Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | certificate factory can load certs from file | Andreas Steffen | 2008-03-25 | 1 | -52/+54 | |
| | ||||||
* | defined *_create_from_file() constructors in ↵ | Andreas Steffen | 2008-03-25 | 1 | -103/+60 | |
| | | | | libstrongswan/credentials/certificates | |||||
* | shortened debug output | Andreas Steffen | 2008-03-21 | 1 | -2/+2 | |
| | ||||||
* | detect trusted self-signed before trust chain verification | Andreas Steffen | 2008-03-21 | 1 | -4/+14 | |
| | ||||||
* | optimized debug output of credential_manager.c | Andreas Steffen | 2008-03-21 | 1 | -21/+21 | |
| | ||||||
* | modified debug text | Andreas Steffen | 2008-03-20 | 1 | -1/+1 | |
| | ||||||
* | cert_cache_t caches subject-issuer relations and subject certificates | Martin Willi | 2008-03-20 | 4 | -3/+293 | |
| | | | | ocsp/crl do not benefit yet due missing lookup function | |||||
* | fallback to random end entity certificate if trustchain building fails | Martin Willi | 2008-03-20 | 1 | -3/+18 | |
| | ||||||
* | (no commit message) | Martin Willi | 2008-03-20 | 2 | -14/+86 | |
| | ||||||
* | added support for certificate requests for not yet known CAs | Martin Willi | 2008-03-20 | 4 | -5/+31 | |
| | ||||||
* | fixed verification of preinstalled certificates | Martin Willi | 2008-03-20 | 1 | -1/+1 | |
| | ||||||
* | more trustchain verification improvements | Martin Willi | 2008-03-20 | 1 | -99/+103 | |
| | | | | should fix crl-revoked and two-certs scenarios | |||||
* | refactored trustchain verification, this should fix #33 | Martin Willi | 2008-03-19 | 7 | -329/+531 | |
| | | | | moved auth_info/ocsp_response credset wrapper to separate files | |||||
* | increased debug level in trust chain verification for auditing purposes | Andreas Steffen | 2008-03-19 | 1 | -31/+50 | |
| | ||||||
* | The introduced SHA1_NOFINAL hasher was not sufficient for EAP-AKA, | Martin Willi | 2008-03-19 | 2 | -38/+25 | |
| | | | | | | as it requires to XOR the key into the hashers state. A new SHA1 based keyed hash function, implemented as PRF, enables EAP-AKA and the FIPS-PRF function to properly use the existing SHA1 implementation. | |||||
* | log nextUpdate of crls and ocsp responses | Andreas Steffen | 2008-03-19 | 1 | -12/+36 | |
| | ||||||
* | fixed stupid bug in fetch_ocsp() | Andreas Steffen | 2008-03-19 | 1 | -1/+1 | |
| | ||||||
* | attempt to achieve consistent debugging output | Andreas Steffen | 2008-03-19 | 5 | -62/+72 | |
| | ||||||
* | fixed shared key lookup in stroke | Martin Willi | 2008-03-19 | 1 | -1/+1 | |
| | ||||||
* | fixed peer_cfg lookup when omitting IDr | Martin Willi | 2008-03-19 | 2 | -3/+18 | |
| | ||||||
* | fixed CRL check return value on revoked certificates | Martin Willi | 2008-03-19 | 4 | -53/+19 | |
| | | | | | fixed possible refcounting bugs generic return_null() implementation | |||||
* | fixed compiler warning | Martin Willi | 2008-03-18 | 1 | -0/+1 | |
| | ||||||
* | added generic payload order rules for notifies | Martin Willi | 2008-03-18 | 1 | -0/+6 | |
| | ||||||
* | fixed ike_cfg lookup in stroke | Martin Willi | 2008-03-18 | 1 | -1/+1 | |
| | ||||||
