Martin Willi
|
45d66f5af6
|
some simplifications to trusted_enumerator_t
|
2008-04-01 10:56:08 +00:00 |
|
Martin Willi
|
1bb85edffe
|
checking pretrusted but bad certificates only once
|
2008-04-01 10:43:44 +00:00 |
|
Andreas Steffen
|
c096472605
|
minor changes in debug output
|
2008-03-31 21:59:32 +00:00 |
|
Andreas Steffen
|
a92ea0ccb3
|
output error message if maximum ca path length is reached
|
2008-03-31 20:42:57 +00:00 |
|
Andreas Steffen
|
58a05045cc
|
utc argument in %#T was missing
|
2008-03-31 14:36:00 +00:00 |
|
Martin Willi
|
0f7ef3d2a0
|
received certificates have least priority
fixed manager unlocking
|
2008-03-31 08:43:18 +00:00 |
|
Martin Willi
|
d69b267d58
|
fixed refcounting in certificate trustchain validation
|
2008-03-31 07:16:12 +00:00 |
|
Martin Willi
|
35b6e2301f
|
fixed crash if crl fetching fails
|
2008-03-28 12:00:51 +00:00 |
|
Martin Willi
|
d55fa9aff7
|
reentrant save cert_cache
|
2008-03-28 08:38:51 +00:00 |
|
Martin Willi
|
ac1fefc2de
|
caching of CRLs
|
2008-03-28 08:14:47 +00:00 |
|
Martin Willi
|
d20e5c6ab5
|
replaced get_public() by create_public_enumerator() to try multiple public keys for signature verification
|
2008-03-27 19:07:23 +00:00 |
|
Martin Willi
|
0d30ba3343
|
use trusted self-signed root CA certificates as trust anchor only
|
2008-03-27 13:38:02 +00:00 |
|
Martin Willi
|
f957f7dfb3
|
implemented cert cache flushing, ipsec purgeocsp
|
2008-03-27 06:37:29 +00:00 |
|
Martin Willi
|
7b88a983d8
|
caching of ocsp responses (experimental), no crl caching yet
|
2008-03-26 15:21:50 +00:00 |
|
Martin Willi
|
e37f7715bf
|
fixed rightca= constraint checking
implemented rightca= for intermediate CAs we do not have the certificate at config load
|
2008-03-26 12:23:46 +00:00 |
|
Martin Willi
|
2d84da89b9
|
fixed auth_info_t.equals()
|
2008-03-26 10:58:19 +00:00 |
|
Martin Willi
|
3c7e72f5b0
|
added equals() method to peer_cfg, ike_cfg, proposals, auth_info
allows easier merging of ipsec.conf connections
replaced some iterators through enumerators
made proposals algorithm_t private using enumerator
|
2008-03-26 10:06:45 +00:00 |
|
Andreas Steffen
|
36617c1ad5
|
shortened debug output
|
2008-03-21 20:36:19 +00:00 |
|
Andreas Steffen
|
02fd225ea5
|
detect trusted self-signed before trust chain verification
|
2008-03-21 19:10:55 +00:00 |
|
Andreas Steffen
|
112482d3f4
|
optimized debug output of credential_manager.c
|
2008-03-21 09:28:25 +00:00 |
|
Martin Willi
|
dfd5cdcb88
|
cert_cache_t caches subject-issuer relations and subject certificates
ocsp/crl do not benefit yet due missing lookup function
|
2008-03-20 14:31:36 +00:00 |
|
Martin Willi
|
fe8f7626d1
|
fallback to random end entity certificate if trustchain building fails
|
2008-03-20 13:14:55 +00:00 |
|
Martin Willi
|
36524c4844
|
added support for certificate requests for not yet known CAs
|
2008-03-20 10:09:56 +00:00 |
|
Martin Willi
|
9be0dc922e
|
fixed verification of preinstalled certificates
|
2008-03-20 09:30:02 +00:00 |
|
Martin Willi
|
44ab7c85d7
|
more trustchain verification improvements
should fix crl-revoked and two-certs scenarios
|
2008-03-20 09:27:57 +00:00 |
|
Martin Willi
|
48acfe98ae
|
refactored trustchain verification, this should fix #33
moved auth_info/ocsp_response credset wrapper to separate files
|
2008-03-19 17:54:54 +00:00 |
|
Andreas Steffen
|
84d8ff64cd
|
increased debug level in trust chain verification for auditing purposes
|
2008-03-19 17:04:09 +00:00 |
|
Andreas Steffen
|
c912c3d382
|
log nextUpdate of crls and ocsp responses
|
2008-03-19 13:11:29 +00:00 |
|
Andreas Steffen
|
2590faa330
|
fixed stupid bug in fetch_ocsp()
|
2008-03-19 12:36:15 +00:00 |
|
Andreas Steffen
|
ae8715f956
|
attempt to achieve consistent debugging output
|
2008-03-19 12:06:38 +00:00 |
|
Martin Willi
|
081ae2eb61
|
fixed CRL check return value on revoked certificates
fixed possible refcounting bugs
generic return_null() implementation
|
2008-03-19 09:44:47 +00:00 |
|
Martin Willi
|
a40708e511
|
fixed compiler warning
|
2008-03-18 14:06:11 +00:00 |
|
Andreas Steffen
|
8d49b51f8b
|
made is_newer() a certificate_t method
|
2008-03-18 10:36:08 +00:00 |
|
Martin Willi
|
9c410a8806
|
refactored buggy trustchain building, fixed refcount bug
|
2008-03-14 15:04:16 +00:00 |
|
Martin Willi
|
552cc11b1f
|
merged the modularization branch (credentials) back to trunk
|
2008-03-13 14:14:44 +00:00 |
|