Tobias Brunner
|
8e48e0009a
|
Add support for PKCS#7/CMS encrypted-data
|
2013-05-08 15:02:39 +02:00 |
|
Tobias Brunner
|
cb38e2f30a
|
Add test vectors for RC2
|
2013-05-08 15:02:38 +02:00 |
|
Tobias Brunner
|
9d4fc8677f
|
Add implementation of the RC2 block cipher (RFC 2268)
|
2013-05-08 15:02:34 +02:00 |
|
Tobias Brunner
|
4076e3ee91
|
Extract PKCS#5 handling from pkcs8 plugin to separate helper class
|
2013-05-08 14:53:08 +02:00 |
|
Tobias Brunner
|
e07e489d5f
|
agent: Use sshkey plugin to parse keys, adds support for ECDSA
|
2013-05-07 17:08:31 +02:00 |
|
Tobias Brunner
|
dd9e366814
|
sshkey: Add support for ECDSA keys
|
2013-05-07 17:08:31 +02:00 |
|
Tobias Brunner
|
cc4408abcb
|
sshkey: Added builder for SSHKEY RSA keys
|
2013-05-07 15:38:28 +02:00 |
|
Tobias Brunner
|
584d656b77
|
Add sshkey plugin stub that will parse RFC 4253 public keys
|
2013-05-07 14:08:51 +02:00 |
|
Tobias Brunner
|
2d7b55bf9b
|
openssl: Define a default for FIPS_MODE
|
2013-05-03 15:11:19 +02:00 |
|
Andreas Steffen
|
f4de6496a2
|
support of OpenSSL FIPS-140-2 library
|
2013-04-16 12:37:04 +02:00 |
|
Martin Willi
|
cf1696cab9
|
Allow SHA1_Init()/SHA1_Update() to fail if OpenSSL version >= 1.0
|
2013-04-10 18:10:30 +02:00 |
|
Martin Willi
|
b52771fbb2
|
Check RSA_public_decrypt() length before constructing and comparing a chunk
If decryption fails, it returns -1. chunk_equals() should catch that error,
but be more explicit in error checking.
|
2013-04-10 18:10:30 +02:00 |
|
Martin Willi
|
97d975b7bb
|
RSA_check_key() may return -1 if it fails
|
2013-04-10 18:10:30 +02:00 |
|
Martin Willi
|
96a09ce226
|
RAND_bytes/RAND_pseudo_bytes returns -1 if it is not supported by RAND method
|
2013-04-10 18:10:30 +02:00 |
|
Martin Willi
|
0faaab20cd
|
Check return value of ECDSA_Verify() correctly
|
2013-04-10 18:10:30 +02:00 |
|
Tobias Brunner
|
419a9a4fcd
|
Make some private functions in plugins static
Fixes monolithic build.
|
2013-03-27 07:32:55 +01:00 |
|
Tobias Brunner
|
5e551da16b
|
Properly cleanup libmysql
Seems to work correctly with recent MySQL versions.
|
2013-03-19 16:33:07 +01:00 |
|
Tobias Brunner
|
11adf114c1
|
Fixed Doxygen comments after scanning complete src directory
|
2013-03-02 18:31:53 +01:00 |
|
Tobias Brunner
|
4c969f7906
|
openssl: The EVP GCM interface requires at least OpenSSL 1.0.1
|
2013-03-01 16:57:45 +01:00 |
|
Tobias Brunner
|
81f9cd39fd
|
openssl: Provide AES-GCM implementation
|
2013-02-28 18:17:42 +01:00 |
|
Tobias Brunner
|
5f7f4fa398
|
Order of arguments in Doxygen comment fixed
|
2013-02-28 18:17:42 +01:00 |
|
Tobias Brunner
|
0d237763dc
|
openssl: Disable PKCS#7/CMS when building against OpenSSL < 0.9.8g
Fixes #292.
|
2013-02-20 18:34:54 +01:00 |
|
Andreas Steffen
|
a4ddc0bb26
|
Encode RSA public keys in RFC 3110 DNSKEY format
|
2013-02-19 12:25:00 +01:00 |
|
Andreas Steffen
|
f2145c8d3a
|
Moved configuration from resolver manager to unbound plugin
Also streamlined log messages in unbound plugin.
