Martin Willi
|
ae10ee6d0b
|
Double check if a cached suite is available, overwrite any old suite state
|
2012-02-07 11:42:57 +01:00 |
|
Tobias Brunner
|
b96eb46d5c
|
Some Doxygen fixes.
|
2012-02-07 11:20:46 +01:00 |
|
Martin Willi
|
06c150365d
|
Fix TLS EAP-MSK derivation, uses different order of randoms than key expansion
|
2012-02-07 10:54:53 +01:00 |
|
Martin Willi
|
1dabf5bfc7
|
Filter TLS suite MAC by HMAC algorithm, as the hash is not necessarily the same
|
2012-02-07 10:54:53 +01:00 |
|
Martin Willi
|
3a87c89b1b
|
Added a tls_socket_t.splice method to wrap a file descriptor into TLS
|
2011-12-31 13:14:49 +01:00 |
|
Martin Willi
|
6a5c86b7ad
|
Implemented TLS session resumption both as client and as server
|
2011-12-31 13:14:49 +01:00 |
|
Martin Willi
|
ca5767621b
|
Implemented a TLS session cache
|
2011-12-31 13:14:49 +01:00 |
|
Martin Willi
|
703c0db894
|
Check for cipherspec changes after each handshake message
|
2011-12-31 13:14:49 +01:00 |
|
Martin Willi
|
4caa380625
|
Separated cipherspec checking and switching, allowing us to defer the second
|
2011-12-31 13:14:49 +01:00 |
|
Martin Willi
|
84da59f609
|
Be less verbose about TLS extensions
|
2011-12-24 14:14:25 +01:00 |
|
Martin Willi
|
ed57dfca3f
|
In TLS 1.2, PRF and HASH function use at least SHA-256, not the MAC hash function
|
2011-12-24 12:42:28 +01:00 |
|
Martin Willi
|
6b01216422
|
Added a getter for the tls_socket file descriptor
|
2011-12-24 12:42:25 +01:00 |
|
Andreas Steffen
|
e7cb8f9b37
|
added dummy libtls_init() function needed for integrity testing
|
2011-11-08 20:27:17 +01:00 |
|
Martin Willi
|
5976e149eb
|
Don't allocate extra memory to MAC the TLS header
|
2011-09-28 17:32:23 +02:00 |
|
Martin Willi
|
b79bb79a66
|
Verify TLS MAC even if padding is invalid to prevent timing attacks
|
2011-09-28 17:16:09 +02:00 |
|
Martin Willi
|
18c4d010f4
|
Install and use libtls as dynamic library, as we have our private libdir now
|
2011-08-08 13:41:09 +02:00 |
|
Tobias Brunner
|
f3bb1bd039
|
Fixed common misspellings.
Mostly found by 'codespell'.
|
2011-07-20 16:14:10 +02:00 |
|
Andreas Steffen
|
7e432eff6b
|
renamed tls_reader|writer to bio_* and moved to libstrongswan
|
2011-05-31 15:46:51 +02:00 |
|
Andreas Steffen
|
7e82d26dd8
|
fixed type
|
2011-05-31 15:46:51 +02:00 |
|
Andreas Steffen
|
deed58393d
|
raw TLS debug output
|
2011-05-29 10:36:41 +02:00 |
|
Andreas Steffen
|
4b06f9f265
|
debug type is EAP_TLS
|
2011-04-21 21:04:11 +02:00 |
|
Andreas Steffen
|
2778b6644b
|
do not include length field in non-fragmented EAP-PEAP packets
|
2011-04-21 19:52:49 +02:00 |
|
Martin Willi
|
5b0bcfb1fc
|
Revert alloc_str changes
This reverts commit fdead26ffe.
This reverts commit 3e2419ebe3.
