Andreas Steffen
35bc60cc68
Added support of EdDSA signatures
2016-12-14 11:15:47 +01:00
Tobias Brunner
f20b3f7b2c
openssl: BoringSSL doesn't provide curve data for ECC Brainpool curves
2016-12-10 12:27:47 +01:00
Tobias Brunner
5078f87a52
plugin-loader: Strip '!' from critical plugin names when setting paths
2016-11-18 12:21:49 +01:00
Martin Willi
bd0aa66e45
curve22519: Add a portable backend implemented in plain C
2016-11-14 16:20:51 +01:00
Martin Willi
7f9bfacd5a
curve25519: Add a plugin providing Curve25519 DH using backend drivers
2016-11-14 16:20:51 +01:00
Martin Willi
1c26835a0a
test-vectors: Add a Curve25519 DH test vector
2016-11-14 16:20:51 +01:00
Andreas Steffen
cb8f436112
added XOF dependencies of bliss and ntru plugins
2016-10-18 16:28:43 +02:00
Tobias Brunner
8564535c23
newhope: Fix Doxygen group name
2016-10-14 18:41:25 +02:00
Tobias Brunner
955ce91652
Fixed some typos, courtesy of codespell
2016-10-14 18:09:09 +02:00
Tobias Brunner
d3beae1311
newhope: Properly release allocated arrays if RNG can't be created
2016-10-14 15:24:04 +02:00
Tobias Brunner
cee01fc9bf
revocation: Cache valid CRL also if certificate is revoked
2016-10-11 17:18:22 +02:00
Tobias Brunner
c72c6e9225
openssl: Fix AES-GCM with BoringSSL
...
BoringSSL only supports a limited list of (hard-coded) algorithms via
EVP_get_cipherbyname(), which does not include AES-GCM. While BoringSSL
deprecated these functions they are also supported by OpenSSL (in BoringSSL
a completely new interface for AEADs was added, which OpenSSL currently does
not support).
2016-10-11 15:29:14 +02:00
Yannick CANN
5f97b73554
ldap: Fix crash in case of empty LDAP response for CRL fetch
...
In case of an empty LDAP result during a CRL fetch (for example, due to
a wrong filter attribute in the LDAP URI, or invalid LDAP configuration),
the call to ldap_result2error() with NULL value for "entry" lead to
a crash.
Closes strongswan/strongswan#52 .
2016-10-06 18:08:51 +02:00
Tobias Brunner
4a6f97d00b
openssl: Add a generic private key loader
2016-10-05 11:32:52 +02:00
Tobias Brunner
437610ace5
pkcs1: Support building of KEY_ANY private keys
...
We try to detect the type of key by parsing the basic structure of the
passed ASN.1 blob.
2016-10-05 11:32:52 +02:00
Raphael Geissert
9a7049635e
pkcs11: Look for the CKA_ID of the cert if it doesn't match the subjectKeyId
...
charon-nm fails to find the private key when its CKA_ID doesn't match the
subjectKeyIdentifier of the X.509 certificate. In such cases, the private
key builder now falls back to enumerating all the certificates, looking for
one that matches the supplied subjectKeyIdentifier. It then uses the CKA_ID
of that certificate to find the corresponding private key.
It effectively means that PKCS#11 tokens where the only identifier to relate
the certificate, the public key, and the private key is the CKA_ID are now
supported by charon-nm.
Fixes #490 .
2016-10-04 12:09:04 +02:00
Andreas Steffen
40f2589abf
gmp: Support of SHA-3 RSA signatures
2016-09-22 17:34:31 +02:00
Andreas Steffen
c54d1ef12c
bliss sampler unit-test: Fixed enumeration type
2016-09-22 10:46:39 +02:00
Andreas Steffen
a3a8b4acae
bliss: bliss_sampler expects XOF type
2016-09-22 09:23:47 +02:00
Andreas Steffen
188b190a70
mgf1: Refactored MGF1 as an XOF
2016-09-21 06:40:52 +02:00
Tobias Brunner
15cbe526ac
unbound: Avoid unnecessary cloning of RR list that caused a memory leak
2016-09-20 15:36:14 +02:00
Tobias Brunner
3a25032c16
unbound: Fix memory leak
2016-09-20 15:36:14 +02:00
Tobias Brunner
fe4ed4578f
padlock: Use builtin bswap32() to fix compilation on FreeBSD
...
Fixes #591 .
