Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | treat sig_alg and algorithm comparison in a consistent way over all ↵ | Andreas Steffen | 2008-03-26 | 2 | -3/+9 | |
| | | | | certificate types | |||||
* | fixed rightca= constraint checking | Martin Willi | 2008-03-26 | 1 | -21/+58 | |
| | | | | implemented rightca= for intermediate CAs we do not have the certificate at config load | |||||
* | fixed auth_info_t.equals() | Martin Willi | 2008-03-26 | 1 | -1/+1 | |
| | ||||||
* | splitted stroke plugin to several files: | Martin Willi | 2008-03-26 | 18 | -3285/+4155 | |
| | | | | | | | | | | | socket: reads messages from socket, dispatching config: process add/del conn, serves configs through backend_t control: controlling of the daemon (up/down/route/...( cred: credential loading, serves creds through credential_set_t ca: ca sections from ipsec.conf, serves cdp's through credential_set_t list: log status information to stroke console (status/statusall/list*) shared_key: shared key implementation for keys read from ipsec.secrets plugin: registers stroke plugin and starts socket w/ thread | |||||
* | added equals() method to peer_cfg, ike_cfg, proposals, auth_info | Martin Willi | 2008-03-26 | 18 | -261/+569 | |
| | | | | | | allows easier merging of ipsec.conf connections replaced some iterators through enumerators made proposals algorithm_t private using enumerator | |||||
* | fixed compiler warnings | Martin Willi | 2008-03-26 | 3 | -10/+15 | |
| | ||||||
* | certificate factory can load certs from file | Andreas Steffen | 2008-03-25 | 12 | -261/+481 | |
| | ||||||
* | added component BUILD_FROM_FILE | Andreas Steffen | 2008-03-25 | 3 | -2/+6 | |
| | ||||||
* | renamed certificate field in x509_cert.c to encoding | Andreas Steffen | 2008-03-25 | 1 | -9/+5 | |
| | ||||||
* | added ac.c | Andreas Steffen | 2008-03-25 | 1 | -0/+55 | |
| | ||||||
* | defined *_create_from_file() constructors in ↵ | Andreas Steffen | 2008-03-25 | 7 | -106/+157 | |
| | | | | libstrongswan/credentials/certificates | |||||
* | fixed refence counts before calling attribute certificate factory | Andreas Steffen | 2008-03-25 | 2 | -66/+24 | |
| | ||||||
* | corrected some doxygen entries | Andreas Steffen | 2008-03-22 | 4 | -26/+13 | |
| | ||||||
* | optimized self-signed certificate detection | Andreas Steffen | 2008-03-21 | 1 | -7/+6 | |
| | ||||||
* | shortened debug output | Andreas Steffen | 2008-03-21 | 1 | -2/+2 | |
| | ||||||
* | detect trusted self-signed before trust chain verification | Andreas Steffen | 2008-03-21 | 1 | -4/+14 | |
| | ||||||
* | self-signed certificates were not marked by x509_cert.c | Andreas Steffen | 2008-03-21 | 1 | -14/+22 | |
| | ||||||
* | added ietf group attribute support to attibute certificate factory | Andreas Steffen | 2008-03-21 | 5 | -2/+11 | |
| | ||||||
* | fixed memory allocation problem in openac | Andreas Steffen | 2008-03-21 | 2 | -14/+10 | |
| | ||||||
* | added BUILD_SERIAL component and fixed several ac bugs | Andreas Steffen | 2008-03-21 | 5 | -9/+21 | |
| | ||||||
* | added VALIDATION_UNKNOWN to cert_validation_names | Andreas Steffen | 2008-03-21 | 1 | -0/+1 | |
| | ||||||
* | added credential factory support for BULD_NOT_BEFORE_TIME and ↵ | Andreas Steffen | 2008-03-21 | 4 | -24/+31 | |
| | | | | BUILD_NOT_AFTER_TIME | |||||
* | added x509_ac_builder plugin | Andreas Steffen | 2008-03-21 | 1 | -0/+5 | |
| | ||||||
