Commit Graph

  • 8a32874a95 x Love Hörnquist Åstrand 2006-12-10 01:09:48 +00:00
  • ed5e62f11c Return error codes on failure, improve error reporting. Love Hörnquist Åstrand 2006-12-10 01:03:46 +00:00
  • 7a0fadc477 (_hx509_private_key_assign_rsa): set a default sig alg Love Hörnquist Åstrand 2006-12-09 12:56:34 +00:00
  • fa270376d8 Pass in hx509_signature_rsa to key collector Love Hörnquist Åstrand 2006-12-09 12:18:09 +00:00
  • 1f4452b34e (try_decrypt): pass down AlgorithmIdentifier that key uses to do sigatures so there is no need to hardcode RSA into this function. Love Hörnquist Åstrand 2006-12-09 12:13:21 +00:00
  • 6f0d8af9a6 x Love Hörnquist Åstrand 2006-12-08 02:48:33 +00:00
  • 90832c9d52 sprinkle more _krb5_pk_copy_error Love Hörnquist Åstrand 2006-12-08 02:48:09 +00:00
  • c2633ac58b Pass filename to the parse functions and use it in the error messages Love Hörnquist Åstrand 2006-12-08 02:35:19 +00:00
  • 76a79be26e Copy more hx509 error strings to krb5 error strings Love Hörnquist Åstrand 2006-12-08 02:30:20 +00:00
  • 64e2e55060 regen, this time with openssl 0.9.8x Love Hörnquist Åstrand 2006-12-08 02:22:06 +00:00
  • e3d4ff2f14 x Love Hörnquist Åstrand 2006-12-08 00:48:28 +00:00
  • 5999737afa add pkix proxy cert policy lang oids Love Hörnquist Åstrand 2006-12-08 00:08:26 +00:00
  • 53256a007f make a note that we MUST check info.proxyPolicy Love Hörnquist Åstrand 2006-12-08 00:02:10 +00:00
  • 188770ff73 x Love Hörnquist Åstrand 2006-12-07 23:48:54 +00:00
  • 184d8c9f29 fix errorstring for PROXY_CERT_NAME_WRONG Love Hörnquist Åstrand 2006-12-07 23:46:58 +00:00
  • 2728037bfe regen Love Hörnquist Åstrand 2006-12-07 23:46:06 +00:00
  • e825c5107c test proxy cert (third level) Love Hörnquist Åstrand 2006-12-07 23:43:21 +00:00
  • 9d3e385800 EXTRA_DIST: add data/proxy10-child-child-test.{key,crt} Love Hörnquist Åstrand 2006-12-07 23:42:16 +00:00
  • 13438750b1 x Love Hörnquist Åstrand 2006-12-07 23:41:53 +00:00
  • 72a670336e Fix names and restrictions on the proxy certificates Love Hörnquist Åstrand 2006-12-07 23:41:06 +00:00
  • 71e4dc1497 Clairfy and make proxy cert handling work for multiple levels, before it was too restrictive. More helpful error message. Love Hörnquist Åstrand 2006-12-07 23:39:26 +00:00
  • a55d8abf5c x Love Hörnquist Åstrand 2006-12-07 22:54:04 +00:00
  • 01fde0e9c5 unbreak id-pe-proxyCertInfo Love Hörnquist Åstrand 2006-12-07 22:53:10 +00:00
  • 7ea26d8dc4 (check_key_usage): print subject, not issuer Love Hörnquist Åstrand 2006-12-07 22:41:26 +00:00
  • eecdea2e20 (check_key_usage): tell what keyusages are missing Love Hörnquist Åstrand 2006-12-07 22:35:27 +00:00
  • d987d9258d Split OtherName printing code to a oid lookup and print function. Love Hörnquist Åstrand 2006-12-07 20:37:57 +00:00
  • 812f7102a1 ops, remove extra stuff copied from the draft Love Hörnquist Åstrand 2006-12-07 20:24:06 +00:00
  • b8fc9ba909 Add id-pkix-on-dnsSRV and related oids Love Hörnquist Åstrand 2006-12-07 20:24:05 +00:00
  • c693f4cd8e AltNames: Print all diffrent names of a GeneralName Love Hörnquist Åstrand 2006-12-07 17:20:09 +00:00
  • 800d5b5cc8 x Love Hörnquist Åstrand 2006-12-07 16:37:53 +00:00
  • 6621f45c1f (Time2string): print hour as hour not min Love Hörnquist Åstrand 2006-12-07 16:34:53 +00:00
  • 801dd6cd8a x Love Hörnquist Åstrand 2006-12-07 16:30:46 +00:00
  • 4e70f181f9 CLEANFILES += test Love Hörnquist Åstrand 2006-12-07 16:30:09 +00:00
  • 758f8afd95 CLEANFILES += test_crypto Love Hörnquist Åstrand 2006-12-07 16:28:14 +00:00
