Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | Fix leak in pki --pkcs7 --decrypt | Martin Willi | 2012-12-19 | 1 | -0/+1 | |
| | ||||||
* | Add a pki command to sign, verify, encrypt and decrypt PKCS#7 containers | Martin Willi | 2012-12-19 | 1 | -0/+391 | |
| | ||||||
* | allow the optional sharing if RSA private keys | Andreas Steffen | 2012-11-22 | 1 | -3/+31 | |
| | ||||||
* | implemented generation of safe primes | Andreas Steffen | 2012-11-18 | 1 | -7/+20 | |
| | ||||||
* | Moved debug.[ch] to utils folder | Tobias Brunner | 2012-10-24 | 2 | -2/+2 | |
| | ||||||
* | Moved data structures to new collections subfolder | Tobias Brunner | 2012-10-24 | 4 | -4/+4 | |
| | ||||||
* | Use centralized hasher names in pki utility | Martin Willi | 2012-07-17 | 4 | -8/+8 | |
| | ||||||
* | Check rng return value when generating serial numbers in pki utility | Tobias Brunner | 2012-07-16 | 2 | -8/+8 | |
| | ||||||
* | certificate_t->issued_by takes an argument to receive signature scheme | Martin Willi | 2012-06-12 | 1 | -1/+1 | |
| | ||||||
* | Merge branch 'ikev1' | Martin Willi | 2012-05-02 | 3 | -0/+12 | |
|\ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Conflicts: configure.in man/ipsec.conf.5.in src/libcharon/encoding/generator.c src/libcharon/encoding/payloads/notify_payload.c src/libcharon/encoding/payloads/notify_payload.h src/libcharon/encoding/payloads/payload.c src/libcharon/network/receiver.c src/libcharon/sa/authenticator.c src/libcharon/sa/authenticator.h src/libcharon/sa/ikev2/tasks/ike_init.c src/libcharon/sa/task_manager.c src/libstrongswan/credentials/auth_cfg.c | |||||
| * | Merge branch 'ikev1-clean' into ikev1-master | Martin Willi | 2012-03-20 | 3 | -0/+12 | |
| |\ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Conflicts: configure.in man/ipsec.conf.5.in src/libcharon/daemon.c src/libcharon/plugins/eap_ttls/eap_ttls_peer.c src/libcharon/plugins/eap_radius/eap_radius_accounting.c src/libcharon/plugins/eap_radius/eap_radius_forward.c src/libcharon/plugins/farp/farp_listener.c src/libcharon/sa/ike_sa.c src/libcharon/sa/keymat.c src/libcharon/sa/task_manager.c src/libcharon/sa/trap_manager.c src/libstrongswan/plugins/x509/x509_cert.c src/libstrongswan/utils.h Applied lost changes of moved files keymat.c and task_manager.c. Updated listener_t.message hook signature in new plugins. | |||||
| | * | Added support for iKEIntermediate flag to ipsec pki. | Tobias Brunner | 2012-03-20 | 3 | -0/+12 | |
| | | | ||||||
* | | | ASN.1 two's complement encoding prevents overflow in CRL serial number | Andreas Steffen | 2012-04-04 | 1 | -10/+18 | |
| | | | ||||||
* | | | moved chunk_skip_zero to chunk.h | Andreas Steffen | 2012-04-03 | 1 | -17/+0 | |
| | | | ||||||
* | | | remove leading zeros in ASN.1 encoded serial numbers | Andreas Steffen | 2012-03-27 | 1 | -2/+22 | |
|/ / | ||||||
* / | pki: Avoid integer overflow when calculating certificate lifetimes. | Tobias Brunner | 2011-12-23 | 3 | -3/+3 | |
|/ | | | | This only works properly if sizeof(time_t) > 4. | |||||
* | Do proper cleanup in error case in pki req. | Tobias Brunner | 2011-04-14 | 1 | -1/+2 | |
| | ||||||
* | Do proper cleanup in some error cases in pki signcrl. | Tobias Brunner | 2011-04-14 | 1 | -2/+4 | |
| | ||||||
* | use DN from pkcs10 request if it exists | Andreas Steffen | 2011-02-07 | 1 | -5/+6 | |
| | ||||||
* | Added support for empty subjects DNs to pki --issue | Martin Willi | 2011-01-05 | 1 | -8/+7 | |
| | ||||||
