3067c89d6c
New snapshot for Michael Fromberger, lets see if this corrupts memory less.
Love Hörnquist Åstrand
2007-05-31 23:24:37 +00:00
349d49a313
add some more people.
Love Hörnquist Åstrand
2007-05-31 23:06:21 +00:00
7d011aac3b
x
Love Hörnquist Åstrand
2007-05-31 23:04:26 +00:00
5e36b724c0
Use the return value before is overwritten by later calls. From Rafal Malinowski
Love Hörnquist Åstrand
2007-05-31 23:01:27 +00:00
786db415e8
Give an minor_status argument to gss_release_oid_set. From Rafa? Malinowski
Love Hörnquist Åstrand
2007-05-31 22:50:06 +00:00
9fe3a53f6d
Allow turning off sending trustedCertifiers in the request.
Love Hörnquist Åstrand
2007-05-31 20:58:07 +00:00
6b156c8b73
update supported algs
Love Hörnquist Åstrand
2007-05-31 20:27:10 +00:00
ec39bb7e2a
Also add some secret key encryption types to the supported list.
Love Hörnquist Åstrand
2007-05-31 19:57:53 +00:00
6eb6bb6ad0
Try pkinit in w2k mode, also add tests for MS SAN.
Love Hörnquist Åstrand
2007-05-31 17:34:17 +00:00
da1be13db5
Handle the ms san in a propper way, still cheat with the realm name.
Love Hörnquist Åstrand
2007-05-31 17:31:43 +00:00
5d2b97b390
x
Love Hörnquist Åstrand
2007-05-31 17:18:10 +00:00
cf4be03dee
Add crl-uri for the ee certs.
Love Hörnquist Åstrand
2007-05-31 17:17:42 +00:00
30b9e222bb
x
Love Hörnquist Åstrand
2007-05-31 17:16:25 +00:00
7110c79ae2
add MS-UPN-SAN
Love Hörnquist Åstrand
2007-05-31 17:16:10 +00:00
8cf89ccd07
add MS-UPN-SAN
Love Hörnquist Åstrand
2007-05-31 17:15:52 +00:00
1c488f05de
If _kdc_pk_check_client failes, bail out directly and hand the error back to the client.
Love Hörnquist Åstrand
2007-05-31 17:15:15 +00:00
20686d11f3
Add missing REVOCATION_STATUS_UNAVAILABLE and fix error message for CLIENT_NAME_MISMATCH.
Love Hörnquist Åstrand
2007-05-31 17:13:58 +00:00
2f5a243c5f
x
Love Hörnquist Åstrand
2007-05-31 16:53:41 +00:00
824d7f6f91
generate a krb5-pkinit-win.conf
Love Hörnquist Åstrand
2007-05-31 16:53:21 +00:00
c0d15418cc
W2K tests.
Love Hörnquist Åstrand
2007-05-31 16:52:40 +00:00
96373f705b
x
Love Hörnquist Åstrand
2007-05-31 16:45:44 +00:00
6da3d7025b
More logging for pk-init client mismatch.
Love Hörnquist Åstrand
2007-05-31 16:45:21 +00:00
605be10f65
x
Love Hörnquist Åstrand
2007-05-31 16:02:03 +00:00
4d85d882e1
Also add a KRB5_PADATA_PK_AS_REQ_WIN for windows pk-init (-9) to make MIT clients happy.
Love Hörnquist Åstrand
2007-05-31 16:00:37 +00:00
0a123869a2
Printf formating.
Love Hörnquist Åstrand
2007-05-31 15:41:41 +00:00
cfe20ce63c
x
Love Hörnquist Åstrand
2007-05-31 15:32:44 +00:00
26d6112116
Add glue for adding CRL dps.
Love Hörnquist Åstrand
2007-05-31 15:32:30 +00:00
93c3659a8c
Readd the crl adding code, it works (somewhat) now.
Love Hörnquist Åstrand
2007-05-31 15:22:36 +00:00
13dd13aa60
add asn1_id_ms_client_authentication.x
Love Hörnquist Åstrand
2007-05-31 14:52:11 +00:00
5de627d609
Do evil things to handle IMPLICIT encoded structures. Add id-ms-client-authentication.
