Martin Willi
|
962300b920
|
Show result of RADIUS authentication along with EAP identity
|
2010-10-07 11:14:09 +02:00 |
|
Martin Willi
|
a8809bb0cb
|
Fixed status_t enum names definition
|
2010-10-04 10:48:00 +02:00 |
|
Martin Willi
|
663e735553
|
Compare subject against all key identifiers in has_subject()
|
2010-09-09 17:46:20 +02:00 |
|
Martin Willi
|
89821331e0
|
Do not change cipherspec while we have buffered handshake fragments pending
|
2010-09-09 14:27:41 +02:00 |
|
Martin Willi
|
30cd31fb69
|
Added a simple led plugin to control Linux LEDs based on IKE activity
|
2010-09-08 12:00:57 +02:00 |
|
Martin Willi
|
7b3c01845f
|
Read the compression type byte for EC groups, only
|
2010-09-08 10:35:29 +02:00 |
|
Martin Willi
|
61df42ccf3
|
Fixed typos
|
2010-09-07 10:24:40 +02:00 |
|
Martin Willi
|
00755453e3
|
Build tls_test script only if TLS stack is enabled
|
2010-09-07 10:21:44 +02:00 |
|
Martin Willi
|
84c9bc4254
|
Added PKCS#11 NEWS
|
2010-09-07 10:21:25 +02:00 |
|
Martin Willi
|
a782b52f6a
|
Added (EAP-)TLS NEWS
|
2010-09-07 10:10:36 +02:00 |
|
Martin Willi
|
31c65eb362
|
Include ec_point_format extension in ClientHello
|
2010-09-06 18:51:38 +02:00 |
|
Martin Willi
|
02281c87a4
|
Added TLS specific EC point formats
|
2010-09-06 18:42:43 +02:00 |
|
Martin Willi
|
ec7d4e70d3
|
Renamed ecp_format to ansi_format, as point formats in TLS use different identifiers
|
2010-09-06 18:37:24 +02:00 |
|
Martin Willi
|
3f5de7b65f
|
Enable the random plugin for scripts
|
2010-09-06 18:11:05 +02:00 |
|
Martin Willi
|
fe559b5156
|
Accept TLS records with zero-length plaintext
|
2010-09-06 17:04:59 +02:00 |
|
Martin Willi
|
adb913adeb
|
Added strongswan.conf option to filter for specific TLS suites
|
2010-09-06 16:51:11 +02:00 |
|
Martin Willi
|
24a5b935e7
|
Added strongswan.conf options to filter cipher suites by specific algorithms
|
2010-09-06 16:51:04 +02:00 |
|
Martin Willi
|
a92a348092
|
Register missing AUTH_HMAC_SHA384 algorithm without truncation
|
2010-09-06 16:50:58 +02:00 |
|
Martin Willi
|
a03eebdf93
|
Fixed key type in TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA
|
2010-09-06 16:50:54 +02:00 |
|
Martin Willi
|
e6cce7ff0d
|
Prepend point format to ECDH public key
|
2010-09-06 15:37:51 +02:00 |
|
Martin Willi
|
e4fd2bb428
|
Log the selected (EC)DH group
|
2010-09-06 15:37:51 +02:00 |
|
Martin Willi
|
0f89143b84
|
Parse unsupported TLS Hello extensions properly
|
2010-09-06 15:37:51 +02:00 |
|
Martin Willi
|
6cf85b35a4
|
Added TLS extension identifiers from RFC 3546
|
2010-09-06 15:37:51 +02:00 |
|
Martin Willi
|
4e68c1cfdc
|
Do not propose (EC)DHE suites if we do not support them
|
2010-09-03 18:24:03 +02:00 |
|
Martin Willi
|
4254257f9d
|
Offer only algorithms/suites we have a registered public key backend for
|
2010-09-03 18:11:03 +02:00 |
|
Martin Willi
|
d987946e80
|
Added a final flag to builder registration to enumerate the actually supported algorithms
