Aleksandr Grinberg
|
4faece7b1e
|
Adding OpenSSL random number functions to openssl plugin
|
2012-06-25 16:35:05 +02:00 |
|
Martin Willi
|
a37f2d2006
|
certificate_t->issued_by takes an argument to receive signature scheme
|
2012-06-12 14:24:49 +02:00 |
|
Martin Willi
|
0c7af2ce27
|
Certificate decoding soft-depends on public key decoding of specific types
|
2012-05-02 14:05:52 +02:00 |
|
Tobias Brunner
|
27f8a61df3
|
OpenSSL plugin parses ECDSA private keys with explicitly specified EC parameters.
This is needed in case the key itself does not contain the parameters,
which is the case for PKCS#8.
|
2012-02-01 18:27:45 +01:00 |
|
Sansar Choinyambuu
|
95e37555c3
|
Reverse the changes made to openssl plugin for signature verification
|
2011-11-28 21:18:05 +01:00 |
|
Sansar Choinyambuu
|
824ace105a
|
Changed the static function name in openssl_rsa_public_key object
Removed unused chunk variable from PTS verify_quote_signature function
|
2011-11-28 21:17:16 +01:00 |
|
Sansar Choinyambuu
|
5fbbfe0a48
|
use openssl rsa_verify function
|
2011-11-28 20:31:13 +01:00 |
|
Sansar Choinyambuu
|
19fa287f6e
|
Reverse the changes made to openssl plugin for signature verification
|
2011-11-28 14:39:53 +01:00 |
|
Sansar Choinyambuu
|
71741df078
|
Changed the static function name in openssl_rsa_public_key object
Removed unused chunk variable from PTS verify_quote_signature function
|
2011-11-28 14:39:53 +01:00 |
|
Sansar Choinyambuu
|
3cd6077b75
|
use openssl rsa_verify function
|
2011-11-28 14:39:53 +01:00 |
|
Thomas Egerer
|
93818392cd
|
Change order of ocsp uris when parsing a cert
|
2011-11-04 11:11:17 +01:00 |
|
Thomas Egerer
|
42e2da606c
|
Use chunk_clear to memwipe shared secret
|
2011-11-04 11:11:17 +01:00 |
|
Martin Willi
|
f5c574e17b
|
Fixed AES key length in openssl plugin
|
2011-10-14 10:05:47 +02:00 |
|
Martin Willi
|
02572b84f9
|
Announce openssl features only if actually supported
|
2011-10-14 10:05:46 +02:00 |
|
Martin Willi
|
9dc54fc56a
|
Add features support to openssl plugin
|
2011-10-14 10:05:45 +02:00 |
|
Tobias Brunner
|
28bcbc297f
|
openssl: Adding support for key usage x509 extension.
|
2011-10-05 15:10:12 +02:00 |
|
Martin Willi
|
24fa80ac91
|
Fixed compiler warnings in openssl plugin
|
2011-09-07 14:23:27 +02:00 |
|
Tobias Brunner
|
0e080d9b64
|
Don't compile login() in openssl_rsa_private_key_t if ENGINE support is disabled in OpenSSL.
|
2011-05-13 13:11:11 +02:00 |
|
Tobias Brunner
|
70f918ec1d
|
chunk_clear not clear_chunk.
|
2011-05-10 15:40:46 +02:00 |
|
Martin Willi
|
f7812f6492
|
Wipe memory after using key material (incomplete, to be continued)
|
2011-05-09 14:36:15 +02:00 |
|
Martin Willi
|
5b0bcfb1fc
|
Revert alloc_str changes
This reverts commit fdead26ffe.
This reverts commit 3e2419ebe3.
