aboutsummaryrefslogtreecommitdiffstats
path: root/src/libstrongswan
Commit message (Collapse)AuthorAgeFilesLines
* The va_list trick does not seem to be portable, revert dots-in-section fix4.4.1Martin Willi2010-07-301-58/+22
| | | | This reverts commit 8f50d06c354cd31fc295afc5598afff4096b5e77.
* Fixed settings lookup if the section/key contains dotsMartin Willi2010-07-291-22/+58
|
* Fix use of snprintf() in IETF attributes to string conversionMartin Willi2010-07-281-2/+11
|
* Fix use of snprintf() in identification DN to ASCII conversionMartin Willi2010-07-281-0/+12
|
* Added support for Certificate, CRL and PKCS10 encoding to PEM pluginMartin Willi2010-07-131-0/+19
|
* Support different encoding types in certificate.get_encoding()Martin Willi2010-07-1313-53/+166
|
* Renamed key_encod{ing,der}_t and constants, prepare for generic credential ↵Martin Willi2010-07-1335-313/+312
| | | | encoding
* Moved keys/key_encoding.[ch] to cred_encoding.[ch]Martin Willi2010-07-1310-9/+9
|
* Fixed doxygen group of cert_validator interfaceMartin Willi2010-07-131-1/+1
|
* Moved addrblock plugin to libcharonMartin Willi2010-07-136-299/+0
|
* Moved CRL/OCSP checking to a dedicated plugin called revocationMartin Willi2010-07-137-531/+757
|
* Made some useful methods in the credential manager publicMartin Willi2010-07-132-15/+70
|
* Moved X509 addrBlock validation to a separate addrblock pluginMartin Willi2010-07-139-59/+303
|
* Added a certificate validation hook to the credential managerMartin Willi2010-07-133-0/+103
|
* Migrated credential manager to INIT/METHOD macrosMartin Willi2010-07-131-161/+127
|
* Moved credential manager to libstrongswanMartin Willi2010-07-1316-0/+4032
|
* Charon uses a generic trunstchain length limit, not only for X509 certificatesMartin Willi2010-07-131-1/+0
|
* Avoid relocking while enumerator is aliveMartin Willi2010-07-061-9/+10
|
* Some Doxygen fixes.Tobias Brunner2010-07-051-4/+4
|
* Use the group constraint in a more generic fashion, not only for attribute ↵Martin Willi2010-07-052-8/+1
| | | | certificates
* Select subjectAltName address family using address length in openssl pluginMartin Willi2010-06-241-2/+12
|
* Select subjectAltName address family using address length in x509 pluginMartin Willi2010-06-241-1/+11
|
* Fixing compilation of the OpenSSL plugin if ENGINE support is disabled.Tobias Brunner2010-06-222-2/+14
| | | | | That is, enable compilation if OpenSSL was configured with OPENSSL_NO_ENGINE.
* Fixing compilation of the OpenSSL plugin if Elliptic Curve support is disabled.Tobias Brunner2010-06-224-3/+25
| | | | | That is, enable compilation if OpenSSL was configured with OPENSSL_NO_EC.
* Fixed plugin checks in Android.mk files.Tobias Brunner2010-06-221-2/+2
|
* Adding a remove_at method to the hash table.Tobias Brunner2010-06-072-9/+36
| | | | This allows to remove key-value pairs while enumerating them.
* Migrated hashtable_t to INIT/METHOD macros.Tobias Brunner2010-06-071-59/+45
|
* traffic_selector_t is gone into libstrongswan, migrate printf hook ↵Martin Willi2010-06-071-5/+8
| | | | registration, too.
* Unwrap subjectKeyIdentifier from OCTET_STRINGMartin Willi2010-05-261-4/+12
|
* Use CAs subjectKeyIdentifier as CRLs authorityKeyIdentifierMartin Willi2010-05-211-1/+1
|
* Added support for CRL generation to x509 pluginMartin Willi2010-05-215-3/+202
|
* Removed is_newer() from certificate_t, obsoleting all implementationsMartin Willi2010-05-2110-182/+2
|
* Added generic implementations for crl_is_newer/certificate_is_newerMartin Willi2010-05-214-1/+68
|
* Migrated x509_crl_t to INIT/METHOD macrosMartin Willi2010-05-211-95/+70
|
* Implemented X.509 CRL reading using OpenSSLMartin Willi2010-05-214-1/+606
|
* Implemented X.509 certificate reading using OpenSSLMartin Willi2010-05-216-2/+1054
|
* Fixed doxygen groupMartin Willi2010-05-201-1/+1
|
* Whitelist OpenSSLs ERR_put_error() in leak-detectiveMartin Willi2010-05-201-0/+1
| | | | | | | As we do not invoke ERR_get/clear_error() in all error cases, the error codes are not removed from the error queue. But it is save to whitelist the put function, as it uses a circular buffer that does not grow beyond ERR_NUM_ERRORS errors (16 by default).
* Option to skip slow addr2line resolution in leak-detectiveMartin Willi2010-05-206-48/+75
|
* Explicitly link gpg-error to gcrypt pluginMartin Willi2010-05-171-1/+1
|
* Support decoding of subjectPublicKeyInfo in openssl without pkcs1 pluginMartin Willi2010-05-052-2/+16
|
* Do not check pointer, but length of a chunkMartin Willi2010-05-051-1/+1
|
* Double-check that a blob passed to is_asn1() is not emptyMartin Willi2010-05-051-1/+7
|
* Do not print filename twice if plugin loading fails, dlerror() contains the ↵Martin Willi2010-05-051-2/+1
| | | | filename
* Implemented base32 encoding of chunks.Martin Willi2010-05-052-0/+75
|
* added getprotobyname to whitelist4.4.0Andreas Steffen2010-05-021-0/+1
|
* We have to rename thread_create on Mac OS X because it conflicts with a syscall.Tobias Brunner2010-04-291-0/+6
|
* The mutex of a thread has to be locked when destroying it.Tobias Brunner2010-04-291-0/+2
|
* Fixed RSA key generation with gcryptMartin Willi2010-04-291-1/+1
|
* PEM encoder supports encoding from RSA components directly, allowing gcrypt ↵Martin Willi2010-04-293-37/+42
| | | | plugin to encode in PEM