Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
| * | openssl: Update x509 API to OpenSSL 1.1.0 | Tobias Brunner | 2016-06-29 | 1 | -12/+48 | |
| | | ||||||
| * | openssl: Update ECDSA API to OpenSSL 1.1.0 | Tobias Brunner | 2016-06-29 | 2 | -5/+24 | |
| | | ||||||
| * | openssl: Update RSA API to OpenSSL 1.1.0 | Tobias Brunner | 2016-06-29 | 2 | -16/+52 | |
| | | ||||||
| * | openssl: Make some utilities take const BIGNUM pointers | Tobias Brunner | 2016-06-29 | 2 | -4/+6 | |
| | | ||||||
| * | openssl: Add macro to define fallback functions for non-opaque OpenSSL versions | Tobias Brunner | 2016-06-29 | 1 | -0/+38 | |
| | | ||||||
| * | openssl: Update DH API to OpenSSL 1.1.0 | Tobias Brunner | 2016-06-29 | 1 | -11/+41 | |
| | | ||||||
| * | openssl: Update crypter API to OpenSSL 1.1.0 | Tobias Brunner | 2016-06-29 | 1 | -12/+17 | |
| | | | | | | | | | | EVP_CIPHER and EVP_CIPHER_CTX are now opaque types, the getters already existed before. | |||||
| * | openssl: Fix mapping from ASN1 to chunk_t with OpenSSL 1.1.0 | Tobias Brunner | 2016-06-29 | 1 | -1/+7 | |
| | | | | | | | | ASN1_OBJECT is now opaque. | |||||
| * | openssl: Update initialization and cleanup for OpenSSL 1.1.0 | Tobias Brunner | 2016-06-29 | 1 | -7/+17 | |
| | | | | | | | | | | | | We can't call OPENSSL_cleanup() as that would prevent us from re-initializing the library again (which we use in the Android app, that loads/unloads plugins). | |||||
| * | openssl: OpenSSL 1.1.0 is thread-safe so we don't have to setup callbacks | Tobias Brunner | 2016-06-29 | 1 | -0/+13 | |
|/ | ||||||
* | testing: Ignore tests/local directory | Tobias Brunner | 2016-06-29 | 1 | -0/+1 | |
| | | | | | This could be used for experimental test scenarios that should not get tracked in the repository. | |||||
* | android: Actually add Android.mk for libtpmtss | Tobias Brunner | 2016-06-28 | 1 | -0/+32 | |
| | ||||||
* | travis: Disable tss-tss2 and aikpub2 but enable TrouSerS and build aikgen | Tobias Brunner | 2016-06-28 | 1 | -2/+5 | |
| | | | | Ubuntu 12.04 does not provide libtss2-dev. | |||||
* | configure: Enable respective TSS if aikgen/-pub2 are enabled | Tobias Brunner | 2016-06-28 | 1 | -2/+10 | |
| | ||||||
* | android: Fix build after adding libtpmtss | Tobias Brunner | 2016-06-28 | 4 | -4/+7 | |
| | ||||||
* | Version bump to 5.5.0dr15.5.0dr1 | Andreas Steffen | 2016-06-26 | 2 | -1/+9 | |
| | ||||||
* | Merge branch 'tpm2' | Andreas Steffen | 2016-06-26 | 43 | -1004/+3198 | |
|\ | | | | | | | | | | | The libtpmtss library supports both TPM 1.2 and TPM 2.0 Trusted Platform Modules. Features comprise capability discovery, listing of PCRs, AIK generation and quote signatures. | |||||
| * | libtpmtss: Added to integrity checks | Andreas Steffen | 2016-06-26 | 4 | -0/+19 | |
| | | ||||||
| * | aikpub2: Output AIK signature algorithm | Andreas Steffen | 2016-06-26 | 1 | -1/+14 | |
| | | ||||||
| * | Refactoring to tpm_tss_quote_info object | Andreas Steffen | 2016-06-26 | 24 | -397/+923 | |
| | | ||||||
| * | libimcv: Changed debug level for functional components from 2 to 3 | Andreas Steffen | 2016-06-26 | 1 | -2/+2 | |
| | | ||||||
| * | libtpmtss: Implemented TSS2 quote() method | Andreas Steffen | 2016-06-26 | 2 | -23/+142 | |