|
2010-09-03 18:09:48 +02:00 |
|
Martin Willi
|
f9c0cf862c
|
Fixed key type of ECDHE_RSA groups
|
2010-09-03 17:24:39 +02:00 |
|
Martin Willi
|
3f7bb88ba3
|
Use a dynamic curve enumerator to list/convert TLS named curves
|
2010-09-03 17:24:23 +02:00 |
|
Martin Willi
|
f4c98ae664
|
Use ECDH group check where appropriate
|
2010-09-03 16:53:36 +02:00 |
|
Martin Willi
|
7d7711aba4
|
Added a generic function to check if a DH group is an EC group
|
2010-09-03 16:22:10 +02:00 |
|
Martin Willi
|
2066918da2
|
Add ECDHE enabled cipher suites, including ECDSA variants
|
2010-09-03 14:54:43 +02:00 |
|
Martin Willi
|
033fe95f0b
|
Added support for a non-truncated SHA384 HMAC variant, as used by TLS
|
2010-09-03 14:54:43 +02:00 |
|
Martin Willi
|
4cdade5aae
|
Select private key based on received cipher suites
|
2010-09-03 14:54:43 +02:00 |
|
Martin Willi
|
37a59a8fbf
|
Support for EC curve Hello extension, EC curve fallback
|
2010-09-03 14:54:43 +02:00 |
|
Martin Willi
|
141d7f7abd
|
Added server support for ECDHE key exchange
|
2010-09-03 14:54:43 +02:00 |
|
Martin Willi
|
5fc7297e38
|
Added client support for ECDHE key exchange
|
2010-09-03 14:54:43 +02:00 |
|
Martin Willi
|
691ca54db5
|
Added TLS EC curve type and name identifiers
|
2010-09-03 14:54:43 +02:00 |
|
Martin Willi
|
ccb65463e7
|
Check for queued TLS alerts after each handshake part
|
2010-09-03 09:33:15 +02:00 |
|
Martin Willi
|
ed60dfa14f
|
Added support for MODP_CUSTOM to gcrypt plugin
|
2010-09-03 09:33:15 +02:00 |
|
Martin Willi
|
42b1ac91c4
|
Added support for MODP_CUSTOM to openssl plugin
|
2010-09-03 09:33:15 +02:00 |
|
Martin Willi
|
ef0a8e5892
|
Add DHE enabled RSA variants to the supported TLS suites
|
2010-09-02 19:33:08 +02:00 |
|
Martin Willi
|
f14358a9b5
|
Added TLS server side support for DHE suites
|
2010-09-02 19:33:08 +02:00 |
|
Martin Willi
|
da3f4a9fd0
|
Added TLS client side support for DHE suites
|
2010-09-02 19:33:08 +02:00 |
|
Martin Willi
|
35d9c15d5e
|
Store a MODP group we use for each TLS suite
|
2010-09-02 19:33:08 +02:00 |
|
Martin Willi
|
08d8b9405b
|
Added support for MODP_CUSTOM to gmp plugin
|
2010-09-02 19:33:08 +02:00 |
|
Martin Willi
|
0abd558a65
|
Added a MODP_CUSTOM DH group which takes g and p as constructor arguments
|
2010-09-02 19:33:08 +02:00 |
|
Martin Willi
|
06109c4717
|
Implemented "signature algorithm" hello extension
|
2010-09-02 19:33:08 +02:00 |
|
Martin Willi
|
731611c525
|
Added TLS extension identifiers
|
2010-09-02 19:33:08 +02:00 |
|
Martin Willi
|
d29a82a9d4
|
Added generic TLS data sign/verify, hash/sig algorithm construction
|
2010-09-02 19:33:08 +02:00 |
|
Martin Willi
|
60c4b3b545
|
Continue with a randomized premaster if decryption failed / version mismatches
|
2010-09-02 19:33:08 +02:00 |
|
Martin Willi
|
dbb7c0306c
|
Support different hash/sig algorithms in handshake signing, including ECDSA
|
2010-09-02 13:07:25 +02:00 |
|
Martin Willi
