a7e3644eb9
(hx509_certs_init): pass the right error code back
Love Hörnquist Åstrand
2006-05-01 13:36:07 +00:00
78cb38d2ef
x
Love Hörnquist Åstrand
2006-05-01 09:26:41 +00:00
bba691f8a8
Spelling/mdoc changes, from Björn Sandell.
Love Hörnquist Åstrand
2006-05-01 09:26:31 +00:00
e0c1c293c5
update .Dd
Love Hörnquist Åstrand
2006-05-01 08:48:56 +00:00
40230797a3
Spelling/mdoc changes, from Björn Sandell.
Love Hörnquist Åstrand
2006-05-01 08:48:55 +00:00
ba82623c97
x
Love Hörnquist Åstrand
2006-05-01 07:13:56 +00:00
8a0179a06a
Spelling/mdoc changes, from Björn Sandell.
Love Hörnquist Åstrand
2006-05-01 07:13:03 +00:00
2644ec46b0
update .Dd and (c)
Love Hörnquist Åstrand
2006-05-01 07:09:16 +00:00
0c4a59b643
Spelling/mdoc changes, from Björn Sandell.
Love Hörnquist Åstrand
2006-05-01 07:05:07 +00:00
fe0b3a491c
Spelling, from Björn Sandell.
Love Hörnquist Åstrand
2006-05-01 07:01:18 +00:00
345ef1316d
x
Love Hörnquist Åstrand
2006-05-01 07:00:25 +00:00
d1e8efa6f7
update .Dd
Love Hörnquist Åstrand
2006-05-01 06:51:29 +00:00
8123d558fe
Spelling, from Björn Sandell
Love Hörnquist Åstrand
2006-05-01 06:51:17 +00:00
9b49a268ec
Revert previous patch. (hx509_ocsp_verify): new function that returns the expiration of certificate in ocsp data-blob
Love Hörnquist Åstrand
2006-04-30 14:57:29 +00:00
37db31f903
Reverse previous patch, lets do it another way.
Love Hörnquist Åstrand
2006-04-30 14:53:05 +00:00
e9f16d62ab
(hx509_revoke_verify): update usage
Love Hörnquist Åstrand
2006-04-30 14:11:55 +00:00
0d24f17608
Make compile.
Love Hörnquist Åstrand
2006-04-30 14:10:15 +00:00
38bd0f7fda
Add the time the crl/ocsp info expire
Love Hörnquist Åstrand
2006-04-30 14:05:57 +00:00
71d1acf5ff
x
Love Hörnquist Åstrand
2006-04-30 08:00:51 +00:00
532985afc3
Don't try pkinit if there is no rsa
Love Hörnquist Åstrand
2006-04-30 07:49:03 +00:00
5d5378db66
x
Love Hörnquist Åstrand
2006-04-30 07:36:43 +00:00
fa7b5da860
(cert2epi): don't include subject if its null
Love Hörnquist Åstrand
2006-04-30 07:36:27 +00:00
832c728396
Add hx509_name_is_null_p
Love Hörnquist Åstrand
2006-04-30 07:35:36 +00:00
4a99bbcc37
remove _hx509_cert_private_sigature
Love Hörnquist Åstrand
2006-04-30 07:35:08 +00:00
5f3de5351d
Expose more of Name.
Love Hörnquist Åstrand
2006-04-29 21:30:21 +00:00
92ed76e969
Send over what trust anchors the client have configured.
Love Hörnquist Åstrand
2006-04-29 21:29:28 +00:00
90a97065b2
x
Love Hörnquist Åstrand
2006-04-29 19:09:43 +00:00
d0b797a71a
Add ExternalPrincipalIdentifiers, shared between several elements.
Love Hörnquist Åstrand
2006-04-29 19:09:22 +00:00
b56704d1f2
x
Love Hörnquist Åstrand
2006-04-29 16:30:01 +00:00
ee6a3fed14
(main): add missing argument to printf
Love Hörnquist Åstrand
2006-04-29 16:29:46 +00:00
465e615c60
x
Love Hörnquist Åstrand
2006-04-29 15:19:35 +00:00
3a2376a988
x
Love Hörnquist Åstrand
2006-04-29 15:16:02 +00:00
11bad1d7b1
clean the server.keytab
Love Hörnquist Åstrand
2006-04-29 15:15:42 +00:00
2a8f4f88bd
clean the tempfile
Love Hörnquist Åstrand
2006-04-29 15:14:57 +00:00
6ba949925f
change principal mapping.
Love Hörnquist Åstrand
2006-04-29 15:14:18 +00:00
e1be108cb3
Add test for pk-init
Love Hörnquist Åstrand
2006-04-29 15:13:53 +00:00
b2f67373e9
Add pkinit glue
Love Hörnquist Åstrand
2006-04-29 15:12:39 +00:00
d9c374fc74
regen, now with EKU in kdc certificate
Love Hörnquist Åstrand
2006-04-29 15:08:41 +00:00
3cbc662bc7
x
Love Hörnquist Åstrand
2006-04-29 15:05:22 +00:00
ab4cf1597e
Add EKU for the KDC certificate
Love Hörnquist Åstrand
2006-04-29 15:05:11 +00:00
03276c9ead
(pk_verify_host): set better error string, only check kdc name/address when we got a hostname/address passed in the the function.
Love Hörnquist Åstrand
2006-04-29 15:04:42 +00:00
36b923f56a
(_kdc_pk_check_client): reorganize and make log when a SAN matches.