|
2013-02-19 12:25:00 +01:00 |
|
Reto Guadagnini
|
cfd07978d0
|
unbound: Implementation of query method of unbound_resolver_t
|
2013-02-19 11:57:21 +01:00 |
|
Reto Guadagnini
|
5a4126b490
|
unbound: Implemented resolver_response_t as unbound_response_t
|
2013-02-19 11:57:21 +01:00 |
|
Reto Guadagnini
|
4a335a2164
|
unbound: Implemented rr_t as unbound_rr_t
|
2013-02-19 11:57:21 +01:00 |
|
Reto Guadagnini
|
9f963a7cfc
|
Added unbound plugin implementing the resolver interface using libunbound
|
2013-02-19 11:57:21 +01:00 |
|
Martin Willi
|
763e86c093
|
Use CURL_TIMEOUT and not CURL_CONNECTTIMEOUT for FETCHER_TIMEOUT in curl
This allows us to use this timeout beyond DNS resolution. For the initial
connect, we use a hardcoded timeout of 10s for now.
|
2013-02-08 11:08:06 +01:00 |
|
Tobias Brunner
|
a3a190b7bd
|
openssl: Properly honor OPENSSL_NO_* defines
|
2013-01-31 17:33:23 +01:00 |
|
Tobias Brunner
|
25637aa5d8
|
Fix Doxygen comment for rdrand plugin
|
2013-01-31 12:11:37 +01:00 |
|
Tobias Brunner
|
572a707765
|
Properly check MSB in openssl plugin's PKCS#7 implementation
|
2013-01-24 23:36:02 +01:00 |
|
Tobias Brunner
|
69c6a60176
|
g_thread_init() is deprecated since Glib 2.23
|
2013-01-24 19:13:40 +01:00 |
|
Martin Willi
|
1449e6dd55
|
Reseed rdrand after every 128bit sample only
|
2013-01-15 17:41:54 +01:00 |
|
Martin Willi
|
2cd6c5115b
|
Use raw opcodes for rdrand to build with older binutils
|
2013-01-11 10:45:14 +01:00 |
|
Martin Willi
|
19ae23452a
|
Provide RNG_TRUE quality in rdrand by mixing reseeded outputs using AES
|
2013-01-11 10:45:14 +01:00 |
|
Martin Willi
|
b9148ea232
|
Provide RNG_STRONG quality in rdrand by forcing PRNG reseed after every sample
|
2013-01-11 10:45:14 +01:00 |
|
Martin Willi
|
9fe24b004d
|
Provide RNG_WEAK quality random generator in rdrand
|
2013-01-11 10:45:14 +01:00 |
|
Martin Willi
|
ed8dc6f132
|
Add a rdrand plugin stub detecting availability of RDRAND instructions
|
2013-01-11 10:45:14 +01:00 |
|
Martin Willi
|
ff318ad3e1
|
Include opensslconf.h before checking its defines
|
2013-01-03 11:12:05 +01:00 |
|
Martin Willi
|
2b9e597b54
|
Don't build OpenSSL PKCS#7 code if OPENSSL_NO_CMS defined
|
2013-01-03 11:05:49 +01:00 |
|
Tobias Brunner
|
ef33a4ab82
|
Fixed some typos, courtesy of codespell
|
2012-12-20 09:35:26 +01:00 |
|
Martin Willi
|
0a344da291
|
Fix up serialNumber in openssl PKCS#7 if it has a leading MSB set
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
71dd4e7895
|
Don't handle PKCS#7 containers with infinite length encodings in pkcs7 plugin
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
3c820cdc23
|
Implement PKCS#7 decryption using openssl
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
2a87944a33
|
Make available wrapped certificates while verifying PKCS#7 signatures in openssl
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
04884be3b5
|
Implement openssl PKCS#7 certficiate enumeration
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
e96d945dcd
|
Fix doxygen grouping regarding containers and PKCS#7
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
03ba8f9e8c
|
Move PKCS#9 attribute lists to pkcs7 plugin, as we currently use it there only
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
804ba5bb50
|
Implement get_attribute() in openssl PKCS#7 backend
|
2012-12-19 10:32:08 +01:00 |
|