Martin Willi
|
1db6bf2f3f
|
If TLS peer authentication not required, the client does nonetheless, allow it to fail
|
2013-03-06 15:53:12 +01:00 |
|
Martin Willi
|
807f2facd0
|
Request a TLS client certificate even if no peer identity is given
This allows a peer to perform client authentication if it wants, but skip
it if not.
|
2013-02-28 16:46:08 +01:00 |
|
Martin Willi
|
257c80cb5b
|
Wrap tls_t.get_{server,peer}_id methods in tls_socket_t
|
2013-02-28 16:46:08 +01:00 |
|
Martin Willi
|
2de481e32b
|
Delegate tls_t.get_{peer,server}_id to handshake layer
This allows to get updated peer identities if the peer can't authenticate,
or does when it is optional.
|
2013-02-28 16:46:08 +01:00 |
|
Martin Willi
|
8b56943222
|
Merge branch 'pt-tls'
|
2013-02-14 17:06:07 +01:00 |
|
Andreas Steffen
|
bd1ee5bdc4
|
make AR identities available to IMVs via IF-IMV 1.4 draft
|
2013-02-11 15:30:44 +01:00 |
|
Martin Willi
|
435348f406
|
Send TLS close notify during tls_socket_t destruction
|
2013-01-15 17:43:05 +01:00 |
|
Martin Willi
|
7bbf7aa97a
|
Send TLS close notify if application returns SUCCESS
|
2013-01-15 17:43:05 +01:00 |
|
Martin Willi
|
c43e8fdec4
|
Block TLS read when sending data, but have to wait for the handshake data first
|
2013-01-15 17:43:05 +01:00 |
|
Martin Willi
|
ee90c78998
|
Use a more POSIXy tls_socket interface with more flexibility.
If an unsufficient read buffer is provided, application data gets cached
for subsequent read() calls.
|
2013-01-15 17:43:05 +01:00 |
|
Tobias Brunner
|
07f826af67
|
Fixed encoding of TLS extensions (elliptic_curves and signature_algorithms)
|
2012-11-28 10:20:14 +01:00 |
|
Tobias Brunner
|
f05b427265
|
Moved debug.[ch] to utils folder
|
2012-10-24 16:00:51 +02:00 |
|
Tobias Brunner
|
12642a6831
|
Moved data structures to new collections subfolder
|
2012-10-24 16:00:49 +02:00 |
|
Tobias Brunner
|
1407a0026f
|
Added missing break when building TLS cipher suites
|
2012-09-28 18:55:40 +02:00 |
|
Martin Willi
|
ab2c989c32
|
Don't allow NULL encryption with PEAP
|
2012-09-12 13:19:52 +02:00 |
|
Martin Willi
|
acada66a35
|
Use memmove on overlapping regions, and operate with correct sizeof()
|
2012-09-12 13:19:52 +02:00 |
|
Martin Willi
|
fb3cf1b708
|
Whitespace cleanups in tls_eap
|
2012-09-12 13:19:52 +02:00 |
|
Martin Willi
|
02cabd0f26
|
Check if TLS handshake received Finished before processing application data
|
2012-08-09 12:10:41 +02:00 |
|
Martin Willi
|
2df12b4c57
|
Fix tls_prf bug introduced with bc474883
|
2012-07-17 11:33:05 +02:00 |
|
Martin Willi
|
87dd205b61
|
Add a return value to hasher_t.allocate_hash()
|
2012-07-16 14:55:06 +02:00 |
|
Martin Willi
|
8bd6a30af1
|
Add a return value to hasher_t.get_hash()
|
2012-07-16 14:55:06 +02:00 |
|
Martin Willi
|
ce73fc19db
|
Add a return value to crypter_t.set_key()
|
2012-07-16 14:53:38 +02:00 |
|
Martin Willi
|
3b96189a2a
|
Add a return value to crypter_t.decrypt()
|
2012-07-16 14:53:38 +02:00 |
|
Martin Willi
|
e35abbe588
|
Add a return value to crypter_t.encrypt
