Andreas Steffen
1ef8b92211
pkcs10: Support of Microsoft CertTypeExtension
...
The msCertificateTypeExtension OID (1.3.6.1.4.1.311.20.2) can
be used in a PKCS#10 certificate request to define a certificate
profile. It consists of an UTF8 string.
pki: profile option
2022-08-24 20:46:44 +02:00
Andreas Steffen
8716f7c03c
scepclient: Removal and replacement by pki subcommands
...
The "ipsec scepclient" tool has been removed and replaced by the
pki subcommands "pki --scep" and "pki --scepca" which implement the
new SCEP RFC 8894 standard that was released in September 2020 and
which supports trusted "certificate renewal" based on the existing
client certificate.
2022-08-24 20:46:44 +02:00
Andreas Steffen
122796df27
pki: Additional pki.scep options for strongswan.conf
2022-08-24 20:46:44 +02:00
Andreas Steffen
93f2901d1a
pki: Created pki --scep man page
2022-08-24 20:46:44 +02:00
Andreas Steffen
7c7a5a0260
pki: Enroll an X.509 certificate with a SCEP server
2022-08-24 20:46:44 +02:00
Andreas Steffen
a9d70bd485
pki: Created pki --scepca man page
2022-08-24 20:46:44 +02:00
Andreas Steffen
6851273944
pki: Get CA certs via SCEP
2022-08-19 23:00:11 +02:00
Andreas Steffen
bcedd65a31
pkcs7: Allow for missing optional content field
...
The content field of type OCTET STRING of a ContentInfo object
with ContentType Data
ContentInfo ::= SEQUENCE {
contentType ContentType,
content
[0] EXPLICIT OCTET STRING OPTIONAL
is optional and can be missing if no data is available
2022-07-29 07:59:00 +02:00
Andreas Steffen
49ddfe91f0
Version bump to 5.9.7
2022-07-29 06:54:09 +02:00
Andreas Steffen
1e444454e1
Version bump to 5.9.7rc1
2022-07-23 14:38:36 +02:00
Andreas Steffen
c01d765c11
testing: Increased memory of KVM instance sun
2022-07-23 14:36:50 +02:00
Andreas Steffen
67f7d8fe8a
testing: Replace deprecated tempfile command by mktemp
2022-07-23 11:28:08 +02:00
Andreas Steffen
110e8e6608
doc: Removed the standards directory
...
This collection of Internet standards and drafts hadn't been
updated for a long time and the documents are readily available
on the Internet anyway. The strongSwan documentation page
https://docs.strongswan.org/docs/5.9/features/ietf.html
specifies which standards are currently supported.
2022-07-12 10:24:42 +02:00
Andreas Steffen
2b474073d9
pem: Support PEM-encoded PKCS#7 container
2022-07-06 20:38:00 +02:00
Andreas Steffen
e8c2ae3c54
Version bump to 5.9.7dr2
2022-06-29 11:33:34 +02:00
Andreas Steffen
b7c167f972
Rename MODP_NONE to KE_NONE
2022-06-29 10:28:50 +02:00
Andreas Steffen
432111720d
Version bump to 5.9.7dr1
2022-05-26 17:41:14 +02:00
Andreas Steffen
3f19a951cf
TCG TNC attribute name changes
...
The TCG TNC IF-M Segmentation standard was implemented based on a
draft version. The attribute names are updated to comply with the
final TCG IF-M Segmentation Specification Version 1.0 Rev. 5
dated 4 April 2016
2022-05-26 17:37:43 +02:00
Andreas Steffen
4cf8cd0321
Version bump to 5.9.6
2022-04-28 22:38:10 +02:00
Andreas Steffen
7df710095e
Version bump to 5.9.6rc1
2022-04-16 10:23:35 +02:00
Andreas Steffen
b2cf5af192
README: Added link to docs.strongswan.org
2022-03-02 21:55:43 +01:00
Andreas Steffen
57d6e96943
Version bump to 5.9.5
2022-01-24 12:01:10 +01:00
Andreas Steffen
1321fdb8aa
Version bump to 5.9.5rc1
2022-01-16 07:48:12 +01:00
Andreas Steffen
85d626e9ae
testing: Modified ikev2/net2net-rfc3779 scenario
2022-01-10 21:14:11 +01:00
Andreas Steffen
36c64589d8
Version bump to 5.9.5dr4
2021-12-31 14:46:31 +01:00
Andreas Steffen
903c68e069
sw-collector: Iterate through history logs
...
