Martin Willi
|
36eafea232
|
Use the AAA Identity for EAP authentication, if given
|
2010-08-31 18:10:23 +02:00 |
|
Martin Willi
|
64d7b0733f
|
Added support for the ipsec.conf aaa_identity keyword
|
2010-08-31 17:52:52 +02:00 |
|
Martin Willi
|
81137552e5
|
Added an AAA identity authentication config option
|
2010-08-31 17:26:20 +02:00 |
|
Martin Willi
|
f9fc5f2045
|
Added strongswan.conf options for EAP-TLS/TTLS fragment size
|
2010-08-31 16:17:01 +02:00 |
|
Martin Willi
|
743f94067e
|
Support processing of partial TLS record headers
|
2010-08-31 16:17:01 +02:00 |
|
Martin Willi
|
1cf8c5f746
|
Migrated EAP-TTLS to the generic TLS helper
|
2010-08-31 16:17:01 +02:00 |
|
Martin Willi
|
be751012c3
|
Migrated EAP-TLS to the generic TLS helper
|
2010-08-31 16:17:01 +02:00 |
|
Martin Willi
|
877c910f04
|
Implemented a generic TLS EAP helper to implement EAP-TLS, TTLS and other variants
|
2010-08-31 16:16:58 +02:00 |
|
Martin Willi
|
ecd98efa9d
|
Support output fragmentation of TLS records
|
2010-08-31 15:54:37 +02:00 |
|
Martin Willi
|
f13a03add0
|
Moved EAP type/code definitions to a seprate header file in libstrongswan
|
2010-08-31 15:35:29 +02:00 |
|
Martin Willi
|
ce1af73907
|
Implemented buffering of partial records in TLS stack
|
2010-08-31 15:35:29 +02:00 |
|
Martin Willi
|
d169aab35e
|
Log TLS handshake subtypes as handshakes
|
2010-08-31 15:35:29 +02:00 |
|
Martin Willi
|
fd0bde9a60
|
Added a TLS debug level option, use debugging hook
|
2010-08-31 15:35:29 +02:00 |
|
Martin Willi
|
4332b5af89
|
Do not strdup() zero length strings in identification_create_from_string()
|
2010-08-31 15:34:45 +02:00 |
|
Martin Willi
|
2291754ddf
|
Unwrap crlNumber INTEGER in openssl CRL parsing
|
2010-08-30 11:23:46 +02:00 |
|
Martin Willi
|
21f80e9dbc
|
Added crl support to pki --print
|
2010-08-30 11:23:45 +02:00 |
|
Martin Willi
|
45684ee65c
|
Fixed pluto smartcard support after introducing encryption schemes
|
2010-08-30 10:14:45 +02:00 |
|
Martin Willi
|
2bf0e74c38
|
Prefer AES/Camellia suites over 3DES/NULL encryption
|
2010-08-25 18:30:09 +02:00 |
|
Martin Willi
|
a596006e3f
|
Send TLS alerts for errors in TLS handshake building
|
2010-08-25 18:24:27 +02:00 |
|
Martin Willi
|
ee88ddd6aa
|
Refactored fragment building, use correct TLS content type for non-first fragments
|
2010-08-25 18:04:59 +02:00 |
|
Martin Willi
|
dfde6570c7
|
Update delete_payload length when adding SPIs
|
2010-08-25 17:04:25 +02:00 |
|
Martin Willi
|
5299719569
|
Migrated delete_payload to INIT/METHOD macros, replaced iterator
|
2010-08-25 17:03:00 +02:00 |
|
Martin Willi
|
e5c6ebb697
|
Use different return values in payload decryption to distinguish between integrity and syntax errors
|
2010-08-25 15:29:53 +02:00 |
|
Martin Willi
|
f1a74a3cab
|
Implemented a TLS utility to test on any TLS secured TCP connection
|
2010-08-25 12:57:13 +02:00 |
|
Martin Willi
|
17102f7b58
|
