Andreas Steffen
626b2e85f0
testing: Update AAA certificate on Freeradius as well
2015-08-05 10:01:21 +02:00
Andreas Steffen
9b1eaf083f
testing: Updated expired AAA server certificate
2015-08-04 21:50:01 +02:00
Andreas Steffen
e0d3a2a873
Version bump to 5.3.3dr3
2015-07-31 17:47:14 +02:00
Andreas Steffen
493ad293b7
testing: Adapted ha/both-active scenario to new jhash values
2015-07-31 14:43:40 +02:00
Andreas Steffen
41458e3362
Version bump to 5.3.3dr2
2015-07-28 14:28:58 +02:00
Andreas Steffen
fbcac07043
testing: Regenerated BLISS certificates due to oracle changes
2015-07-27 22:09:08 +02:00
Andreas Steffen
e57190c312
Use MGF1 with SHA-512 as BLISS random oracle
2015-07-27 22:09:08 +02:00
Andreas Steffen
2096d54198
Improved legibility of swanctl CRL listings
2015-07-22 17:46:15 +02:00
Andreas Steffen
aaeb524cea
testing: Updated loop ca certificates
2015-07-22 17:11:00 +02:00
Andreas Steffen
450c6e8dd9
testing: Added swanctl --list-authorities output to do-tests
2015-07-22 13:27:08 +02:00
Andreas Steffen
73cbd5c7f8
testing: Updated all swanctl scenarios and added some new ones
2015-07-22 13:27:08 +02:00
Andreas Steffen
db69295d2e
tests: Introduced IPV6 flag in tests.conf
2015-07-21 23:17:14 +02:00
Andreas Steffen
6b265c5e5c
tests: Introduced SWANCTL flag in test.conf
2015-07-21 23:17:14 +02:00
Andreas Steffen
3d9bfb607c
tests: fixed evaltest of swanctl/rw-cert scenario
2015-07-21 23:17:13 +02:00
Andreas Steffen
f335e2f848
tests: fixed description of swanctl ip-pool scenarios
2015-07-21 23:17:13 +02:00
Andreas Steffen
41aa7eb531
Version bump to 5.3.3dr1
2015-07-21 23:15:36 +02:00
Andreas Steffen
63d370387d
vici: Certification Authority support added.
...
CDP and OCSP URIs for a one or multiple certification authorities
can be added via the VICI interface. swanctl allows to read
definitions from a new authorities section.
2015-07-21 13:02:30 +02:00
Andreas Steffen
e194349148
vici: Compute rekey_bytes and rekey_packets if life_bytes and life_packets are defined
2015-07-20 21:34:09 +02:00
Andreas Steffen
3ea5d437fb
Version bump to 5.3.2
2015-06-08 09:56:34 +02:00
Andreas Steffen
9bb7307825
Fix timeattack script compilation under ARM
2015-06-05 12:09:38 +02:00
Andreas Steffen
bd60bcc3c2
Updated SWID attribute list
2015-06-02 06:51:41 +02:00
Andreas Steffen
f284c17890
Version bump to 5.3.1
2015-06-01 09:50:48 +02:00
Andreas Steffen
b8399a2edc
testing: use a decent PSK
2015-05-30 16:56:41 +02:00
Andreas Steffen
1047d44b57
testing: Added ha/active-passive scenario
2015-05-30 16:48:17 +02:00
Andreas Steffen
eb423ebb54
Added 5.3.1 caption to NEWS
2015-05-28 06:26:43 +02:00
Andreas Steffen
dedd0ad07c
Check for NULL installed packages enumerator
2015-05-24 11:15:36 +02:00
Andreas Steffen
5d5a74b077
Fixed os_info path in strongswan.conf
2015-05-24 11:13:51 +02:00
Andreas Steffen
d6b75c9563
List attribute request entries also during build
2015-05-24 09:17:29 +02:00
Andreas Steffen
e6952442f2
Exempt ignored PA-TNC attributes from error handling
2015-05-20 06:13:15 +02:00
Andreas Steffen
362e87e3e0
testing: Updated carol's certificate from research CA and dave's certificate from sales CA
2015-04-26 16:52:06 +02:00
Andreas Steffen
d04e47a9eb
