use monotonic time source in convar->timed_wait, and in the scheduler using it
|
2009-08-31 15:13:48 +02:00 |
|
Martin Willi
|
3f310c0d1f
|
implemented a monotonic timestamping function, unaffected from system time changes
|
2009-08-31 15:03:35 +02:00 |
|
Martin Willi
|
1d39663f7a
|
do not depend on gcrypt autoconf macros
|
2009-08-31 13:14:54 +02:00 |
|
Martin Willi
|
8706a151ff
|
added ECGDSA specific OIDs
|
2009-08-31 10:34:00 +02:00 |
|
Martin Willi
|
8365f7cd81
|
fixed crash in crl listing
|
2009-08-31 10:21:38 +02:00 |
|
Martin Willi
|
bf3b8c90d0
|
added workaround to parse PEM encoded PGP key with KEY_RSA
|
2009-08-28 17:25:07 +02:00 |
|
Martin Willi
|
4593ef51fd
|
implemented PGP Secret-Key Packet parsing
|
2009-08-28 17:23:58 +02:00 |
|
Martin Willi
|
caf1af1d9f
|
fixed memleak
|
2009-08-28 16:16:39 +02:00 |
|
Martin Willi
|
10b2898d3c
|
verify that the ECDSA auth signature was done with the correct curve
|
2009-08-27 17:58:02 +02:00 |
|
Martin Willi
|
472cb4ce77
|
distinguish between RFC 4754 (concatenated) and RFC 3279 (DER encoded) ECDSA signatures
|
2009-08-27 17:37:42 +02:00 |
|
Martin Willi
|
cec37b643a
|
fixed return value
|
2009-08-27 15:28:45 +02:00 |
|
Martin Willi
|
7ef310f5b4
|
do not append a NULL paramter to ECDSA algorithmIdentifiers
|
2009-08-27 15:28:21 +02:00 |
|
Martin Willi
|
9436b31c94
|
PKI tool supports certificate verification
|
2009-08-27 14:43:40 +02:00 |
|
Martin Willi
|
ed75a4dd69
|
do not flush cached encodings, keys are responsible for it
|
2009-08-27 13:59:30 +02:00 |
|
Martin Willi
|
85fd609ed6
|
whitelist openssl ecdsa_check function
|
2009-08-27 13:59:30 +02:00 |
|
Martin Willi
|
5e97fa9900
|
PKI tool supports generation of self-signed certificates
|
2009-08-27 13:59:30 +02:00 |
|
Martin Willi
|
8b10355c84
|
support generation of EC certificates
|
2009-08-27 13:59:30 +02:00 |
|
Martin Willi
|
82749537e2
|
added support for SIGN_ECDSA_WITH_SHA1 signature scheme in openssl
|
2009-08-27 13:59:30 +02:00 |
|
Martin Willi
|
eb73685dac
|
create algorithmIdentifier dynamically from OID database
|
2009-08-27 13:59:30 +02:00 |
|
Martin Willi
|
c03b095ebe
|
use subjectPublicKeyInfo encoding type directly
|
2009-08-27 13:59:30 +02:00 |
|
Martin Willi
|
09fe3c7e4c
|
pkcs1 encoder supports subjectPublicKeyInfo encoding
|
2009-08-27 13:59:30 +02:00 |
|
Martin Willi
|
d5dd43e777
|
implemented fingerprinting support for PKI tool
|
2009-08-27 10:41:07 +02:00 |
|
Martin Willi
|
1a8ef8aabc
|
fixed memleak in openssl fingerprinting
|
2009-08-27 10:40:49 +02:00 |
|
Martin Willi
|
b12c6d163d
|
do openssl fingerprinting/encoding directly, openssl provides all functions
|
2009-08-27 09:58:38 +02:00 |
|
Martin Willi
|
2ee8cd04bd
|
key encoding gained a cache() method, allows caching of externally created encodings
|
2009-08-27 09:57:49 +02:00 |
|
Martin Willi
|
083142c4a0
|
encoding public EC keys is not really possible without subjectPublicKeyInfo
|
2009-08-26 16:15:38 +02:00 |
|
Martin Willi
|
6a8791cd1f
|
complain about build errors in non-recursive cases only
|
2009-08-26 14:44:05 +02:00 |
|
Martin Willi
|
d16fd64d39
|
openac (and tools) do not depend on gmp anymore
|
2009-08-26 14:08:20 +02:00 |
|
Martin Willi
|
500f515a64
|
moved chunk_increment() function to libstrongswan
|
