Tobias Brunner
3101120c75
tls-crypto: Enumerate x25519/448 and rename constant for consistency
2021-02-12 11:45:44 +01:00
Tobias Brunner
281766c5e6
tls-crypto: Filter TLS cipher suites by min/max version
...
There is no point proposing legacy (or future) cipher suites depending on
the proposed TLS versions. It was actually possible to negotiate and use
cipher suites only defined for TLS 1.2 with earlier TLS versions.
2021-02-12 11:45:44 +01:00
bytinbit and ryru
7a2b02667c
libtls: Implement TLS 1.3 handshake on client-side
...
The code is a minimal handshake with the HelloRetryRequest message
implementation missing.
Can be tested with an OpenSSL server running TLS 1.3. The server must
be at least version 1.1.1 (September 2018).
Co-authored-by: ryru <[email protected] >
2021-02-12 11:45:44 +01:00
Martin Willi
ac5717c9e9
tls: Export a function to list supported TLS cipher suites
2014-04-01 14:28:55 +02:00
Martin Willi
9020f7d0b9
Add a return value to tls_crypto_t.derive_secrets()
2012-07-16 14:53:33 +02:00
Tobias Brunner
b96eb46d5c
Some Doxygen fixes.
2012-02-07 11:20:46 +01:00
Martin Willi
6a5c86b7ad
Implemented TLS session resumption both as client and as server
2011-12-31 13:14:49 +01:00
Andreas Steffen
7e432eff6b
renamed tls_reader|writer to bio_* and moved to libstrongswan
2011-05-31 15:46:51 +02:00
Martin Willi
02281c87a4
Added TLS specific EC point formats
2010-09-06 18:42:43 +02:00
Martin Willi
ec7d4e70d3
Renamed ecp_format to ansi_format, as point formats in TLS use different identifiers
2010-09-06 18:37:24 +02:00
Martin Willi
e6cce7ff0d
Prepend point format to ECDH public key
2010-09-06 15:37:51 +02:00
Martin Willi
3f7bb88ba3
Use a dynamic curve enumerator to list/convert TLS named curves
2010-09-03 17:24:23 +02:00
Martin Willi
4cdade5aae
Select private key based on received cipher suites
2010-09-03 14:54:43 +02:00
Martin Willi
37a59a8fbf
Support for EC curve Hello extension, EC curve fallback
2010-09-03 14:54:43 +02:00
Martin Willi
691ca54db5
Added TLS EC curve type and name identifiers
2010-09-03 14:54:43 +02:00
Martin Willi
35d9c15d5e
Store a MODP group we use for each TLS suite
2010-09-02 19:33:08 +02:00
Martin Willi
d29a82a9d4
Added generic TLS data sign/verify, hash/sig algorithm construction
2010-09-02 19:33:08 +02:00
Martin Willi
dbb7c0306c
Support different hash/sig algorithms in handshake signing, including ECDSA
2010-09-02 13:07:25 +02:00
Martin Willi
99dcaea9bd
Added TLS ClientCertificateType identifiers
2010-09-02 13:07:24 +02:00
Martin Willi
9dd2ca924e
Added TLS specific Hash and Signature Algorithm identifiers
2010-09-02 13:07:24 +02:00
Martin Willi
96b2fbcc2c
Introducing simple purposes for the TLS stack, switches various options
2010-08-20 15:09:08 +02:00
Andreas Steffen
a6444fcdd4
EAP-TLS and EAP-TTLS use different constant MSK PRF label
2010-08-07 11:26:04 +02:00
Martin Willi
37d2d7e158
Whitespace cleanups
2010-08-05 13:58:49 +02:00
Andreas Steffen
4657b3a42a
log selected TLS version and cipher suite
2010-08-05 01:21:59 +02:00
Martin Willi
0f82a47063
Moved TLS stack to its own library
2010-08-03 15:39:26 +02:00