-
c812802482
NID_hash and NID_ec_curver were interchanged
Andreas Steffen
2009-08-27 20:11:49 +02:00
-
10b2898d3c
verify that the ECDSA auth signature was done with the correct curve
Martin Willi
2009-08-27 17:58:02 +02:00
-
472cb4ce77
distinguish between RFC 4754 (concatenated) and RFC 3279 (DER encoded) ECDSA signatures
Martin Willi
2009-08-27 17:36:17 +02:00
-
78aa4ebd62
OID_EC_PUBLICKEY has a parameters field, defining the elliptic curve
Andreas Steffen
2009-08-27 16:34:16 +02:00
-
263872c47d
added OID_EC_PUBLIC_KEY algorithmIdentifier
Andreas Steffen
2009-08-27 16:07:59 +02:00
-
050649ac41
cosmetics
Andreas Steffen
2009-08-27 15:33:22 +02:00
-
cec37b643a
fixed return value
Martin Willi
2009-08-27 15:28:45 +02:00
-
7ef310f5b4
do not append a NULL paramter to ECDSA algorithmIdentifiers
Martin Willi
2009-08-27 15:28:21 +02:00
-
9436b31c94
PKI tool supports certificate verification
Martin Willi
2009-08-27 14:43:40 +02:00
-
ed75a4dd69
do not flush cached encodings, keys are responsible for it
Martin Willi
2009-08-27 13:58:48 +02:00
-
85fd609ed6
whitelist openssl ecdsa_check function
Martin Willi
2009-08-27 13:40:48 +02:00
-
5e97fa9900
PKI tool supports generation of self-signed certificates
Martin Willi
2009-08-27 13:34:57 +02:00
-
8b10355c84
support generation of EC certificates
Martin Willi
2009-08-27 13:34:06 +02:00
-
82749537e2
added support for SIGN_ECDSA_WITH_SHA1 signature scheme in openssl
Martin Willi
2009-08-27 13:22:01 +02:00
-
eb73685dac
create algorithmIdentifier dynamically from OID database
Martin Willi
2009-08-27 13:14:01 +02:00
-
c03b095ebe
use subjectPublicKeyInfo encoding type directly
Martin Willi
2009-08-27 13:09:31 +02:00
-
09fe3c7e4c
pkcs1 encoder supports subjectPublicKeyInfo encoding
Martin Willi
2009-08-27 13:07:34 +02:00
-
fb70fc24d3
revoked soon-to-expire carol certificate
Andreas Steffen
2009-08-27 13:36:02 +02:00
-
87cb92d944
renewed expiring strongSwan certicates for UML scenarios
Andreas Steffen
2009-08-27 13:20:48 +02:00
-
d5dd43e777
implemented fingerprinting support for PKI tool
Martin Willi
2009-08-27 10:41:07 +02:00
-
1a8ef8aabc
fixed memleak in openssl fingerprinting
Martin Willi
2009-08-27 10:40:49 +02:00
-
b12c6d163d
do openssl fingerprinting/encoding directly, openssl provides all functions
Martin Willi
2009-08-27 09:58:38 +02:00
-
2ee8cd04bd
key encoding gained a cache() method, allows caching of externally created encodings
Martin Willi
2009-08-27 09:57:49 +02:00
-
277627043e
pgp plugin required in ikev1/net2net-pgp-v3|v4 scenarios
Andreas Steffen
2009-08-26 23:42:05 +02:00
-
9df7699419
dnskey plugin required in ikev1/net2net-rsa scenario
Andreas Steffen
2009-08-26 23:11:06 +02:00
-
706c6abe70
ikev1 psk scenarios don't need pkcs1 and pem plugins
Andreas Steffen
2009-08-26 22:46:39 +02:00
-
7c512d8b21
fixed typo
Andreas Steffen
2009-08-26 22:25:24 +02:00
-
51a9db85f4
streamlined file loading labels
Andreas Steffen
2009-08-26 22:02:00 +02:00
-
289ce4ade6
use --outform consistantly
Andreas Steffen
2009-08-26 18:55:18 +02:00
-
2f1f17f137
the option has been changed to --outform
Andreas Steffen
2009-08-26 18:41:19 +02:00
-
a05c4a856e
added pki/.libs/pki to the libs
Andreas Steffen
2009-08-26 18:27:04 +02:00
-
ca275b383f
fixed two typos
Andreas Steffen
2009-08-26 17:29:57 +02:00
-
083142c4a0
encoding public EC keys is not really possible without subjectPublicKeyInfo
Martin Willi
2009-08-26 16:15:38 +02:00
-
6a8791cd1f
complain about build errors in non-recursive cases only
Martin Willi
2009-08-26 14:44:05 +02:00
-
d16fd64d39
openac (and tools) do not depend on gmp anymore
Martin Willi
2009-08-26 14:08:20 +02:00
-
