Commit Graph
131 Commits
Author SHA1 Message Date
Martin Willi b8cbb6451c ported some hard-to-merge cherries back to trunk :-/
shame, svn, shame: this was ways to complicated
	we should consider a switch to git...
2008-11-12 15:09:24 +00:00
Martin Willi 479f295049 fixed compiler warnings issued by:
gcc 4.3
	curl.h gcc type-checking
	glibc with enabled FORTIFY_SOURCE checking
2008-11-11 18:37:19 +00:00
Martin Willi 2abc66b977 proper cleanup of openssl locking code 2008-11-05 12:37:37 +00:00
Martin Willi 3ac5a0db8c replaced most pthread_mutex/cond_t by wrapped mutex/condvar_t variant 2008-11-05 11:29:56 +00:00
Martin Willi e13389a7f7 got rid of deprecated create_iterator_locked() 2008-11-05 08:32:38 +00:00
Martin Willi 7854475f42 OpenSSL requires a signature length of exactly RSA_size() 2008-11-04 14:05:42 +00:00
Martin Willi d4f08fe324 removed superfluous get_other_public_value in diffie_hellman_t interface 2008-11-04 13:12:11 +00:00
Martin Willi ddd7e6c656 fixed bignum export if BN_num_bytes() != DH_size() 2008-11-04 13:05:00 +00:00
Martin Willi dcbea444ee fixed memleak 2008-11-04 13:01:36 +00:00
Martin Willi 7de6da0c88 added locking mechanism for multithreaded use of OpenSSL 2008-11-03 16:14:12 +00:00
Martin Willi ee66fa625e removed accidently checked in debug code 2008-11-03 12:40:42 +00:00
Martin Willi d6dc9db5ef reverted 4541, does not fix the problem 2008-11-03 09:44:20 +00:00
Martin Willi e301a69d6c removed 0-byte truncation, fixes random Openssl RSA signature verification failures 2008-10-31 17:07:04 +00:00
Martin Willi a13862be61 fixed crash in openssl signature verification if sizeof(size_t) != sizeof(int) (64bit) 2008-10-31 17:05:40 +00:00
Andreas Steffen f5ab7f5f57 refining changeset 4483 by introducing charon.dh_exponent_ansi_x9_42 key 2008-10-28 01:59:01 +00:00
Andreas Steffen aeaa6a9b45 remove unused local DH_EXPONENT_ENTROPY definition 2008-10-27 00:02:22 +00:00
Andreas Steffen 21a45f2f2d use 512 bits of entropy for secret DH exponents 2008-10-26 23:53:52 +00:00
Andreas Steffen d1cbe55127 implemented ipsec listalgs as a stroke command 2008-10-08 07:00:13 +00:00
Andreas Steffen af09048e35 get_subject() of a CERT_TRUSTED_PUBKEY object returns ID_PUBKEY_INFO_SHA1 hash consistent with the IKEv2 keyid philosophy 2008-10-08 03:35:52 +00:00
Andreas Steffen 95fd1dedb3 Implemented BUILD_BLOB_ASN1_DER for the CERT_TRUSTED_PUBKEY subtype 2008-10-08 01:19:26 +00:00
Martin Willi ceff3064fe using signed return value for read() 2008-09-30 06:27:50 +00:00
Martin Willi cdaf57ec34 fixed DH value range testing 2008-09-17 09:02:30 +00:00
Martin Willi 73f6886a50 checking mpz_export return value properly
fixes a potential DoS attack if a DH value of zero gets processed
2008-09-17 08:10:48 +00:00
Martin Willi 6af6f88a79 agent plugin optionally accepts a BUILD_PUBLIC_KEY to select a specific private key from the agent 2008-09-04 08:35:11 +00:00
Martin Willi 21c9546321 libstrongswan agent plugin to use ssh-agent for RSA signatures 2008-09-02 11:04:26 +00:00
Martin Willi f7c17aa15c refactored credential builder
allow enumeration of matching builders
	try a second builder if the first one fails
	builder clones resources internally on demand
	caller frees added resources on failure and success
	stricter handling of non-supported build parts
2008-09-02 11:00:13 +00:00
Martin Willi e577ad3985 creating default IKE proposals dynamically using algorithm enumeration API 2008-08-28 11:07:57 +00:00
Martin Willi f1b014b9a3 separated sha1_prf implementation from sha1_hasher 2008-08-28 10:57:24 +00:00
Andreas Steffen dc6a2edd0d corrected caption 2008-08-21 11:58:58 +00:00
Martin Willi 2d6559b107 added sqlite busy handler: retries on locking conflicts 2008-08-21 09:25:06 +00:00
Martin Willi fc861b0b7e added a driver type getter for database implementations 2008-07-21 11:13:06 +00:00
Martin Willi 11e855179e using token enumerator to parser plugin list 2008-07-02 08:19:43 +00:00
Martin Willi 7da767f773 sqlite plugin requires libsqlite3 => 3.3.1 to share connections
use recursive locking if libsqlite3 < 3.5.0
2008-06-30 11:06:18 +00:00
Martin Willi 854a2e1760 fixed ifndef typo for MYSQL_DATA_TRUNCATED check 2008-06-26 07:31:52 +00:00
Martin Willi 236083cb56 fixed plugin loader destruction 2008-06-25 14:53:49 +00:00
Tobias Brunner 1b7d2e31a6 enabling support for hardware accelerators in OpenSSL 2008-06-25 12:39:32 +00:00
Martin Willi fae6e24dad reintroducing MYSQL_DATA_TRUNCATED if supported on that mysql version 2008-06-24 14:30:14 +00:00
Martin Willi eec675bf8c enumerating loaded plugins in "ipsec statusall" 2008-06-24 12:49:04 +00:00
Andreas Steffen 0d12006def support of ECDSA signatures for all certificate types 2008-06-22 17:41:07 +00:00
Martin Willi 1345ebad0f removed unused MYSQL_DATA_TRUNCATED check for compatibility with older mysql versions 2008-06-20 07:37:55 +00:00
Martin Willi 66860d3b8f loading PEM encoded public keys 2008-06-11 14:10:02 +00:00
Tobias Brunner a57e0580f6 refactoring 2008-06-10 09:19:18 +00:00
Tobias Brunner ea0823dffd ECDSA with OpenSSL 2008-06-10 09:08:27 +00:00
Tobias Brunner 2904403e96 parsing of subjectPublicKeyInfo of x509 certificates extracted 2008-06-10 09:00:42 +00:00
Martin Willi e581a31d6a link against openssl crypto library only 2008-06-06 08:04:42 +00:00
Martin Willi 0f7aecf402 fixed NULL string mysql parameter 2008-06-05 08:24:55 +00:00
Andreas Steffen 7fe3ae88e4 handle default key sizes in openssl_crypter 2008-05-28 12:20:38 +00:00
Andreas Steffen ed26207d08 fixed copy-and-paste error 2008-05-23 19:23:04 +00:00
Andreas Steffen 49b2395e3b check if parsing of the RSA public key in an X.509 certificate was successful 2008-05-23 19:22:37 +00:00
Martin Willi 5e17e35c8d fixed some compiler warnings 2008-05-23 15:49:43 +00:00