2009-08-26 14:07:26 +02:00 |
|
Martin Willi
|
d4df33f255
|
pki tool supports public key extraction from private key, certificates
|
2009-08-26 13:05:17 +02:00 |
|
Martin Willi
|
df5c60bc5d
|
added a BUILD_FROM_FD option, supporting credential parsing from stdin
|
2009-08-26 13:03:23 +02:00 |
|
Martin Willi
|
7c577c8ea2
|
started implementation of a PKI tool, currently supporting RSA|ECDSA key generation
|
2009-08-26 11:23:55 +02:00 |
|
Martin Willi
|
08ed551ce0
|
implemented openssl EC key generation
|
2009-08-26 11:23:55 +02:00 |
|
Martin Willi
|
a0b850450f
|
fixed openssl RSA private key encoding
|
2009-08-26 11:23:55 +02:00 |
|
Martin Willi
|
16db1207cf
|
keyids in SQL use ID_KEY_ID type with subjectPublicKey SHA1 hash
|
2009-08-26 11:23:55 +02:00 |
|
Martin Willi
|
41f57038e4
|
tests load pem/pkcs1 plugins, pubkey plugin not needed anymore
|
2009-08-26 11:23:55 +02:00 |
|
Martin Willi
|
0df451bc07
|
use ./configured plugins in keyid scripts
|
2009-08-26 11:23:55 +02:00 |
|
Martin Willi
|
500aa2607f
|
accept PEM encoded keys in keyid scripts
|
2009-08-26 11:23:55 +02:00 |
|
Martin Willi
|
94dde8a0ab
|
migrated scripts to new fingerprinting API
|
2009-08-26 11:23:55 +02:00 |
|
Martin Willi
|
9c3d2b3d60
|
updated medsrv and test to new fingerprint/encoding API
|
2009-08-26 11:23:55 +02:00 |
|
Martin Willi
|
1cd0d7969a
|
updated load-tester plugin to new fingerprinting API
|
2009-08-26 11:23:53 +02:00 |
|
Martin Willi
|
8eefe4617f
|
use only KEY_ID_PUBKEY_SHA1 fingerprint charon internally
|
2009-08-26 11:23:53 +02:00 |
|
Martin Willi
|
87d2026341
|
updated nm plugin to new fingerprinting API
|
2009-08-26 11:23:53 +02:00 |
|
Martin Willi
|
cb4f09eff3
|
updated agent plugin to new fingerprint/encoding API
|
2009-08-26 11:23:53 +02:00 |
|
Martin Willi
|
c5cd195c6c
|
updated stroke plugin to fingerprinting API
|
2009-08-26 11:23:53 +02:00 |
|
Martin Willi
|
64fdbce4da
|
updated charon to new fingerprinting API
|
2009-08-26 11:23:53 +02:00 |
|
Martin Willi
|
b4b68b64b8
|
updated pluto to new fingerprinting API
|
2009-08-26 11:23:52 +02:00 |
|
Martin Willi
|
5bceb90c86
|
updated scepclient to new encoding API
|
2009-08-26 11:23:52 +02:00 |
|
Martin Willi
|
8d09681559
|
updated pubkey plugin to new fingerprinting API
|
2009-08-26 11:23:52 +02:00 |
|
Martin Willi
|
6b6ece636c
|
updated x509 plugin to public key/x509 API changes
|
2009-08-26 11:23:52 +02:00 |
|
Martin Willi
|
a5e3153a36
|
updated x509/CRL/AC API to align with public key, authKeyIdentifier is a chunk
|
2009-08-26 11:23:52 +02:00 |
|
Martin Willi
|
e35c3e2a03
|
updated openssl plugin to new private/public key API, use encoder framework
|
2009-08-26 11:23:52 +02:00 |
|
Martin Willi
|
cbd5138948
|
updated gcrypt plugin to new private/public key API, use encoder framework
|
2009-08-26 11:23:52 +02:00 |
|
Martin Willi
|
741680d179
|
updated gmp plugin to new private/public key API, use encoder framework
|
2009-08-26 11:23:52 +02:00 |
|
Martin Willi
|
1384a42e1b
|
changed get_id/get_encoding API of private/public key to use new encoding framework
|
2009-08-26 11:23:52 +02:00 |
|
Martin Willi
|
1ef69b01ab
|
removed obsolete fingerprint identification types
|
2009-08-26 11:23:52 +02:00 |
|
Martin Willi
|
edd354db6f
|
