Tobias Brunner
a413571f3b
public-key: Add optional parameters argument to verify() method
2017-11-08 16:48:10 +01:00
Tobias Brunner
677072accc
public-key: Add RSASSA-PSS signature scheme identifier
2017-11-08 16:48:10 +01:00
Tobias Brunner
4e7b7db62f
certificates: Use shared destructor for x509_cdp_t
2017-09-18 10:54:19 +02:00
Tobias Brunner
578d893b4a
credential-manager: Log issuer identity if not found
2017-07-27 13:28:13 +02:00
Tobias Brunner
0b756fbe95
auth-cfg: Don't limit subjectAltName check to received certificates
...
Otherwise this won't work if the certificate is only locally available.
2017-07-27 13:27:19 +02:00
Tobias Brunner
b2473e94a2
Fixed some typos, courtesy of codespell
2017-05-26 14:44:06 +02:00
Tobias Brunner
2e4d110d1e
linked-list: Change return value of find_first() and signature of its callback
...
This avoids the unportable five pointer hack.
2017-05-26 13:56:44 +02:00
Tobias Brunner
525cc46cab
Change interface for enumerator_create_filter() callback
...
This avoids the unportable 5 pointer hack, but requires enumerating in
the callback.
2017-05-26 13:56:44 +02:00
Tobias Brunner
95a63bf281
Migrate all enumerators to venumerate() interface change
2017-05-26 13:56:44 +02:00
Adrian-Ken Rueegsegger
6a8a44be88
credential-manager: Prefer local over global sets
...
Invert set enumeration order to first enumerate local and then global
credential sets.
2017-05-23 16:36:35 +02:00
Andreas Steffen
db1ab1cd99
Reference Edwards-curve signature RFCs
2017-03-20 21:18:00 +01:00
Martin Willi
6c2465b446
builder: Define a builder part for X.509 RFC 3779 address blocks
2017-02-27 09:36:48 +01:00
Tobias Brunner
bafd851896
mem-cred: Add methods to add/remove shared keys with unique identifiers
...
Also added is a method to enumerate the unique identifiers.
2017-02-16 19:21:12 +01:00
Tobias Brunner
dd5ee9d415
mem-cred: Add method to remove a private key with a specific fingerprint
2017-02-16 19:21:12 +01:00
Andreas Steffen
f2eb367adc
Implemented EdDSA for IKEv2 using a pro forma Identity hash function
2016-12-14 11:15:48 +01:00
Andreas Steffen
35bc60cc68
Added support of EdDSA signatures
2016-12-14 11:15:47 +01:00
Andreas Steffen
880c312458
Fixed in-place update of cached base and delta CRLs
2016-10-30 16:37:24 +01:00
Andreas Steffen
2271ebb325
Newer CRLs replace older versions of the CRL in the cache
2016-10-26 12:48:54 +02:00
Tobias Brunner
9ba6548766
mem-cred: Support storing a delta CRL together with its base
...
So far every "newer" CRL (higher serial or by date) replaced an existing
"older" CRL. This meant that delta CRLs replaced an existing base CRL
and that base CRLs weren't added if a delta CRL was already stored. So
the base had to be re-fetched every time after a delta CRL was added.
With this change one delta CRL to the latest base may be stored. A newer
delta CRL will replace an existing delta CRL (but not its base, older
base CRLs are removed, though). And a newer base will replace the existing
base and optional delta CRL.
2016-10-11 17:18:22 +02:00
Andreas Steffen
40f2589abf
gmp: Support of SHA-3 RSA signatures
2016-09-22 17:34:31 +02:00
Tobias Brunner
8efcc78f2b
auth-cfg-wrapper: Fix memory leak with hash-and-URL certificates
...
We wrap the auth-cfg object and its contents, so there is no need to get
an additional reference for the enumerated certificate.
Fixes a44bb9345f ("merged multi-auth branch back into trunk")
2016-09-12 16:20:34 +02:00
Tobias Brunner
0ba905cf24
mem-cred: Fix memory leak when replacing existing CRLs
...
Fixes #1442 .
2016-05-11 12:16:36 +02:00
Andreas Steffen
b12c53ce77
Use standard unsigned integer types
2016-03-24 18:52:48 +01:00
Tobias Brunner
755d076fec
Fix some Doxygen issues
2016-03-11 12:25:14 +01:00
Tobias Brunner
ef9171ad1e
auth-cfg: Add a rule to suspend certificate validation constraints
2016-03-10 11:07:14 +01:00
Tobias Brunner
f371effc5d
credential-manager: Check cache queue when destroying trusted certificate enumerator
...
We already do this in the trusted public key enumerator (which
internally uses the trusted certificate enumerator) but should do so
also when this enumerator is used directly (since the public key
enumerator has the read lock the additional call will just be skipped
there).
