Andreas Steffen
65ce7ec0c4
Version bump to 5.5.3
2017-05-29 12:02:48 +02:00
Andreas Steffen
38a8ecadb7
x509: nameConstraints sequence does not require a loop
...
Fixes: CVE-2017-9023
2017-05-29 11:05:04 +02:00
Andreas Steffen
f2f9edbbc0
unit-tests: Updated asn1-parser tests
2017-05-29 11:05:04 +02:00
Andreas Steffen
407fcca200
asn1-parser: Fix CHOICE parsing
...
Fixes: CVE-2017-9023
2017-05-29 11:05:04 +02:00
Andreas Steffen
89f05ed5a9
imv-swid: Fixed memory leak in http REST interface
2017-05-29 10:59:22 +02:00
Andreas Steffen
29e1c58643
leak-detective: Whitelisted memory leaks in FHH IMCs and IMVs
2017-05-29 10:59:04 +02:00
Andreas Steffen
c82be739bc
imv-test: Fixed memory leak in server retry use case
2017-05-29 10:58:33 +02:00
Andreas Steffen
fca4e70bd3
libtnccs: Fixed memory leak of global variables in libxml2
2017-05-29 10:57:34 +02:00
Andreas Steffen
2d5a79bf59
testing: Added swanctl/rw-eap-md5-id-rsa scenario
2017-05-26 14:36:25 +02:00
Andreas Steffen
7272fa0c8d
README: Converted to swanctl configuration scheme
2017-05-26 14:36:25 +02:00
Andreas Steffen
a5f7a4c790
Version bump to 5.3.3dr2
2017-05-08 22:38:12 +02:00
Andreas Steffen
b0dcf33f0f
x509: Evaluate return codes of parsing functions
2017-05-08 16:44:25 +02:00
Andreas Steffen
d38d1fcd68
Version bump to 5.5.3dr1
2017-04-26 21:29:42 +02:00
Andreas Steffen
25217488d2
testing: Created swanctl/rw-eap-aka-sql-rsa scenario
2017-04-26 20:38:23 +02:00
Andreas Steffen
64f9fa9e9f
testing: Created ikev2/rw-eap-aka-sql-rsa scenario
...
This test scenario tests the eap-simaka-sql plugin.
2017-04-26 20:38:23 +02:00
Andreas Steffen
2fad3460fa
eap-simaka-sql: Fixed database column from use to used
2017-04-26 20:38:00 +02:00
Andreas Steffen
bb2ba9f15d
Version bump to 5.5.2
2017-03-27 16:57:03 +02:00
Andreas Steffen
c5ccf933ec
testing: List BLIS certs in swanctl/rw-newhope-bliss scenario
2017-03-27 16:56:50 +02:00
Andreas Steffen
7c672e6118
Version bump to 5.2.2rc1
2017-03-21 09:09:43 +01:00
Andreas Steffen
1732ca7b5b
testing: Updated OCSP certificate for carol
2017-03-21 09:09:06 +01:00
Andreas Steffen
efc1b98461
Allow x25519 as an alias of the curve25519 KE algorithm
2017-03-20 21:18:00 +01:00
Andreas Steffen
db1ab1cd99
Reference Edwards-curve signature RFCs
2017-03-20 21:18:00 +01:00
Andreas Steffen
2b233c8a64
The tpm plugin offers random number generation
...
The tpm plugin can be used to derive true random numbers from a
TPM 2.0 device. The get_random method must be explicitly enabled
in strongswan.conf with the plugin.tpm.use_rng = yes option.
2017-03-20 21:16:10 +01:00
Andreas Steffen
25bfb338a2
Version bump to 5.5.2dr7
2017-03-06 20:21:40 +01:00
Andreas Steffen
4a620a97a0
aikpub2: Removed aikpub2 tool
...
The aikpub2 tool has been replaced by pki --pub|--req --keyid hex ..
where keyid indicates the TPM 2.0 private key object handle. Thus
either the public key in PKCS#1 format can be extracted or a PKCS#10
certificate request signed by the TPM private key can be generated.
