Martin Willi
|
b318e0ab57
|
Load certificates from global suite configuration file
|
2011-01-05 16:45:40 +01:00 |
|
Martin Willi
|
e78ec86d27
|
Added a Suite B conftest utility skeleton using libcharon
|
2011-01-05 16:45:40 +01:00 |
|
Martin Willi
|
65697c2734
|
Added a CIDR notation based host constructor
|
2011-01-05 16:45:40 +01:00 |
|
Martin Willi
|
84f89634ef
|
Moved logger initialization from libcharon to charon
|
2011-01-05 16:45:40 +01:00 |
|
Martin Willi
|
33bfdf6f37
|
Fixed public key construction from PKCS#11 private key
|
2010-12-23 10:29:01 +01:00 |
|
Martin Willi
|
78a547c999
|
Added NEWS for af-alg plugin
|
2010-12-20 10:22:14 +01:00 |
|
Martin Willi
|
23a737eb29
|
Probe for supported AF_ALG algorithms, register dynamically
|
2010-12-20 10:09:20 +01:00 |
|
Martin Willi
|
4ee5d97d57
|
Register algorithms with dependencies only if dependency available
|
2010-12-20 10:00:39 +01:00 |
|
Martin Willi
|
d214ebdf82
|
Register some less common AF_ALG ciphers (cast5, serpent, twofish, blowfish)
|
2010-12-20 09:52:02 +01:00 |
|
Martin Willi
|
533151692f
|
Implemented PRFs using AF_ALG
|
2010-12-20 09:52:02 +01:00 |
|
Martin Willi
|
06eb35efb0
|
Use the AF_ALG wrapper in hasher, crypter and signer
|
2010-12-20 09:52:02 +01:00 |
|
Martin Willi
|
1b5de7ce3b
|
Use a generic AF_ALG wrapper for common operations
|
2010-12-20 09:52:02 +01:00 |
|
Martin Willi
|
a5c973b955
|
Implemented crypter on top of AF_ALG
|
2010-12-20 09:52:02 +01:00 |
|
Martin Willi
|
e75e1c9473
|
Implemented signer interface using AF_ALG
|
2010-12-20 09:52:02 +01:00 |
|
Martin Willi
|
6f08911321
|
Implemented hasher based on AF_ALG
|
2010-12-20 09:52:02 +01:00 |
|
Martin Willi
|
fd67d39e93
|
Added Linux AF_ALG header
|
2010-12-20 09:52:02 +01:00 |
|
Martin Willi
|
71c87e3483
|
Added plugin stub for AF_ALG
|
2010-12-20 09:52:02 +01:00 |
|
Martin Willi
|
e44817df6f
|
Added NEWS about TFC padding
|
2010-12-20 09:51:33 +01:00 |
|
Martin Willi
|
6c302616f1
|
Added a tfc ipsec.conf keyword to control Traffic Flow Confidentiality
|
2010-12-20 09:45:39 +01:00 |
|
Martin Willi
|
55df72e6d5
|
Do not use TFC padding if peer does not support ESPv3
|
2010-12-20 09:45:39 +01:00 |
|
Martin Willi
|
37788b1d06
|
Added a TFC padding option to child_cfg
|
2010-12-20 09:45:39 +01:00 |
|
Martin Willi
|
d86bb6ef4d
|
Implemented Traffic Flow Confidentiality padding in kernel_interface
|
2010-12-20 09:45:39 +01:00 |
|
Martin Willi
|
cf5866b9c0
|
Renamed purgex509/crl to purgecerts/crls to be consistent with list commands
|
2010-12-10 11:21:55 +01:00 |
|
Martin Willi
|
6aa144ddb7
|
Added options to flush CRLs/X509 certs from the cert cache
|
2010-12-10 09:45:22 +01:00 |
|
Martin Willi
|
86993d6b90
|
Never register IKE_SA during checkout_new, as rekeying keeps it checked out
|
2010-12-07 16:30:38 +01:00 |
|
Martin Willi
|
b78ca4b04c
|
Do not query for CKA_ALWAYS_AUTHENTICATE if PKCS#11 Cryptoki version < 2.20
|
