Andreas Steffen
4a97999466
Version bump to 5.5.2dr1
2016-10-30 17:34:05 +01:00
Andreas Steffen
880c312458
Fixed in-place update of cached base and delta CRLs
2016-10-30 16:37:24 +01:00
Andreas Steffen
2271ebb325
Newer CRLs replace older versions of the CRL in the cache
2016-10-26 12:48:54 +02:00
Andreas Steffen
e6a4bd83ff
Version bump to 5.5.1
2016-10-20 12:57:00 +02:00
Andreas Steffen
4d77fcbec9
Version bump to 5.5.1rc2
2016-10-18 18:14:57 +02:00
Andreas Steffen
ba6c7a52c0
testing: Renewed expired certificates
2016-10-18 18:13:58 +02:00
Andreas Steffen
cb8f436112
added XOF dependencies of bliss and ntru plugins
2016-10-18 16:28:43 +02:00
Andreas Steffen
d167776ff9
testing: enable MACsec in guest kernel
2016-10-18 16:25:19 +02:00
Andreas Steffen
a617223ed5
Version bump to 5.5.1rc1
2016-10-11 19:21:36 +02:00
Andreas Steffen
8a56405a82
Merge branch 'cache-crls'
2016-10-11 17:19:29 +02:00
Andreas Steffen
85b5a6ace2
Save both base and delta CRLs to disk
2016-10-11 17:18:22 +02:00
Andreas Steffen
2a2669ee3e
vici: strongswan.conf cache_crls = yes saves fetched CRLs to disk
2016-10-11 17:18:22 +02:00
Andreas Steffen
a9562a3f58
testing: Added swanctl/net2net-multicast scenario
2016-09-27 18:36:28 +02:00
Andreas Steffen
d7e0ce2878
testing: Added ikev2/net2net-multicast scenario
2016-09-27 18:36:28 +02:00
Andreas Steffen
6b3e408ba5
Version bump to 5.5.1dr5
2016-09-22 17:36:37 +02:00
Andreas Steffen
d505658038
testing: Added swanctl/net2net-sha3-rsa-cert and swanctl/rw-eap-tls-sha3-rsa scenarios
2016-09-22 17:34:31 +02:00
Andreas Steffen
40f2589abf
gmp: Support of SHA-3 RSA signatures
2016-09-22 17:34:31 +02:00
Andreas Steffen
c54d1ef12c
bliss sampler unit-test: Fixed enumeration type
2016-09-22 10:46:39 +02:00
Andreas Steffen
a3a8b4acae
bliss: bliss_sampler expects XOF type
2016-09-22 09:23:47 +02:00
Andreas Steffen
e31ed9ab98
Version bump to 5.5.1dr4
2016-09-21 14:14:42 +02:00
Andreas Steffen
188b190a70
mgf1: Refactored MGF1 as an XOF
2016-09-21 06:40:52 +02:00
Andreas Steffen
8aaa6de322
Version bump to 5.5.1dr3
2016-09-15 11:45:17 +02:00
Andreas Steffen
29a48b4c69
Merge branch 'flush-certs'
2016-09-15 11:39:16 +02:00
Andreas Steffen
2c7cfe7630
vici: flush-certs command flushes certificate cache
...
When fresh CRLs are released with a high update frequency (e.g.
every 24 hours) or OCSP is used then the certificate cache gets
quickly filled with stale CRLs or OCSP responses. The new VICI
flush-certs command allows to flush e.g. cached CRLs or OCSP
responses only. Without the type argument all kind of certificates
(e.g. also received end entity and intermediate CA certificates)
are purged.