2017-03-06 19:35:05 +01:00
Andreas Steffen
ab94f76df6
pki: Add key object handle of smartcard or TPM private key as an argument to pki --keyid
2017-03-06 18:54:09 +01:00
Andreas Steffen
cfdccc93f5
utils: chunk_from_hex() skips optional 0x prefix
2017-03-06 18:54:09 +01:00
Andreas Steffen
2d41e1c51c
pki: Edited keyid parameter use in various pki man pages and usage outputs
2017-03-06 18:54:09 +01:00
Andreas Steffen
6885375e66
Version bump to 5.5.2dr6
2017-03-03 09:34:50 +01:00
Andreas Steffen
2da6a5f541
Add keyid of smartcard or TPM private key as an argument to pki --req
2017-03-02 20:30:24 +01:00
Andreas Steffen
f43850b3b9
Version bump to 5.5.2dr5
2017-02-23 17:31:11 +01:00
Andreas Steffen
af9341c2c0
Use of TPM 2.0 private keys for signatures via tpm plugin
2017-02-22 12:18:26 +01:00
Andreas Steffen
e8736028e6
Implement signatures with private keys bound to TPM 2.0
2017-02-21 20:37:32 +01:00
Andreas Steffen
9ad147ac63
Version bump to 5.5.2dr4
2017-01-02 15:46:27 +01:00
Andreas Steffen
bda3a573f4
Merge branch 'disable_ocsp'
2017-01-02 14:35:39 +01:00
Andreas Steffen
91a4a4aa83
testing: Added swanctl/ocsp-disabled scenario
2017-01-02 14:34:39 +01:00
Andreas Steffen
db0953d41f
testing: Added swanctl/ocsp-signer-cert scenario
2017-01-02 14:34:18 +01:00
Andreas Steffen
e3f63c6469
revocation: OCSP and/or CRL fetching can be disabled
2016-12-30 18:12:53 +01:00
Andreas Steffen
08253bbba3
testing: Convert swanctl scenarios to curve-25519
2016-12-30 16:22:12 +01:00
Andreas Steffen
65797c9faf
Version bump to 5.5.2dr3 and Linux kernel 4.9
2016-12-17 18:10:13 +01:00
Andreas Steffen
470e61ae77
testing: strongTNC does not come with django.db any more
2016-12-17 18:09:20 +01:00
Andreas Steffen
3c1e5ad6ce
testing: Added ikev2/net2net-ed25519 scenario
2016-12-17 18:07:29 +01:00
Andreas Steffen
bd2f2b11fc
stroke: Load general PKCS#8 private keys
2016-12-17 18:06:11 +01:00
Andreas Steffen
9da89eeb4f
Merge branch 'Ed25519'
2016-12-16 12:24:54 +01:00
Andreas Steffen
4f19112b1f
Moved Ed25519 tests to libstrongswan
2016-12-14 11:57:36 +01:00
Andreas Steffen
e9c2b6658b
unit-tests: Completed coverage of hasher, crypter and libnttfft
2016-12-14 11:15:48 +01:00
Andreas Steffen
94ae1ac18e
Added swanctl/net2net-ed2559 scenario and needed Ed25519 certificates
2016-12-14 11:15:48 +01:00
Andreas Steffen
f2eb367adc
Implemented EdDSA for IKEv2 using a pro forma Identity hash function
2016-12-14 11:15:48 +01:00
Andreas Steffen
d47ad3d67e
Added Ed25519 ref10 implementation from libsodium
2016-12-14 11:15:47 +01:00
Andreas Steffen
35bc60cc68
Added support of EdDSA signatures
2016-12-14 11:15:47 +01:00
Andreas Steffen
011195f1a9
Version bump to 5.5.2dr2
2016-11-14 16:20:51 +01:00
Andreas Steffen
99c03e9a11
testing: make curve25519 the default DH group
2016-11-14 16:20:51 +01:00
Andreas Steffen
4a97999466
Version bump to 5.5.2dr1
2016-10-30 17:34:05 +01:00
Andreas Steffen
880c312458
Fixed in-place update of cached base and delta CRLs
2016-10-30 16:37:24 +01:00
Andreas Steffen
2271ebb325
Newer CRLs replace older versions of the CRL in the cache
2016-10-26 12:48:54 +02:00
Andreas Steffen
e6a4bd83ff
Version bump to 5.5.1
2016-10-20 12:57:00 +02:00
Andreas Steffen
4d77fcbec9
Version bump to 5.5.1rc2
2016-10-18 18:14:57 +02:00
Andreas Steffen
ba6c7a52c0
testing: Renewed expired certificates
2016-10-18 18:13:58 +02:00
Andreas Steffen
cb8f436112
added XOF dependencies of bliss and ntru plugins
2016-10-18 16:28:43 +02:00
Andreas Steffen
d167776ff9
testing: enable MACsec in guest kernel
2016-10-18 16:25:19 +02:00
Andreas Steffen
a617223ed5
Version bump to 5.5.1rc1
2016-10-11 19:21:36 +02:00
Andreas Steffen
8a56405a82
Merge branch 'cache-crls'
2016-10-11 17:19:29 +02:00
Andreas Steffen
85b5a6ace2
Save both base and delta CRLs to disk
2016-10-11 17:18:22 +02:00
Andreas Steffen
2a2669ee3e
vici: strongswan.conf cache_crls = yes saves fetched CRLs to disk
2016-10-11 17:18:22 +02:00
Andreas Steffen
a9562a3f58
testing: Added swanctl/net2net-multicast scenario
2016-09-27 18:36:28 +02:00
Andreas Steffen
d7e0ce2878
testing: Added ikev2/net2net-multicast scenario
2016-09-27 18:36:28 +02:00
Andreas Steffen
6b3e408ba5
Version bump to 5.5.1dr5
2016-09-22 17:36:37 +02:00
Andreas Steffen
d505658038
testing: Added swanctl/net2net-sha3-rsa-cert and swanctl/rw-eap-tls-sha3-rsa scenarios
2016-09-22 17:34:31 +02:00
Andreas Steffen
40f2589abf
gmp: Support of SHA-3 RSA signatures
2016-09-22 17:34:31 +02:00
Andreas Steffen
c54d1ef12c
bliss sampler unit-test: Fixed enumeration type
2016-09-22 10:46:39 +02:00
Andreas Steffen
a3a8b4acae
bliss: bliss_sampler expects XOF type
2016-09-22 09:23:47 +02:00
Andreas Steffen
e31ed9ab98
Version bump to 5.5.1dr4
2016-09-21 14:14:42 +02:00
Andreas Steffen
188b190a70
mgf1: Refactored MGF1 as an XOF
2016-09-21 06:40:52 +02:00
Andreas Steffen
8aaa6de322
Version bump to 5.5.1dr3
2016-09-15 11:45:17 +02:00
Andreas Steffen
29a48b4c69
Merge branch 'flush-certs'
2016-09-15 11:39:16 +02:00
Andreas Steffen
2c7cfe7630
vici: flush-certs command flushes certificate cache
...