| | | ||||||
| * | libtpmtss: Implemented TSS2 read_pcr() method | Andreas Steffen | 2016-06-22 | 1 | -6/+114 | |
| | | ||||||
| * | libimcv: migrate pts to tpm_tss | Andreas Steffen | 2016-06-22 | 12 | -496/+572 | |
| | | ||||||
| * | libtpmtss: Get TPM 2.0 capabilities | Andreas Steffen | 2016-06-22 | 4 | -2/+227 | |
| | | ||||||
| * | libtpmtss: Retrieve TPM 1.2 version info | Andreas Steffen | 2016-06-22 | 3 | -3/+75 | |
| | | ||||||
| * | Created libtpmtss library handling access to v1.2 and v2.0 TPMs | Andreas Steffen | 2016-06-22 | 15 | -403/+927 | |
| | | ||||||
| * | aikpub2: --handle option retrieves public key from TPM 2.0 NVRAM | Andreas Steffen | 2016-06-22 | 2 | -30/+147 | |
| | | ||||||
| * | aikpub2: Convert TSS 2.0 AIK public key blob into PKCS#1 format | Andreas Steffen | 2016-06-22 | 7 | -5/+400 | |
|/ | ||||||
* | testing: Start charon before Apache in tnc/tnccs-20-pdp-pt-tls | Tobias Brunner | 2016-06-21 | 1 | -1/+1 | |
| | | | | | | | | | | | | | The change in c423d0e8a124 ("testing: Fix race in tnc/tnccs-20-pdp-pt-tls scenario") is not really ideal as now the vici plugin might not yet be ready when `swanctl --load-creds` is called. Perhaps starting charon before Apache causes enough delay. Once we switch to charon-systemd this isn't a problem anymore as starting the unit will block until everything is up and ready. Also, the individual swanctl calls will be redundant as the default service unit calls --load-all. But start scripts do run before charon-systemd signals that the daemon is ready, so using these would work too then. | |||||
* | testing: Only load selected plugins in swanctl | Tobias Brunner | 2016-06-20 | 1 | -0/+4 | |
| | | | | | | | | | The main issue is that the ldap and curl plugins, or rather the libraries they use, initialize GnuTLS (curl, strangely, even when it is, by its own account, linked against OpenSSL). Some of these allocations are only freed once the libraries are unloaded. This means that the leak detective causes invalid frees when swanctl is terminated and libraries are unloaded after the leak detective is already deinitialized. | |||||
* | Merge branch 'exchange-collisions' | Tobias Brunner | 2016-06-17 | 54 | -329/+6479 | |
|\ | | | | | | | | | | | | | | | | | | | Improves the handling of IKEv2 exchange collisions in several corner cases. TEMPORARY_FAILURE and CHILD_SA_NOT_FOUND notifies that were defined with RFC 7296 are now handled and sent as appropriate. The behavior in these situations is tested with new unit tests. Fixes #379, #464, #876, #1293. | |||||
| * | unit-tests: Add tests for expires after CHILD_SA rekeying | Tobias Brunner | 2016-06-17 | 1 | -0/+129 | |
| | | ||||||
| * | child-rekey: Only rekey installed CHILD_SAs | Tobias Brunner | 2016-06-17 | 1 | -7/+14 | |
| | | | | | | | | | | | | | | | | | | | | | | | | Depending on the lifetimes a CHILD_SA we rekeyed as responder might expire shortly afterwards. We don't want to rekey it again. When retrying due to an INVALID_KE_PAYLOAD notify the expected state is CHILD_REKEYING if it is anything else (e.g. due to a collision) we ignore it. We also abort the exchange properly if we don't find the CHILD_SA, no need for an empty INFORMATIONAL exchange anymore. | |||||
