Tobias Brunner
|
0d237763dc
|
openssl: Disable PKCS#7/CMS when building against OpenSSL < 0.9.8g
Fixes #292.
|
2013-02-20 18:34:54 +01:00 |
|
Martin Willi
|
de399f550d
|
Add a cert_validator hook allowing plugins to provide custom lifetime checking
|
2013-02-19 14:31:18 +01:00 |
|
Martin Willi
|
790e00aaa9
|
Make cert_validator_t.validate optional to implement
|
2013-02-19 14:31:18 +01:00 |
|
Andreas Steffen
|
a4ddc0bb26
|
Encode RSA public keys in RFC 3110 DNSKEY format
|
2013-02-19 12:25:00 +01:00 |
|
Andreas Steffen
|
f2145c8d3a
|
Moved configuration from resolver manager to unbound plugin
Also streamlined log messages in unbound plugin.
|
2013-02-19 12:25:00 +01:00 |
|
Reto Guadagnini
|
cfd07978d0
|
unbound: Implementation of query method of unbound_resolver_t
|
2013-02-19 11:57:21 +01:00 |
|
Reto Guadagnini
|
5a4126b490
|
unbound: Implemented resolver_response_t as unbound_response_t
|
2013-02-19 11:57:21 +01:00 |
|
Reto Guadagnini
|
62ea67e700
|
Implemented rr_set_t interface
|
2013-02-19 11:57:21 +01:00 |
|
Reto Guadagnini
|
4a335a2164
|
unbound: Implemented rr_t as unbound_rr_t
|
2013-02-19 11:57:21 +01:00 |
|
Reto Guadagnini
|
9f963a7cfc
|
Added unbound plugin implementing the resolver interface using libunbound
|
2013-02-19 11:57:21 +01:00 |
|
Reto Guadagnini
|
b1505b345b
|
Added manager for DNS resolvers
|
2013-02-19 11:57:21 +01:00 |
|
Reto Guadagnini
|
ffdeeb6609
|
Added interface for DNS resolvers
|
2013-02-19 11:57:21 +01:00 |
|
Martin Willi
|
4755ab505d
|
Add a global return_success() method implementation
|
2013-02-14 17:17:45 +01:00 |
|
Martin Willi
|
de32b8aed6
|
Add a convenience method to check pen_type_t for vendor and type
|
2013-02-14 17:17:30 +01:00 |
|
Martin Willi
|
d03b338487
|
Add a comparison function for pen_type_t
|
2013-02-14 17:17:22 +01:00 |
|
Martin Willi
|
9db54bbcd4
|
Whitespace and comment cleanups in pen.[ch]
|
2013-02-14 17:17:07 +01:00 |
|
Martin Willi
|
e212033ef2
|
Merge branch 'ike-dscp'
|
2013-02-14 17:11:35 +01:00 |
|
Martin Willi
|
8b56943222
|
Merge branch 'pt-tls'
|
2013-02-14 17:06:07 +01:00 |
|
Martin Willi
|
763e86c093
|
Use CURL_TIMEOUT and not CURL_CONNECTTIMEOUT for FETCHER_TIMEOUT in curl
This allows us to use this timeout beyond DNS resolution. For the initial
connect, we use a hardcoded timeout of 10s for now.
|
2013-02-08 11:08:06 +01:00 |
|
Martin Willi
|
1116689944
|
Add a DSCP value with getter/setter on packet_t
|
2013-02-06 15:20:32 +01:00 |
|
Martin Willi
|
82c884c015
|
Set sockaddr family on ifreq instead of casted familiy specific sockaddr
Fixes a strict-aliasing rule compiler warning with older gcc.
