Martin Willi
|
b8cbb6451c
|
ported some hard-to-merge cherries back to trunk :-/
shame, svn, shame: this was ways to complicated
we should consider a switch to git...
|
2008-11-12 15:09:24 +00:00 |
|
Martin Willi
|
479f295049
|
fixed compiler warnings issued by:
gcc 4.3
curl.h gcc type-checking
glibc with enabled FORTIFY_SOURCE checking
|
2008-11-11 18:37:19 +00:00 |
|
Tobias Brunner
|
ea625fabf9
|
merging kernel_klips plugin back into trunk
|
2008-11-11 09:22:00 +00:00 |
|
Martin Willi
|
c198fc5548
|
whitelisting localtime_r
|
2008-11-10 16:44:27 +00:00 |
|
Martin Willi
|
f821bfb2b3
|
fixed leak in host_create_from_string("%any")
|
2008-11-10 16:42:05 +00:00 |
|
Martin Willi
|
c9ef4cee46
|
settings section enumeration
printf style key lookup
|
2008-11-07 15:08:53 +00:00 |
|
Andreas Steffen
|
e2764b3937
|
use of host_create_any() for %any address
|
2008-11-07 05:15:19 +00:00 |
|
Martin Willi
|
ebf0e20ae7
|
fixed leak
fixed build if !HAVE_BACKTRACE
|
2008-11-06 14:05:58 +00:00 |
|
Martin Willi
|
e76078e877
|
use read-write locks in crypto factory for parallelization
|
2008-11-05 16:21:57 +00:00 |
|
Martin Willi
|
27ed987ef7
|
wrapped all pthread_rwlock_t in profilable rwlock_t
|
2008-11-05 16:12:54 +00:00 |
|
Martin Willi
|
c1be64eaff
|
wrapped rwlock with profiling support
|
2008-11-05 15:51:57 +00:00 |
|
Martin Willi
|
0214012508
|
threshhold and ./configure option for lock profiler
|
2008-11-05 14:36:57 +00:00 |
|
Martin Willi
|
f7237cf37a
|
separated backtrace functionality from leak_detective, used in
leak_detective
mutex profiling
signal handler
|
2008-11-05 13:58:19 +00:00 |
|
Martin Willi
|
2abc66b977
|
proper cleanup of openssl locking code
|
2008-11-05 12:37:37 +00:00 |
|
Martin Willi
|
a492eb2033
|
fixed iterator regression introduced in [4577]
|
2008-11-05 11:55:17 +00:00 |
|
Martin Willi
|
3ac5a0db8c
|
replaced most pthread_mutex/cond_t by wrapped mutex/condvar_t variant
|
2008-11-05 11:29:56 +00:00 |
|
Martin Willi
|
2662806b2c
|
get rid of unused iterator hook functions
|
2008-11-05 08:37:09 +00:00 |
|
Martin Willi
|
e13389a7f7
|
got rid of deprecated create_iterator_locked()
|
2008-11-05 08:32:38 +00:00 |
|
Martin Willi
|
e10b0d0fc0
|
simple mutex profiler
|
2008-11-05 07:57:26 +00:00 |
|
Andreas Steffen
|
61670ba284
|
support of %any address string
|
2008-11-05 04:53:45 +00:00 |
|
Andreas Steffen
|
7c4fd176db
|
handle 0.0.0.0 string and af == AF_INET6
|
2008-11-05 00:41:46 +00:00 |
|
Martin Willi
|
7854475f42
|
OpenSSL requires a signature length of exactly RSA_size()
|
2008-11-04 14:05:42 +00:00 |
|
Martin Willi
|
d4f08fe324
|
removed superfluous get_other_public_value in diffie_hellman_t interface
|
2008-11-04 13:12:11 +00:00 |
|
Martin Willi
|
ddd7e6c656
|
fixed bignum export if BN_num_bytes() != DH_size()
|
2008-11-04 13:05:00 +00:00 |
|
Martin Willi
|
dcbea444ee
|
fixed memleak
|
2008-11-04 13:01:36 +00:00 |
|
Martin Willi
|
7de6da0c88
|
added locking mechanism for multithreaded use of OpenSSL
|
2008-11-03 16:14:12 +00:00 |
|
Martin Willi
|