Added a simple high level TLS wrapper for sockets
|
2010-08-25 12:52:53 +02:00 |
|
Martin Willi
|
bd23b9086e
|
Initialize output chunk before appending data to it
|
2010-08-25 12:43:21 +02:00 |
|
Martin Willi
|
3dd06bd4ed
|
Added private key support to in-memory credential set
|
2010-08-25 10:28:23 +02:00 |
|
Martin Willi
|
72c6335de9
|
Added certificate support to in-memory credential set
|
2010-08-25 10:28:22 +02:00 |
|
Martin Willi
|
8427c78611
|
Added a ike_name logger option to prefix the IKE_SA name on each line
|
2010-08-25 09:55:37 +02:00 |
|
Martin Willi
|
69e8bb2e8d
|
Pass NULL peer identity to omit TLS peer authentication, added eap-ttls.request_peer_auth option
|
2010-08-24 11:34:43 +02:00 |
|
Martin Willi
|
a2c1235969
|
Skip the close notify if application layer completes successfully
|
2010-08-24 10:30:24 +02:00 |
|
Martin Willi
|
bda7d9d940
|
Added generic TLS purposes
|
2010-08-24 08:45:49 +02:00 |
|
Martin Willi
|
f55f9c4e1e
|
Client sends empty EAP-TTLS packet on fatal alerts to properly shut down TLS
|
2010-08-24 08:45:49 +02:00 |
|
Martin Willi
|
c5142f110e
|
Check if the application layer has completed successfully
|
2010-08-24 08:45:49 +02:00 |
|
Martin Willi
|
1475800080
|
Moved TLS record parsing/generation to tls.c
|
2010-08-24 08:45:49 +02:00 |
|
Martin Willi
|
c310881a11
|
Added a TLS purpose for EAP-TTLS with client authentication
|
2010-08-23 15:13:48 +02:00 |
|
Martin Willi
|
5ff8c62707
|
EAP-TLS clients send an empty packet on failure to properly shut down a TLS session
|
2010-08-23 15:13:41 +02:00 |
|
Martin Willi
|
e6f3ef1330
|
Implemented TLS Alert handling
|
2010-08-23 15:13:37 +02:00 |
|
Martin Willi
|
908e752201
|
Rebuild library.lo after changing ./configure options
|
2010-08-23 12:01:48 +02:00 |
|
Martin Willi
|
e0fcf43cf8
|
Build a trustchain even if no trust anchor is given
|
2010-08-23 12:01:43 +02:00 |
|
Martin Willi
|
c49475dae1
|
Accept encryption payloads with no wrapped payloads
|
2010-08-23 11:30:36 +02:00 |
|
Martin Willi
|
4f60466a01
|
Fall back to shifting with 32-bit words if 64-bit byte order conversion function missing
|
2010-08-23 10:10:36 +02:00 |
|
Martin Willi
|
835ec23aff
|
Use enum mappings to resolve debug group
|
2010-08-23 09:47:04 +02:00 |
|
Martin Willi
|
f9efac2ba3
|
Implemented generic enum name to enum value mapping
|
2010-08-23 09:47:03 +02:00 |
|
Martin Willi
|
f154e30431
|
Verify negotiated TLS version
|
2010-08-23 09:47:03 +02:00 |
|
Martin Willi
|
3c19b3461f
|
Introducing a dedicated debug message group for libtls
|
2010-08-23 09:47:03 +02:00 |
|
Martin Willi
|
0bcef5fe7a
|
Streamlined TLS debugging output
|
2010-08-23 09:45:33 +02:00 |
|
Martin Willi
|
96b2fbcc2c
|
Introducing simple purposes for the TLS stack, switches various options
|
2010-08-20 15:09:08 +02:00 |
|
Martin Willi
|
6291fbedcb
|
Fixed compiler warning
|
2010-08-20 15:09:08 +02:00 |
|
Martin Willi
|
cb3f0c9b31