Love Hörnquist Åstrand
2007-05-31 14:51:46 +00:00
ee3f87c182
Fix printing of CRL DPnames (I hate IMPLICIT encoded structures).
Love Hörnquist Åstrand
2007-05-31 14:50:20 +00:00
ed26f9615e
x
Love Hörnquist Åstrand
2007-05-31 13:15:24 +00:00
27cd38c109
make ca and alias of certificate-sign
Love Hörnquist Åstrand
2007-05-31 13:14:55 +00:00
1500d27b4a
create windows client certificate
Love Hörnquist Åstrand
2007-05-31 02:46:45 +00:00
7cf5b55729
(hx509_crypto_select): copy AI to the right place.
Love Hörnquist Åstrand
2007-05-31 02:46:17 +00:00
499cb7937a
Add ca --ms-upn.
Love Hörnquist Åstrand
2007-05-31 02:45:11 +00:00
071db50a3f
add --ms-upn and add more EKU's for pk-init client.
Love Hörnquist Åstrand
2007-05-31 02:44:39 +00:00
db080434b8
Add hx509_ca_tbs_add_san_ms_upn and refactor code.
Love Hörnquist Åstrand
2007-05-31 02:43:58 +00:00
1a6adc6188
Resurect killed e.
Love Hörnquist Åstrand
2007-05-31 02:42:48 +00:00
5637570ff9
x
Love Hörnquist Åstrand
2007-05-30 23:19:40 +00:00
465d8ec3b1
check for aes256-cbc
Love Hörnquist Åstrand
2007-05-30 23:19:26 +00:00
d00446cd32
check for aes256-cbc
Love Hörnquist Åstrand
2007-05-30 23:19:01 +00:00
2561afcc85
test windows stuff
Love Hörnquist Åstrand
2007-05-30 23:18:34 +00:00
425857b25d
test windows stuff
Love Hörnquist Åstrand
2007-05-30 23:18:14 +00:00
d7d356f871
add ca --domain-controller option, add secret key option to avaible.
Love Hörnquist Åstrand
2007-05-30 23:03:28 +00:00
659e8dd094
Add hx509_ca_tbs_set_domaincontroller.
Love Hörnquist Åstrand
2007-05-30 23:02:53 +00:00
9081ac940b
add ca --domain-controller
Love Hörnquist Åstrand
2007-05-30 22:58:21 +00:00
14de225227
id-ms-cert-enroll-domaincontroller
Love Hörnquist Åstrand
2007-05-30 22:08:14 +00:00
8411d0dcfb
Add asn1_id_ms_cert_enroll_domaincontroller.x
Love Hörnquist Åstrand
2007-05-30 22:06:12 +00:00
3ad5f3008b
x
Love Hörnquist Åstrand
2007-05-30 19:12:04 +00:00
82fa4fb114
Don't prefix all symbols with _
Love Hörnquist Åstrand
2007-05-30 19:09:56 +00:00
199b3b5a75
x
Love Hörnquist Åstrand
2007-05-30 18:53:02 +00:00
1018087342
hook for testing secrety key algs
Love Hörnquist Åstrand
2007-05-30 18:43:48 +00:00
217f3d4680
Add selection code for secret key crypto.
Love Hörnquist Åstrand
2007-05-30 18:42:34 +00:00
60df0e8122
Force des3 for win2k.
Love Hörnquist Åstrand
2007-05-30 18:41:59 +00:00
c1da454788
Add HX509_SELECT_SECRET_ENC.
Love Hörnquist Åstrand
2007-05-30 18:38:14 +00:00
2c99856c1c
Add wrapping to ContentInfo wrapping to COMPAT_WIN2K.
Love Hörnquist Åstrand
2007-05-30 18:33:36 +00:00
e7b0a46e77
Fix warning.
Love Hörnquist Åstrand
2007-05-30 16:53:35 +00:00
f2f278d34e
x x
Love Hörnquist Åstrand
2007-05-30 15:08:50 +00:00
acfd5a4121
Catch errors and return the up the stack.