  • 2dc81f5710 CLEANFILES += vis.h Love Hörnquist Åstrand 2006-12-07 16:26:50 +00:00
  • 5e5521c9e1 Include <pkinit_asn1.h>. Love Hörnquist Åstrand 2006-12-07 16:16:46 +00:00
  • 8bf7f3a2dd Prettyprint SAN/IAN Love Hörnquist Åstrand 2006-12-07 16:14:52 +00:00
  • 01dad85177 Print more of the SAN's, esp id-pkinit-san. Love Hörnquist Åstrand 2006-12-07 16:11:57 +00:00
  • 4c9ebfbbfb x Love Hörnquist Åstrand 2006-12-06 22:09:00 +00:00
  • 4c95f50117 (EXTRA_DIST): add data/pkinit-proxy* files Love Hörnquist Åstrand 2006-12-06 22:08:43 +00:00
  • 08789bb39c x Love Hörnquist Åstrand 2006-12-06 21:24:24 +00:00
  • e1bac0567e (_kdc_as_rep): add AD-INITAL-VERIFIED-CAS to the encrypted ticket Love Hörnquist Åstrand 2006-12-06 21:24:10 +00:00
  • 8300ee6ee2 (_kdc_add_inital_verified_cas): new function, adds an empty (for now) AD_INITIAL_VERIFIED_CAS to tell the clients that we vouches for the CA. Love Hörnquist Åstrand 2006-12-06 21:21:11 +00:00
  • 9fed7e931e (_kdc_tkt_add_if_relevant_ad): use _kdc_tkt_add_if_relevant_ad to add the SignedPath. Love Hörnquist Åstrand 2006-12-06 21:16:03 +00:00
  • eb2670591c (_kdc_tkt_add_if_relevant_ad): new function. Love Hörnquist Åstrand 2006-12-06 21:15:20 +00:00
  • 5eb5bcc668 x Love Hörnquist Åstrand 2006-12-06 20:20:41 +00:00
  • 9c8dccd37d (EXTRA_DIST): add tst-crypto* files Love Hörnquist Åstrand 2006-12-06 20:20:21 +00:00
  • b30dd88ab0 x Love Hörnquist Åstrand 2006-12-06 14:54:59 +00:00
  • 0923df342a fix test for COM_ERR Love Hörnquist Åstrand 2006-12-06 13:47:57 +00:00
  • 8872637199 x Love Hörnquist Åstrand 2006-12-06 13:36:46 +00:00
  • a2bf2a8e79 Make the directories test automake conditional so automake can include directories in make dist step. Love Hörnquist Åstrand 2006-12-06 13:36:36 +00:00
  • 0dff0819ef set automake symbol COM_ERR when we build local com_err Love Hörnquist Åstrand 2006-12-06 13:32:55 +00:00
  • bd5258540f x Love Hörnquist Åstrand 2006-12-06 13:10:32 +00:00
  • 85bcc19262 (_kdc_pk_rd_padata): leak less memory for ExternalPrincipalIdentifiers Love Hörnquist Åstrand 2006-12-06 13:10:21 +00:00
  • b6b9423a2b (hx509_query_match_issuer_serial): make a copy of the data Love Hörnquist Åstrand 2006-12-06 13:08:31 +00:00
  • 24ce3844d0 update (c) Love Hörnquist Åstrand 2006-12-06 12:31:09 +00:00
  • a36abf458c Remove unused function. Love Hörnquist Åstrand 2006-12-06 12:25:47 +00:00
  • eadd6575cf x Love Hörnquist Åstrand 2006-12-06 12:21:46 +00:00
  • dcf2f6807a (hx509_query_match_issuer_serial): allow matching on issuer and serial num Love Hörnquist Åstrand 2006-12-06 12:21:35 +00:00
  • 528e4e53e7 Parse and use PA-PK-AS-REQ.trustedCertifiers Love Hörnquist Åstrand 2006-12-06 12:21:02 +00:00
  • ef6bf7a0fe (find_CMSIdentifier): require the certificate we are looking for to be valid. Love Hörnquist Åstrand 2006-12-06 11:30:44 +00:00
  • 12008ec7fc x Love Hörnquist Åstrand 2006-12-06 10:43:29 +00:00
  • 65d743807c Add comment that the anchors in the signed data really should be the trust anchors of the client. Love Hörnquist Åstrand 2006-12-06 10:42:41 +00:00
  • 6dbdfd41fc x Love Hörnquist Åstrand 2006-12-06 10:36:15 +00:00
  • 8bc1396160 (_hx509_calculate_path): add flag to allow leaving out trust anchor Love Hörnquist Åstrand 2006-12-06 10:35:16 +00:00
  • d58d796709 (hx509_cms_create_signed_1): when building the path, omit the trust anchors. Love Hörnquist Åstrand 2006-12-06 10:34:39 +00:00
