Tobias Brunner
|
1407a0026f
|
Added missing break when building TLS cipher suites
|
2012-09-28 18:55:40 +02:00 |
|
Martin Willi
|
ab2c989c32
|
Don't allow NULL encryption with PEAP
|
2012-09-12 13:19:52 +02:00 |
|
Martin Willi
|
acada66a35
|
Use memmove on overlapping regions, and operate with correct sizeof()
|
2012-09-12 13:19:52 +02:00 |
|
Martin Willi
|
fb3cf1b708
|
Whitespace cleanups in tls_eap
|
2012-09-12 13:19:52 +02:00 |
|
Martin Willi
|
02cabd0f26
|
Check if TLS handshake received Finished before processing application data
|
2012-08-09 12:10:41 +02:00 |
|
Martin Willi
|
2df12b4c57
|
Fix tls_prf bug introduced with bc474883
|
2012-07-17 11:33:05 +02:00 |
|
Martin Willi
|
87dd205b61
|
Add a return value to hasher_t.allocate_hash()
|
2012-07-16 14:55:06 +02:00 |
|
Martin Willi
|
8bd6a30af1
|
Add a return value to hasher_t.get_hash()
|
2012-07-16 14:55:06 +02:00 |
|
Martin Willi
|
ce73fc19db
|
Add a return value to crypter_t.set_key()
|
2012-07-16 14:53:38 +02:00 |
|
Martin Willi
|
3b96189a2a
|
Add a return value to crypter_t.decrypt()
|
2012-07-16 14:53:38 +02:00 |
|
Martin Willi
|
e35abbe588
|
Add a return value to crypter_t.encrypt
|
2012-07-16 14:53:37 +02:00 |
|
Martin Willi
|
bb5eb15ccc
|
Check rng return value when generating TLS session identifiers
|
2012-07-16 14:53:37 +02:00 |
|
Tobias Brunner
|
126eb2af59
|
Check rng return value when generating secrets and IVs in libtls
|
2012-07-16 14:53:37 +02:00 |
|
Martin Willi
|
f3ca96b2bf
|
Add a return value to prf_t.set_key()
|
2012-07-16 14:53:34 +02:00 |
|
Martin Willi
|
bc47488323
|
Add a return value to prf_t.get_bytes()
|
2012-07-16 14:53:33 +02:00 |
|
Martin Willi
|
e7d98b8c99
|
Add a return value to tls_prf_t.set_key()
|
2012-07-16 14:53:33 +02:00 |
|
Martin Willi
|
97b30b93b0
|
Add a return value to tls_prf_t.get_bytes()
|
2012-07-16 14:53:33 +02:00 |
|
Martin Willi
|
2d56575d52
|
Add a return value to signer_t.set_key()
|
2012-07-16 14:53:33 +02:00 |
|
Martin Willi
|
9020f7d0b9
|
Add a return value to tls_crypto_t.derive_secrets()
|
2012-07-16 14:53:33 +02:00 |
|
Martin Willi
|
2e96de60a8
|
Add a return value to signer_t.get_signature()
|
2012-07-16 14:53:33 +02:00 |
|
Martin Willi
|
cbfbba7d86
|
Add a return value to signer_t.allocate_signature()
|
2012-07-16 14:53:32 +02:00 |
|
Andreas Steffen
|
6245edf37e
|
eliminate message length field in EAP-TNC
|
2012-07-11 17:09:05 +02:00 |
|
Andreas Steffen
|
c36680962c
|
allow to transmit 64k TLS Handshake and Application messages via EAP-[T]TLS
|
2012-07-11 17:09:04 +02:00 |
|
Andreas Steffen
|
dfe82160e4
|
some tls_eap optimizations
|
2012-07-11 17:09:04 +02:00 |
|
Andreas Steffen
|
3bd452f8f3
|
max_message_count = 0 disables limit
|
2012-07-11 17:09:04 +02:00 |
|
Andreas Steffen
|
da67c37d65
|
log invalid TLS packet length
|
2012-07-11 17:09:04 +02:00 |
|
Martin Willi
|
b188f23199
|
Install dev headers only if --with-dev-headers= option is set
|
2012-07-11 11:16:31 +02:00 |
|
Martin Willi
|
2a6bcbbdee
|
Install libtls development headers
|
2012-07-11 10:51:01 +02:00 |
|
Martin Willi
|
ae10ee6d0b
|
Double check if a cached suite is available, overwrite any old suite state
|
2012-02-07 11:42:57 +01:00 |
|
Tobias Brunner
|
b96eb46d5c
|
Some Doxygen fixes.