|
2012-07-16 14:53:37 +02:00 |
|
Martin Willi
|
bb5eb15ccc
|
Check rng return value when generating TLS session identifiers
|
2012-07-16 14:53:37 +02:00 |
|
Tobias Brunner
|
126eb2af59
|
Check rng return value when generating secrets and IVs in libtls
|
2012-07-16 14:53:37 +02:00 |
|
Martin Willi
|
f3ca96b2bf
|
Add a return value to prf_t.set_key()
|
2012-07-16 14:53:34 +02:00 |
|
Martin Willi
|
bc47488323
|
Add a return value to prf_t.get_bytes()
|
2012-07-16 14:53:33 +02:00 |
|
Martin Willi
|
e7d98b8c99
|
Add a return value to tls_prf_t.set_key()
|
2012-07-16 14:53:33 +02:00 |
|
Martin Willi
|
97b30b93b0
|
Add a return value to tls_prf_t.get_bytes()
|
2012-07-16 14:53:33 +02:00 |
|
Martin Willi
|
2d56575d52
|
Add a return value to signer_t.set_key()
|
2012-07-16 14:53:33 +02:00 |
|
Martin Willi
|
9020f7d0b9
|
Add a return value to tls_crypto_t.derive_secrets()
|
2012-07-16 14:53:33 +02:00 |
|
Martin Willi
|
2e96de60a8
|
Add a return value to signer_t.get_signature()
|
2012-07-16 14:53:33 +02:00 |
|
Martin Willi
|
cbfbba7d86
|
Add a return value to signer_t.allocate_signature()
|
2012-07-16 14:53:32 +02:00 |
|
Andreas Steffen
|
6245edf37e
|
eliminate message length field in EAP-TNC
|
2012-07-11 17:09:05 +02:00 |
|
Andreas Steffen
|
c36680962c
|
allow to transmit 64k TLS Handshake and Application messages via EAP-[T]TLS
|
2012-07-11 17:09:04 +02:00 |
|
Andreas Steffen
|
dfe82160e4
|
some tls_eap optimizations
|
2012-07-11 17:09:04 +02:00 |
|
Andreas Steffen
|
3bd452f8f3
|
max_message_count = 0 disables limit
|
2012-07-11 17:09:04 +02:00 |
|
Andreas Steffen
|
da67c37d65
|
log invalid TLS packet length
|
2012-07-11 17:09:04 +02:00 |
|
Martin Willi
|
b188f23199
|
Install dev headers only if --with-dev-headers= option is set
|
2012-07-11 11:16:31 +02:00 |
|
Martin Willi
|
2a6bcbbdee
|
Install libtls development headers
|
2012-07-11 10:51:01 +02:00 |
|
Martin Willi
|
ae10ee6d0b
|
Double check if a cached suite is available, overwrite any old suite state
|
2012-02-07 11:42:57 +01:00 |
|
Tobias Brunner
|
b96eb46d5c
|
Some Doxygen fixes.
|
2012-02-07 11:20:46 +01:00 |
|
Martin Willi
|
06c150365d
|
Fix TLS EAP-MSK derivation, uses different order of randoms than key expansion
|
2012-02-07 10:54:53 +01:00 |
|
Martin Willi
|
1dabf5bfc7
|
Filter TLS suite MAC by HMAC algorithm, as the hash is not necessarily the same
|
2012-02-07 10:54:53 +01:00 |
|
Martin Willi
|
3a87c89b1b
|
Added a tls_socket_t.splice method to wrap a file descriptor into TLS
|
2011-12-31 13:14:49 +01:00 |
|
Martin Willi
|
6a5c86b7ad
|
Implemented TLS session resumption both as client and as server
|
2011-12-31 13:14:49 +01:00 |
|
Martin Willi
|
ca5767621b
|
Implemented a TLS session cache
|
2011-12-31 13:14:49 +01:00 |
|
Martin Willi
|
703c0db894
|
Check for cipherspec changes after each handshake message
|
2011-12-31 13:14:49 +01:00 |
|
Martin Willi
|
4caa380625
|
Separated cipherspec checking and switching, allowing us to defer the second
|
2011-12-31 13:14:49 +01:00 |
|