* | initialize library in openac | Andreas Steffen | 2008-03-21 | 2 | -5/+24 | |
| | ||||||
* | suppress IKEv2-specific policy flags in pluto. Patch contributed by Heiko ↵ | Andreas Steffen | 2008-03-21 | 1 | -0/+8 | |
| | | | | Hund from Astaro. | |||||
* | optimized debug output of credential_manager.c | Andreas Steffen | 2008-03-21 | 1 | -21/+21 | |
| | ||||||
* | removed build.h include | Andreas Steffen | 2008-03-20 | 1 | -2/+0 | |
| | ||||||
* | refactored openac and its attribute certificate factory | Andreas Steffen | 2008-03-20 | 12 | -275/+1542 | |
| | ||||||
* | modified debug text | Andreas Steffen | 2008-03-20 | 1 | -1/+1 | |
| | ||||||
* | cert_cache_t caches subject-issuer relations and subject certificates | Martin Willi | 2008-03-20 | 4 | -3/+293 | |
| | | | | ocsp/crl do not benefit yet due missing lookup function | |||||
* | fallback to random end entity certificate if trustchain building fails | Martin Willi | 2008-03-20 | 1 | -3/+18 | |
| | ||||||
* | (no commit message) | Martin Willi | 2008-03-20 | 2 | -14/+86 | |
| | ||||||
* | some C libraries need _GNU_SOURCE for rwlocks | Martin Willi | 2008-03-20 | 1 | -0/+2 | |
| | ||||||
* | added support for certificate requests for not yet known CAs | Martin Willi | 2008-03-20 | 4 | -5/+31 | |
| | ||||||
* | added $ | Andreas Steffen | 2008-03-20 | 1 | -0/+2 | |
| | ||||||
* | fixed verification of preinstalled certificates | Martin Willi | 2008-03-20 | 1 | -1/+1 | |
| | ||||||
* | included utils/linked_list.h | Andreas Steffen | 2008-03-20 | 1 | -0/+1 | |
| | ||||||
* | more trustchain verification improvements | Martin Willi | 2008-03-20 | 1 | -99/+103 | |
| | | | | should fix crl-revoked and two-certs scenarios | |||||
* | cleaned up includes | Andreas Steffen | 2008-03-20 | 1 | -1/+3 | |
| | ||||||
* | CA certificates are allowed to sign OCSP responsed without OCSP_SIGNER flag | Martin Willi | 2008-03-20 | 1 | -1/+2 | |
| | ||||||
* | refactored trustchain verification, this should fix #33 | Martin Willi | 2008-03-19 | 7 | -329/+531 | |
| | | | | moved auth_info/ocsp_response credset wrapper to separate files | |||||
* | increased debug level in trust chain verification for auditing purposes | Andreas Steffen | 2008-03-19 | 1 | -31/+50 | |
| | ||||||
* | removed unimplemented private/public key function declarations | Martin Willi | 2008-03-19 | 2 | -47/+0 | |
| | ||||||
* | The introduced SHA1_NOFINAL hasher was not sufficient for EAP-AKA, | Martin Willi | 2008-03-19 | 10 | -109/+183 | |
| | | | | | | as it requires to XOR the key into the hashers state. A new SHA1 based keyed hash function, implemented as PRF, enables EAP-AKA and the FIPS-PRF function to properly use the existing SHA1 implementation. | |||||
* | log nextUpdate of crls and ocsp responses | Andreas Steffen | 2008-03-19 | 1 | -12/+36 | |
| | ||||||
* | fixed stupid bug in fetch_ocsp() | Andreas Steffen | 2008-03-19 | 1 | -1/+1 | |
| | ||||||
* | attempt to achieve consistent debugging output | Andreas Steffen | 2008-03-19 | 7 | -69/+79 | |
| | ||||||
* | fixed shared key lookup in stroke | Martin Willi | 2008-03-19 | 1 | -1/+1 | |
| | ||||||
* | fixed peer_cfg lookup when omitting IDr | Martin Willi | 2008-03-19 | 2 | -3/+18 | |
| | ||||||
* | fixed CRL check return value on revoked certificates | Martin Willi | 2008-03-19 | 6 | -53/+32 | |
| | | | | | fixed possible refcounting bugs generic return_null() implementation |