|
2013-02-06 15:20:32 +01:00 |
|
Andreas Steffen
|
cf29fc075a
|
time is a time_t pointer
|
2013-02-04 13:05:29 +01:00 |
|
Andreas Steffen
|
459c50ccb8
|
print PEN value 0xfffffe as Unassigned
|
2013-02-03 18:52:59 +01:00 |
|
Tobias Brunner
|
a3a190b7bd
|
openssl: Properly honor OPENSSL_NO_* defines
|
2013-01-31 17:33:23 +01:00 |
|
Tobias Brunner
|
25637aa5d8
|
Fix Doxygen comment for rdrand plugin
|
2013-01-31 12:11:37 +01:00 |
|
Tobias Brunner
|
58fd1f3eef
|
Don't use pointer to a union member in host_create_from_string_and_family()
|
2013-01-25 13:18:50 +01:00 |
|
Tobias Brunner
|
572a707765
|
Properly check MSB in openssl plugin's PKCS#7 implementation
|
2013-01-24 23:36:02 +01:00 |
|
Tobias Brunner
|
69c6a60176
|
g_thread_init() is deprecated since Glib 2.23
|
2013-01-24 19:13:40 +01:00 |
|
Martin Willi
|
51dbcf6497
|
After merging the used trustchain with config, move used certificate to front
|
2013-01-18 11:59:27 +01:00 |
|
Martin Willi
|
9a06a93ce7
|
Try to build a trustchain for all configured certificates before enforcing one
This enables the daemon to select from multiple configured certificates
by building trustchains against the received certificate requests.
|
2013-01-18 09:33:15 +01:00 |
|
Martin Willi
|
f29783af8c
|
Make AUTH_RULE_SUBJECT cert multi-valued
Constraints having multiple subject certs defined are fulfilled if
authentication used one of the listed certificates.
|
2013-01-18 09:33:15 +01:00 |
|
Martin Willi
|
7fb81886b9
|
Add a bio_reader_t constructor variant freeing passed data during destruction
|
2013-01-15 17:43:05 +01:00 |
|
Martin Willi
|
47af9848a2
|
Add a chunk_from_str() initializer that does not include 0-terminator
|
2013-01-15 17:43:05 +01:00 |
|
Martin Willi
|
1449e6dd55
|
Reseed rdrand after every 128bit sample only
|
2013-01-15 17:41:54 +01:00 |
|
Martin Willi
|
426f34baf9
|
Respect given address family when resolving "%any"
|
2013-01-14 10:26:12 +01:00 |
|
Tobias Brunner
|
37fb404833
|
Android.mk of libstrongswan updated
|
2013-01-14 09:16:33 +01:00 |
|
Martin Willi
|
54a1a75b2f
|
Don't use bio_writer_t.skip() to write length field when appending more data
If the writer reallocates its buffer, the length pointer might not be valid
anymore, or even worse, point to an arbitrary allocation.
|
2013-01-11 14:57:08 +01:00 |
|
Martin Willi
|
2cd6c5115b
|
Use raw opcodes for rdrand to build with older binutils
|
2013-01-11 10:45:14 +01:00 |
|
Martin Willi
|
19ae23452a
|
Provide RNG_TRUE quality in rdrand by mixing reseeded outputs using AES
|
2013-01-11 10:45:14 +01:00 |
|
Martin Willi
|
b9148ea232
|
Provide RNG_STRONG quality in rdrand by forcing PRNG reseed after every sample
|
2013-01-11 10:45:14 +01:00 |
|
Martin Willi
|
9fe24b004d
|
Provide RNG_WEAK quality random generator in rdrand
|
2013-01-11 10:45:14 +01:00 |
|
Martin Willi
|
ed8dc6f132
|
Add a rdrand plugin stub detecting availability of RDRAND instructions
|
2013-01-11 10:45:14 +01:00 |
|
Martin Willi
|
ff318ad3e1
|
Include opensslconf.h before checking its defines
|
2013-01-03 11:12:05 +01:00 |
|
Martin Willi
|
2b9e597b54
|
Don't build OpenSSL PKCS#7 code if OPENSSL_NO_CMS defined
|
2013-01-03 11:05:49 +01:00 |
|
Tobias Brunner
|
ef33a4ab82
|
Fixed some typos, courtesy of codespell
|
2012-12-20 09:35:26 +01:00 |
|
Martin Willi
|
0a344da291
|
Fix up serialNumber in openssl PKCS#7 if it has a leading MSB set
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
71dd4e7895
|
Don't handle PKCS#7 containers with infinite length encodings in pkcs7 plugin
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
3c820cdc23
|
Implement PKCS#7 decryption using openssl
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
2a87944a33
|
Make available wrapped certificates while verifying PKCS#7 signatures in openssl
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
04884be3b5
|
Implement openssl PKCS#7 certficiate enumeration
|
2012-12-19 10:32:08 +01:00 |
|