The logrotate function causes the apt history to be split into
several parts at arbitrary points in time. If history.log only
is parsed then some package installation changes stored in
zipped backup history files might get lost.
Thus sw-collector now searches all backup history files until
a date older than the current event stored in the collector.db
database is found, so that no entries get overlooked.
2021-12-31 14:33:22 +01:00
Andreas Steffen
0b76ca13ab
libtpmtss: Some minor improvements
2021-12-19 13:50:07 +01:00
Andreas Steffen
dadcd9060e
Version bump to 5.9.5dr3
2021-12-11 16:39:34 +01:00
Andreas Steffen
8249e6afad
libtpmtss: Establish session with TPM 2.0
...
Using the trusted RSA or ECC Endorsement Key of the TPM 2.0 a
secure session is established via RSA public key encryption or
an ephemeral ECDH key exchange, respectively.
The session allows HMAC-based authenticated communication with
the TPM 2.0 and the exchanged parameters can be encrypted where
necessary to guarantee confidentiality.
2021-12-11 16:21:59 +01:00
Andreas Steffen
01485770fd
gcrypt: Support of AES-CFB encryption
2021-12-06 13:43:45 +01:00
Andreas Steffen
2d1a1cc907
botan: Support of AES-CFB encryption
2021-12-06 13:28:31 +01:00
Andreas Steffen
54d7e39d40
wolfssl: Support of AES-CFB encryption
2021-12-06 12:53:11 +01:00
Andreas Steffen
695a04d146
openssl: Support of AES-CFB encryption
2021-12-06 12:52:37 +01:00
Andreas Steffen
4124b1d376
Version bump to 5.9.5dr2
2021-11-18 22:06:09 +01:00
Andreas Steffen
fe5399d287
Merge branch 'rsa-oaep-encryption'
2021-11-11 10:03:17 +01:00
Andreas Steffen
519db56f2f
testing: Added RSA PKCS1 encryption tests
2021-11-10 21:06:10 +01:00
Andreas Steffen
6bb5c4f2bb
testing: Added RSA OAEP encryption tests
2021-11-10 21:06:10 +01:00
Andreas Steffen
93bf894cd2
gcrypt: Support RSA OAEP SHA1 encryption/decryption
2021-11-10 21:06:10 +01:00
Andreas Steffen
b50e8a88ff
gcrypt: Enable RSA PKCS1 encryption/decryption
2021-11-10 20:17:49 +01:00
Andreas Steffen
be52ad7c6d
botan: RSA OAEP labels are not supported
2021-11-10 20:03:22 +01:00
Andreas Steffen
9cfdc32597
wolfssl: Support OAEP labels
2021-11-10 20:03:22 +01:00
Andreas Steffen
6adb543341
openssl: Implemented RSA OAEP encryption/decryption with optional labels
2021-11-10 20:03:22 +01:00
Andreas Steffen
4abb29f639
credentials: Added void *params to public_key encrypt() and private_key decrypt() methods
2021-11-09 17:58:28 +01:00
Andreas Steffen
c8341fca61
botan: Fully enable RSA OAEP decryption
2021-11-09 17:58:28 +01:00
Andreas Steffen
bcbf1862d7
Version bump to 5.9.5dr1
2021-10-26 08:04:19 +02:00
Andreas Steffen
f0935a63ed
testing: Optimized plugin use in pkcs8 scenarios
2021-10-23 11:44:15 +02:00
Andreas Steffen
9c7288d6f1
testing: Minimum required plugins for net2net-pkcs12 scenarios
2021-10-22 11:39:20 +02:00
Andreas Steffen
66fa7c959a
Version bump to 5.9.4
2021-10-18 11:45:53 +02:00
Andreas Steffen
8cc89b505e
testing: Correctly remove pkcs8 key after test case
2021-10-18 11:45:31 +02:00
Andreas Steffen
1ecb0b8133
Version bump to 5.9.4rc1
2021-10-12 08:54:03 +02:00
Andreas Steffen
740038e401
Version bump to 5.9.4dr3
2021-10-04 15:47:05 +02:00
Andreas Steffen
1b21a00fa7
Version bump to 5.9.4dr2
2021-09-21 14:18:16 +02:00
Andreas Steffen
3e2841572b
testing: Switch to Python 3
...
