Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | Allow support for CA-certificate retrieval in scepclient4.6.0 | Thomas Egerer | 2011-11-04 | 1 | -0/+21 |
| | | | | | I think somehow this functionality got lost in the way from strongswan-2.7.0... | ||||
* | Fix 'ipsec pool --status' for empty pools. | Tobias Brunner | 2011-11-04 | 1 | -1/+7 |
| | |||||
* | Syntax error in sqlite.sql fixed. | Tobias Brunner | 2011-11-04 | 1 | -1/+1 |
| | |||||
* | if available link libsimaka to checksum_builder | Andreas Steffen | 2011-11-04 | 1 | -0/+4 |
| | |||||
* | use the correct USE_SIMAKA conditional | Andreas Steffen | 2011-11-04 | 1 | -1/+1 |
| | |||||
* | fixed integrity tests of plugins using libsimaka | Andreas Steffen | 2011-11-04 | 9 | -8/+4 |
| | |||||
* | Change order of ocsp uris when parsing a cert | Thomas Egerer | 2011-11-04 | 1 | -1/+1 |
| | |||||
* | Handle certificates being on hold in a CRL | Thomas Egerer | 2011-11-04 | 3 | -1/+14 |
| | | | | | | | Certificates which are set on hold in a CRL might be removed from any subsequent CRL. Hence you cannot conclude that a certificate is revoked for good in this case, you would try to retrieve an update CRL to see if the certificate on hold is still on it or not. | ||||
* | Memwipe request after sa update, too | Thomas Egerer | 2011-11-04 | 1 | -0/+1 |
| | |||||
* | Use chunk_clear to memwipe shared secret | Thomas Egerer | 2011-11-04 | 1 | -1/+1 |
| | |||||
* | Change order of destroy/get_ref function calls | Thomas Egerer | 2011-11-04 | 1 | -1/+1 |
| | | | | | Since DESTROY_IF might destroy the peer_cfg, a get_ref on a freed object is subject to fail. | ||||
* | Fix resource leak in x509_ocsp_response | Thomas Egerer | 2011-11-04 | 1 | -0/+4 |
| | |||||
* | Extend xfrm_attr_type_names by newly added enum values | Thomas Egerer | 2011-11-04 | 1 | -2/+6 |
| | |||||
* | Silently install route again, even if it did not change. | Tobias Brunner | 2011-11-04 | 2 | -2/+12 |
| | | | | | Address/interface changes can cause the route to disappear. Afterwards the route might look the same but that does not mean it is still installed. | ||||
* | Compile warning fixed in kernel interfaces. | Tobias Brunner | 2011-11-04 | 2 | -2/+2 |
| | |||||
* | Common spelling errors fixed. | Tobias Brunner | 2011-11-03 | 4 | -4/+4 |
| | |||||
* | pkcs11: Make public key operations on tokens optional. | Tobias Brunner | 2011-11-03 | 1 | -20/+21 |
| | |||||
* | pkcs11: Make sure a key can be used for a given signature scheme. | Tobias Brunner | 2011-11-02 | 3 | -16/+31 |
| | |||||
* | pkcs11: Register ECDSA feature. | Tobias Brunner | 2011-11-02 | 1 | -1/+10 |
| | |||||
* | pkcs11: We have to create our own hashes for some signature schemes. | Tobias Brunner | 2011-11-02 | 4 | -12/+81 |
| | |||||
* | pkcs11: Lookup the public key of a private key by CKA_ID. | Tobias Brunner | 2011-11-02 | 2 | -0/+125 |
| | | | | | | Currently this only works if a public key object with the same ID is available, if there isn't one we could search for a certificate with the same ID and extract the key from there. | ||||
* | pkcs11: Search for private keys in a more generic way. | Tobias Brunner | 2011-11-02 | 1 | -20/+19 |
| | | | | | | Also, don't extract the public key directly from the private key. Some tokens actually do not return the public exponent (it's not required). We have to find a different way to get the public key. | ||||