500f515a64
moved chunk_increment() function to libstrongswan
Martin Willi
2009-08-26 14:07:26 +02:00
-
d4df33f255
pki tool supports public key extraction from private key, certificates
Martin Willi
2009-08-26 13:05:17 +02:00
-
df5c60bc5d
added a BUILD_FROM_FD option, supporting credential parsing from stdin
Martin Willi
2009-08-26 13:03:23 +02:00
-
7c577c8ea2
started implementation of a PKI tool, currently supporting RSA|ECDSA key generation
Martin Willi
2009-08-26 11:22:09 +02:00
-
08ed551ce0
implemented openssl EC key generation
Martin Willi
2009-08-26 11:20:13 +02:00
-
a0b850450f
fixed openssl RSA private key encoding
Martin Willi
2009-08-26 11:19:06 +02:00
-
16db1207cf
keyids in SQL use ID_KEY_ID type with subjectPublicKey SHA1 hash
Martin Willi
2009-08-25 14:29:48 +02:00
-
41f57038e4
tests load pem/pkcs1 plugins, pubkey plugin not needed anymore
Martin Willi
2009-08-25 13:21:50 +02:00
-
0df451bc07
use ./configured plugins in keyid scripts
Martin Willi
2009-08-25 11:31:08 +02:00
-
500aa2607f
accept PEM encoded keys in keyid scripts
Martin Willi
2009-08-25 11:30:42 +02:00
-
94dde8a0ab
migrated scripts to new fingerprinting API
Martin Willi
2009-08-25 11:29:51 +02:00
-
9c3d2b3d60
updated medsrv and test to new fingerprint/encoding API
Martin Willi
2009-08-25 15:37:33 +02:00
-
1cd0d7969a
updated load-tester plugin to new fingerprinting API
Martin Willi
2009-08-24 16:57:09 +02:00
-
8eefe4617f
use only KEY_ID_PUBKEY_SHA1 fingerprint charon internally
Martin Willi
2009-08-24 16:06:59 +02:00
-
87d2026341
updated nm plugin to new fingerprinting API
Martin Willi
2009-08-24 16:06:21 +02:00
-
cb4f09eff3
updated agent plugin to new fingerprint/encoding API
Martin Willi
2009-08-24 15:10:18 +02:00
-
c5cd195c6c
updated stroke plugin to fingerprinting API
Martin Willi
2009-08-24 14:20:59 +02:00
-
64fdbce4da
updated charon to new fingerprinting API
Martin Willi
2009-08-24 14:20:29 +02:00
-
b4b68b64b8
updated pluto to new fingerprinting API
Martin Willi
2009-08-24 14:19:51 +02:00
-
5bceb90c86
updated scepclient to new encoding API
Martin Willi
2009-08-24 14:19:16 +02:00
-
8d09681559
updated pubkey plugin to new fingerprinting API
Martin Willi
2009-08-24 14:15:03 +02:00
-
6b6ece636c
updated x509 plugin to public key/x509 API changes
Martin Willi
2009-08-24 14:11:44 +02:00
-
a5e3153a36
updated x509/CRL/AC API to align with public key, authKeyIdentifier is a chunk
Martin Willi
2009-08-24 14:10:26 +02:00
-
e35c3e2a03
updated openssl plugin to new private/public key API, use encoder framework
Martin Willi
2009-08-24 14:09:18 +02:00
-
cbd5138948
updated gcrypt plugin to new private/public key API, use encoder framework
Martin Willi
2009-08-24 14:07:32 +02:00
-
741680d179
updated gmp plugin to new private/public key API, use encoder framework
Martin Willi
2009-08-24 14:06:41 +02:00
-
1384a42e1b
changed get_id/get_encoding API of private/public key to use new encoding framework
Martin Willi
2009-08-24 14:04:23 +02:00
-
1ef69b01ab
removed obsolete fingerprint identification types
Martin Willi
2009-08-24 14:21:38 +02:00
-
edd354db6f
added generic implementation helpers for private_key_t.equals/belongs_to, public_key_t.equals
Martin Willi
2009-08-24 14:00:43 +02:00
-
0dd2defc5a
added a seperate chache lookup, as encode() requires arguments expensive to build
Martin Willi
2009-08-24 11:12:07 +02:00
-
64e77e8fbb
use credential builder API to parse trusted public keys
Martin Willi
2009-08-21 13:53:19 +02:00
-
d1b3e8607e
implemented PGP fingerprinting
Martin Willi
2009-08-19 16:26:29 +02:00
-
e773fe4cab
implemented pkcs1 private/public key encoding and fingerprinting
Martin Willi