2010-11-18 08:56:12 +01:00 |
|
Martin Willi
|
cfa18d14f1
|
Use static args for C_Initialize(), OpenSC does not get a copy of the pointers
|
2010-11-18 08:44:22 +01:00 |
|
Martin Willi
|
93a9926805
|
Added getter for arbitrary environment variables
|
2010-11-17 16:46:23 +01:00 |
|
Martin Willi
|
d93060759e
|
Remove obsolete pool_size argument in processor_create()
|
2010-11-16 09:39:06 +01:00 |
|
Martin Willi
|
9cda39923e
|
Added a PKCS#11 module option to enforce OS Locking functions
|
2010-11-12 16:14:03 +01:00 |
|
Martin Willi
|
213884f947
|
Print full source route on DBG2 that gets installed
|
2010-11-11 09:59:02 +01:00 |
|
Martin Willi
|
57398f621a
|
Do not use CKA_TRUSTED attribute for Cryptoki version < 2.20, handling all certs as trusted
|
2010-11-10 18:36:15 +01:00 |
|
Martin Willi
|
59df2d2a6f
|
Add flags for PKCS#11 libraries with reduced feature set
|
2010-11-10 18:36:15 +01:00 |
|
Martin Willi
|
851d60484e
|
Added a stroke rekey command to trigger IKE/CHILD_SA rekeying manually
|
2010-11-03 15:12:05 +01:00 |
|
Martin Willi
|
bb16217581
|
Store proposal number in proposal_t to reuse it in the selected proposal
According to RFC 5996 3.3.1, we MUST reuse the proposal number of
the selected proposal in the SA payload reply.
|
2010-10-28 15:08:14 +02:00 |
|
Martin Willi
|
d454c586ab
|
Migrated proposal_t to INIT/METHOD macros
|
2010-10-28 13:06:20 +00:00 |
|
Martin Willi
|
806b69a467
|
Migrated proposal_substructure to INIT/METHOD macros, removed unused methods
|
2010-10-28 13:06:20 +00:00 |
|
Martin Willi
|
80f93f20a4
|
Migrated sa_payload to INIT/METHOD macros, removed unused methods
|
2010-10-28 13:06:19 +00:00 |
|
Martin Willi
|
c8f5aaf0a4
|
Renamed mem_cred_t clear function internally to clear_, fixes potential name conflict
|
2010-10-28 13:06:19 +00:00 |
|
Martin Willi
|
185c2669d5
|
Set ownership of all HA ClusterIP control files
|
2010-10-20 14:55:26 +02:00 |
|
Martin Willi
|
384b69d964
|
Set ownership/permissions of HA control socket
|
2010-10-20 14:54:51 +02:00 |
|
Martin Willi
|
e3bde0ef82
|
Prefer the 'server identifier' attribute address to send DHCP requests to
|
2010-10-18 12:32:16 +02:00 |
|
Martin Willi
|
18a4f86500
|
Added NEWS about multiple RADIUS servers, LED plugin
|
2010-10-15 10:13:35 +02:00 |
|
Martin Willi
|
ac544be241
|
Fixed IKEv2 RFC number in NEWS
|
2010-10-15 10:00:55 +02:00 |
|
Martin Willi
|
962300b920
|
Show result of RADIUS authentication along with EAP identity
|
2010-10-07 11:14:09 +02:00 |
|
Martin Willi
|
a8809bb0cb
|
Fixed status_t enum names definition
|
2010-10-04 10:48:00 +02:00 |
|
Martin Willi
|
663e735553
|
Compare subject against all key identifiers in has_subject()
|
2010-09-09 17:46:20 +02:00 |
|
Martin Willi
|
89821331e0
|
Do not change cipherspec while we have buffered handshake fragments pending
|
2010-09-09 14:27:41 +02:00 |
|
Martin Willi
|
30cd31fb69
|
Added a simple led plugin to control Linux LEDs based on IKE activity