ee66fa625e
|
removed accidently checked in debug code
|
2008-11-03 12:40:42 +00:00 |
|
Martin Willi
|
d6dc9db5ef
|
reverted 4541, does not fix the problem
|
2008-11-03 09:44:20 +00:00 |
|
Martin Willi
|
e301a69d6c
|
removed 0-byte truncation, fixes random Openssl RSA signature verification failures
|
2008-10-31 17:07:04 +00:00 |
|
Martin Willi
|
a13862be61
|
fixed crash in openssl signature verification if sizeof(size_t) != sizeof(int) (64bit)
|
2008-10-31 17:05:40 +00:00 |
|
Martin Willi
|
19aff61b19
|
reverted changeset 4529:
Camellia is 22 in IKEv1, but not-yet defined in IKEv2
in IKEv2, 22 is reserved for AES-XTS
|
2008-10-30 13:21:21 +00:00 |
|
Andreas Steffen
|
fdaed5289a
|
added Camellia CBC to list of encryption algorithms
|
2008-10-30 03:31:36 +00:00 |
|
Martin Willi
|
f65ba4e978
|
prf handles zero-length allocations graceful
|
2008-10-29 14:12:54 +00:00 |
|
Andreas Steffen
|
f5ab7f5f57
|
refining changeset 4483 by introducing charon.dh_exponent_ansi_x9_42 key
|
2008-10-28 01:59:01 +00:00 |
|
Andreas Steffen
|
aeaa6a9b45
|
remove unused local DH_EXPONENT_ENTROPY definition
|
2008-10-27 00:02:22 +00:00 |
|
Andreas Steffen
|
21a45f2f2d
|
use 512 bits of entropy for secret DH exponents
|
2008-10-26 23:53:52 +00:00 |
|
Martin Willi
|
104c28d603
|
fixed perl oid generation
|
2008-10-16 15:38:48 +00:00 |
|
Martin Willi
|
f868dc0ca2
|
condvar->wait() can handle recursive mutex
|
2008-10-16 11:29:42 +00:00 |
|
Tobias Brunner
|
1adaa02bb2
|
merging kernel_pfkey plugin back from kernel-interface branch
|
2008-10-14 08:46:31 +00:00 |
|
Andreas Steffen
|
d1cbe55127
|
implemented ipsec listalgs as a stroke command
|
2008-10-08 07:00:13 +00:00 |
|
Andreas Steffen
|
af09048e35
|
get_subject() of a CERT_TRUSTED_PUBKEY object returns ID_PUBKEY_INFO_SHA1 hash consistent with the IKEv2 keyid philosophy
|
2008-10-08 03:35:52 +00:00 |
|
Andreas Steffen
|
95fd1dedb3
|
Implemented BUILD_BLOB_ASN1_DER for the CERT_TRUSTED_PUBKEY subtype
|
2008-10-08 01:19:26 +00:00 |
|
Martin Willi
|
0592212f23
|
fixed builder_cancel macro to return NULL on failed build
|
2008-10-06 13:08:49 +00:00 |
|
Martin Willi
|
ceff3064fe
|
using signed return value for read()
|
2008-09-30 06:27:50 +00:00 |
|
Martin Willi
|
cdaf57ec34
|
fixed DH value range testing
|
2008-09-17 09:02:30 +00:00 |
|
Martin Willi
|
73f6886a50
|
checking mpz_export return value properly
fixes a potential DoS attack if a DH value of zero gets processed
|
2008-09-17 08:10:48 +00:00 |
|
Andreas Steffen
|
b33c11b6c7
|
stroke parses and lists AC groups
|
2008-09-17 02:17:01 +00:00 |
|
Andreas Steffen
|
07d7f9a402
|
time values in strongswan.conf can be optionally specified in days (d), hours (h), minutes (m), or seconds (s)
|
2008-09-04 16:19:46 +00:00 |
|
Martin Willi
|
6af6f88a79
|
agent plugin optionally accepts a BUILD_PUBLIC_KEY to select a specific private key from the agent
|
2008-09-04 08:35:11 +00:00 |
|
Martin Willi
|
21c9546321
|
libstrongswan agent plugin to use ssh-agent for RSA signatures
|
2008-09-02 11:04:26 +00:00 |
|