  • 7a308c3ab3 add HX509_CALCULATE_PATH_NO_ANCHOR Love Hörnquist Åstrand 2006-12-06 10:32:42 +00:00
  • dddb1000d7 x Love Hörnquist Åstrand 2006-12-06 10:25:12 +00:00
  • e99ef09706 (rsa_create_signature): Abort when signature is longer, not shorter. Love Hörnquist Åstrand 2006-12-06 10:23:14 +00:00
  • 2243d26b39 x Love Hörnquist Åstrand 2006-12-06 08:05:36 +00:00
  • 3154e1056e Use strcspn to remove \n from string returned by fgets. From Björn Sandell Love Hörnquist Åstrand 2006-12-06 08:04:05 +00:00
  • 9de2bce244 x Love Hörnquist Åstrand 2006-12-06 07:48:46 +00:00
  • e7a2d233f5 Add rsakey.der to EXTRA_DIST. Love Hörnquist Åstrand 2006-12-06 07:48:27 +00:00
  • 6134eea21c x Love Hörnquist Åstrand 2006-12-05 23:47:28 +00:00
  • a3ece41637 Provide time to _hx509_calculate_path so we don't send no longer valid certs to our peer. Love Hörnquist Åstrand 2006-12-05 23:47:11 +00:00
  • 0528938895 (find_parent): when checking for certs and its not a trust anchor, require time be in range. (_hx509_query_match_cert): Add time validity-testing to query mask Love Hörnquist Åstrand 2006-12-05 23:46:19 +00:00
  • db093bb975 add time validity-testing to query mask Love Hörnquist Åstrand 2006-12-05 23:44:32 +00:00
  • caf1dff34b Tests for CMS SignedData with incomplete chain from the signer. Love Hörnquist Åstrand 2006-12-05 23:43:45 +00:00
  • 38f4b80b48 x Love Hörnquist Åstrand 2006-12-05 22:45:42 +00:00
  • db71758e08 Add test_crypto.in to EXTRA_DIST. Love Hörnquist Åstrand 2006-12-05 22:28:00 +00:00
  • 8079e0a3dd Split built programs and scripts for tests Love Hörnquist Åstrand 2006-12-05 19:57:07 +00:00
  • 52d401d7cd 0.8pre again Love Hörnquist Åstrand 2006-12-05 11:57:15 +00:00
  • 4a62d54c04 rc2 Love Hörnquist Åstrand 2006-12-05 11:30:20 +00:00
  • fb4bac7d1a x Love Hörnquist Åstrand 2006-12-05 07:44:08 +00:00
  • 7930ababe4 Add more spaces to allow sh to parse this Love Hörnquist Åstrand 2006-12-05 07:39:08 +00:00
  • 0afbff54bc x Love Hörnquist Åstrand 2006-12-04 23:55:05 +00:00
  • 084786dcf9 Explain what the fixed "sha1" checksum test tries to test. Love Hörnquist Åstrand 2006-12-04 23:53:30 +00:00
  • 9eb0921481 x Love Hörnquist Åstrand 2006-12-04 23:42:50 +00:00
  • 238e717568 Clear errno before calling the strtol functions. From Paul Stoeber to OpenBSD by Ray Lai and Björn Sandell. Love Hörnquist Åstrand 2006-12-04 23:41:18 +00:00
  • 623e559f60 x Love Hörnquist Åstrand 2006-12-04 23:37:17 +00:00
  • 487bcca4e2 Use strcspn to remove \n from fgets result. Prompted by change by Ray Lai of OpenBSD via Björn Sandell. Love Hörnquist Åstrand 2006-12-04 23:36:36 +00:00
  • 63579afa99 Report to syslog strings that start with NUL; prevents negative index array access. Ray Lai of OpenBSD via Björn Sandell. Love Hörnquist Åstrand 2006-12-04 23:27:08 +00:00
  • 768fb6de89 x Love Hörnquist Åstrand 2006-12-04 23:22:01 +00:00
  • a4990b9b3c x Love Hörnquist Åstrand 2006-12-04 21:56:34 +00:00
  • 7a5f41d9a1 rsa and crypto engine test cases Love Hörnquist Åstrand 2006-12-04 21:40:56 +00:00
  • 26b0f36b4f Make faster and less verbose Love Hörnquist Åstrand 2006-12-04 21:40:19 +00:00
  • 31bfa2d1cb test rsa key Love Hörnquist Åstrand 2006-12-04 21:36:19 +00:00
  • c50d6599af Test rsa operations Love Hörnquist Åstrand 2006-12-04 21:33:05 +00:00
  • 49c442c958 Fix the rsa-decrypt failed case that been hauting me for a while. Love Hörnquist Åstrand 2006-12-04 21:31:30 +00:00
  • d37ea650ff Revert preious, something fishy is going on. Love Hörnquist Åstrand 2006-12-02 09:14:55 +00:00