2016-09-13 17:02:59 +02:00
Andreas Steffen
de44fd748a
pt-tls-client: Added support of ECDSA keys
2016-08-31 17:06:47 +02:00
Andreas Steffen
288ee54875
libimcv: No need to load AIK pubkey if AIK certificate is available
2016-08-31 16:12:55 +02:00
Andreas Steffen
d2577aa3c5
Version bump to 5.5.1dr2
2016-08-26 22:55:41 +02:00
Andreas Steffen
d125941802
libtpmtss: TCTI finalization call changed
2016-08-25 13:22:51 +02:00
Andreas Steffen
36bf2b1bc5
conf: aikpub2.opt added to Makefile.am
2016-08-25 13:22:51 +02:00
Andreas Steffen
ce20979ce2
testing: Virtual IPs went missing
2016-08-16 17:18:17 +02:00
Andreas Steffen
3bca51e430
unit-tests: Removed unused variable
2016-08-11 17:01:33 +02:00
Andreas Steffen
5afaf0dba2
Version bump to 5.5.1dr1
2016-08-10 18:11:53 +02:00
Andreas Steffen
53332c9390
Merge branch 'newhope'
2016-08-10 16:23:04 +02:00
Andreas Steffen
c1a1f9f548
testing: Added swanctl/rw-newhope-bliss scenario
2016-08-10 15:14:26 +02:00
Andreas Steffen
1e0dc2c329
testing: Add chapoly, ntru and newhope plugins to crypto and integrity tests
2016-08-10 14:34:27 +02:00
Andreas Steffen
277ef8c2fa
testing: Added ikev2/rw-newhope-bliss scenario
2016-08-10 14:22:00 +02:00
Andreas Steffen
1342bd3386
unit-tests: Created newhope unit-tests
2016-08-10 14:22:00 +02:00
Andreas Steffen
393688aea0
Created newhope plugin implementing the New Hope key exchange algorithm
2016-08-10 14:22:00 +02:00
Andreas Steffen
1fddb0b92e
xof: Added ChaCha20 stream as XOF
2016-08-06 12:09:05 +02:00
Andreas Steffen
8993cb556e
utils: Defined uletoh16() and htole16()
2016-08-06 12:09:05 +02:00
Andreas Steffen
b8070e2c85
integrity-test: Added ntru_param_sets to read-only segment
2016-07-29 12:36:15 +02:00
Andreas Steffen
17e4ca6ac9
integrity-test: Added bliss_param_sets to read-only segment
2016-07-29 12:36:15 +02:00
Andreas Steffen
7256c68da0
integrity-test: check code and ro segments of libnttfft
2016-07-29 12:36:15 +02:00
Andreas Steffen
d305f251a5
Created libnttfft
...
This makes Number Theoretic Transforms (NTT) based on the efficient
Fast-Fourier-Transform (FFT) available to multiple plugins.
2016-07-29 12:36:15 +02:00
Andreas Steffen
65f2ecb86d
Share twiddle factors table between 512 and 1024 point FFT
2016-07-29 12:36:14 +02:00
Andreas Steffen
68075fb7a7
Implemented FFT with n = 1024 and q = 11289 using Montgomery arithmetic
2016-07-29 12:36:14 +02:00
Andreas Steffen
a7d626118f
bliss: Implemented FFT with fast Montgomery arithmetic
2016-07-29 12:36:14 +02:00
Andreas Steffen
5ff88c9622
xof: Implemented SHAKE128 and SHAKE256 Extended Output Functions
2016-07-29 12:36:14 +02:00
Andreas Steffen
04208ac5d4
xof: Defined Extended Output Functions
2016-07-29 12:36:14 +02:00
Andreas Steffen
7f65a8c271
vici: Increased various string buffers to BUF_LEN (512 bytes)
2016-07-29 12:34:40 +02:00
Andreas Steffen
fa1865094d
integrity-test: Added charon-systemd
2016-07-29 12:33:32 +02:00
Andreas Steffen
eda8907b90
Added SHA-3 signature OIDs
2016-07-26 13:34:45 +02:00
Andreas Steffen
5ce749bcfc
unit-tests: Decreased loop count of FFT speed test to 10'000
2016-07-22 21:27:42 +02:00
Andreas Steffen
10ebb3c914
unit-tests: Added bliss_fft_speed test
2016-07-22 11:58:10 +02:00
Andreas Steffen
6f4b73615b
Merge branch 'tss2-sapi'
2016-07-20 11:26:45 +02:00
Andreas Steffen
0274163674
libtpmtss: Use pkconfig to configure TSS 2.0 includes and libraries
2016-07-20 11:26:07 +02:00
Andreas Steffen
74de8c3727
Version bump to 5.5.0
2016-07-13 13:26:16 +02:00
Andreas Steffen
8fafbffdb7
Version bump to 5.5.0rc1
2016-06-30 16:28:28 +02:00
Andreas Steffen
37ffa99cf2
imcv: Added EFI HCRTM event
2016-06-30 16:20:10 +02:00
Andreas Steffen
ee2644dd3f
testing: Version bump to 4.6.3 kernel and strongSwan 5.5.0
2016-06-30 16:20:10 +02:00
Andreas Steffen
6a24637dcb
Version bump to 5.5.0dr1
2016-06-26 20:11:30 +02:00
Andreas Steffen
4b1513ed59
Merge branch 'tpm2'
...
The libtpmtss library supports both TPM 1.2 and TPM 2.0 Trusted
Platform Modules. Features comprise capability discovery,
listing of PCRs, AIK generation and quote signatures.