|
99dcaea9bd
|
Added TLS ClientCertificateType identifiers
|
2010-09-02 13:07:24 +02:00 |
|
Martin Willi
|
9dd2ca924e
|
Added TLS specific Hash and Signature Algorithm identifiers
|
2010-09-02 13:07:24 +02:00 |
|
Martin Willi
|
ea6d7cb4be
|
Fixed typos in tls_writer method descriptions
|
2010-09-02 13:07:24 +02:00 |
|
Martin Willi
|
bbdc85b66e
|
Respect key types in stroke key/certificate backend
|
2010-09-02 13:07:23 +02:00 |
|
Martin Willi
|
0ac49c3292
|
Added an enumerator for registered credential builders
|
2010-09-02 10:49:02 +02:00 |
|
Martin Willi
|
b019136596
|
Migrated credential_factory to INIT/METHOD macros
|
2010-09-02 10:49:02 +02:00 |
|
Martin Willi
|
93709d1093
|
Do not process any more TLS handshake messages on fatal alerts
|
2010-08-31 18:10:24 +02:00 |
|
Martin Willi
|
33b1a2567f
|
Load a left/rightcert2 for EAP-TLS even if no left/rightauth2 is defined
|
2010-08-31 18:10:23 +02:00 |
|
Martin Willi
|
c811479986
|
Strictly check if the server certificate matches the TLS server identity
|
2010-08-31 18:10:23 +02:00 |
|
Martin Willi
|
36eafea232
|
Use the AAA Identity for EAP authentication, if given
|
2010-08-31 18:10:23 +02:00 |
|
Martin Willi
|
64d7b0733f
|
Added support for the ipsec.conf aaa_identity keyword
|
2010-08-31 17:52:52 +02:00 |
|
Martin Willi
|
81137552e5
|
Added an AAA identity authentication config option
|
2010-08-31 17:26:20 +02:00 |
|
Martin Willi
|
f9fc5f2045
|
Added strongswan.conf options for EAP-TLS/TTLS fragment size
|
2010-08-31 16:17:01 +02:00 |
|
Martin Willi
|
743f94067e
|
Support processing of partial TLS record headers
|
2010-08-31 16:17:01 +02:00 |
|
Martin Willi
|
1cf8c5f746
|
Migrated EAP-TTLS to the generic TLS helper
|
2010-08-31 16:17:01 +02:00 |
|
Martin Willi
|
be751012c3
|
Migrated EAP-TLS to the generic TLS helper
|
2010-08-31 16:17:01 +02:00 |
|
Martin Willi
|
877c910f04
|
Implemented a generic TLS EAP helper to implement EAP-TLS, TTLS and other variants
|
2010-08-31 16:16:58 +02:00 |
|
Martin Willi
|
ecd98efa9d
|
Support output fragmentation of TLS records
|
2010-08-31 15:54:37 +02:00 |
|
Martin Willi
|
f13a03add0
|
Moved EAP type/code definitions to a seprate header file in libstrongswan
|
2010-08-31 15:35:29 +02:00 |
|
Martin Willi
|
ce1af73907
|
Implemented buffering of partial records in TLS stack
|
2010-08-31 15:35:29 +02:00 |
|
Martin Willi
|
d169aab35e
|
Log TLS handshake subtypes as handshakes
|
2010-08-31 15:35:29 +02:00 |
|
Martin Willi
|
fd0bde9a60
|
Added a TLS debug level option, use debugging hook
|
2010-08-31 15:35:29 +02:00 |
|
Martin Willi
|
4332b5af89
|
Do not strdup() zero length strings in identification_create_from_string()
|
2010-08-31 15:34:45 +02:00 |
|
Martin Willi
|
2291754ddf
|
Unwrap crlNumber INTEGER in openssl CRL parsing
|
2010-08-30 11:23:46 +02:00 |
|
Martin Willi
|
21f80e9dbc
|
Added crl support to pki --print
|
2010-08-30 11:23:45 +02:00 |
|
Martin Willi
|