testing: Wait for DH crypto tests to complete
2015-04-26 11:51:49 +02:00
Andreas Steffen
79b5a33c11
imv_policy_manager: Added capability to execute an allow or block shell command string
2015-04-26 10:55:24 +02:00
Andreas Steffen
ce354443bf
testing: Migration of KVM framework to Linux 4.x kernel
2015-04-25 18:05:00 +02:00
Andreas Steffen
17a2e00a31
Version bump to 5.3.1dr1
2015-04-24 11:35:42 +02:00
Andreas Steffen
c1c6506391
Fixed PB-TNC directionality debug message
2015-04-24 11:16:16 +02:00
Andreas Steffen
ff96400d13
Wipe auxiliary key store
2015-03-28 10:44:23 +01:00
Andreas Steffen
b07fb365ef
Added PB-TNC test options to strongswan.conf man page
2015-03-27 21:05:00 +01:00
Andreas Steffen
883c11caa0
Added tnc/tnccs-20-fail-init and tnc/tnccs-20-fail-resp scenarios
2015-03-27 20:56:44 +01:00
Andreas Steffen
ef5f96366e
Version bump to 5.3.0
2015-03-27 20:56:44 +01:00
Andreas Steffen
619e0b4235
Fixed PB-TNC error handling
2015-03-27 20:56:44 +01:00
Andreas Steffen
193e057509
Added configurations for 3.18 and 3.19 KMV guest kernels
2015-03-27 20:56:44 +01:00
Andreas Steffen
8b36323b8c
Fixed strongswan.conf man page entry of imc-attestation
2015-03-27 20:56:44 +01:00
Andreas Steffen
85aa509e84
Added tnc/tnccs-20-pt-tls scenario
2015-03-27 20:56:43 +01:00
Andreas Steffen
cf9befcba4
Version bump to 5.3.0rc1
2015-03-23 23:15:31 +01:00
Andreas Steffen
be04f90815
testing: added tnc/tnccs-20-mutual scenario
2015-03-23 23:01:13 +01:00
Andreas Steffen
7b4a96b2f7
Implemented PB-TNC mutual half-duplex protocol
2015-03-23 22:25:43 +01:00
Andreas Steffen
c6aed8aa21
Optionally announce PB-TNC mutual protocol capability
2015-03-23 22:25:43 +01:00
Andreas Steffen
80322d2cee
Split IF-TNCCS 2.0 protocol processing into separate TNC client and server handlers
2015-03-23 22:25:42 +01:00
Andreas Steffen
afc1b67344
Version bump to 5.3.0dr2
2015-03-16 17:15:58 +01:00
Andreas Steffen
08feb4548a
Replace kid by aik_id in ITA TBOOT functional component
2015-03-16 17:15:28 +01:00
Andreas Steffen
d35143bb8d
Fixed two BLISS key type identifier strings
2015-03-16 17:08:14 +01:00
Andreas Steffen
e035935068
Added availability of TNC AR IP address to IMVs to NEWS
2015-03-15 12:30:32 +01:00
Andreas Steffen
b6685211fb
Create TPM TBOOT Measurement group
2015-03-15 12:24:05 +01:00
Andreas Steffen
8fa9312f09
Updated products in imv database
2015-03-08 17:18:34 +01:00
Andreas Steffen
20f90d7160
attest: output trusted flag and device description
2015-03-08 17:17:11 +01:00
Andreas Steffen
00cd79b678
Make access requestor IP address available to TNC server
2015-03-08 17:17:11 +01:00
Andreas Steffen
3fcb59b62a
use SHA512 for moon's BLISS signature
2015-03-04 14:08:37 +01:00
Andreas Steffen
8f5521cbac
Fixed a memory leak in the attribute segmentation code
2015-02-27 15:13:26 +01:00
Andreas Steffen
ca316734e8
Updated Ubuntu 14.04 kernel version
2015-02-27 08:45:37 +01:00
Andreas Steffen
03b4d11ace
Fixed compiler warnings
2015-02-27 08:44:16 +01:00
Andreas Steffen
c6595222d6
Version bump to 5.3.0dr1
2015-02-26 09:12:54 +01:00
Andreas Steffen
27bd0fed93
Allow SHA256 and SHA384 data hash for BLISS signatures.
...
The default is SHA512 since this hash function is also
used for the c_indices random oracle.
