Martin Willi
|
c3e7b3de0b
|
openssl: parse X.509 extended key usage from extension parsing loop
Otherwise parsing gets aborted if unknown critical extensions are handled as
error.
|
2013-07-18 12:17:53 +02:00 |
|
Martin Willi
|
3f55f203ee
|
openssl: show which critical X.509 extension is not supported
|
2013-07-18 12:17:53 +02:00 |
|
Andreas Steffen
|
126778679f
|
Recognize critical IssuingDistributionPoint CRL extension
|
2013-07-12 09:00:47 +02:00 |
|
Martin Willi
|
324b90cc46
|
openssl: RAND_pseudo_bytes() returns 0 if bytes are not cryptographically strong
For our purposes with RNG_WEAK this is fine, so accept a zero return value.
|
2013-07-04 11:09:54 +02:00 |
|
Michael Rossberg
|
5e4b1ad20a
|
openssl: add support for IP addr blocks in X.509 certificates
|
2013-05-24 15:09:47 +02:00 |
|
Tobias Brunner
|
bd538e8c4a
|
openssl: Only warn about unavailable FIPS mode if the user requested it
|
2013-05-08 15:23:14 +02:00 |
|
Tobias Brunner
|
904390e887
|
openssl: Cleanup thread specific error buffer
|
2013-05-08 15:02:40 +02:00 |
|
Tobias Brunner
|
3ee2af97bf
|
openssl: Don't use deprecated CRYPTO_set_id_callback() with OpenSSL >= 1.0.0
|
2013-05-08 15:02:40 +02:00 |
|
Tobias Brunner
|
780900ab0e
|
openssl: Add PKCS#12 parsing via OpenSSL
|
2013-05-08 15:02:40 +02:00 |
|
Tobias Brunner
|
651d5ab8e7
|
openssl: Properly cleanup OpenSSL library
|
2013-05-08 15:02:40 +02:00 |
|
Tobias Brunner
|
1f2a34d6d8
|
Add support for untruncated HMAC-SHA-512
|
2013-05-08 15:02:39 +02:00 |
|
Tobias Brunner
|
2d7b55bf9b
|
openssl: Define a default for FIPS_MODE
|
2013-05-03 15:11:19 +02:00 |
|
Andreas Steffen
|
f4de6496a2
|
support of OpenSSL FIPS-140-2 library
|
2013-04-16 12:37:04 +02:00 |
|
Martin Willi
|
cf1696cab9
|
Allow SHA1_Init()/SHA1_Update() to fail if OpenSSL version >= 1.0
|
2013-04-10 18:10:30 +02:00 |
|
Martin Willi
|
b52771fbb2
|
Check RSA_public_decrypt() length before constructing and comparing a chunk
If decryption fails, it returns -1. chunk_equals() should catch that error,
but be more explicit in error checking.
|
2013-04-10 18:10:30 +02:00 |
|
Martin Willi
|
97d975b7bb
|
RSA_check_key() may return -1 if it fails
|
2013-04-10 18:10:30 +02:00 |
|
Martin Willi
|
96a09ce226
|
RAND_bytes/RAND_pseudo_bytes returns -1 if it is not supported by RAND method
|
2013-04-10 18:10:30 +02:00 |
|
Martin Willi
|
0faaab20cd
|
Check return value of ECDSA_Verify() correctly
|
2013-04-10 18:10:30 +02:00 |
|
Tobias Brunner
|
4c969f7906
|
openssl: The EVP GCM interface requires at least OpenSSL 1.0.1
|
2013-03-01 16:57:45 +01:00 |
|
Tobias Brunner
|
81f9cd39fd
|
openssl: Provide AES-GCM implementation
|
2013-02-28 18:17:42 +01:00 |
|
Tobias Brunner
|
0d237763dc
|
openssl: Disable PKCS#7/CMS when building against OpenSSL < 0.9.8g
Fixes #292.
