Tobias Brunner
9f91f0b3c8
openssl: Add support for SHAKE128/256
2020-03-10 14:12:34 +01:00
Tobias Brunner
112de13f1f
openssl: Add support for SHA-3
2020-03-10 14:12:34 +01:00
Tobias Brunner
61769fd1e3
openssl: Don't check signature if issuer doesn't match always
...
Doing this for the self-signed check also (i.e. if this and issuer are
the same) is particularly useful if the issuer uses a different key type.
Otherwise, we'd try to verify the signature with an incompatible key
that would result in a log message.
Fixes #3357 .
2020-03-06 11:12:07 +01:00
Josh Soref
b3ab7a48cc
Spelling fixes
...
* accumulating
* acquire
* alignment
* appropriate
* argument
* assign
* attribute
* authenticate
* authentication
* authenticator
* authority
* auxiliary
* brackets
* callback
* camellia
* can't
* cancelability
* certificate
* choinyambuu
* chunk
* collector
* collision
* communicating
* compares
* compatibility
* compressed
* confidentiality
* configuration
* connection
* consistency
* constraint
* construction
* constructor
* database
* decapsulated
* declaration
* decrypt
* derivative
* destination
* destroyed
* details
* devised
* dynamic
* ecapsulation
* encoded
* encoding
* encrypted
* enforcing
* enumerator
* establishment
* excluded
* exclusively
* exited
* expecting
* expire
* extension
* filter
* firewall
* foundation
* fulfillment
* gateways
* hashing
* hashtable
* heartbeats
* identifier
* identifiers
* identities
* identity
* implementers
* indicating
* initialize
* initiate
* initiation
* initiator
* inner
* instantiate
* legitimate
* libraries
* libstrongswan
* logger
* malloc
* manager
* manually
* measurement
* mechanism
* message
* network
* nonexistent
* object
* occurrence
* optional
* outgoing
* packages
* packets
* padding
* particular
* passphrase
* payload
* periodically
* policies
* possible
* previously
* priority
* proposal
* protocol
* provide
* provider
* pseudo
* pseudonym
* public
* qualifier
* quantum
* quintuplets
* reached
* reading
* recommendation to
* recommendation
* recursive
* reestablish
* referencing
* registered
* rekeying
* reliable
* replacing
* representing
* represents
* request
* request
* resolver
* result
* resulting
* resynchronization
* retriable
* revocation
* right
* rollback
* rule
* rules
* runtime
* scenario
* scheduled
* security
* segment
* service
* setting
* signature
* specific
* specified
* speed
* started
* steffen
* strongswan
* subjectaltname
* supported
* threadsafe
* traffic
* tremendously
* treshold
* unique
* uniqueness
* unknown
* until
* upper
* using
* validator
* verification
* version
* version
* warrior
Closes strongswan/strongswan#164 .
2020-02-11 18:23:07 +01:00
Tobias Brunner
baf29263d5
pem: Support parsing PEM-encoded Ed448 keys
2020-02-10 13:37:31 +01:00
Tobias Brunner
85a35fc99d
openssl: Support certificates with Ed25519/448 keys
2020-02-10 13:37:31 +01:00
Tobias Brunner
3361f81f1c
pkcs1: Support parsing Ed448 public keys
2020-02-10 13:37:31 +01:00
Tobias Brunner
0f141fb095
soup: Use soup_session_new() to avoid deprecation warning
...
There are a ton of libsoup/GLib-related "leaks" that we can't whitelist
and with leak detective active there is a delay that interestingly doesn't
happen with soup_session_sync_new(), so tests failed with a timeout (actually
they hung due to the lock in the fetcher manager).
On Travis, the curl plugin is used for the tests, so that's not an issue
there (and without LD the tests complete quickly and successfully).
2020-02-05 10:49:35 +01:00
Tobias Brunner
776433505b
x509: Replace problematic calls of chunk_from_chars() for keyUsage extension
...
