Tobias Brunner
|
37fb404833
|
Android.mk of libstrongswan updated
|
2013-01-14 09:16:33 +01:00 |
|
Martin Willi
|
54a1a75b2f
|
Don't use bio_writer_t.skip() to write length field when appending more data
If the writer reallocates its buffer, the length pointer might not be valid
anymore, or even worse, point to an arbitrary allocation.
|
2013-01-11 14:57:08 +01:00 |
|
Martin Willi
|
2cd6c5115b
|
Use raw opcodes for rdrand to build with older binutils
|
2013-01-11 10:45:14 +01:00 |
|
Martin Willi
|
19ae23452a
|
Provide RNG_TRUE quality in rdrand by mixing reseeded outputs using AES
|
2013-01-11 10:45:14 +01:00 |
|
Martin Willi
|
b9148ea232
|
Provide RNG_STRONG quality in rdrand by forcing PRNG reseed after every sample
|
2013-01-11 10:45:14 +01:00 |
|
Martin Willi
|
9fe24b004d
|
Provide RNG_WEAK quality random generator in rdrand
|
2013-01-11 10:45:14 +01:00 |
|
Martin Willi
|
ed8dc6f132
|
Add a rdrand plugin stub detecting availability of RDRAND instructions
|
2013-01-11 10:45:14 +01:00 |
|
Martin Willi
|
ff318ad3e1
|
Include opensslconf.h before checking its defines
|
2013-01-03 11:12:05 +01:00 |
|
Martin Willi
|
2b9e597b54
|
Don't build OpenSSL PKCS#7 code if OPENSSL_NO_CMS defined
|
2013-01-03 11:05:49 +01:00 |
|
Tobias Brunner
|
ef33a4ab82
|
Fixed some typos, courtesy of codespell
|
2012-12-20 09:35:26 +01:00 |
|
Martin Willi
|
0a344da291
|
Fix up serialNumber in openssl PKCS#7 if it has a leading MSB set
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
71dd4e7895
|
Don't handle PKCS#7 containers with infinite length encodings in pkcs7 plugin
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
3c820cdc23
|
Implement PKCS#7 decryption using openssl
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
2a87944a33
|
Make available wrapped certificates while verifying PKCS#7 signatures in openssl
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
04884be3b5
|
Implement openssl PKCS#7 certficiate enumeration
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
e96d945dcd
|
Fix doxygen grouping regarding containers and PKCS#7
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
36f2e11c70
|
Enable pkcs7 plugin when building scepclient on Android
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
03ba8f9e8c
|
Move PKCS#9 attribute lists to pkcs7 plugin, as we currently use it there only
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
804ba5bb50
|
Implement get_attribute() in openssl PKCS#7 backend
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
063ae4e52a
|
Allocate data returned by pkcs7_t.get_attribute()
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
c61723c69f
|
Implement OpenSSL PKCS#7 signed-data parsing and verification
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
568ad938d1
|
Add a stub for OpenSSL PKCS#7 parsing
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
1865fb929a
|
Remove unused monolithic PKCS#7 code
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
6d21c61a09
|
Fix encryption algorithm/key size argument processing in PKCS#7 enveloped-data
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
ee97055835
|
Properly clone PKCS#7 attributes passed to builder
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
8ccf5a4731
|
Fix enum names for container_type_t
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
9e967d7dda
|
Add an enumerator for PKCS#7 contained certificates
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
d3d706f4fc
|
Add a getter for signed PKCS#7 attributes
|
2012-12-19 10:32:08 +01:00 |
|
Martin Willi
|
b95b4730f5
|
Support multiple signerInfos while parsing PKCS#7 signed-data
|
2012-12-19 10:32:07 +01:00 |
|
Martin Willi
|
5d932e4f01
|
Support encoding of PKCS#7 enveloped-data containers
|
2012-12-19 10:32:07 +01:00 |
|
Martin Willi
|
32745a28cf
|
Support encoding of PKCS#7 signed-data containers
|
2012-12-19 10:32:07 +01:00 |
|
Martin Willi
|
3c2986bf0a
|
Support encoding of PKCS#7 "data" containers
|
2012-12-19 10:32:07 +01:00 |
|
Martin Willi
|
637a8abb72
|
Add builder parts to generate PKCS#7 containers
|
2012-12-19 10:32:07 +01:00 |
|
Martin Willi
|
d7aa09104f
|
Implement PKCS#7 enveloped-data parsing and decryption
|
2012-12-19 10:32:07 +01:00 |
|
Martin Willi
|
98bbe0760f
|
Implement PKCS#7 signed-data parsing and verification
|
2012-12-19 10:32:07 +01:00 |
|
Martin Willi
|
83ed1464e3
|
Implement PKCS#7 "data" content type parsing
|
2012-12-19 10:32:07 +01:00 |
|
Martin Willi
|
ed1c430334
|
certificate_t.has_subject() matches for certificate serialNumber
|
2012-12-19 10:32:07 +01:00 |
|
Martin Willi
|
9de6a7a85c
|
Implement generic PKCS#7 contentInfo parsing
|
2012-12-19 10:32:07 +01:00 |
|
Martin Willi
|
bd20f040fd
|
Add a plugin stub for PKCS#7 containers
|
2012-12-19 10:32:07 +01:00 |
|
Martin Willi
|
692f560546
|
Add container plugin features
|
2012-12-19 10:32:07 +01:00 |
|
Martin Willi
|
fc67a932ba
|
Add a generic interface for crypto containers and a more specific PKCS#7 interface
|
2012-12-19 10:32:07 +01:00 |
|
Martin Willi
|
67ca44ccbd
|
Rebuild PKCS#9 encoding after adding new attributes
|
2012-12-19 10:32:07 +01:00 |
|
Martin Willi
|
60c9b5da8d
|
Don't store additional encoding for each PKCS#9 attribute
|
2012-12-19 10:32:07 +01:00 |
|
Martin Willi
|
7f9fedc9bd
|
Unify PKCS#9 set_attribute* methods to a single add_attribute
This way the PKCS#9 implementation does not have to know
the encoding types for values
|
2012-12-19 10:32:07 +01:00 |
|
Martin Willi
|
c1005c120c
|
PKCS#9 coding style cleanups
|
2012-12-19 10:32:07 +01:00 |
|
Martin Willi
|
f0c02e27c4
|
Remove external build_encoding method in PKCS#9
|
2012-12-19 10:32:07 +01:00 |
|
Martin Willi
|
4185c64464
|
Use a ./configure check to detect pthread spinlock availability
_POSIX_SPIN_LOCKS does not seem to be defined correctly on all
systems (Debian libc 2.3.6). Fixes #262.
|
2012-12-18 09:51:33 +01:00 |
|
Martin Willi
|
b091d80aff
|
Replace optionsfrom LGPLv2 header by a GPLv2
|
2012-11-30 18:00:39 +01:00 |
|
Martin Willi
|
7277e4719e
|
Consolidated %any(6) host_t parsing
|
2012-11-29 10:22:52 +01:00 |
|
Martin Willi
|
98d0fd25a8
|
Remove numeric conversion from resolver, it is done directly in host_t
|
2012-11-29 10:22:52 +01:00 |
|