|
Register missing SHA256 authenticator with no truncation, as used by TLS
|
2010-08-20 12:11:21 +02:00 |
|
Martin Willi
|
6e413d9ce9
|
Added more TLS cipher suites we already support
|
2010-08-20 12:11:21 +02:00 |
|
Martin Willi
|
a2bfc45bfd
|
Build TLS cipher suite list in a generic fashion
|
2010-08-20 12:11:21 +02:00 |
|
Martin Willi
|
2e64455ee1
|
Fixed crypter keymat derivation bug
|
2010-08-19 19:28:08 +02:00 |
|
Martin Willi
|
44582075e0
|
Added ctr, ccm, gcm plugin NEWS
|
2010-08-19 19:09:01 +02:00 |
|
Martin Willi
|
23cf96773a
|
Improve GCM performance by factor 2-3 by shifting full 32/64 bit words
|
2010-08-19 19:08:57 +02:00 |
|
Martin Willi
|
1a64981048
|
Implemented a gcm plugin providing GCM mode based on CBC crypters
|
2010-08-19 19:05:15 +02:00 |
|
Martin Willi
|
026355af42
|
Added AES-GCM test vectors
|
2010-08-19 19:05:15 +02:00 |
|
Martin Willi
|
37e52c3fbf
|
Added a crypto transform stress test for profiling
|
2010-08-19 19:05:14 +02:00 |
|
Martin Willi
|
9d3e174a1e
|
Give a benchmark point for each operation to compare different transforms
|
2010-08-19 19:05:14 +02:00 |
|
Martin Willi
|
80a93a1335
|
Implemented a ccm plugin providing CCM mode based on CBC crypters
|
2010-08-19 19:05:14 +02:00 |
|
Martin Willi
|
7ba89ccd7f
|
Added helper macros to define portable bitfields with gcc
|
2010-08-19 19:05:14 +02:00 |
|
Martin Willi
|
f9277ac426
|
Added AES-CCM test vectors
|
2010-08-19 19:05:14 +02:00 |
|
Martin Willi
|
8ca9e255d8
|
Added support for AEAD test vectors to test-vectors plugin
|
2010-08-19 19:05:13 +02:00 |
|
Martin Willi
|
08a5a708fc
|
Include CCM/GCM algorithms in IKEv2 proposals, if supported
|
2010-08-19 19:05:05 +02:00 |
|
Martin Willi
|
3f6a2d3343
|
Added proposal strings for Camellia CCM algorithm identifiers
|
2010-08-19 19:02:34 +02:00 |
|
Martin Willi
|
84eb3aa456
|
Implemented IKEv2 keymat derivation for AEAD algorithms
|
2010-08-19 19:02:34 +02:00 |
|
Martin Willi
|
9d49f79f55
|
List registered AEAD algorithms in listalgs
|
2010-08-19 19:02:34 +02:00 |
|
Martin Willi
|
77b55e8a96
|
Added support for AEAD algorithms to crypto factory
|
2010-08-19 19:02:34 +02:00 |
|
Martin Willi
|
e09a87d652
|
Added AEAD support to crypto tester
|
2010-08-19 19:02:33 +02:00 |
|
Martin Willi
|
b519071299
|
Use AEAD wrapper for encryption payload encryption/decryption
|
2010-08-19 19:02:33 +02:00 |
|
Martin Willi
|
7fc4b0814f
|
Make function to test if an encryption algorithm is an AEAD alg public
|
2010-08-19 19:02:16 +02:00 |
|
Martin Willi
|
df8d0d8703
|
Implemented an AEAD wrapper for traditional crypter/signer transforms
|
2010-08-19 12:35:54 +02:00 |
|
Martin Willi
|
92a4540aca
|
Migrated generator_t to INIT/METHOD macros
|
2010-08-19 12:35:53 +02:00 |
|
Martin Willi
|
0cca7427c7
|
Migrated encryption_payload to INIT/METHOD macros
|
2010-08-19 12:35:53 +02:00 |
|
Martin Willi
|
7c9d8e1476
|
Migrated message_t to INIT/METHOD macros