2016-06-26 18:40:01 +02:00
Andreas Steffen
b031593641
libtpmtss: Added to integrity checks
2016-06-26 18:19:05 +02:00
Andreas Steffen
2343c48341
aikpub2: Output AIK signature algorithm
2016-06-26 18:19:05 +02:00
Andreas Steffen
721ed31b39
Refactoring to tpm_tss_quote_info object
2016-06-26 18:19:05 +02:00
Andreas Steffen
12e1a06987
libimcv: Changed debug level for functional components from 2 to 3
2016-06-26 18:19:05 +02:00
Andreas Steffen
57e80492eb
libtpmtss: Implemented TSS2 quote() method
2016-06-26 18:19:05 +02:00
Andreas Steffen
bc67802ac8
libtpmtss: Implemented TSS2 read_pcr() method
2016-06-22 15:33:44 +02:00
Andreas Steffen
30d4989aec
libimcv: migrate pts to tpm_tss
2016-06-22 15:33:44 +02:00
Andreas Steffen
8301dc859c
libtpmtss: Get TPM 2.0 capabilities
2016-06-22 15:33:44 +02:00
Andreas Steffen
fedc6769dc
libtpmtss: Retrieve TPM 1.2 version info
2016-06-22 15:33:43 +02:00
Andreas Steffen
c08753bdf4
Created libtpmtss library handling access to v1.2 and v2.0 TPMs
2016-06-22 15:33:43 +02:00
Andreas Steffen
6337770845
aikpub2: --handle option retrieves public key from TPM 2.0 NVRAM
2016-06-22 15:33:43 +02:00
Andreas Steffen
87d356dc47
aikpub2: Convert TSS 2.0 AIK public key blob into PKCS#1 format
2016-06-22 15:33:43 +02:00
Andreas Steffen
310b583925
Merge branch 'test-timing'
2016-05-15 19:03:49 +02:00
Andreas Steffen
78adb5a7b1
testing: Changed gcrypt-ikev1 scenarios to swanctl
2016-05-15 19:02:57 +02:00
Andreas Steffen
141ac4df8f
testing: wait until connections are loaded
2016-05-15 19:02:57 +02:00
Andreas Steffen
1aeaccad11
Version bump to 5.4.1dr4
2016-05-13 12:49:52 +02:00
Andreas Steffen
26aa9c638d
Version bump to 5.4.1dr3
2016-05-08 09:06:16 +02:00
Andreas Steffen
6a6876390d
swanctl: indicate initiator and responder in --list-sas
2016-05-07 17:54:56 +02:00
Andreas Steffen
ab1cebda3a
Version bump to 5.4.1dr2
2016-05-06 22:29:32 +02:00
Andreas Steffen
7cf3a5ae15
Merge branch 'fwd-policy-prio'
2016-05-06 22:28:44 +02:00
Andreas Steffen
b9522f9d64
swanctl: Do not display rekey times for shunts
2016-05-05 14:53:22 +02:00
Andreas Steffen
d95f2ab0cf
Merge branch 'list-conns-plus'
2016-05-04 18:16:32 +02:00
Andreas Steffen
ff4e01dab5
testing: Use reauthentication and set CHILD_SA rekey time, bytes and packets limits
2016-05-04 18:13:52 +02:00
Andreas Steffen
b1df631212
vici list-conns sends reauthentication and rekeying time information
2016-05-04 18:13:52 +02:00
Andreas Steffen
e88f21cf65
swanctl: --list-conns shows eap_id, xauth_id and aaa_id
2016-05-04 18:13:52 +02:00
Andreas Steffen
87381a55a9
testing: uses xauth_id in swanctl/xauth-rsa scenario
2016-05-04 18:13:52 +02:00
Andreas Steffen
278497f2ba
testing: Use absolute path of imv_policy_manager
2016-04-26 17:15:37 +02:00
Andreas Steffen
ef84ad0e11
Updated products in IMV database
2016-04-26 17:15:37 +02:00
Andreas Steffen
afcd466192
swanctl: list EAP type in --list-conns
2016-04-26 17:15:37 +02:00
Andreas Steffen
b85422b90c
testing: -D and -u options in sfdisk are not supported any more
2016-04-26 17:15:37 +02:00
Andreas Steffen
c87f428836
leak-detective: added _IO_file_doallocate to whitelist
2016-04-24 23:34:44 +02:00
Andreas Steffen
4e3234afb4
swanctl: log errors to stderr
2016-04-24 23:33:23 +02:00
Andreas Steffen
029d3a0ce6
testing: updated testing.conf
2016-04-24 13:36:31 +02:00
Andreas Steffen
0ff486f507
testing: Added swanctl/rw-multi-ciphers-ikev1 scenario
2016-04-12 18:50:58 +02:00
Andreas Steffen
c407f163e6
Version bump to 5.4.1dr1
2016-04-11 10:24:12 +02:00
Andreas Steffen
b1c89bb0f9
Merge branch 'kernel-policies'
2016-04-11 10:19:21 +02:00
Andreas Steffen
d3af3b799f
Extended IPsec kernel policy scheme
...
The kernel policy now considers src and dst port masks as well as
restictions to a given network interface. The base priority is
100'000 for passthrough shunts, 200'000 for IPsec policies,
300'000 for IPsec policy traps and 400'000 for fallback drop shunts.
The values 1..30'000 can be used for manually set priorities.
2016-04-09 16:51:02 +02:00
Andreas Steffen
d3edc8aa0f
testing: Added swanctl/manual_prio scenario
2016-04-09 16:51:02 +02:00