* | Use incremented serial of base CRL when signing delta CRL | Martin Willi | 2011-01-05 | 1 | -0/+2 | |
| | ||||||
* | Slightly renamed different policyConstraints to distinguish them better | Martin Willi | 2011-01-05 | 2 | -12/+12 | |
| | ||||||
* | Added inhibitAnyPolicy constraint support to pki tool | Martin Willi | 2011-01-05 | 3 | -5/+21 | |
| | ||||||
* | Use a generic getter for all numerical X.509 constraints | Martin Willi | 2011-01-05 | 1 | -10/+10 | |
| | ||||||
* | Added support for delta CRLs to pki tool | Martin Willi | 2011-01-05 | 3 | -18/+91 | |
| | ||||||
* | Simplified format of x509 CRL URI parsing/enumerator | Martin Willi | 2011-01-05 | 2 | -14/+30 | |
| | ||||||
* | Added policyConstraints support to pki tool | Martin Willi | 2011-01-05 | 3 | -45/+86 | |
| | ||||||
* | Slightly renamed X509_NO_PATH_LEN_CONSTRAINT to use it for ↵ | Martin Willi | 2011-01-05 | 3 | -3/+3 | |
| | | | | PolicyConstraints, too | |||||
* | Added policyMappings support to pki tool | Martin Willi | 2011-01-05 | 3 | -12/+121 | |
| | ||||||
* | Added certificatePolicy options to pki tool | Martin Willi | 2011-01-05 | 3 | -4/+135 | |
| | ||||||
* | pki --issue/self support permitted/excluded NameConstraints | Martin Willi | 2011-01-05 | 2 | -18/+56 | |
| | ||||||
* | pki --print prints NameConstraints | Martin Willi | 2011-01-05 | 1 | -0/+25 | |
| | ||||||
* | CRLSign keyUsage or CA basicConstraint are sufficient for CRL validation | Martin Willi | 2011-01-05 | 1 | -2/+2 | |
| | ||||||
* | pki tool shows and builds crlSign keyUsage | Martin Willi | 2011-01-05 | 3 | -2/+14 | |
| | ||||||
* | Added --crlissuer option to pki --issue | Martin Willi | 2011-01-05 | 1 | -18/+25 | |
| | ||||||
* | Added support for CRL Issuers to x509 and OpenSSL plugins | Martin Willi | 2011-01-05 | 1 | -3/+8 | |
| | ||||||
* | Added crl support to pki --print | Martin Willi | 2010-08-30 | 1 | -7/+52 | |
| | ||||||
* | Use bits instead of bytes for a private/public key | Martin Willi | 2010-08-10 | 1 | -1/+1 | |
| | ||||||
* | Added PKCS#11 private key support to the pki tool | Martin Willi | 2010-08-04 | 4 | -22/+81 | |
| | ||||||
* | Use a dedicated build part for challenge passwords, BUILD_PASSPHRASE gets ↵ | Martin Willi | 2010-08-04 | 1 | -1/+1 | |
| | | | | obsolete | |||||
* | Added pki PEM encoding support for certificates, CRLs and PKCS10 requests | Martin Willi | 2010-07-13 | 6 | -14/+46 | |
| | ||||||
* | Support different encoding types in certificate.get_encoding() | Martin Willi | 2010-07-13 | 4 | -8/+4 | |
| | ||||||
* | Renamed key_encod{ing,der}_t and constants, prepare for generic credential ↵ | Martin Willi | 2010-07-13 | 4 | -10/+10 | |
| | | | | encoding | |||||
* | Changed default lifetime of certificates to 3 years | Martin Willi | 2010-05-31 | 2 | -4/+4 | |
| | ||||||
* | Support extendedKeyUsage flags in self-signed certificates | Martin Willi | 2010-05-31 | 1 | -0/+16 | |
| | ||||||
* | Added a --signcrl command to the pki utility | Martin Willi | 2010-05-21 | 1 | -0/+375 | |
| | ||||||
* | Added a --print command to pki that dumps different credentials | Martin Willi | 2010-05-20 | 1 | -0/+368 | |
| | ||||||
* | Adding DBG_LIB to all calls of libstrongswan's version of DBG*. | Tobias Brunner | 2010-04-06 | 1 | -4/+4 | |
| | ||||||
* | fixed short option name | Andreas Steffen | 2010-04-04 | 1 | -1/+1 | |
| | ||||||
* | we don't accept a serial number with leading zeroes | Andreas Steffen | 2010-03-14 | 2 | -0/+10 | |
| |