As noted in 8ea13bbc5c newer compilers might optimize out the
assignment leading to invalid values in the keyUsage extension (as the
length was still set, the extension was encoded, just not with the
intended values).
Fixes #3249 .
2020-01-30 18:18:28 +01:00
Tobias Brunner
2cb4af6696
wolfssl: Use pkg-config to check for wolfSSL
...
The other checks trigger an automatic install of the old and incompatible
Ubuntu package on LGTM.
2020-01-30 17:12:05 +01:00
Tobias Brunner
1147973661
pkcs11: Avoid naming conflict with method parameter
2020-01-28 15:32:43 +01:00
Tobias Brunner
26f20cc258
aesni: Namespace include guard for AES-CMAC
...
Was the same as in the cmac plugin.
2020-01-28 15:32:43 +01:00
Tobias Brunner
90df054f14
plugin-constructors: Remove unused import for sys
2020-01-28 15:29:40 +01:00
Tobias Brunner
3bc0c9807a
sha3: Fix readLane() macro on big-endian platforms
2020-01-20 11:05:17 +01:00
Tobias Brunner
846dde91ae
wolfssl: Undef RSA_PSS_SALT_LEN_DEFAULT as wolfSSL 4.3.0 defines it as enum
2020-01-13 15:49:57 +01:00
Tobias Brunner
8d9a7fcae3
drbg: Fix Doxygen group in headers
2019-12-12 11:09:06 +01:00
Tobias Brunner
a669145086
Fixed some typos, courtesy of codespell
2019-12-12 11:09:06 +01:00
Thomas Egerer
cf18951efd
openssl: Make some additional arguments const
...
Related to openssl 1.1.x changes.
Signed-off-by: Thomas Egerer <[email protected] >
2019-12-11 13:09:04 +01:00
Tobias Brunner
e3e0fe41ab
sshkey: Rename variables that conflict with function argument
2019-12-09 11:34:30 +01:00
Tobias Brunner
6b347d5232
openssl: Ensure underlying hash algorithm is available during HMAC init
...
Without this we only would learn that the algorithm isn't actually
available (e.g. due to FIPS mode) when set_key() is called later, so there
isn't any automatic fallback to other implementations.
Fixes #3284 .
2019-12-06 10:27:24 +01:00
Tobias Brunner
27756b081c
revocation: Check that nonce in OCSP response matches
2019-12-06 09:52:30 +01:00
Tobias Brunner
cd0e4d5297
x509: Correctly parse nonce in OCSP response
...
Fixes: d7dc677ee5 ("x509: Correctly encode nonce in OCSP request")
2019-12-06 09:52:30 +01:00
Tobias Brunner
5333db58ac
x509: Add getter for nonce in OCSP request/response implementations
2019-12-06 09:50:55 +01:00
Andreas Steffen
a43407df52
drbg: Don't generate more than 2^16 bytes
2019-11-28 21:29:26 +01:00
Andreas Steffen
86a4b95eac
drbg: Use AES_ECB encryption
2019-11-28 17:03:09 +01:00
Andreas Steffen
b7e840af5c
gcrypt: Added AES_ECB support
2019-11-28 17:03:09 +01:00
Andreas Steffen
a46e436e29
af-alg: Added AES_ECB support
2019-11-28 17:03:09 +01:00
Andreas Steffen
f884ee6497
aes: Added AES_ECB support
2019-11-28 17:03:09 +01:00
Andreas Steffen
6f44bd6fe8
openssl: Added AES_ECB support
2019-11-28 17:03:08 +01:00
Andreas Steffen
20f3d04b13
aesni: Added AES_ECB support
2019-11-28 17:03:08 +01:00
Andreas Steffen
11e9d2b8d1
drbg: The drbg instance owns the entropy rng
2019-11-28 09:55:56 +01:00
Tobias Brunner
45c8399d78
Add missing strings to several enum string definitions
2019-10-28 14:26:32 +01:00
Tobias Brunner
1b96e4a465
drbg-ctr: Remove unused variable
2019-10-21 10:32:59 +02:00
David Garske
29f7017663
wolfssl: Fix for issue with blinding not defined
...