|
2010-09-08 12:00:57 +02:00 |
|
Martin Willi
|
7b3c01845f
|
Read the compression type byte for EC groups, only
|
2010-09-08 10:35:29 +02:00 |
|
Martin Willi
|
61df42ccf3
|
Fixed typos
|
2010-09-07 10:24:40 +02:00 |
|
Martin Willi
|
00755453e3
|
Build tls_test script only if TLS stack is enabled
|
2010-09-07 10:21:44 +02:00 |
|
Martin Willi
|
84c9bc4254
|
Added PKCS#11 NEWS
|
2010-09-07 10:21:25 +02:00 |
|
Martin Willi
|
a782b52f6a
|
Added (EAP-)TLS NEWS
|
2010-09-07 10:10:36 +02:00 |
|
Martin Willi
|
31c65eb362
|
Include ec_point_format extension in ClientHello
|
2010-09-06 18:51:38 +02:00 |
|
Martin Willi
|
02281c87a4
|
Added TLS specific EC point formats
|
2010-09-06 18:42:43 +02:00 |
|
Martin Willi
|
ec7d4e70d3
|
Renamed ecp_format to ansi_format, as point formats in TLS use different identifiers
|
2010-09-06 18:37:24 +02:00 |
|
Martin Willi
|
3f5de7b65f
|
Enable the random plugin for scripts
|
2010-09-06 18:11:05 +02:00 |
|
Martin Willi
|
fe559b5156
|
Accept TLS records with zero-length plaintext
|
2010-09-06 17:04:59 +02:00 |
|
Martin Willi
|
adb913adeb
|
Added strongswan.conf option to filter for specific TLS suites
|
2010-09-06 16:51:11 +02:00 |
|
Martin Willi
|
24a5b935e7
|
Added strongswan.conf options to filter cipher suites by specific algorithms
|
2010-09-06 16:51:04 +02:00 |
|
Martin Willi
|
a92a348092
|
Register missing AUTH_HMAC_SHA384 algorithm without truncation
|
2010-09-06 16:50:58 +02:00 |
|
Martin Willi
|
a03eebdf93
|
Fixed key type in TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA
|
2010-09-06 16:50:54 +02:00 |
|
Martin Willi
|
e6cce7ff0d
|
Prepend point format to ECDH public key
|
2010-09-06 15:37:51 +02:00 |
|
Martin Willi
|
e4fd2bb428
|
Log the selected (EC)DH group
|
2010-09-06 15:37:51 +02:00 |
|
Martin Willi
|
0f89143b84
|
Parse unsupported TLS Hello extensions properly
|
2010-09-06 15:37:51 +02:00 |
|
Martin Willi
|
6cf85b35a4
|
Added TLS extension identifiers from RFC 3546
|
2010-09-06 15:37:51 +02:00 |
|
Martin Willi
|
4e68c1cfdc
|
Do not propose (EC)DHE suites if we do not support them
|
2010-09-03 18:24:03 +02:00 |
|
Martin Willi
|
4254257f9d
|
Offer only algorithms/suites we have a registered public key backend for
|
2010-09-03 18:11:03 +02:00 |
|
Martin Willi
|
d987946e80
|
Added a final flag to builder registration to enumerate the actually supported algorithms
|
2010-09-03 18:09:48 +02:00 |
|
Martin Willi
|
f9c0cf862c
|
Fixed key type of ECDHE_RSA groups
|
2010-09-03 17:24:39 +02:00 |
|
Martin Willi
|
3f7bb88ba3
|
Use a dynamic curve enumerator to list/convert TLS named curves
|
2010-09-03 17:24:23 +02:00 |
|
Martin Willi
|
f4c98ae664
|
Use ECDH group check where appropriate
|
2010-09-03 16:53:36 +02:00 |
|
Martin Willi
|
7d7711aba4
|
Added a generic function to check if a DH group is an EC group
|
2010-09-03 16:22:10 +02:00 |
|
Martin Willi
|
2066918da2
|
Add ECDHE enabled cipher suites, including ECDSA variants