Love Hörnquist Åstrand
2007-05-30 15:07:09 +00:00
26c0e3189d
catch failures from _krb5_principalname2krb5_principal
Love Hörnquist Åstrand
2007-05-30 14:32:26 +00:00
caf5ba8c9a
x
Love Hörnquist Åstrand
2007-05-30 14:13:49 +00:00
fa4a82327c
Spelling.
Love Hörnquist Åstrand
2007-05-30 14:09:09 +00:00
becdb44583
more testing of lifetimes
Love Hörnquist Åstrand
2007-05-30 13:58:46 +00:00
ccb10b7022
x x
Love Hörnquist Åstrand
2007-05-30 13:57:07 +00:00
80ca373dea
remove more files
Love Hörnquist Åstrand
2007-05-30 13:55:50 +00:00
d78b157123
x
Love Hörnquist Åstrand
2007-05-30 13:38:11 +00:00
dcf2f42e79
Allow matching by MS UPN SAN, note that this delta doesn't deal with case of realm.
Love Hörnquist Åstrand
2007-05-30 13:37:44 +00:00
ee246ab9ac
Use gss oid_set functions from mechglue
Love Hörnquist Åstrand
2007-05-17 18:44:31 +00:00
b2684d8ed2
Drop the gss oid_set function for the krb5 mech, use the mech glue versions instead. Pointed out by Rafal Malinowski.
Love Hörnquist Åstrand
2007-05-17 18:42:30 +00:00
07aeb14a0c
document krb5_crypto_overhead
Love Hörnquist Åstrand
2007-05-16 18:49:27 +00:00
a40b591677
x
Love Hörnquist Åstrand
2007-05-16 18:30:13 +00:00
5e5c20fe90
(krb5_crypto_overhead): return static overhead of encryption.
Love Hörnquist Åstrand
2007-05-16 18:28:27 +00:00
88bbe318c5
x
Love Hörnquist Åstrand
2007-05-14 18:04:11 +00:00
87bdbf8e2c
Set session key only if we are returned a session key.
Love Hörnquist Åstrand
2007-05-14 18:03:39 +00:00
e44dcb7458
x
Love Hörnquist Åstrand
2007-05-14 03:15:30 +00:00
99df08ed7e
switched MIN to min to make compile on solaris.
Love Hörnquist Åstrand
2007-05-14 03:12:05 +00:00
23a4352ee6
x
Love Hörnquist Åstrand
2007-05-14 02:44:02 +00:00
b843a3219b
update ms urls, from David Love.
Love Hörnquist Åstrand
2007-05-14 02:43:25 +00:00
7455d1213d
Fix version number of ticket, it should be 5 not the kvno.
Love Hörnquist Åstrand
2007-05-14 02:31:46 +00:00
8accec008c
x
Love Hörnquist Åstrand
2007-05-13 06:57:43 +00:00
7971b73f40
add more mechtypes
Love Hörnquist Åstrand
2007-05-13 06:57:21 +00:00
7e11830fdc
x
Love Hörnquist Åstrand
2007-05-11 00:41:05 +00:00
b313013d8f
Add struct units; as a forward declaration. Pointed out by Marcus Watts.
Love Hörnquist Åstrand
2007-05-11 00:39:41 +00:00
463e05edd6
x
Love Hörnquist Åstrand
2007-05-10 23:52:02 +00:00
d90201bfe3
Indent.
Love Hörnquist Åstrand
2007-05-10 23:49:51 +00:00
6c52c9cd90
x
Love Hörnquist Åstrand
2007-05-10 23:19:20 +00:00
64ff82a9eb
add test-crypto command
Love Hörnquist Åstrand
2007-05-10 23:18:58 +00:00
09acc9cae1
test crypto command
Love Hörnquist Åstrand
2007-05-10 23:16:38 +00:00
bb64783393
(hx509_cms_create_signed_1): if no eContentType is given, use pkcs7-data.
Love Hörnquist Åstrand
2007-05-10 22:53:44 +00:00