* | added false positive signature check | Martin Willi | 2008-03-18 | 1 | -0/+6 | |
| | ||||||
* | added missing test case file ([3607]) | Martin Willi | 2008-03-18 | 1 | -0/+61 | |
| | ||||||
* | creating public key from RSA private key | Martin Willi | 2008-03-18 | 2 | -2/+4 | |
| | | | | RSA key generation and signature test | |||||
* | made is_newer() a certificate_t method | Andreas Steffen | 2008-03-18 | 2 | -78/+121 | |
| | ||||||
* | better normalized tables for SQL plugin (IDs) | Martin Willi | 2008-03-18 | 6 | -286/+453 | |
| | ||||||
* | enforcing x509_flags on certificate construction | Martin Willi | 2008-03-17 | 1 | -23/+12 | |
| | ||||||
* | logging to SQL database | Martin Willi | 2008-03-15 | 6 | -1/+255 | |
| | ||||||
* | correctly unregister IKE_SA at the bus | Martin Willi | 2008-03-15 | 1 | -1/+1 | |
| | ||||||
* | removed X509_PEER flag; flags are meant to read cert, not to store ↵ | Martin Willi | 2008-03-14 | 1 | -21/+12 | |
| | | | | | | | additional state in cert removed x509_t.set_flags for the reason above implemented a simple, generic shared_key_t | |||||
* | credential lookup in mysql/sqlite database | Martin Willi | 2008-03-14 | 7 | -2/+493 | |
| | ||||||
* | refactored buggy trustchain building, fixed refcount bug | Martin Willi | 2008-03-14 | 1 | -105/+91 | |
| | ||||||
* | SQL schema for MySQL and SQLite, test data | Martin Willi | 2008-03-14 | 4 | -89/+165 | |
| | ||||||
* | two small fixes | Tobias Brunner | 2008-03-13 | 3 | -5/+5 | |
| | ||||||
* | fixed apidoc grouping | Martin Willi | 2008-03-13 | 2 | -2/+2 | |
| | ||||||
* | added NetworkManager prototype DBUS policy, applet config | Martin Willi | 2008-03-13 | 2 | -0/+29 | |
| | ||||||
* | added old and unmaintained prototype of NetworkManager applet and authenticator | Martin Willi | 2008-03-13 | 3 | -0/+244 | |
| | ||||||
* | merged the modularization branch (credentials) back to trunk | Martin Willi | 2008-03-13 | 250 | -10583/+12994 | |
| | ||||||
* | improved P2P_NAT debugging | Andreas Steffen | 2008-02-27 | 2 | -4/+7 | |
| | ||||||
* | refactored connect_manager_t to use the find functions on linked lists | Tobias Brunner | 2008-02-14 | 1 | -157/+65 | |
| | ||||||
* | split connections with different virtual IPs in different peer_cfgs | Martin Willi | 2008-02-05 | 4 | -31/+49 | |
| | | | | respect different peer_cfg's when initiating a CHILD_SA within an existing IKE_SA | |||||
* | implemented IKEV2 EAP-SIM server and client test module that use triplets ↵ | Andreas Steffen | 2008-02-04 | 4 | -141/+725 | |
| | | | | stored in a file. For details see the scenario 'ikev2/rw-eap-sim-rsa' | |||||
* | use identifiers in EAP_SUCCESS/EAP_FAILURE payloads | Martin Willi | 2008-02-04 | 3 | -15/+19 | |
| | ||||||
* | next_payload must be of type u_int8_t | Andreas Steffen | 2008-02-01 | 1 | -1/+2 | |
| | ||||||
* | NAT-T conditions were not inherited during IKE_SA rekeying | Andreas Steffen | 2008-01-29 | 1 | -1/+8 | |
| | ||||||
* | added missing hasher include | Martin Willi | 2008-01-03 | 1 | -0/+1 | |
| | ||||||
* | fixed EAP-MD5 to accept Name attribute in challenge | Martin Willi | 2007-12-18 | 1 | -1/+2 | |
| |