2015-02-26 08:56:12 +01:00
Andreas Steffen
a7f0ab786d
unit-tests: Completed BLISS tests
2015-02-25 21:45:34 +01:00
Andreas Steffen
bfb708ea23
Check for null pointer before applying memwipe()
2015-02-25 21:45:34 +01:00
Andreas Steffen
c2aca9eed2
Implemented improved BLISS-B signature algorithm
2015-02-25 21:45:34 +01:00
Andreas Steffen
ecf605c6e1
trusted_enumerate requires an additional argument
2015-01-21 23:54:53 +01:00
Andreas Steffen
5028644943
Updated RFC3779 certificates
2014-12-28 12:53:16 +01:00
Andreas Steffen
e9878d72db
Version bump to 5.2.2
2014-12-23 15:40:02 +01:00
Andreas Steffen
ee3b135687
unit-tests: Adapted to coverity fixes
2014-12-23 15:40:01 +01:00
Andreas Steffen
6139c8e524
Fixed bad bit shift and sign extension errors
2014-12-23 15:40:01 +01:00
Andreas Steffen
ac0cb2d363
Updated BLISS CA certificate in ikev2/rw-ntru-bliss scenario
2014-12-12 13:55:03 +01:00
Andreas Steffen
9b4e411c50
Also initialize s_sign
2014-12-12 13:24:11 +01:00
Andreas Steffen
3e654a13ee
Cache only support fingerprint types
2014-12-12 13:08:40 +01:00
Andreas Steffen
8aaf36c6e3
Fix ambiguities and gcc compiler warning
2014-12-12 12:48:31 +01:00
Andreas Steffen
dce6f69546
Version bump to 5.2.2rc1
2014-12-12 12:00:20 +01:00
Andreas Steffen
c44f481ae0
Updated BLISS scenario keys and certificates to new format
2014-12-12 12:00:20 +01:00
Andreas Steffen
881cffb826
Use bitspender->get_bytes() method in ntru_trits
2014-12-12 12:00:20 +01:00
Andreas Steffen
83447555a6
Use Huffman code in BLISS signature
2014-12-12 12:00:20 +01:00
Andreas Steffen
9394e26426
Include design parameters in generated Huffman code files
2014-12-12 12:00:20 +01:00
Andreas Steffen
443346f56a
Pack private key arrays
2014-12-10 22:45:30 +01:00
Andreas Steffen
df5b2ade59
Automatic generation of optimized Huffman codes
2014-12-09 11:58:18 +01:00
Andreas Steffen
7442d2a208
unit-tests: added bliss_sampler test
2014-12-09 11:58:17 +01:00
Andreas Steffen
03f2a52e9c
Expanded bliss_bitpacker to 32 bits
2014-12-09 11:58:17 +01:00
Andreas Steffen
32d19652f1
Version bump to 5.2.2dr1
2014-11-29 15:00:10 +01:00
Andreas Steffen
9b01a061ec
Increased check size du to INITIAL_CONTACT notify
2014-11-29 14:57:41 +01:00
Andreas Steffen
c02ebf1ecd
Renewed expired certificates
2014-11-29 14:51:18 +01:00
Andreas Steffen
b6bb32e658
Implemented full BLISS support for IKEv2 public key authentication and the pki tool
2014-11-29 14:51:18 +01:00
Andreas Steffen
43d9247599
Created ikev2/rw-ntru-bliss scenario
2014-11-29 14:51:18 +01:00
Andreas Steffen
0d8a3f5d01
Applied bit packing to BLISS public key
2014-11-29 14:51:18 +01:00
Andreas Steffen
bf749fa1fb
Wipe BLISS private key memory
2014-11-29 14:51:17 +01:00
Andreas Steffen
b352ee4266
Created bliss_bitpacker class to encode BLISS signatures
2014-11-29 14:51:17 +01:00
Andreas Steffen
7143667bdd
Skip the unused bits field of the ASN.1 BIT STRING encoding
2014-11-29 14:51:17 +01:00
Andreas Steffen
5a50e364e6
Store NTT A of BLISS public key a
2014-11-29 14:51:17 +01:00
Andreas Steffen
3e1f6edc5a
unit-tests: created bliss_sign test suite
2014-11-29 14:51:17 +01:00
Andreas Steffen
e71813e56d
Finished BLISS signature generation
2014-11-29 14:51:17 +01:00
Andreas Steffen
edd72b6bb9
Implemented Gaussian rejection sampler
...
The bliss_sampler class uses the mgf1_bitspender as a
pseudo-random source.
2014-11-29 14:51:16 +01:00
Andreas Steffen
72bb7eec9c
Implemented get_byte() method for mgf1_bitspender class
...
The new get_byte() method returns a pseudo-random byte at a time.
Changed the get_bits() interface to the same interface as get_byte().
Updated the mgf1 unit-tests accordingly.
2014-11-29 14:51:16 +01:00
Andreas Steffen
5f7a9ea9c3
Added support for BLISS-III
2014-11-29 14:51:16 +01:00
Andreas Steffen
f673966b9f
Started implementing BLISS signature generation
2014-11-29 14:51:16 +01:00
Andreas Steffen
56009f2001
Store and parse BLISS private and public keys in DER and PEM format
...
Additionally generate SHA-1 fingerprints of raw BLISS subjectPublicKey
and subjectPublicKeyInfo objects.
Some basic functions used by the bliss_public_key class are shared
with the bliss_private_key class.
2014-11-29 14:51:16 +01:00