Josh Soref
b3ab7a48cc
Spelling fixes
...
* accumulating
* acquire
* alignment
* appropriate
* argument
* assign
* attribute
* authenticate
* authentication
* authenticator
* authority
* auxiliary
* brackets
* callback
* camellia
* can't
* cancelability
* certificate
* choinyambuu
* chunk
* collector
* collision
* communicating
* compares
* compatibility
* compressed
* confidentiality
* configuration
* connection
* consistency
* constraint
* construction
* constructor
* database
* decapsulated
* declaration
* decrypt
* derivative
* destination
* destroyed
* details
* devised
* dynamic
* ecapsulation
* encoded
* encoding
* encrypted
* enforcing
* enumerator
* establishment
* excluded
* exclusively
* exited
* expecting
* expire
* extension
* filter
* firewall
* foundation
* fulfillment
* gateways
* hashing
* hashtable
* heartbeats
* identifier
* identifiers
* identities
* identity
* implementers
* indicating
* initialize
* initiate
* initiation
* initiator
* inner
* instantiate
* legitimate
* libraries
* libstrongswan
* logger
* malloc
* manager
* manually
* measurement
* mechanism
* message
* network
* nonexistent
* object
* occurrence
* optional
* outgoing
* packages
* packets
* padding
* particular
* passphrase
* payload
* periodically
* policies
* possible
* previously
* priority
* proposal
* protocol
* provide
* provider
* pseudo
* pseudonym
* public
* qualifier
* quantum
* quintuplets
* reached
* reading
* recommendation to
* recommendation
* recursive
* reestablish
* referencing
* registered
* rekeying
* reliable
* replacing
* representing
* represents
* request
* request
* resolver
* result
* resulting
* resynchronization
* retriable
* revocation
* right
* rollback
* rule
* rules
* runtime
* scenario
* scheduled
* security
* segment
* service
* setting
* signature
* specific
* specified
* speed
* started
* steffen
* strongswan
* subjectaltname
* supported
* threadsafe
* traffic
* tremendously
* treshold
* unique
* uniqueness
* unknown
* until
* upper
* using
* validator
* verification
* version
* version
* warrior
Closes strongswan/strongswan#164 .
2020-02-11 18:23:07 +01:00
Andreas Steffen
1b510c0467
pubkey-authenticator: Append RSAPSS salt length to debug output
2018-10-26 09:55:07 +02:00
Tobias Brunner
b88f2b3815
pubkey-authenticator: Query private key for supported signature schemes
2018-10-26 09:03:09 +02:00
Tobias Brunner
6627706786
eap-authenticator: Add support for authentication with PPK
2018-09-10 18:03:03 +02:00
Tobias Brunner
18f8249415
pubkey-authenticator: Add support for authentication with PPK
2018-09-10 18:03:03 +02:00
Tobias Brunner
46bdeaf359
psk-authenticator: Add support for authentication with PPK
2018-09-10 18:03:03 +02:00
Tobias Brunner
3fbc95cf54
keymat_v2: Add support for PPKs
2018-09-10 18:03:01 +02:00
Tobias Brunner
1b67166921
Unify format of HSR copyright statements
2018-05-23 16:32:53 +02:00
Tobias Brunner
6143f926ef
ike: Reject certificates that are not compliant with RFC 4945
2018-05-22 09:50:47 +02:00
Tobias Brunner
a48f3d8939
ikev2: Use correct type to check for selected signature scheme
...
The previous code was obviously incorrect and caused strange side effects
depending on the compiler and its optimization flags (infinite looping seen
with GCC 4.8.4, segfault when destroying the private key in build() seen
with clang 4.0.0 on FreeBSD).
Fixes #2579 .