2009-08-19 16:10:08 +02:00
-
934d49a4f9
chunk_cat/cata/create_cat/length accept the sensitive data clearing mode 's'
Martin Willi
2009-08-19 16:02:20 +02:00
-
957d116328
in addition to 'm'/'c' mode, asn1_wrap accepts a 's' mode clearing sensitive information
Martin Willi
2009-08-19 16:00:48 +02:00
-
d9b24887a4
added a facility to hand out fingerprinting/key encoding to the pkcs1/pgp/... plugins
Martin Willi
2009-08-18 17:48:34 +02:00
-
831520d895
gmp uses component builder to build public- from private-key
Martin Willi
2009-08-18 09:58:12 +02:00
-
8380503168
gcrypt uses component builder to build public- from private-key
Martin Willi
2009-08-18 09:47:41 +02:00
-
b457e08fca
moved PGP code to pluto and gpg plugin
Martin Willi
2009-08-17 15:56:08 +02:00
-
7033a70fd0
gmp plugin makes use of pkcs1/pgp/dnskey plugins
Martin Willi
2009-08-17 14:58:42 +02:00
-
cbfafc1125
enforce RSA_PRIME1 > RSA_PRIME2 (p > q) in PGP
Martin Willi
2009-08-17 15:30:20 +02:00
-
5ef478aaee
implemented RFC3110 key builder in a plugin, added generic DNSKEY RR parsing
Martin Willi
2009-08-17 14:45:52 +02:00
-
3addf4e937
renamed BUILD_BLOB_RFC_3110 to BUILD_BLOB_DNSKEY, we potentially support other key types
Martin Willi
2009-08-17 14:11:39 +02:00
-
caa00e7ab7
pluto uses KEY_ANY builder to parse PGP public keys
Martin Willi
2009-08-17 13:48:50 +02:00
-
9493dd2ce0
implemented a pgp plugin providing PGP key parsing builders
Martin Willi
2009-08-17 13:46:04 +02:00
-
4e3d1e804e
make use of the pkcs1 plugin in gcrypt rsa key parsing
Martin Willi
2009-08-14 17:21:03 +02:00
-
3044774323
removed subjectPublicKeyInfo parsing, provided by pkcs1 plugin
Martin Willi
2009-08-14 16:51:12 +02:00
-
1e0f69373a
implemented a pkcs1 plugin providing PKCS#1 key parsing builders
Martin Willi
2009-08-14 16:48:40 +02:00
-
750bbcf9a8
added support for %prompt-ing private key passhprases in strokes "ipsec secrets"
Martin Willi
2009-08-14 15:01:35 +02:00
-
7c2d883af7
show more information if building a credential fails
Martin Willi
2009-08-14 13:19:47 +02:00
-
833dcfa530
log loaded private key/certificates
Martin Willi
2009-08-13 17:14:41 +02:00
-
3f9ec06f6f
added getnetbyname/gethostbyname2 to leak detective whitelist, used by pluto
Martin Willi
2009-08-13 16:47:57 +02:00
-
d47dc6d170
clone blobs passed to parse functions, check before free
Martin Willi
2009-08-13 16:47:27 +02:00
-
89556140d0
fixed builder signature
Martin Willi
2009-08-13 16:05:06 +02:00
-
ddf7c6ac7b
do not enumerate builders returning NULL
Martin Willi
2009-08-13 16:04:45 +02:00
-
2b7e085dea
updated pubkey_speed test to use pem plugin
Martin Willi
2009-08-13 15:39:29 +02:00
-
cbb62e8f4c
handle pluto specific certificates under CRED_CERTIFICATE, not as own credential kind
Martin Willi
2009-08-13 15:05:14 +02:00
-
f11a78f10a
unified pluto builder implementations
Martin Willi
2009-08-13 14:18:58 +02:00
-
94463a33b4
removed obsolete PEM code in pluto/libstrongswan
Martin Willi
2009-08-13 13:47:31 +02:00
-
ccd0a624b6
use credential builder to build crls
Martin Willi
2009-08-13 13:37:14 +02:00
-
37f5a0da2c
use credential builder to build attribute certificates
Martin Willi
2009-08-13 11:15:31 +02:00
-
a5dc4a9585
moved builder hooks to a separate file
Martin Willi
2009-08-13 10:48:22 +02:00
-
11aa7e7869
use a pluto specific credential builder to build pluto cert_t's
Martin Willi
2009-08-12 17:27:15 +02:00
-
c486fa8158
removed obsolete pgp private key parsing, done by libstrongswan
Martin Willi
2009-08-12 16:14:26 +02:00
-
dc816eacdf
use libstrongswan for private key loading, whack callback to read passphrase
Martin Willi
2009-08-12 16:13:18 +02:00