|
2012-02-07 11:20:46 +01:00 |
|
Martin Willi
|
06c150365d
|
Fix TLS EAP-MSK derivation, uses different order of randoms than key expansion
|
2012-02-07 10:54:53 +01:00 |
|
Martin Willi
|
1dabf5bfc7
|
Filter TLS suite MAC by HMAC algorithm, as the hash is not necessarily the same
|
2012-02-07 10:54:53 +01:00 |
|
Martin Willi
|
3a87c89b1b
|
Added a tls_socket_t.splice method to wrap a file descriptor into TLS
|
2011-12-31 13:14:49 +01:00 |
|
Martin Willi
|
6a5c86b7ad
|
Implemented TLS session resumption both as client and as server
|
2011-12-31 13:14:49 +01:00 |
|
Martin Willi
|
ca5767621b
|
Implemented a TLS session cache
|
2011-12-31 13:14:49 +01:00 |
|
Martin Willi
|
703c0db894
|
Check for cipherspec changes after each handshake message
|
2011-12-31 13:14:49 +01:00 |
|
Martin Willi
|
4caa380625
|
Separated cipherspec checking and switching, allowing us to defer the second
|
2011-12-31 13:14:49 +01:00 |
|
Martin Willi
|
84da59f609
|
Be less verbose about TLS extensions
|
2011-12-24 14:14:25 +01:00 |
|
Martin Willi
|
ed57dfca3f
|
In TLS 1.2, PRF and HASH function use at least SHA-256, not the MAC hash function
|
2011-12-24 12:42:28 +01:00 |
|
Martin Willi
|
6b01216422
|
Added a getter for the tls_socket file descriptor
|
2011-12-24 12:42:25 +01:00 |
|
Andreas Steffen
|
e7cb8f9b37
|
added dummy libtls_init() function needed for integrity testing
|
2011-11-08 20:27:17 +01:00 |
|
Martin Willi
|
5976e149eb
|
Don't allocate extra memory to MAC the TLS header
|
2011-09-28 17:32:23 +02:00 |
|
Martin Willi
|
b79bb79a66
|
Verify TLS MAC even if padding is invalid to prevent timing attacks
|
2011-09-28 17:16:09 +02:00 |
|
Martin Willi
|
18c4d010f4
|
Install and use libtls as dynamic library, as we have our private libdir now
|
2011-08-08 13:41:09 +02:00 |
|
Tobias Brunner
|
f3bb1bd039
|
Fixed common misspellings.
Mostly found by 'codespell'.
|
2011-07-20 16:14:10 +02:00 |
|
Andreas Steffen
|
7e432eff6b
|
renamed tls_reader|writer to bio_* and moved to libstrongswan
|
2011-05-31 15:46:51 +02:00 |
|
Andreas Steffen
|
7e82d26dd8
|
fixed type
|
2011-05-31 15:46:51 +02:00 |
|
Andreas Steffen
|
deed58393d
|
raw TLS debug output
|
2011-05-29 10:36:41 +02:00 |
|
Andreas Steffen
|
4b06f9f265
|
debug type is EAP_TLS
|
2011-04-21 21:04:11 +02:00 |
|
Andreas Steffen
|
2778b6644b
|
do not include length field in non-fragmented EAP-PEAP packets
|
2011-04-21 19:52:49 +02:00 |
|