* | pkcs11: Added support to encode ECDSA public keys. | Tobias Brunner | 2011-11-02 | 1 | -0/+89 |
| | |||||
* | pkcs11: Parse ECDSA public keys and find/create them on tokens. | Tobias Brunner | 2011-11-02 | 1 | -2/+177 |
| | |||||
* | pkcs11: Added generic functions to find/create public keys on tokens. | Tobias Brunner | 2011-11-02 | 1 | -40/+75 |
| | |||||
* | pkcs11: Store public key length in bits. | Tobias Brunner | 2011-11-02 | 1 | -3/+3 |
| | |||||
* | pkcs11: Fix encoding of RSA public keys. | Tobias Brunner | 2011-11-02 | 1 | -0/+4 |
| | |||||
* | pkcs11: Use create_object_attr_enumerator to encode RSA public key. | Tobias Brunner | 2011-11-02 | 1 | -17/+7 |
| | |||||
* | pkcs11: Instead of a mutex use a new session to do multipart operations. | Tobias Brunner | 2011-11-02 | 2 | -40/+66 |
| | |||||
* | pkcs11: Function added to retrieve multiple attributes from a single object. | Tobias Brunner | 2011-11-02 | 2 | -6/+62 |
| | |||||
* | pkcs11: Memory leak fixed in DH/ECDH implementation. | Tobias Brunner | 2011-11-02 | 1 | -0/+2 |
| | |||||
* | pkcs11: Invalid free fixed in DH/ECDH implementation. | Tobias Brunner | 2011-11-02 | 1 | -1/+4 |
| | |||||
* | pkcs11: Changed how pkcs11-manager is initialized. | Tobias Brunner | 2011-11-02 | 1 | -42/+32 |
| | | | | | The manager is now created directly, but events and certificate loading is deferred. | ||||
* | pkcs11: Add attributes to specify what we use the DH/ECDH keys for. | Tobias Brunner | 2011-11-02 | 1 | -2/+10 |
| | |||||
* | charon must load libtls if available | Andreas Steffen | 2011-11-02 | 1 | -0/+4 |
| | |||||
* | fixed integrity tests of plugins using libtls or libtnccs | Andreas Steffen | 2011-11-02 | 14 | -18/+43 |
| | |||||
* | pkcs11: Allow to build pkcs11 plugin on Android. | Tobias Brunner | 2011-10-31 | 1 | -0/+2 |
| | |||||
* | pkcs11: Use callback registration for pkcs11-manager. | Tobias Brunner | 2011-10-31 | 1 | -25/+73 |
| | | | | | | Otherwise a plugin providing X509 decoding capabilities might be unloaded before the manager which will result in a segmentation fault when certificates in the manager's credential sets are to be destroyed. | ||||
* | pkcs11: Merged the ECDH into the DH implementation. | Tobias Brunner | 2011-10-31 | 6 | -405/+210 |
| | |||||
* | pkcs11: Use get_ck_attribute for ECDH. | Tobias Brunner | 2011-10-31 | 1 | -63/+13 |
| | |||||
* | pkcs11: Use get_ck_attribute for DH. | Tobias Brunner | 2011-10-31 | 1 | -28/+6 |
| | |||||
* | pkcs11: Method added to library to extract a single attribute from an object. | Tobias Brunner | 2011-10-31 | 2 | -1/+50 |
| | |||||
* | pkcs11: Added names for CKA_* constants. | Tobias Brunner | 2011-10-31 | 2 | -1/+123 |
| | |||||
* | pkcs11: Added support for ECDH. | Tobias Brunner | 2011-10-31 | 4 | -1/+422 |
| | |||||
* | pkcs11: Added definitions needed for ECDH to pkcs11.h. | Tobias Brunner | 2011-10-31 | 1 | -0/+24 |
| | |||||
* | pkcs11: Specify object class and key type when deriving DH secrets. | Tobias Brunner | 2011-10-31 | 1 | -0/+4 |
| | | | | pkcs11_softtoken on OpenSolaris requires this (probably others too). | ||||
* | pkcs11: Add features support. | Tobias Brunner | 2011-10-31 | 3 | -84/+90 |
| | |||||
* | pkcs11: Added support for DH. | Tobias Brunner | 2011-10-31 | 4 | -0/+377 |
| | |||||
* | pkcs11: Error message fixed. | Tobias Brunner | 2011-10-31 | 1 | -1/+1 |
| | |||||
* | pkcs11: Added support to generate random numbers on a token. | Tobias Brunner | 2011-10-31 | 4 | -0/+201 |
| |