When fresh CRLs are released with a high update frequency (e.g.
every 24 hours) or OCSP is used then the certificate cache gets
quickly filled with stale CRLs or OCSP responses. The new VICI
flush-certs command allows to flush e.g. cached CRLs or OCSP
responses only. Without the type argument all kind of certificates
(e.g. also received end entity and intermediate CA certificates)
are purged.
2016-09-13 17:02:59 +02:00
Andreas Steffen
de44fd748a
pt-tls-client: Added support of ECDSA keys
2016-08-31 17:06:47 +02:00
Andreas Steffen
288ee54875
libimcv: No need to load AIK pubkey if AIK certificate is available
2016-08-31 16:12:55 +02:00
Andreas Steffen
d2577aa3c5
Version bump to 5.5.1dr2
2016-08-26 22:55:41 +02:00
Andreas Steffen
d125941802
libtpmtss: TCTI finalization call changed
2016-08-25 13:22:51 +02:00
Andreas Steffen
36bf2b1bc5
conf: aikpub2.opt added to Makefile.am
2016-08-25 13:22:51 +02:00
Andreas Steffen
ce20979ce2
testing: Virtual IPs went missing
2016-08-16 17:18:17 +02:00
Andreas Steffen
3bca51e430
unit-tests: Removed unused variable
2016-08-11 17:01:33 +02:00
Andreas Steffen
5afaf0dba2
Version bump to 5.5.1dr1
2016-08-10 18:11:53 +02:00
Andreas Steffen
53332c9390
Merge branch 'newhope'
2016-08-10 16:23:04 +02:00
Andreas Steffen
c1a1f9f548
testing: Added swanctl/rw-newhope-bliss scenario
2016-08-10 15:14:26 +02:00
Andreas Steffen
1e0dc2c329
testing: Add chapoly, ntru and newhope plugins to crypto and integrity tests
2016-08-10 14:34:27 +02:00
Andreas Steffen
277ef8c2fa
testing: Added ikev2/rw-newhope-bliss scenario
2016-08-10 14:22:00 +02:00
Andreas Steffen
1342bd3386
unit-tests: Created newhope unit-tests
2016-08-10 14:22:00 +02:00
Andreas Steffen
393688aea0
Created newhope plugin implementing the New Hope key exchange algorithm
2016-08-10 14:22:00 +02:00
Andreas Steffen
1fddb0b92e
xof: Added ChaCha20 stream as XOF
2016-08-06 12:09:05 +02:00
Andreas Steffen
8993cb556e
utils: Defined uletoh16() and htole16()
2016-08-06 12:09:05 +02:00
Andreas Steffen
b8070e2c85
integrity-test: Added ntru_param_sets to read-only segment
2016-07-29 12:36:15 +02:00
Andreas Steffen
17e4ca6ac9
integrity-test: Added bliss_param_sets to read-only segment
2016-07-29 12:36:15 +02:00
Andreas Steffen
7256c68da0
integrity-test: check code and ro segments of libnttfft
2016-07-29 12:36:15 +02:00
Andreas Steffen
d305f251a5
Created libnttfft
...
This makes Number Theoretic Transforms (NTT) based on the efficient
Fast-Fourier-Transform (FFT) available to multiple plugins.
2016-07-29 12:36:15 +02:00
Andreas Steffen
65f2ecb86d
Share twiddle factors table between 512 and 1024 point FFT
2016-07-29 12:36:14 +02:00
Andreas Steffen
68075fb7a7
Implemented FFT with n = 1024 and q = 11289 using Montgomery arithmetic
2016-07-29 12:36:14 +02:00
Andreas Steffen
a7d626118f
bliss: Implemented FFT with fast Montgomery arithmetic
2016-07-29 12:36:14 +02:00
Andreas Steffen
5ff88c9622
xof: Implemented SHAKE128 and SHAKE256 Extended Output Functions
2016-07-29 12:36:14 +02:00