Thomas Egerer
|
93818392cd
|
Change order of ocsp uris when parsing a cert
|
2011-11-04 11:11:17 +01:00 |
|
Thomas Egerer
|
42e2da606c
|
Use chunk_clear to memwipe shared secret
|
2011-11-04 11:11:17 +01:00 |
|
Martin Willi
|
f5c574e17b
|
Fixed AES key length in openssl plugin
|
2011-10-14 10:05:47 +02:00 |
|
Martin Willi
|
02572b84f9
|
Announce openssl features only if actually supported
|
2011-10-14 10:05:46 +02:00 |
|
Martin Willi
|
9dc54fc56a
|
Add features support to openssl plugin
|
2011-10-14 10:05:45 +02:00 |
|
Tobias Brunner
|
28bcbc297f
|
openssl: Adding support for key usage x509 extension.
|
2011-10-05 15:10:12 +02:00 |
|
Martin Willi
|
24fa80ac91
|
Fixed compiler warnings in openssl plugin
|
2011-09-07 14:23:27 +02:00 |
|
Tobias Brunner
|
0e080d9b64
|
Don't compile login() in openssl_rsa_private_key_t if ENGINE support is disabled in OpenSSL.
|
2011-05-13 13:11:11 +02:00 |
|
Tobias Brunner
|
70f918ec1d
|
chunk_clear not clear_chunk.
|
2011-05-10 15:40:46 +02:00 |
|
Martin Willi
|
f7812f6492
|
Wipe memory after using key material (incomplete, to be continued)
|
2011-05-09 14:36:15 +02:00 |
|
Martin Willi
|
5b0bcfb1fc
|
Revert alloc_str changes
This reverts commit fdead26ffe.
This reverts commit 3e2419ebe3.
This reverts commit 17ce69b47a.
|
2011-04-21 13:35:31 +02:00 |
|
Martin Willi
|
3e2419ebe3
|
Use thread save settings alloc_str function where appropriate
|
2011-04-21 10:48:16 +02:00 |
|
Martin Willi
|
c55818ebb0
|
Added a (not yet implemented) plugin_t method to reload plugin configuration
|
2011-04-15 10:07:13 +02:00 |
|
Martin Willi
|
787b5884aa
|
Added a get_name() function to plugin_t, create_plugin_enumerator enumerates over plugin_t
|
2011-04-15 10:07:12 +02:00 |
|
Andreas Steffen
|
d390b3b901
|
[hopefully] fixed pathlen problem on ARM platforms
|
2011-02-10 15:51:18 +01:00 |
|
Andreas Steffen
|
c4fd3b2f42
|
introduced libstrongswan.x509.enforce_critical parameter
|
2011-02-05 09:01:18 +01:00 |
|
Andreas Steffen
|
8b42864884
|
fixed checking of unknown critical extensions in openssl_x509
|
2011-01-31 14:37:48 +01:00 |
|
Martin Willi
|
b3d359e58f
|
Use a generic getter for all numerical X.509 constraints
|
2011-01-05 16:46:05 +01:00 |
|
Martin Willi
|
55e4d8982f
|
Added support for delta CRLs to x509 plugin
|
2011-01-05 16:46:03 +01:00 |
|
Martin Willi
|
a6478a0402
|
Simplified format of x509 CRL URI parsing/enumerator
|
2011-01-05 16:46:03 +01:00 |
|
Martin Willi
|
e24a02a28f
|
Fail on critical extensions in openssl CRLs
|
2011-01-05 16:46:03 +01:00 |
|
Martin Willi
|
a742d97fb8
|
Added support for policyConstraints to x509 plugin
|
2011-01-05 16:46:02 +01:00 |
|
Martin Willi
|
5dba5852fc
|
Slightly renamed X509_NO_PATH_LEN_CONSTRAINT to use it for PolicyConstraints, too
|
2011-01-05 16:46:02 +01:00 |
|
Martin Willi
|
5a0caa4b3a
|
Added policyMappings support to x509 plugin
|
2011-01-05 16:46:02 +01:00 |
|
Martin Willi
|
20bd78106e
|
Added certificatePolicy support to x509 plugin
|
2011-01-05 16:46:02 +01:00 |
|
Martin Willi
|
b0892d094c
|
Fail when parsing unsupported critical extensions in openssl_x509
|
2011-01-05 16:46:02 +01:00 |
|
Martin Willi
|
a6850b8499
|
Do not parse certificates with invalid version in openssl plugin
|
2011-01-05 16:46:01 +01:00 |
|
Martin Willi
|
dbfbbec368
|
Added name constraint enumerator to x509 interface
|
2011-01-05 16:46:00 +01:00 |
|
Martin Willi
|
4e508517d7
|
Added support for CRL Issuers to x509 and OpenSSL plugins
|
2011-01-05 16:45:55 +01:00 |
|
Andreas Steffen
|
5932f41fcc
|
trace back crypto algorithms to the plugins that registered them
|
2010-12-18 16:31:12 +01:00 |
|
Tobias Brunner
|
ed174fd7e2
|
Added missing include for RAND_seed and RAND_status.