|
2010-08-19 12:35:53 +02:00 |
|
Martin Willi
|
5555b900b2
|
Migrated keymat to INIT/METHOD macros
|
2010-08-19 12:35:53 +02:00 |
|
Martin Willi
|
6c620d5ee0
|
Test append mode for signers verify_signature
|
2010-08-19 12:35:53 +02:00 |
|
Martin Willi
|
ba31fe1fd6
|
Use a seperate section for each nested struct member in INIT macro
|
2010-08-18 12:15:03 +02:00 |
|
Martin Willi
|
a369a5ece9
|
Do not free registered algorithms, plugins are responsible for unregistering
|
2010-08-16 17:06:28 +02:00 |
|
Martin Willi
|
1b0eff58e0
|
Implemented algorithm benchmarking during registration
|
2010-08-16 17:06:28 +02:00 |
|
Martin Willi
|
e2c3b4820b
|
Variable key length crypters use default key length if zero given
|
2010-08-16 17:06:27 +02:00 |
|
Martin Willi
|
806ec8b1d6
|
Properly handle zero length in chunk_alloc[a]/chunk_clone[a]
|
2010-08-16 17:06:27 +02:00 |
|
Martin Willi
|
e8bf9d6e16
|
Migrated crypto_factory to INIT/METHOD macros
|
2010-08-16 17:06:27 +02:00 |
|
Martin Willi
|
aed2bf0bd9
|
Migrated crypto_tester to INIT/METHOD macros
|
2010-08-16 17:06:27 +02:00 |
|
Martin Willi
|
714d0bfd37
|
Only include certificates with CA flag in TLS cert request
|
2010-08-16 09:20:19 +02:00 |
|
Martin Willi
|
272f0e1ae4
|
Added a counter mode wrapper plugin operating on existing CBC crypters
|
2010-08-13 19:39:59 +02:00 |
|
Martin Willi
|
c03b0d7e6b
|
Added support for Camellia cipher to xcbc
|
2010-08-13 17:11:54 +02:00 |
|
Martin Willi
|
c7776e0aa8
|
Support Camellia XCBC algorithms in proposal
|
2010-08-13 17:11:54 +02:00 |
|
Martin Willi
|
5a2dbd5c37
|
Added private Camellia XCBC identifiers for PRFs and signers
|
2010-08-13 17:11:53 +02:00 |
|
Martin Willi
|
a57b63c940
|
Added Camellia XCBC test vectors
|
2010-08-13 17:11:53 +02:00 |
|
Martin Willi
|
42cbe87fc7
|
Implemented AES/Camellia counter mode in gcrypt
|
2010-08-13 17:11:53 +02:00 |
|
Martin Willi
|
3b77c27a5b
|
Added Camellia, AES-CTR to default IKE proposal, if supported
|
2010-08-13 17:11:53 +02:00 |
|
Martin Willi
|
1ee98dbb4a
|
Added Camellia CTR mode proposal keywords
|
2010-08-13 17:11:53 +02:00 |
|
Martin Willi
|
3102d8669d
|
Use IV length of a crypter instead of block size for IV calculations
|
2010-08-13 17:11:53 +02:00 |
|
Martin Willi
|
f7c04c5b37
|
Add dedicated getter for the IV size to the crypter_t interface
|
2010-08-13 17:11:53 +02:00 |
|
Martin Willi
|
7156b951f5
|
Migrated xcbc plugin to INIT/METHOD macros
|
2010-08-13 17:11:53 +02:00 |
|
Martin Willi
|
5ab7d9c296
|
Migrated hmac plugin to INIT/METHOD macros
|
2010-08-13 17:11:53 +02:00 |
|
Martin Willi
|
af403cafa1
|
Migrated des plugin to INIT/METHOD macros
|
2010-08-13 17:11:53 +02:00 |
|
Martin Willi
|
00c7e9af17
|
Migrated blowfish plugin to INIT/METHOD macros
|
2010-08-13 17:11:53 +02:00 |
|
Martin Willi
|
1fff2afe57
|
Migrated the aes plugin to INIT/METHOD macros
|
2010-08-13 17:11:53 +02:00 |
|