Both swidGenerator and strongTNC were migrated to Python 3.
This allows to migrate all testing scripts to Python 3, too.
2021-09-21 09:47:43 +02:00
Andreas Steffen
91896264b2
sec-updater: Use latest versions
2021-09-09 22:54:38 +02:00
Andreas Steffen
d23ca7f345
os_info: Parse /etc/os-release first
2021-09-09 22:54:38 +02:00
Andreas Steffen
0eb1d6c0e6
Version bump to 5.9.4dr1
2021-08-22 10:55:37 +02:00
Andreas Steffen
4817d5ed0d
Version bump to 5.9.3
2021-07-06 14:00:39 +02:00
Andreas Steffen
a09a905e1d
vici: Suppress trailing nul character
2021-07-06 12:06:23 +02:00
Andreas Steffen
30fab57124
Version bump to 5.9.3rc1
2021-06-24 09:18:54 +02:00
Andreas Steffen
4baca5ca80
testing: Fixed ikev2/farp scenario
2021-06-22 12:32:35 +02:00
Andreas Steffen
dbd1534875
Version bump to 5.9.3dr4
2021-06-22 10:33:07 +02:00
Andreas Steffen
eba2622587
testing: Migrate ikev2-stroke-bye scenarios to vici
2021-06-22 10:23:06 +02:00
Andreas Steffen
706c58b291
testing: Fixed pretest script of ikev1/rw-psk-aggressive scenario
2021-06-21 12:03:36 +02:00
Andreas Steffen
9c85a52956
Version bump to 5.9.3dr3
2021-06-04 09:28:17 +02:00
Andreas Steffen
cc4338267e
testing: Added openssl-ikev2/net2net-sha3-rsa-cert scenario
2021-06-03 14:20:06 +02:00
Andreas Steffen
5688e631e3
openssl: Support SHA-3 based RSA_EMSA_PKCS1 signatures
2021-06-03 14:20:06 +02:00
Andreas Steffen
de5ca4021a
testing: Test wolfssl plugin
2021-06-03 10:22:59 +02:00
Andreas Steffen
8bbd7bbd36
wolfssl: Full support of SHA3 signatures
2021-06-03 10:20:18 +02:00
Andreas Steffen
e0044e5f48
credential_factory: Store name of plugin registering a builder
2021-06-01 21:12:46 +02:00
Andreas Steffen
62c5ef035c
wolfssl: Set RSA key type
2021-05-30 12:40:08 +02:00
Andreas Steffen
d415673565
Version bump to 5.9.3dr2
2021-05-21 10:00:41 +02:00
Andreas Steffen
7c5a2974b9
testing: Reorganizing IKEv1 and IKEv2 examples
...
For documentation purposes the new folders ikev1-algs, ikev2-algs,
ikev1-multi-ca and ikev2-multi-ca have been created. Most of the
test cases have now been converted to the vici interface. The
remaining legacy stroke scenarios yet to be converted have been put
into the ikev2-stroke-bye folder.
For documentation purposes some legacy stroke scenarios will be kept
in the ikev1-stroke, ikev2-stroke and ipv6-stroke folders.