Love Hörnquist Åstrand
2006-04-29 14:30:01 +00:00
a4e67a6533
(hx509_cert_get_base_subject): reject un-canon proxy certs, not the reverse (add_to_list): constify and fix argument order to copy_octet_string (hx509_cert_find_subjectAltName_otherName): make work
Love Hörnquist Åstrand
2006-04-29 14:22:41 +00:00
fea62ab3b7
x
Love Hörnquist Åstrand
2006-04-28 16:43:26 +00:00
5a7018a15e
pkinit certificates
Love Hörnquist Åstrand
2006-04-28 16:42:59 +00:00
9275975f0f
Generate pkinit certificates.
Love Hörnquist Åstrand
2006-04-28 16:41:56 +00:00
c6c3668d19
Add pkinit glue.
Love Hörnquist Åstrand
2006-04-28 16:41:17 +00:00
d8af61b107
Add pkcs11 example.
Love Hörnquist Åstrand
2006-04-28 14:06:16 +00:00
c0fba2d7ff
Add openssl ca example
Love Hörnquist Åstrand
2006-04-28 13:26:13 +00:00
c896e8ae74
Add kinit example.
Love Hörnquist Åstrand
2006-04-28 13:22:15 +00:00
059ee70ad1
x
Love Hörnquist Åstrand
2006-04-28 13:16:32 +00:00
3ec5202b77
More options and some text about windows clients, certificate and KDCs.
Love Hörnquist Åstrand
2006-04-28 13:16:20 +00:00
04c94a1d76
x
Love Hörnquist Åstrand
2006-04-28 12:23:24 +00:00
665526d2df
x
Love Hörnquist Åstrand
2006-04-28 11:28:38 +00:00
4b90cf5552
Example pki-mapping file.
Love Hörnquist Åstrand
2006-04-28 11:27:19 +00:00
feb2699d9b
(hx509_verify_hostname): implement stub function
Love Hörnquist Åstrand
2006-04-28 11:24:10 +00:00
e5194fdc60
(pk_verify_host): verify hostname/address
Love Hörnquist Åstrand
2006-04-28 11:23:35 +00:00
bfd894ccf4
x
Love Hörnquist Åstrand
2006-04-28 10:52:27 +00:00
5e97c59ab7
Add missing ;'s, found by bison on a SuSE 8.2 machine.
Love Hörnquist Åstrand
2006-04-28 10:51:35 +00:00
cc3201fd9f
x
Love Hörnquist Åstrand
2006-04-28 07:37:27 +00:00
0db21e2b07
Bump hdb interface version to 4.
Love Hörnquist Åstrand
2006-04-28 07:37:11 +00:00
9d3cae3291
x
Love Hörnquist Åstrand
2006-04-27 20:52:35 +00:00
81ea1bb05f
Document --credential=principal.
Love Hörnquist Åstrand
2006-04-27 20:52:12 +00:00
ca6c6b5caa
x
Love Hörnquist Åstrand
2006-04-27 14:34:15 +00:00
149c2d1e5d
Sprinkle more ap-req now that the credential is removed from the cache using kdestroy --credential=
Love Hörnquist Åstrand
2006-04-27 14:34:03 +00:00
25621f44fd
check that AP_OPTS_MUTUAL_REQUIRED matches, check seqnumber
Love Hörnquist Åstrand
2006-04-27 14:17:27 +00:00
385c718ea1
x
Love Hörnquist Åstrand
2006-04-27 12:38:59 +00:00
d4c22d7bf8
Build as-req.
Love Hörnquist Åstrand
2006-04-27 12:38:29 +00:00
0c6b815385
Sprinkel some as-req
Love Hörnquist Åstrand
2006-04-27 12:38:03 +00:00
506b246491
simple test program checking that as ap-req/as-rep exchange works
Love Hörnquist Åstrand
2006-04-27 12:37:09 +00:00
2497e2d799
x
Love Hörnquist Åstrand
2006-04-27 12:01:32 +00:00
76ee5cb311
(tgs_rep2): check that the client exists in the kerberos database if its local request.
Love Hörnquist Åstrand
2006-04-27 12:01:09 +00:00
5c9982831b
pass down HDB_F_GET_ flags as appropriate
Love Hörnquist Åstrand
2006-04-27 11:33:21 +00:00
357ca89f2d
(_kdc_db_fetch4): pass down flags though krb5_425_conv_principal_ext2
Love Hörnquist Åstrand
2006-04-27 11:32:13 +00:00
2a5d097734
x
Love Hörnquist Åstrand
2006-04-27 11:19:53 +00:00
eea5f34855
Pass in HDB_F_GET_ANY to all ->hdb fetch to hint what entries we are looking for
Love Hörnquist Åstrand
2006-04-27 11:18:52 +00:00
06660d5790
x
Love Hörnquist Åstrand
2006-04-27 11:10:51 +00:00
988af20ec2
set and clear error string
Love Hörnquist Åstrand
2006-04-27 11:10:07 +00:00
5f22b44baa
Break out the that we request from principal from the entry and pass it in as a separate argument.
Love Hörnquist Åstrand
2006-04-27 11:09:30 +00:00
e4adaa6783
Break out the that we request from principal from the entry and pass it in as a seprate argument.
Love Hörnquist Åstrand
2006-04-27 11:06:57 +00:00
83d3254750
(_kdc_db_fetch): Break out the that we request from principal from the entry and pass it in as a seprate argument.
Love Hörnquist Åstrand
2006-04-27 11:05:25 +00:00
d176572cbc
(hdb_get_entry): Break out the that we request from principal from the entry and pass it in as a seprate argument.
Love Hörnquist Åstrand
2006-04-27 11:01:30 +00:00