This reverts commit 17ce69b47a.
|
2011-04-21 13:35:31 +02:00 |
|
Martin Willi
|
3e2419ebe3
|
Use thread save settings alloc_str function where appropriate
|
2011-04-21 10:48:16 +02:00 |
|
Martin Willi
|
2db8b58f62
|
Continue without client authentication if no matching certificate found
|
2011-04-14 20:02:12 +02:00 |
|
Martin Willi
|
6a8f1a578f
|
Ignore TLS certificate requests as peer if peer authentication disabled
|
2011-04-14 20:02:12 +02:00 |
|
Martin Willi
|
1c21f47a06
|
Send TLS Server Name Indication as peer if server identity is a FQDN
|
2011-04-14 20:02:12 +02:00 |
|
Martin Willi
|
eea2bdb203
|
Fix tls_writer wrap functions
|
2011-04-14 20:02:11 +02:00 |
|
Andreas Steffen
|
a9ee43e96a
|
added TLS renegotiation_info extension
|
2011-04-14 16:54:46 +02:00 |
|
Andreas Steffen
|
1bee89d339
|
added TLS_PURPOSE_EAP_PEAP
|
2011-04-05 18:16:28 +02:00 |
|
Andreas Steffen
|
6f69fb0134
|
implemented get|set_identifier() for tls_eap_t
|
2011-04-05 18:14:58 +02:00 |
|
Tobias Brunner
|
84545f6e7c
|
Some typos fixed.
|
2011-02-07 11:39:41 +01:00 |
|
Martin Willi
|
8118707845
|
Increase tls_writer buffer by at least 4 bytes
|
2011-01-19 14:41:59 +01:00 |
|
Andreas Steffen
|
f10e72341c
|
cast enumerated algorithm type as int
|
2010-12-18 20:24:53 +01:00 |
|
Andreas Steffen
|
5932f41fcc
|
trace back crypto algorithms to the plugins that registered them
|
2010-12-18 16:31:12 +01:00 |
|
Andreas Steffen
|
58d73d38bc
|
output TLS-independent error messages
|
2010-12-05 14:55:18 +01:00 |
|
Andreas Steffen
|
4d178affbb
|
call is_complete() if tls protocol returns with SUCCESS
|
2010-11-16 11:52:06 +01:00 |
|
Andreas Steffen
|
0cfdbaff2c
|
set EAP-TTLS/TNC version also in acknowledgement packets
|
2010-10-04 14:39:49 +02:00 |
|
Martin Willi
|
89821331e0
|
Do not change cipherspec while we have buffered handshake fragments pending
|
2010-09-09 14:27:41 +02:00 |
|
Andreas Steffen
|
3b7eb3a9f4
|
added explanatory comments
|
2010-09-09 08:57:13 +02:00 |
|
Andreas Steffen
|
de29e3a683
|
max max_message_count configurable and move it into tls_eap_t
|
2010-09-08 12:58:45 +02:00 |
|
Andreas Steffen
|
99b0f633c2
|
handle TLS_PURPOSE_EAP_TNC
|
2010-09-08 12:58:45 +02:00 |
|
Andreas Steffen
|
51b385d44d
|
moved tls_t existance test into tls_eap_create() again
|
2010-09-08 11:09:11 +02:00 |
|
Andreas Steffen
|
d2b1d4378e
|
generalized tls_eap_t to support EAP_TNC wrapping the TNC_IF_TNCCS protocol
|
2010-09-08 11:01:53 +02:00 |
|
Martin Willi
|
7b3c01845f
|
Read the compression type byte for EC groups, only
|
2010-09-08 10:35:29 +02:00 |
|
Martin Willi
|
31c65eb362
|
Include ec_point_format extension in ClientHello
|
2010-09-06 18:51:38 +02:00 |
|
Martin Willi
|
02281c87a4
|
Added TLS specific EC point formats
|
2010-09-06 18:42:43 +02:00 |
|
Martin Willi
|
ec7d4e70d3
|
Renamed ecp_format to ansi_format, as point formats in TLS use different identifiers
|
2010-09-06 18:37:24 +02:00 |
|
Martin Willi
|
fe559b5156
|
Accept TLS records with zero-length plaintext
|
2010-09-06 17:04:59 +02:00 |
|
Martin Willi
|
adb913adeb
|
Added strongswan.conf option to filter for specific TLS suites
|
2010-09-06 16:51:11 +02:00 |
|