2021-05-21 09:42:50 +02:00
Andreas Steffen
09df86c033
Version bump to 5.9.3dr1
2021-03-31 09:59:55 +02:00
Andreas Steffen
66ba50b217
testing: Migrated p2pnat/medsrv-psk scenario to vici
2021-03-30 22:12:00 +02:00
Andreas Steffen
03e1272ff2
testing: Migrated p2pnat/behind-same-nat scenario to vici
2021-03-30 22:12:00 +02:00
Andreas Steffen
68154033bb
testing: Store mars credentials in the swanctl directory
2021-03-30 22:12:00 +02:00
Andreas Steffen
2cbf7da51a
testing: Migrated redirect-active scenario to vici
2021-03-30 22:12:00 +02:00
Andreas Steffen
511b860916
testing: Migrated ha/both-active scenario to vici
2021-03-30 18:57:49 +02:00
Andreas Steffen
5c22e94f0f
testing: Migrated ha/active-passive scenario to vici
2021-03-30 18:57:49 +02:00
Andreas Steffen
737f7fce51
testing: Switched PTS measurements to /usr/sbin
...
Due to Debian 10 linking /bin to /usr/bin which drastically
increased the number of files in /bin, the PTS measurement
was switched to /usr/sbin with a lesser number of files.
2021-03-23 10:54:48 +01:00
Andreas Steffen
f412c97648
wolfssl: Support SHAKE_256
2021-03-20 11:19:12 +01:00
Andreas Steffen
a91eb3eb96
wolfssl: Support SHA3
2021-03-20 11:15:42 +01:00
Andreas Steffen
b57215ba2b
wolfssl: Support AES_ECB
2021-03-20 11:15:42 +01:00
Andreas Steffen
bd323ae6c8
openssl: Migrate from deprecated EC_POINT_[set|get]_affine_coordinates_GFp() functions
2021-03-19 08:50:27 +01:00
Andreas Steffen
6aef079f59
testing: Bump guest kernel to Linux 5.11
2021-03-07 14:39:44 +01:00
Andreas Steffen
87ba3a424d
Version bump to 5.9.2
2021-02-26 11:30:13 +01:00
Andreas Steffen
356f87355b
Version bump to 5.9.2rc2
2021-02-21 10:40:34 +01:00
Andreas Steffen
20c47af319
testing: Use TLS 1.3 in TNC PT-TLS tests
2021-02-21 09:48:34 +01:00
Andreas Steffen
9f55246018
testing: Added mgf1 plugin to load statement
2021-02-19 17:41:44 +01:00
Andreas Steffen
283b352cee
Merge branch 'tls-fixes'
2021-02-18 20:28:33 +01:00
Andreas Steffen
d08fa4bd0a
Version bump to 5.9.2rc1
2021-02-18 20:16:17 +01:00
Andreas Steffen
0d43b39931
testing: extended sleep time tkm/xfrmproxy tests
2021-02-12 09:44:00 +01:00
Andreas Steffen
ab58f95b12
Version bump to 5.9.2dr2
2021-02-12 08:17:54 +01:00
Andreas Steffen
fcb595f961
Version bump to 5.9.2dr1
2021-01-08 11:00:15 +01:00
Andreas Steffen
2889133cc0
imc_attestation: Fixed double free of tpm_version_info chunk
2021-01-08 11:00:15 +01:00
Andreas Steffen
08760dd927
tpm: Intel FW TPM always uses locality 0
2021-01-08 11:00:15 +01:00
Andreas Steffen
2ea1dac203
libimcv: Support symlinks introduced by usrmerge
...
Debian, Ubuntu, Fedora et. al. started to apply usrmerge to their
latest Linux distributions, i.e. /bin, /sbin, and /lib are now
symbolical links to /usr/bin, /usr/sbin, and /usr/lib, respectively.
Since executables and libraries are contained only once in Linux
packages (e.g. /bin/cp in coreutils but not /usr/bin/cp) this leads
to missing file measurments due to the symlinks when doing remote
attestation.
The new ita_attr_symlinks PA-TNC attribute fixes this problem by
collecting symbolic links pointing to directories on the client
platform.
2021-01-08 11:00:15 +01:00
Andreas Steffen
9b4a2322d6
libimcv: Evaluate IMA SHA-256 measurements
2021-01-08 11:00:15 +01:00
Andreas Steffen
f397fc02e9
configure: Fixed test for imv_swima
2020-12-24 13:08:49 +01:00
Andreas Steffen
0fc6767097
Version bump to 5.9.1
2020-11-10 20:45:13 +01:00