Martin Willi
|
64e77e8fbb
|
use credential builder API to parse trusted public keys
|
2009-08-26 11:23:52 +02:00 |
|
Martin Willi
|
d1b3e8607e
|
implemented PGP fingerprinting
|
2009-08-26 11:23:51 +02:00 |
|
Martin Willi
|
e773fe4cab
|
implemented pkcs1 private/public key encoding and fingerprinting
|
2009-08-26 11:23:51 +02:00 |
|
Martin Willi
|
934d49a4f9
|
chunk_cat/cata/create_cat/length accept the sensitive data clearing mode 's'
|
2009-08-26 11:23:51 +02:00 |
|
Martin Willi
|
957d116328
|
in addition to 'm'/'c' mode, asn1_wrap accepts a 's' mode clearing sensitive information
|
2009-08-26 11:23:51 +02:00 |
|
Martin Willi
|
d9b24887a4
|
added a facility to hand out fingerprinting/key encoding to the pkcs1/pgp/... plugins
|
2009-08-26 11:23:51 +02:00 |
|
Martin Willi
|
831520d895
|
gmp uses component builder to build public- from private-key
|
2009-08-26 11:23:51 +02:00 |
|
Martin Willi
|
8380503168
|
gcrypt uses component builder to build public- from private-key
|
2009-08-26 11:23:51 +02:00 |
|
Martin Willi
|
b457e08fca
|
moved PGP code to pluto and gpg plugin
|
2009-08-26 11:23:51 +02:00 |
|
Martin Willi
|
7033a70fd0
|
gmp plugin makes use of pkcs1/pgp/dnskey plugins
|
2009-08-26 11:23:51 +02:00 |
|
Martin Willi
|
cbfafc1125
|
enforce RSA_PRIME1 > RSA_PRIME2 (p > q) in PGP
|
2009-08-26 11:23:51 +02:00 |
|
Martin Willi
|
5ef478aaee
|
implemented RFC3110 key builder in a plugin, added generic DNSKEY RR parsing
|
2009-08-26 11:23:51 +02:00 |
|
Martin Willi
|
3addf4e937
|
renamed BUILD_BLOB_RFC_3110 to BUILD_BLOB_DNSKEY, we potentially support other key types
|
2009-08-26 11:23:51 +02:00 |
|
Martin Willi
|
9493dd2ce0
|
implemented a pgp plugin providing PGP key parsing builders
|
2009-08-26 11:23:50 +02:00 |
|
Martin Willi
|
4e3d1e804e
|
make use of the pkcs1 plugin in gcrypt rsa key parsing
|
2009-08-26 11:23:50 +02:00 |
|
Martin Willi
|
3044774323
|
removed subjectPublicKeyInfo parsing, provided by pkcs1 plugin
|
2009-08-26 11:23:50 +02:00 |
|
Martin Willi
|
1e0f69373a
|
implemented a pkcs1 plugin providing PKCS#1 key parsing builders
|
2009-08-26 11:23:50 +02:00 |
|
Martin Willi
|
7c2d883af7
|
show more information if building a credential fails
|
2009-08-26 11:23:50 +02:00 |
|
Martin Willi
|
3f9ec06f6f
|
added getnetbyname/gethostbyname2 to leak detective whitelist, used by pluto
|
2009-08-26 11:23:50 +02:00 |
|
Martin Willi
|
ddf7c6ac7b
|
do not enumerate builders returning NULL
|
2009-08-26 11:23:50 +02:00 |
|
Martin Willi
|
cbb62e8f4c
|
handle pluto specific certificates under CRED_CERTIFICATE, not as own credential kind
|
2009-08-26 11:23:49 +02:00 |
|
Martin Willi
|
94463a33b4
|
removed obsolete PEM code in pluto/libstrongswan
|
2009-08-26 11:23:49 +02:00 |
|
Martin Willi
|
11aa7e7869
|
use a pluto specific credential builder to build pluto cert_t's
|
2009-08-26 11:23:49 +02:00 |
|
Martin Willi
|
4d15129160
|
pass along X509 flags when loading PEM encoded data
|
2009-08-26 11:23:49 +02:00 |
|
Martin Willi
|
280469923d
|
make use of the pem helper plugin to load credentials
|
2009-08-26 11:23:49 +02:00 |
|
Martin Willi
|
c9db16b7dd
|
added file loading support to pem plugin, using mmap()
|
2009-08-26 11:23:48 +02:00 |
|
Martin Willi
|
160f4c225d
|
moved PEM parsing functionality to its own plugin
|
2009-08-26 11:23:48 +02:00 |
|
Andreas Steffen
|
fc0ed07c1f
|
pruned OID tree
|
2009-08-18 18:24:26 +02:00 |
|
Andreas Steffen
|
c8b543a6fc
|
fixed wrong emailAddress OID introduced by revision c31687da
|
2009-08-18 17:52:00 +02:00 |
|
Tobias Brunner
|
f1777dff59
|
Replacing gethostbyname, gethostbyname2 and their _r variants with getaddrinfo to increase portability.