2016-08-31 10:52:55 +02:00
Andreas Steffen
3bca51e430
unit-tests: Removed unused variable
2016-08-11 17:01:33 +02:00
Andreas Steffen
1342bd3386
unit-tests: Created newhope unit-tests
2016-08-10 14:22:00 +02:00
Andreas Steffen
393688aea0
Created newhope plugin implementing the New Hope key exchange algorithm
2016-08-10 14:22:00 +02:00
Andreas Steffen
1fddb0b92e
xof: Added ChaCha20 stream as XOF
2016-08-06 12:09:05 +02:00
Andreas Steffen
b8070e2c85
integrity-test: Added ntru_param_sets to read-only segment
2016-07-29 12:36:15 +02:00
Andreas Steffen
17e4ca6ac9
integrity-test: Added bliss_param_sets to read-only segment
2016-07-29 12:36:15 +02:00
Andreas Steffen
7256c68da0
integrity-test: check code and ro segments of libnttfft
2016-07-29 12:36:15 +02:00
Andreas Steffen
d305f251a5
Created libnttfft
...
This makes Number Theoretic Transforms (NTT) based on the efficient
Fast-Fourier-Transform (FFT) available to multiple plugins.
2016-07-29 12:36:15 +02:00
Andreas Steffen
65f2ecb86d
Share twiddle factors table between 512 and 1024 point FFT
2016-07-29 12:36:14 +02:00
Andreas Steffen
68075fb7a7
Implemented FFT with n = 1024 and q = 11289 using Montgomery arithmetic
2016-07-29 12:36:14 +02:00
Andreas Steffen
a7d626118f
bliss: Implemented FFT with fast Montgomery arithmetic
2016-07-29 12:36:14 +02:00
Andreas Steffen
5ff88c9622
xof: Implemented SHAKE128 and SHAKE256 Extended Output Functions
2016-07-29 12:36:14 +02:00
Andreas Steffen
04208ac5d4
xof: Defined Extended Output Functions
2016-07-29 12:36:14 +02:00
Andreas Steffen
5ce749bcfc
unit-tests: Decreased loop count of FFT speed test to 10'000
2016-07-22 21:27:42 +02:00
Andreas Steffen
10ebb3c914
unit-tests: Added bliss_fft_speed test
2016-07-22 11:58:10 +02:00
Tobias Brunner
1fafc56b95
Fixed some typos, courtesy of codespell
2016-07-04 12:18:51 +02:00
Tobias Brunner
7c81219bb8
plugin-loader: Allow selective modification of the default plugin list
...
This change allows selectively modifying the default plugin list by setting
the `load` setting of individual plugins (e.g. to disable them or to change
their priority) without enabling charon.load_modular and having to configure
a section and a load statement for every plugin.
2016-06-29 11:16:48 +02:00
Tobias Brunner
fedec33f5a
openssl: Update GCM/crypter API to OpenSSL 1.1.0
2016-06-29 11:09:38 +02:00
Tobias Brunner
97b1a27f43
openssl: Update HMAC API to OpenSSL 1.1.0
2016-06-29 11:09:38 +02:00
Tobias Brunner
cd08eb84cb
openssl: Don't use deprecated RAND_pseudo_bytes()
2016-06-29 11:09:38 +02:00
Tobias Brunner
985d7b1c67
openssl: Update PKCS#12 API to OpenSSL 1.1.0
2016-06-29 11:09:37 +02:00
Tobias Brunner
a9f388e368
openssl: Update PKCS#7 API to OpenSSL 1.1.0
2016-06-29 11:09:37 +02:00
Tobias Brunner
989ba4b6cd
openssl: Update CRL API to OpenSSL 1.1.0
...
There is currently no way to compare the outer and inner algorithms
encoded in a parsed CRL. X509_CRL_verify() does not seem to check that
either, though (unlike X509_verify()).
2016-06-29 11:09:37 +02:00
Tobias Brunner
08d7e1f190
openssl: Update x509 API to OpenSSL 1.1.0
2016-06-29 11:09:37 +02:00
Tobias Brunner
6688f7986e
openssl: Update ECDSA API to OpenSSL 1.1.0
2016-06-29 11:09:37 +02:00
Tobias Brunner
3fb2c8edb7
openssl: Update RSA API to OpenSSL 1.1.0
2016-06-29 11:09:37 +02:00
Tobias Brunner
375a5ed240
openssl: Make some utilities take const BIGNUM pointers
2016-06-29 11:09:37 +02:00