Closes strongswan/strongswan#156 .
2019-10-21 09:56:55 +02:00
Andreas Steffen
e36af6fc2f
gmp: Use NIST DRBG for RSA key pair generation
2019-10-18 16:24:39 +02:00
Andreas Steffen
6d3a743d90
ntru: Replaced ntru_drbg by drbg
2019-10-16 16:46:24 +02:00
Andreas Steffen
737375a2d2
drbg: Implemented NIST SP-800-90A DRBG
2019-10-16 16:46:24 +02:00
David Garske
1a256ca65a
wolfssl: Fixes for building with OpenSSL compatibility layer
...
Resolves conflicts with building against wolfSSL when
`--enable-opensslextra` is set, namely the `WOLFSSL_HMAC_H_`,
`RNG` and `ASN1_*` name conflicts.
Closes strongswan/strongswan#151 .
2019-09-26 09:06:11 +02:00
Tobias Brunner
095a2c2eac
openssl: Don't manually seed DRBG with OpenSSL 1.1.1
...
According to the documentation, it's generally not necessary to manually
seed OpenSSL's DRBG (and it actually can cause the daemon to lock up
during start up on systems with low entropy if OpenSSL is already trying
to seed it itself and holds the lock). While that might already have been
the case with earlier versions, it's not explicitly stated in their
documentation. So we keep the code for these versions.
2019-09-24 16:42:46 +02:00
Tobias Brunner
17c9972252
Fixed some typos, courtesy of codespell
2019-08-28 14:03:41 +02:00
Tobias Brunner
b9949e98c2
Some whitespace fixes
...
Didn't change some of the larger testing scripts that use an inconsistent
indentation style.
2019-08-22 15:18:06 +02:00
Tobias Brunner
6051d9b5e4
botan: Replace deprecated FFI function calls
...
Several "wrapper" functions have been marked deprecated with 2.11.0.
2019-07-02 11:35:21 +02:00
Andreas Steffen
df6441a13f
pki: Allow inclusion of [unsupported] critical X.509 extension
2019-05-08 14:56:48 +02:00
Tobias Brunner
a4abb263c9
openssl: Fix build with OpenSSL 1.1.1 without compatibility layer
...
If OpenSSL is built with --api, defines for deprecated functions in
OpenSSL's header files are not visible anymore.
Fixes #3045 .
2019-05-08 14:28:18 +02:00
Tobias Brunner
02b348403a
Fixed some typos, courtesy of codespell
2019-04-29 15:09:20 +02:00
Tobias Brunner
c546c1ba71
nonce: Allow overriding the RNG quality used to generate nonces
...
Usually, changing this won't be necessary (actually, some plugins
specifically use different DRGBs for RNG_WEAK in order to separate
the public nonces from random data used for e.g. DH).
But for experts with special plugin configurations this might be
more flexible and avoids code changes.
2019-04-29 10:49:35 +02:00
Tobias Brunner
d3329ee540
wolfssl: Fixes, code style changes and some refactorings
...
The main fixes are
* the generation of fingerprints for RSA, ECDSA, and EdDSA
* the encoding of ECDSA private keys
* calculating p and q for RSA private keys
* deriving the public key for raw Ed25519 private keys
Also, instead of numeric literals for buffer lengths ASN.1 related
constants are used.
2019-04-24 12:26:08 +02:00
Sean Parkinson
c92eade82c
wolfssl: Add wolfSSL plugin for cryptographic implementations
2019-04-24 11:40:14 +02:00
Tobias Brunner
a21710d380
openssl: Add support for ChaCha20-Poly1305
...
It's available since OpenSSL 1.1.0.
2019-03-08 15:55:52 +01:00
Tobias Brunner
8fc6b2d0e0
openssl: Generalize the GCM implementation a bit
...
This will allow us to use the implementation also for other algorithms.
2019-03-08 15:55:52 +01:00