added generic implementation helpers for private_key_t.equals/belongs_to, public_key_t.equals
|
2009-08-26 11:23:52 +02:00 |
|
Martin Willi
|
0dd2defc5a
|
added a seperate chache lookup, as encode() requires arguments expensive to build
|
2009-08-26 11:23:52 +02:00 |
|
Martin Willi
|
64e77e8fbb
|
use credential builder API to parse trusted public keys
|
2009-08-26 11:23:52 +02:00 |
|
Martin Willi
|
d1b3e8607e
|
implemented PGP fingerprinting
|
2009-08-26 11:23:51 +02:00 |
|
Martin Willi
|
e773fe4cab
|
implemented pkcs1 private/public key encoding and fingerprinting
|
2009-08-26 11:23:51 +02:00 |
|
Martin Willi
|
934d49a4f9
|
chunk_cat/cata/create_cat/length accept the sensitive data clearing mode 's'
|
2009-08-26 11:23:51 +02:00 |
|
Martin Willi
|
957d116328
|
in addition to 'm'/'c' mode, asn1_wrap accepts a 's' mode clearing sensitive information
|
2009-08-26 11:23:51 +02:00 |
|
Martin Willi
|
d9b24887a4
|
added a facility to hand out fingerprinting/key encoding to the pkcs1/pgp/... plugins
|
2009-08-26 11:23:51 +02:00 |
|
Martin Willi
|
831520d895
|
gmp uses component builder to build public- from private-key
|
2009-08-26 11:23:51 +02:00 |
|
Martin Willi
|
8380503168
|
gcrypt uses component builder to build public- from private-key
|
2009-08-26 11:23:51 +02:00 |
|
Martin Willi
|
b457e08fca
|
moved PGP code to pluto and gpg plugin
|
2009-08-26 11:23:51 +02:00 |
|
Martin Willi
|
7033a70fd0
|
gmp plugin makes use of pkcs1/pgp/dnskey plugins
|
2009-08-26 11:23:51 +02:00 |
|
Martin Willi
|
cbfafc1125
|
enforce RSA_PRIME1 > RSA_PRIME2 (p > q) in PGP
|
2009-08-26 11:23:51 +02:00 |
|
Martin Willi
|
5ef478aaee
|
implemented RFC3110 key builder in a plugin, added generic DNSKEY RR parsing
|
2009-08-26 11:23:51 +02:00 |
|
Martin Willi
|
3addf4e937
|
renamed BUILD_BLOB_RFC_3110 to BUILD_BLOB_DNSKEY, we potentially support other key types
|
2009-08-26 11:23:51 +02:00 |
|
Martin Willi
|
caa00e7ab7
|
pluto uses KEY_ANY builder to parse PGP public keys
|
2009-08-26 11:23:50 +02:00 |
|
Martin Willi
|
9493dd2ce0
|
implemented a pgp plugin providing PGP key parsing builders
|
2009-08-26 11:23:50 +02:00 |
|
Martin Willi
|
4e3d1e804e
|
make use of the pkcs1 plugin in gcrypt rsa key parsing
|
2009-08-26 11:23:50 +02:00 |
|
Martin Willi
|
3044774323
|
removed subjectPublicKeyInfo parsing, provided by pkcs1 plugin
|
2009-08-26 11:23:50 +02:00 |
|
Martin Willi
|
1e0f69373a
|
implemented a pkcs1 plugin providing PKCS#1 key parsing builders
|
2009-08-26 11:23:50 +02:00 |
|
Martin Willi
|
750bbcf9a8
|
added support for %prompt-ing private key passhprases in strokes "ipsec secrets"
|
2009-08-26 11:23:50 +02:00 |
|
Martin Willi
|
7c2d883af7
|
show more information if building a credential fails
|
2009-08-26 11:23:50 +02:00 |
|
Martin Willi
|
833dcfa530
|
log loaded private key/certificates
|
2009-08-26 11:23:50 +02:00 |
|
Martin Willi
|
3f9ec06f6f
|
added getnetbyname/gethostbyname2 to leak detective whitelist, used by pluto
|
2009-08-26 11:23:50 +02:00 |
|
Martin Willi
|
d47dc6d170
|
clone blobs passed to parse functions, check before free
|
2009-08-26 11:23:50 +02:00 |
|
Martin Willi
|
89556140d0
|
fixed builder signature
|
2009-08-26 11:23:50 +02:00 |
|
Martin Willi
|
ddf7c6ac7b
|
do not enumerate builders returning NULL
|
2009-08-26 11:23:50 +02:00 |
|