|
2010-10-21 14:16:09 +02:00 |
|
Martin Willi
|
663e735553
|
Compare subject against all key identifiers in has_subject()
|
2010-09-09 17:46:20 +02:00 |
|
Martin Willi
|
d987946e80
|
Added a final flag to builder registration to enumerate the actually supported algorithms
|
2010-09-03 18:09:48 +02:00 |
|
Martin Willi
|
42b1ac91c4
|
Added support for MODP_CUSTOM to openssl plugin
|
2010-09-03 09:33:15 +02:00 |
|
Martin Willi
|
2291754ddf
|
Unwrap crlNumber INTEGER in openssl CRL parsing
|
2010-08-30 11:23:46 +02:00 |
|
Martin Willi
|
ba31fe1fd6
|
Use a seperate section for each nested struct member in INIT macro
|
2010-08-18 12:15:03 +02:00 |
|
Martin Willi
|
e2c3b4820b
|
Variable key length crypters use default key length if zero given
|
2010-08-16 17:06:27 +02:00 |
|
Martin Willi
|
f7c04c5b37
|
Add dedicated getter for the IV size to the crypter_t interface
|
2010-08-13 17:11:53 +02:00 |
|
Martin Willi
|
4ec53e95f5
|
Double check that the OpenSSL RNG has been seeded, do so otherwise
|
2010-08-11 10:12:50 +02:00 |
|
Martin Willi
|
d775af9d18
|
Implemented RSA en-/decryption in openssl plugin
|
2010-08-11 09:53:45 +02:00 |
|
Martin Willi
|
07d2b39123
|
Parse important extendedKeyUsage flags in openssl plugin
|
2010-08-10 18:46:31 +02:00 |
|
Martin Willi
|
a0a8aaaf4f
|
Parse UPN subjectAltName in openssl plugin
|
2010-08-10 18:46:31 +02:00 |
|
Martin Willi
|
a944d2092b
|
Use bits instead of bytes for a private/public key
|
2010-08-10 18:46:30 +02:00 |
|
Martin Willi
|
33ddaaabec
|
Added support for different encryption schemes to private/public keys
|
2010-08-10 18:46:30 +02:00 |
|
Martin Willi
|
57202484e4
|
Migrated remaining classes in openssl plugin to INIT/METHOD macros
|
2010-08-10 18:46:30 +02:00 |
|
Martin Willi
|
0556667dca
|
Use credential sets to load smartcard keys
|
2010-08-04 09:26:21 +02:00 |
|
Martin Willi
|
0b8b664056
|
Pass the PKCS11 keyid as chunk, not as string
|
2010-08-04 09:26:20 +02:00 |
|
Martin Willi
|
353d10d590
|
Reuse generic passphrase build part, not a dedicated PIN part
|
2010-08-04 09:26:20 +02:00 |
|
Martin Willi
|
3479c27931
|
Support module names in %smartcard specifier, streamlined smartcard building
|
2010-08-04 09:26:20 +02:00 |
|
Martin Willi
|
0406eeaacb
|
Support different encoding types in certificate.get_encoding()
|
2010-07-13 13:53:20 +02:00 |
|