|
2013-02-20 18:34:54 +01:00 |
|
Tobias Brunner
|
a3a190b7bd
|
openssl: Properly honor OPENSSL_NO_* defines
|
2013-01-31 17:33:23 +01:00 |
|
Tobias Brunner
|
572a707765
|
Properly check MSB in openssl plugin's PKCS#7 implementation
|
2013-01-24 23:36:02 +01:00 |
|
Martin Willi
|
ff318ad3e1
|
Include opensslconf.h before checking its defines
|
2013-01-03 11:12:05 +01:00 |
|
Martin Willi
|
2b9e597b54
|
Don't build OpenSSL PKCS#7 code if OPENSSL_NO_CMS defined
|
2013-01-03 11:05:49 +01:00 |
|
Martin Willi
|
0a344da291
|
Fix up serialNumber in openssl PKCS#7 if it has a leading MSB set
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
3c820cdc23
|
Implement PKCS#7 decryption using openssl
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
2a87944a33
|
Make available wrapped certificates while verifying PKCS#7 signatures in openssl
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
04884be3b5
|
Implement openssl PKCS#7 certficiate enumeration
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
804ba5bb50
|
Implement get_attribute() in openssl PKCS#7 backend
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
c61723c69f
|
Implement OpenSSL PKCS#7 signed-data parsing and verification
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
568ad938d1
|
Add a stub for OpenSSL PKCS#7 parsing
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
ed1c430334
|
certificate_t.has_subject() matches for certificate serialNumber
|
2012-12-19 10:32:07 +01:00 |
|
Tobias Brunner
|
f05b427265
|
Moved debug.[ch] to utils folder
|
2012-10-24 16:00:51 +02:00 |
|
Tobias Brunner
|
12642a6831
|
Moved data structures to new collections subfolder
|
2012-10-24 16:00:49 +02:00 |
|
Tobias Brunner
|
a05f3b2021
|
Make sure first argument is an int when using %.*s to print e.g. chunks
|
2012-09-28 18:01:49 +02:00 |
|
Tobias Brunner
|
3570c43968
|
openssl: Fix registration of the PUBKEY builder
libtls drops support for RSA suites if it does not find an RSA backend
(final builder for RSA public keys).
|
2012-08-18 17:49:57 +02:00 |
|
Martin Willi
|
610f90a8b9
|
Use centralized hasher names in openssl plugin
|
2012-07-17 17:32:00 +02:00 |
|
Martin Willi
|
082b0d7249
|
Support void return values in OpenSSL 0.9.8 HMAC functions
|
2012-07-17 10:58:53 +02:00 |
|
Martin Willi
|
3aca89c8e6
|
Resetting OpenSSL HMAC with NULL key reuses existing key
|
2012-07-16 14:55:07 +02:00 |
|
Martin Willi
|
9138f49e6a
|
Make sure HMAC_Init is called before HMAC_Update, fixes crash
|
2012-07-16 14:55:07 +02:00 |
|
Martin Willi
|
e3b2e900e6
|
Add a return value to hasher_t.reset()
|
2012-07-16 14:55:06 +02:00 |
|
Martin Willi
|
87dd205b61
|
Add a return value to hasher_t.allocate_hash()
|
2012-07-16 14:55:06 +02:00 |
|
Martin Willi
|
8bd6a30af1
|
Add a return value to hasher_t.get_hash()
|
2012-07-16 14:55:06 +02:00 |
|
Martin Willi
|
ce73fc19db
|
Add a return value to crypter_t.set_key()
|
2012-07-16 14:53:38 +02:00 |
|
Martin Willi
|
3b96189a2a
|
Add a return value to crypter_t.decrypt()
|
2012-07-16 14:53:38 +02:00 |
|
Martin Willi
|
e35abbe588
|
Add a return value to crypter_t.encrypt
|
2012-07-16 14:53:37 +02:00 |
|
Martin Willi
|
6ac8d861d9
|
Add a return value to mac_t.set_key()
|
2012-07-16 14:53:37 +02:00 |
|
Martin Willi
|
27e1eabbb5
|
Add a return value to mac_t.get_bytes()
|
2012-07-16 14:53:37 +02:00 |
|
Tobias Brunner
|
99dc3d2c15
|
Check rng return value when seeding OpenSSL RNG
|
2012-07-16 14:53:36 +02:00 |
|