This reverts commit 17ce69b47a.
|
2011-04-21 13:35:31 +02:00 |
|
Martin Willi
|
3e2419ebe3
|
Use thread save settings alloc_str function where appropriate
|
2011-04-21 10:48:16 +02:00 |
|
Martin Willi
|
c55818ebb0
|
Added a (not yet implemented) plugin_t method to reload plugin configuration
|
2011-04-15 10:07:13 +02:00 |
|
Martin Willi
|
787b5884aa
|
Added a get_name() function to plugin_t, create_plugin_enumerator enumerates over plugin_t
|
2011-04-15 10:07:12 +02:00 |
|
Andreas Steffen
|
d390b3b901
|
[hopefully] fixed pathlen problem on ARM platforms
|
2011-02-10 15:51:18 +01:00 |
|
Andreas Steffen
|
c4fd3b2f42
|
introduced libstrongswan.x509.enforce_critical parameter
|
2011-02-05 09:01:18 +01:00 |
|
Andreas Steffen
|
8b42864884
|
fixed checking of unknown critical extensions in openssl_x509
|
2011-01-31 14:37:48 +01:00 |
|
Martin Willi
|
b3d359e58f
|
Use a generic getter for all numerical X.509 constraints
|
2011-01-05 16:46:05 +01:00 |
|
Martin Willi
|
55e4d8982f
|
Added support for delta CRLs to x509 plugin
|
2011-01-05 16:46:03 +01:00 |
|
Martin Willi
|
a6478a0402
|
Simplified format of x509 CRL URI parsing/enumerator
|
2011-01-05 16:46:03 +01:00 |
|
Martin Willi
|
e24a02a28f
|
Fail on critical extensions in openssl CRLs
|
2011-01-05 16:46:03 +01:00 |
|
Martin Willi
|
a742d97fb8
|
Added support for policyConstraints to x509 plugin
|
2011-01-05 16:46:02 +01:00 |
|
Martin Willi
|
5dba5852fc
|
Slightly renamed X509_NO_PATH_LEN_CONSTRAINT to use it for PolicyConstraints, too
|
2011-01-05 16:46:02 +01:00 |
|
Martin Willi
|
5a0caa4b3a
|
Added policyMappings support to x509 plugin
|
2011-01-05 16:46:02 +01:00 |
|
Martin Willi
|
20bd78106e
|
Added certificatePolicy support to x509 plugin
|
2011-01-05 16:46:02 +01:00 |
|
Martin Willi
|
b0892d094c
|
Fail when parsing unsupported critical extensions in openssl_x509
|
2011-01-05 16:46:02 +01:00 |
|
Martin Willi
|
a6850b8499
|
Do not parse certificates with invalid version in openssl plugin
|
2011-01-05 16:46:01 +01:00 |
|
Martin Willi
|
dbfbbec368
|
Added name constraint enumerator to x509 interface
|
2011-01-05 16:46:00 +01:00 |
|
Martin Willi
|
4e508517d7
|
Added support for CRL Issuers to x509 and OpenSSL plugins
|
2011-01-05 16:45:55 +01:00 |
|
Andreas Steffen
|
5932f41fcc
|
trace back crypto algorithms to the plugins that registered them
|
2010-12-18 16:31:12 +01:00 |
|
Tobias Brunner
|
ed174fd7e2
|
Added missing include for RAND_seed and RAND_status.
|
2010-10-21 14:16:09 +02:00 |
|
Martin Willi
|
663e735553
|
Compare subject against all key identifiers in has_subject()
|
2010-09-09 17:46:20 +02:00 |
|
Martin Willi
|
d987946e80
|
Added a final flag to builder registration to enumerate the actually supported algorithms
|
2010-09-03 18:09:48 +02:00 |
|
Martin Willi
|
42b1ac91c4
|
Added support for MODP_CUSTOM to openssl plugin
|
2010-09-03 09:33:15 +02:00 |
|
Martin Willi
|
2291754ddf
|
Unwrap crlNumber INTEGER in openssl CRL parsing
|
2010-08-30 11:23:46 +02:00 |
|
Martin Willi
|
ba31fe1fd6
|
Use a seperate section for each nested struct member in INIT macro
|
2010-08-18 12:15:03 +02:00 |
|
Martin Willi
|
e2c3b4820b
|
Variable key length crypters use default key length if zero given
|
2010-08-16 17:06:27 +02:00 |
|
Martin Willi
|
f7c04c5b37
|
Add dedicated getter for the IV size to the crypter_t interface
|
2010-08-13 17:11:53 +02:00 |
|
Martin Willi
|
4ec53e95f5
|
Double check that the OpenSSL RNG has been seeded, do so otherwise
|
2010-08-11 10:12:50 +02:00 |
|
Martin Willi
|
d775af9d18
|
Implemented RSA en-/decryption in openssl plugin
|
2010-08-11 09:53:45 +02:00 |
|