|
2010-09-03 14:54:43 +02:00 |
|
Martin Willi
|
033fe95f0b
|
Added support for a non-truncated SHA384 HMAC variant, as used by TLS
|
2010-09-03 14:54:43 +02:00 |
|
Martin Willi
|
4cdade5aae
|
Select private key based on received cipher suites
|
2010-09-03 14:54:43 +02:00 |
|
Martin Willi
|
37a59a8fbf
|
Support for EC curve Hello extension, EC curve fallback
|
2010-09-03 14:54:43 +02:00 |
|
Martin Willi
|
141d7f7abd
|
Added server support for ECDHE key exchange
|
2010-09-03 14:54:43 +02:00 |
|
Martin Willi
|
5fc7297e38
|
Added client support for ECDHE key exchange
|
2010-09-03 14:54:43 +02:00 |
|
Martin Willi
|
691ca54db5
|
Added TLS EC curve type and name identifiers
|
2010-09-03 14:54:43 +02:00 |
|
Martin Willi
|
ccb65463e7
|
Check for queued TLS alerts after each handshake part
|
2010-09-03 09:33:15 +02:00 |
|
Martin Willi
|
ed60dfa14f
|
Added support for MODP_CUSTOM to gcrypt plugin
|
2010-09-03 09:33:15 +02:00 |
|
Martin Willi
|
42b1ac91c4
|
Added support for MODP_CUSTOM to openssl plugin
|
2010-09-03 09:33:15 +02:00 |
|
Martin Willi
|
ef0a8e5892
|
Add DHE enabled RSA variants to the supported TLS suites
|
2010-09-02 19:33:08 +02:00 |
|
Martin Willi
|
f14358a9b5
|
Added TLS server side support for DHE suites
|
2010-09-02 19:33:08 +02:00 |
|
Martin Willi
|
da3f4a9fd0
|
Added TLS client side support for DHE suites
|
2010-09-02 19:33:08 +02:00 |
|
Martin Willi
|
35d9c15d5e
|
Store a MODP group we use for each TLS suite
|
2010-09-02 19:33:08 +02:00 |
|
Martin Willi
|
08d8b9405b
|
Added support for MODP_CUSTOM to gmp plugin
|
2010-09-02 19:33:08 +02:00 |
|
Martin Willi
|
0abd558a65
|
Added a MODP_CUSTOM DH group which takes g and p as constructor arguments
|
2010-09-02 19:33:08 +02:00 |
|
Martin Willi
|
06109c4717
|
Implemented "signature algorithm" hello extension
|
2010-09-02 19:33:08 +02:00 |
|
Martin Willi
|
731611c525
|
Added TLS extension identifiers
|
2010-09-02 19:33:08 +02:00 |
|
Martin Willi
|
d29a82a9d4
|
Added generic TLS data sign/verify, hash/sig algorithm construction
|
2010-09-02 19:33:08 +02:00 |
|
Martin Willi
|
60c4b3b545
|
Continue with a randomized premaster if decryption failed / version mismatches
|
2010-09-02 19:33:08 +02:00 |
|
Martin Willi
|
dbb7c0306c
|
Support different hash/sig algorithms in handshake signing, including ECDSA
|
2010-09-02 13:07:25 +02:00 |
|
Martin Willi
|
99dcaea9bd
|
Added TLS ClientCertificateType identifiers
|
2010-09-02 13:07:24 +02:00 |
|
Martin Willi
|
9dd2ca924e
|
Added TLS specific Hash and Signature Algorithm identifiers
|
2010-09-02 13:07:24 +02:00 |
|
Martin Willi
|
ea6d7cb4be
|
Fixed typos in tls_writer method descriptions
|
2010-09-02 13:07:24 +02:00 |
|
Martin Willi
|
bbdc85b66e
|
Respect key types in stroke key/certificate backend
|
2010-09-02 13:07:23 +02:00 |
|
Martin Willi
|
0ac49c3292
|
Added an enumerator for registered credential builders
|
2010-09-02 10:49:02 +02:00 |
|