Tobias Brunner
|
69c6a60176
|
g_thread_init() is deprecated since Glib 2.23
|
2013-01-24 19:13:40 +01:00 |
|
Martin Willi
|
51dbcf6497
|
After merging the used trustchain with config, move used certificate to front
|
2013-01-18 11:59:27 +01:00 |
|
Martin Willi
|
9a06a93ce7
|
Try to build a trustchain for all configured certificates before enforcing one
This enables the daemon to select from multiple configured certificates
by building trustchains against the received certificate requests.
|
2013-01-18 09:33:15 +01:00 |
|
Martin Willi
|
f29783af8c
|
Make AUTH_RULE_SUBJECT cert multi-valued
Constraints having multiple subject certs defined are fulfilled if
authentication used one of the listed certificates.
|
2013-01-18 09:33:15 +01:00 |
|
Martin Willi
|
7fb81886b9
|
Add a bio_reader_t constructor variant freeing passed data during destruction
|
2013-01-15 17:43:05 +01:00 |
|
Martin Willi
|
47af9848a2
|
Add a chunk_from_str() initializer that does not include 0-terminator
|
2013-01-15 17:43:05 +01:00 |
|
Martin Willi
|
1449e6dd55
|
Reseed rdrand after every 128bit sample only
|
2013-01-15 17:41:54 +01:00 |
|
Martin Willi
|
426f34baf9
|
Respect given address family when resolving "%any"
|
2013-01-14 10:26:12 +01:00 |
|
Tobias Brunner
|
37fb404833
|
Android.mk of libstrongswan updated
|
2013-01-14 09:16:33 +01:00 |
|
Martin Willi
|
54a1a75b2f
|
Don't use bio_writer_t.skip() to write length field when appending more data
If the writer reallocates its buffer, the length pointer might not be valid
anymore, or even worse, point to an arbitrary allocation.
|
2013-01-11 14:57:08 +01:00 |
|
Martin Willi
|
2cd6c5115b
|
Use raw opcodes for rdrand to build with older binutils
|
2013-01-11 10:45:14 +01:00 |
|
Martin Willi
|
19ae23452a
|
Provide RNG_TRUE quality in rdrand by mixing reseeded outputs using AES
|
2013-01-11 10:45:14 +01:00 |
|
Martin Willi
|
b9148ea232
|
Provide RNG_STRONG quality in rdrand by forcing PRNG reseed after every sample
|
2013-01-11 10:45:14 +01:00 |
|
Martin Willi
|
9fe24b004d
|
Provide RNG_WEAK quality random generator in rdrand
|
2013-01-11 10:45:14 +01:00 |
|
Martin Willi
|
ed8dc6f132
|
Add a rdrand plugin stub detecting availability of RDRAND instructions
|
2013-01-11 10:45:14 +01:00 |
|
Martin Willi
|
ff318ad3e1
|
Include opensslconf.h before checking its defines
|
2013-01-03 11:12:05 +01:00 |
|
Martin Willi
|
2b9e597b54
|
Don't build OpenSSL PKCS#7 code if OPENSSL_NO_CMS defined
|
2013-01-03 11:05:49 +01:00 |
|
Tobias Brunner
|
ef33a4ab82
|
Fixed some typos, courtesy of codespell
|
2012-12-20 09:35:26 +01:00 |
|
Martin Willi
|
0a344da291
|
Fix up serialNumber in openssl PKCS#7 if it has a leading MSB set
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
71dd4e7895
|
Don't handle PKCS#7 containers with infinite length encodings in pkcs7 plugin
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
3c820cdc23
|
Implement PKCS#7 decryption using openssl
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
2a87944a33
|
Make available wrapped certificates while verifying PKCS#7 signatures in openssl
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
04884be3b5
|
Implement openssl PKCS#7 certficiate enumeration
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
e96d945dcd
|
Fix doxygen grouping regarding containers and PKCS#7
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
36f2e11c70
|
Enable pkcs7 plugin when building scepclient on Android
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
03ba8f9e8c
|
Move PKCS#9 attribute lists to pkcs7 plugin, as we currently use it there only
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
804ba5bb50
|
Implement get_attribute() in openssl PKCS#7 backend
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
063ae4e52a
|
Allocate data returned by pkcs7_t.get_attribute()
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
c61723c69f
|
Implement OpenSSL PKCS#7 signed-data parsing and verification
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
568ad938d1
|
Add a stub for OpenSSL PKCS#7 parsing
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
1865fb929a
|
Remove unused monolithic PKCS#7 code
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
6d21c61a09
|
Fix encryption algorithm/key size argument processing in PKCS#7 enveloped-data
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
ee97055835
|
Properly clone PKCS#7 attributes passed to builder
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
8ccf5a4731
|
Fix enum names for container_type_t
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
9e967d7dda
|
Add an enumerator for PKCS#7 contained certificates
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
d3d706f4fc
|
Add a getter for signed PKCS#7 attributes
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
b95b4730f5
|
Support multiple signerInfos while parsing PKCS#7 signed-data
|
2012-12-19 10:32:07 +01:00 |
|
Martin Willi
|
5d932e4f01
|
Support encoding of PKCS#7 enveloped-data containers
|
2012-12-19 10:32:07 +01:00 |
|
Martin Willi
|
32745a28cf
|
Support encoding of PKCS#7 signed-data containers
|
2012-12-19 10:32:07 +01:00 |
|
Martin Willi
|
3c2986bf0a
|
Support encoding of PKCS#7 "data" containers
|
2012-12-19 10:32:07 +01:00 |
|
Martin Willi
|
637a8abb72
|
Add builder parts to generate PKCS#7 containers
|
2012-12-19 10:32:07 +01:00 |
|
Martin Willi
|
d7aa09104f
|
Implement PKCS#7 enveloped-data parsing and decryption
|
2012-12-19 10:32:07 +01:00 |
|
Martin Willi
|
98bbe0760f
|
Implement PKCS#7 signed-data parsing and verification
|
2012-12-19 10:32:07 +01:00 |
|
Martin Willi
|
83ed1464e3
|
Implement PKCS#7 "data" content type parsing
|
2012-12-19 10:32:07 +01:00 |
|
Martin Willi
|
ed1c430334
|
certificate_t.has_subject() matches for certificate serialNumber
|
2012-12-19 10:32:07 +01:00 |
|
Martin Willi
|
9de6a7a85c
|
Implement generic PKCS#7 contentInfo parsing
|
2012-12-19 10:32:07 +01:00 |
|
Martin Willi
|
bd20f040fd
|
Add a plugin stub for PKCS#7 containers
|
2012-12-19 10:32:07 +01:00 |
|
Martin Willi
|
692f560546
|
Add container plugin features
|
2012-12-19 10:32:07 +01:00 |
|
Martin Willi
|
fc67a932ba
|
Add a generic interface for crypto containers and a more specific PKCS#7 interface
|
2012-12-19 10:32:07 +01:00 |
|
Martin Willi
|
67ca44ccbd
|
Rebuild PKCS#9 encoding after adding new attributes
|
2012-12-19 10:32:07 +01:00 |
|