| * | Report test coverage of libcharon and starter | Tobias Brunner | 2016-06-17 | 2 | -0/+6 | |
| | | ||||||
| * | unit-tests: Add test for CHILD_SA rekey if a retry due to an ↵ | Tobias Brunner | 2016-06-17 | 1 | -0/+143 | |
| | | | | | | | | INVALID_KE_PAYLOAD is delayed | |||||
| * | child-rekey: Ignore failed colliding CHILD_SA rekeyings | Tobias Brunner | 2016-06-17 | 1 | -1/+10 | |
| | | | | | | | | | | | | | | If a passive rekeying fails due to an INVALID_KE_PAYLOAD we don't want to consider this task later when resolving collisions. This previously might have caused the wrong SA to get deleted/installed based on the nonces in the unsuccessful exchange. | |||||
| * | unit-tests: Add test for collision between IKE_SA rekey and CHILD_SA creation | Tobias Brunner | 2016-06-17 | 3 | -0/+108 | |
| | | ||||||
| * | child-create: Retry creating the CHILD_SA if TEMPORARY_FAILURE is received | Tobias Brunner | 2016-06-17 | 1 | -4/+33 | |
| | | | | | | | | We queue a delayed task that is initiated after a while. | |||||
| * | ikev2: Add possibility to delay initiation of a queued task | Tobias Brunner | 2016-06-17 | 5 | -66/+189 | |
| | | | | | | | | | | | | | | | | | | | | | | Such a task is not initiated unless a certain time has passed. This allows delaying certain tasks but avoids problems if we'd do this via a scheduled job (e.g. if the IKE_SA is rekeyed in the meantime). If the IKE_SA is rekeyed the delay of such tasks is reset when the tasks are adopted i.e. they get executed immediately on the new IKE_SA. This hasn't been implemented for IKEv1 yet. | |||||
| * | ike: Reduce RETRY_INTERVAL a bit | Tobias Brunner | 2016-06-17 | 1 | -2/+2 | |
| | | | | | | | | Retry exchanges between 5 and 15 seconds after a temporary failure. | |||||
| * | ike-rekey: Return TEMPORARY_FAILURE when concurrently creating a CHILD_SA | Tobias Brunner | 2016-06-17 | 1 | -14/+35 | |
| | | ||||||
| * | unit-tests: Add tests for IKE rekeying if INVALID_KE_PAYLOAD notifies are ↵ | Tobias Brunner | 2016-06-17 | 1 | -0/+470 | |
| | | | | | | | | received | |||||
| * | ike: Add configuration option to switch to preferring supplied proposals ↵ | Tobias Brunner | 2016-06-17 | 6 | -10/+26 | |
| | | | | | | | | over local ones | |||||
| * | child-cfg: Add option to prefer supplied proposals over locally configured ones | Tobias Brunner | 2016-06-17 | 4 | -23/+38 | |
| | | ||||||
| * | ike-cfg: Add option to prefer supplied proposals over locally configured ones | Tobias Brunner | 2016-06-17 | 5 | -32/+48 | |
| | | ||||||
| * | proposal: Remove MODP_NONE from IKE proposals parsed from strings | Tobias Brunner | 2016-06-17 | 1 | -0/+10 | |
| | | ||||||
| * | proposal: Handle MODP_NONE in both directions when selecting proposals | Tobias Brunner | 2016-06-17 | 4 | -6/+97 | |
| | | ||||||
| * | proposal: Parse modpnone as MODP_NONE(0) | Tobias Brunner | 2016-06-17 | 1 | -0/+1 | |
| | | ||||||
| * | ike-rekey: Make sure to ignore task when detecting collisions if ike-init ↵ | Tobias Brunner | 2016-06-17 | 1 | -1/+2 | |
| | | | | | | | | | | | | | | subtask failed For instance, if INVALID_KE_PAYLOAD is returned we don't want this task to affect any active rekeying (no new SA has been established so far). |