2018-03-21 10:12:59 +01:00
Tobias Brunner
36ae037b81
ikev2: Add hash algorithm used for RSASSA-PSS signature to log message
2017-11-17 09:30:53 +01:00
Tobias Brunner
3fc66e5743
ikev2: Use helpers to build signature auth data
2017-11-08 16:48:10 +01:00
Tobias Brunner
6f97c0d50b
ikev2: Enumerate RSA/PSS schemes and use them if enabled
2017-11-08 16:48:10 +01:00
Tobias Brunner
24b2ede283
ikev2: Support signing with RSASSA-PSS via RFC 7427 signature auth
2017-11-08 16:48:10 +01:00
Tobias Brunner
5f7be58177
ikev2: Verify RSASSA-PSS signatures via RFC 7427 signature auth
2017-11-08 16:48:10 +01:00
Tobias Brunner
84b1c06d0e
keymat_v2: Pass/receive signature schemes as signature_param_t objects
2017-11-08 16:48:10 +01:00
Tobias Brunner
54f8d09261
auth-cfg: Store signature schemes as signature_params_t objects
...
Due to circular references the hasher_from_signature_scheme() helper
does not take a signature_params_t object.
2017-11-08 16:48:10 +01:00
Tobias Brunner
de280c2e03
private-key: Add optional parameters argument to sign() method
2017-11-08 16:48:10 +01:00
Tobias Brunner
a413571f3b
public-key: Add optional parameters argument to verify() method
2017-11-08 16:48:10 +01:00
Tobias Brunner
43b59d1323
ikev2: Don't use SHA-1 for RFC 7427 signature authentication
...
RFC 8247 demoted it to MUST NOT.
References #2427 .
2017-11-08 16:47:24 +01:00
Thomas Egerer
267c1f7083
keymat: Allow keymat to modify signature scheme(s)
...
Signed-off-by: Thomas Egerer <[email protected] >
2017-02-08 10:32:17 +01:00
Andreas Steffen
40f2589abf
gmp: Support of SHA-3 RSA signatures
2016-09-22 17:34:31 +02:00
Andreas Steffen
b12c53ce77
Use standard unsigned integer types
2016-03-24 18:52:48 +01:00
Tobias Brunner
a05cff1ec0
ikev2: Don't do online revocation checks in pubkey authenticator if requested
...
We also update the auth config so the constraints are not enforced.
2016-03-10 11:07:14 +01:00
Tobias Brunner
5452e3d66e
credential-manager: Make online revocation checks optional for public key enumerator
2016-03-10 11:07:14 +01:00
Tobias Brunner
e37e6d6dca
ikev2: Always store signature scheme in auth-cfg
...
As we use a different rule we can always store the scheme.
2016-03-04 16:19:53 +01:00
Thomas Egerer
c8a0781334
ikev2: Diversify signature scheme rule
...
This allows for different signature schemes for IKE authentication and
trustchain verification.
Signed-off-by: Thomas Egerer <[email protected] >
2016-03-04 16:19:53 +01:00
Thomas Egerer
3d15269af9
ikev2: Add debug message about failed IKE authentication
...
Signed-off-by: Thomas Egerer <[email protected] >
2016-02-02 16:16:49 +01:00
Tobias Brunner
49a20ef019
ikev2: Store outer EAP method used to authenticate remote peer in auth-cfg
...
This allows symmetric configuration of EAP methods (i.e. the same value
in leftauth and rightauth) when mutual EAP-only authentication is used.
Previously the client had to configure rightauth=eap or rightauth=any,
which prevented it from using this same config as responder.
2015-08-19 16:19:05 +02:00
Tobias Brunner
6967948241
Initialize variables that some compilers seem to warn about
2015-08-13 15:12:38 +02:00
Martin Willi
161a015782
utils: Use chunk_equals_const() for all cryptographic purposes
2015-04-14 12:02:51 +02:00
Tobias Brunner
708dff0700
ikev2: Move code in pubkey authenticator's build() method into separate functions
2015-03-09 16:59:07 +01:00
Tobias Brunner
03a340c6c6
ikev2: Try all eligible signature schemes
...