|
2009-08-14 16:14:32 +02:00 |
|
Tobias Brunner
|
26965b4ef3
|
OpenSolaris needs libsocket and libnsl for socket().
|
2009-08-14 14:50:53 +02:00 |
|
Tobias Brunner
|
cc396286e8
|
Defined some missing fixed-width int types on OpenSolaris.
|
2009-08-14 14:50:22 +02:00 |
|
Tobias Brunner
|
3901937d14
|
OpenSolaris defines MUTEX_DEFAULT therefore we rename the members of the enums mutex/condvar/rwlock_type_t.
|
2009-08-14 13:30:59 +02:00 |
|
Tobias Brunner
|
8b6a5ce5ba
|
We need to include alloca.h on OpenSolaris.
|
2009-08-14 13:25:22 +02:00 |
|
Tobias Brunner
|
3974b2fb07
|
FreeBSD's libc does not support backtrace(), but libexecinfo optionally replicates this function (and the other defined in execinfo.h).
|
2009-08-07 18:46:25 +02:00 |
|
Andreas Steffen
|
5d8306de68
|
use SS_RC_FIRST and SS_RC_LAST
|
2009-08-06 16:42:44 +02:00 |
|
Andreas Steffen
|
3646c8a159
|
abort pluto or charon if initialization fails
|
2009-08-06 16:32:52 +02:00 |
|
Andreas Steffen
|
994b80b513
|
activated CAMELLIA_CBC cipher in openssl plugin
|
2009-08-05 22:46:53 +02:00 |
|
Andreas Steffen
|
b6f739c13b
|
support of SHA224-based certificate signatures
|
2009-08-05 22:01:44 +02:00 |
|
Martin Willi
|
3d2f73b92f
|
parse RDNs in multiple SEQUENCEs in all SETs of a DN
|
2009-08-03 15:24:48 +02:00 |
|
Tobias Brunner
|
b2117eee20
|
Make accept(2) and recvfrom(2) cancellation points on Mac OS X.
|
2009-07-30 14:06:26 +02:00 |
|
Andreas Steffen
|
e1089f5906
|
added file and segment lengths to checksum.c
|
2009-07-21 22:23:51 +02:00 |
|
Martin Willi
|
fcac8f6571
|
filter objects for segment checksumming by dlpi_name, excludes rare false positives
|
2009-07-21 15:10:24 +02:00 |
|
Martin Willi
|
7655843ab5
|
enumerate executable sections only to build checksum
|
2009-07-21 15:00:18 +02:00 |
|
Martin Willi
|
acd4afc997
|
announce integrity testing only once
|
2009-07-21 14:58:14 +02:00 |
|
Andreas Steffen
|
def1777eca
|
streamlined integrity test output some more
|
2009-07-18 11:23:27 +02:00 |
|
Andreas Steffen
|
e3f3b004e2
|
fix test vector error output
|
2009-07-17 20:36:21 +02:00 |
|
Andreas Steffen
|
eab241fb56
|
stop strongswan if integrity check of libstrongswan or daemon fails
|
2009-07-17 20:33:19 +02:00 |
|
Andreas Steffen
|
6b04ba288d
|
streamlined debug output of integrity tests
|
2009-07-17 17:00:17 +02:00 |
|
Andreas Steffen
|
521aa00fb1
|
shortened cypto test output
|
2009-07-17 16:36:01 +02:00 |
|