45684ee65c
|
Fixed pluto smartcard support after introducing encryption schemes
|
2010-08-30 10:14:45 +02:00 |
|
Martin Willi
|
2bf0e74c38
|
Prefer AES/Camellia suites over 3DES/NULL encryption
|
2010-08-25 18:30:09 +02:00 |
|
Martin Willi
|
a596006e3f
|
Send TLS alerts for errors in TLS handshake building
|
2010-08-25 18:24:27 +02:00 |
|
Martin Willi
|
ee88ddd6aa
|
Refactored fragment building, use correct TLS content type for non-first fragments
|
2010-08-25 18:04:59 +02:00 |
|
Martin Willi
|
dfde6570c7
|
Update delete_payload length when adding SPIs
|
2010-08-25 17:04:25 +02:00 |
|
Martin Willi
|
5299719569
|
Migrated delete_payload to INIT/METHOD macros, replaced iterator
|
2010-08-25 17:03:00 +02:00 |
|
Martin Willi
|
e5c6ebb697
|
Use different return values in payload decryption to distinguish between integrity and syntax errors
|
2010-08-25 15:29:53 +02:00 |
|
Martin Willi
|
f1a74a3cab
|
Implemented a TLS utility to test on any TLS secured TCP connection
|
2010-08-25 12:57:13 +02:00 |
|
Martin Willi
|
17102f7b58
|
Added a simple high level TLS wrapper for sockets
|
2010-08-25 12:52:53 +02:00 |
|
Martin Willi
|
bd23b9086e
|
Initialize output chunk before appending data to it
|
2010-08-25 12:43:21 +02:00 |
|
Martin Willi
|
3dd06bd4ed
|
Added private key support to in-memory credential set
|
2010-08-25 10:28:23 +02:00 |
|
Martin Willi
|
72c6335de9
|
Added certificate support to in-memory credential set
|
2010-08-25 10:28:22 +02:00 |
|
Martin Willi
|
8427c78611
|
Added a ike_name logger option to prefix the IKE_SA name on each line
|
2010-08-25 09:55:37 +02:00 |
|
Martin Willi
|
69e8bb2e8d
|
Pass NULL peer identity to omit TLS peer authentication, added eap-ttls.request_peer_auth option
|
2010-08-24 11:34:43 +02:00 |
|
Martin Willi
|
a2c1235969
|
Skip the close notify if application layer completes successfully
|
2010-08-24 10:30:24 +02:00 |
|
Martin Willi
|
bda7d9d940
|
Added generic TLS purposes
|
2010-08-24 08:45:49 +02:00 |
|
Martin Willi
|
f55f9c4e1e
|
Client sends empty EAP-TTLS packet on fatal alerts to properly shut down TLS
|
2010-08-24 08:45:49 +02:00 |
|
Martin Willi
|
c5142f110e
|
Check if the application layer has completed successfully
|
2010-08-24 08:45:49 +02:00 |
|
Martin Willi
|
1475800080
|
Moved TLS record parsing/generation to tls.c
|
2010-08-24 08:45:49 +02:00 |
|
Martin Willi
|
c310881a11
|
Added a TLS purpose for EAP-TTLS with client authentication
|
2010-08-23 15:13:48 +02:00 |
|
Martin Willi
|
5ff8c62707
|
EAP-TLS clients send an empty packet on failure to properly shut down a TLS session
|
2010-08-23 15:13:41 +02:00 |
|
Martin Willi
|
e6f3ef1330
|
Implemented TLS Alert handling
|
2010-08-23 15:13:37 +02:00 |
|
Martin Willi
|
908e752201
|
Rebuild library.lo after changing ./configure options
|
2010-08-23 12:01:48 +02:00 |
|
Martin Willi
|
e0fcf43cf8
|
Build a trustchain even if no trust anchor is given
|
2010-08-23 12:01:43 +02:00 |
|