Previously, we failed without recovery if a private key did not support
a selected signature scheme (based on key strength and the other peer's
supported hash algorithms).
2015-03-09 16:59:07 +01:00
Tobias Brunner
4e6f102842
ikev2: Try all RSA signature schemes if none is configured
2015-03-04 13:54:12 +01:00
Tobias Brunner
b67ae0f89c
ikev2: Add an option to disable constraints against signature schemes
...
If this is disabled the schemes configured in `rightauth` are only
checked against signature schemes used in the certificate chain and
signature schemes used during IKEv2 are ignored.
Disabling this could be helpful if existing connections with peers that
don't support RFC 7427 use signature schemes in `rightauth` to verify
certificate chains.
2015-03-04 13:54:11 +01:00
Tobias Brunner
cc048f0c50
ikev2: Fall back to SHA-1 signatures for RSA
...
This is really just a fallback to "classic" IKEv2 authentication if the other
peer supports no stronger hash algorithms.
2015-03-04 13:54:10 +01:00
Tobias Brunner
0bdc79b5f9
ikev2: Select a signature scheme appropriate for the given key
...
By enumerating hashes we'd use SHA-1 by default. This way stronger
signature schemes are preferred.
2015-03-04 13:54:10 +01:00
Tobias Brunner
0b14ce5802
ikev2: Log the actual signature scheme used for RFC 7427 authentication
2015-03-04 13:54:09 +01:00
Tobias Brunner
a7bbe59f85
ikev2: Store signature scheme used to verify peer in auth_cfg
...
This enables late connection switching based on the signature scheme used
for IKEv2 and allows to enforce stronger signature schemes.
This may break existing connections with peers that don't support RFC 7427
if signature schemes are currently used in `rightauth` for certificate chain
validation and if the configured schemes are stronger than the default used
for IKE (e.g. SHA-1 for RSA).
2015-03-04 13:54:09 +01:00
Tobias Brunner
6a2a9bfb48
ikev2: Remove private AUTH_BLISS method
...
We use the new signature authentication instead for this. This is not
backward compatible but we only released one version with BLISS support,
and the key format will change anyway with the next release.
2015-03-04 13:54:09 +01:00
Tobias Brunner
295e37ab66
ikev2: Handle RFC 7427 signature authentication in pubkey authenticator
2015-03-04 13:54:09 +01:00
Martin Willi
0c608316dd
ikev2: Merge EAP client authentication details if EAP methods provides them
2015-03-03 14:08:00 +01:00
Andreas Steffen
b6bb32e658
Implemented full BLISS support for IKEv2 public key authentication and the pki tool
2014-11-29 14:51:18 +01:00
Martin Willi
3ecfc83c6b
payload: Use common prefixes for all payload type identifiers
...
The old identifiers did not use a proper namespace and often clashed with
other defines.
2014-06-04 15:53:03 +02:00
Martin Willi
d8a94c18c6
Apply a mutual EAP auth_cfg not before the EAP method completes
2013-02-26 13:15:27 +01:00
Tobias Brunner
7f2e3091ee
Log the proper type for virtual EAP methods
2012-08-31 11:42:03 +02:00
Tobias Brunner
cc4eec56f7
Encode EAP-Naks in expanded format if we got an expanded type request
...
Since methods defined by the IETF (vendor ID 0) could also be encoded in
expanded type format the previous check was insufficient.
2012-08-31 11:40:27 +02:00
Tobias Brunner
78e8dca94f
Allow clients to request a configured EAP method via EAP-Nak
2012-08-31 11:40:27 +02:00
Tobias Brunner
34742f1bf8
Virtual EAP methods handle EAP-Naks themselves
2012-08-31 11:40:27 +02:00
Tobias Brunner
af04233e14
Send EAP-Nak with supported types if requested type is unsupported
2012-08-31 11:40:27 +02:00