2016-03-10 11:07:14 +01:00
Tobias Brunner
5452e3d66e
credential-manager: Make online revocation checks optional for public key enumerator
2016-03-10 11:07:14 +01:00
Tobias Brunner
3c23a75120
auth-cfg: Make IKE signature schemes configurable
...
This also restores the charon.signature_authentication_constraints
functionality, that is, if no explicit IKE signature schemes are
configured we apply all regular signature constraints as IKE constraints.
2016-03-04 16:19:54 +01:00
Thomas Egerer
c8a0781334
ikev2: Diversify signature scheme rule
...
This allows for different signature schemes for IKE authentication and
trustchain verification.
Signed-off-by: Thomas Egerer <[email protected] >
2016-03-04 16:19:53 +01:00
Andreas Steffen
cc874350b8
Apply pubkey and signature constraints in vici plugin
2015-12-17 17:49:48 +01:00
Andreas Steffen
02d431022c
Refactored certificate management for the vici and stroke interfaces
2015-12-12 00:19:24 +01:00
Andreas Steffen
9dd8bfb2ce
Changed some certificate_type_names and added x509_flag_names
2015-12-11 18:26:55 +01:00
Andreas Steffen
fd90f0613c
Print OCSP single responses
2015-12-11 18:26:53 +01:00
Andreas Steffen
3317d0e77b
Standardized printing of certificate information
...
The certificate_printer class allows the printing of certificate
information to a text file (usually stdout). This class is used
by the pki --print and swanctl --list-certs commands as well as
by the stroke plugin.
2015-12-11 18:26:53 +01:00
Tobias Brunner
310a099be4
auth-cfg: Prefer merged rules over existing ones when moving them
...
This is particularly important for single valued rules (e.g.
identities). When copying values this is already handled correctly
by the enumerator and add().
2015-11-12 14:21:06 +01:00
Andreas Steffen
a88d958933
Explicitly mention SHA2 algorithm in BLISS OIDs and signature schemes
2015-11-06 14:55:31 +01:00
Andreas Steffen
f6fede934b
Support BLISS signatures with SHA-3 hash
2015-11-03 21:35:09 +01:00
Tobias Brunner
fdb90723b7
auth-cfg: Don't enforce EAP_RADIUS
...
Basically the same as e79b0e07e4 . EAP_RADIUS is also a virtual method
that will identify itself as a different EAP method later.
2015-08-21 11:40:07 +02:00
Tobias Brunner
58db4edb2c
mem-cred: We don't need a write lock when looking for a certificate
2015-08-20 19:19:37 +02:00
Tobias Brunner
522b1920b6
mem-cred: Add a method to atomically replace all certificates
2015-08-20 19:19:12 +02:00
Tobias Brunner
e79b0e07e4
auth-cfg: Don't enforce EAP_DYNAMIC
...
We now store the actual method on the auth config, which won't match
anymore if rightauth=eap-dynamic is configured.
2015-08-20 18:38:16 +02:00
Tobias Brunner
774c8c3847
auth-cfg: Matching one CA should be enough, similar to peer certificates
...
Not sure if defining multiple CA constraints and enforcing _all_ of them,
i.e. the previous behavior, makes even sense. To ensure a very specific
chain it should be enough to define the last intermediate CA. On the
other hand, the ability to define multiple CAs could simplify configuration.
This can currently only be used with swanctl/VICI based configs as `rightca`
only takes a single DN.
2015-08-17 14:04:19 +02:00
Tobias Brunner
f809e485fb
Fixed some typos
2015-08-13 15:12:34 +02:00
Tobias Brunner
83dcb2d46d
credential-manager: Store BLISS key strength in auth config
2015-03-04 13:54:11 +01:00
Tobias Brunner
ddb09a0603
auth-cfg: Add BLISS key strength constraint
2015-03-04 13:54:11 +01:00
Tobias Brunner
1f648d756b
public-key: Add helper to determine acceptable signature schemes for keys
2015-03-04 13:54:10 +01:00
Tobias Brunner
353294ea5c
public-key: Add helper to map signature schemes to ASN.1 OIDs
...
There is a similar function to map key_type_t and hasher_t to an OID,
but this maps schemes directly (and to use the other function we'd
have to have a function to map schemes to hash algorithms first).
2015-03-04 13:54:08 +01:00
Tobias Brunner
0f29f5ed02
public-key: Add helper to determine key type from signature scheme
2015-03-04 13:54:08 +01:00
Martin Willi
ef2c61bc92
mem-cred: Add a method to unify certificate references, without adding it
...
In contrast to add_cert_ref(), get_cert_ref() does not add the certificate to
the set, but only finds a reference to the same certificate, if found.
2015-03-03 13:50:26 +01:00
Andreas Steffen
27bd0fed93
Allow SHA256 and SHA384 data hash for BLISS signatures.
...
The default is SHA512 since this hash function is also
used for the c_indices random oracle.
2015-02-26 08:56:12 +01:00