4d9b604abe
Pick out certs in chain.
Love Hörnquist Åstrand
2006-03-31 02:45:00 +00:00
93e4629277
clean ev.data and ev.data.out
Love Hörnquist Åstrand
2006-03-31 02:01:07 +00:00
1ecf995c65
x
Love Hörnquist Åstrand
2006-03-31 02:00:04 +00:00
a36d831663
TODO list
Love Hörnquist Åstrand
2006-03-31 01:58:41 +00:00
d567d58fea
x
Love Hörnquist Åstrand
2006-03-31 01:53:49 +00:00
94e1fd1616
Add code to load OCSPBasicOCSPResponse files, reload crl when its changed on disk.
Love Hörnquist Åstrand
2006-03-31 01:52:33 +00:00
7c1b919893
Update for ocsp merge. handle building path w/o subject (using subject key id)
Love Hörnquist Åstrand
2006-03-31 01:51:22 +00:00
54c42411cb
_hx509_map_file changed prototype.
Love Hörnquist Åstrand
2006-03-31 01:49:37 +00:00
34b94bcd88
_hx509_map_file changed prototype, returns struct stat if requested.
Love Hörnquist Åstrand
2006-03-31 01:48:48 +00:00
3c28ff7607
Add stub for ocsp-fetch, _hx509_map_file changed prototype, add ocsp parsing to verify command.
Love Hörnquist Åstrand
2006-03-31 01:47:31 +00:00
d4919738d7
Add command ocsp-fetch
Love Hörnquist Åstrand
2006-03-31 01:45:47 +00:00
de44f94103
rename HX509_CTX_CRL_MISSING_OK to HX509_CTX_VERIFY_MISSING_OK now that we have OCSP glue
Love Hörnquist Åstrand
2006-03-31 01:43:10 +00:00
39ecd03c1e
Include OCSP.
Love Hörnquist Åstrand
2006-03-31 01:02:16 +00:00
7677242d01
RFC2560 - Online Certificate Status Protocol
Love Hörnquist Åstrand
2006-03-31 01:01:01 +00:00
f9160af5a1
(LDAP_message2entry): in declaration set variable_name as "hdb_entry_ex" (hdb_ldap_common): change "arg" in condition (if) to "search_base" (hdb_ldapi_create): change "serach_base" to "search_base" From Alex V. Labuta.
Love Hörnquist Åstrand
2006-03-30 09:03:27 +00:00
6a3ce9e3ae
Add <krb5-types.h> to make it compile on Solaris, from Alex V. Labuta.
Love Hörnquist Åstrand
2006-03-30 08:57:37 +00:00
3e1be53a7b
x
Love Hörnquist Åstrand
2006-03-30 04:41:10 +00:00
fb6af46d0e
Put all the IMPORTed headers into the headerfile to avoid hidden depencies.
Love Hörnquist Åstrand
2006-03-30 04:40:52 +00:00
c107edc050
x
Love Hörnquist Åstrand
2006-03-30 03:36:53 +00:00
ff8a601d49
(krb5_get_init_creds_opt_set_pkinit); fix prototype
Love Hörnquist Åstrand
2006-03-30 03:36:32 +00:00
145960cda9
Add pool of certificates to help certificate path building for clients sending incomplete path in the signedData.
Love Hörnquist Åstrand
2006-03-30 03:12:06 +00:00
945efb8a96
Add pool of certificates to help certificate path building for clients sending incomplete path in the signedData.
Love Hörnquist Åstrand
2006-03-28 19:57:25 +00:00
4d27cc0683
x
Love Hörnquist Åstrand
2006-03-28 13:13:38 +00:00
654d1bcf68
(_hx509_pbe_decrypt): try all passwords, not just the first one.
Love Hörnquist Åstrand
2006-03-28 13:12:09 +00:00
3cca5384bd
x
Love Hörnquist Åstrand
2006-03-28 04:52:15 +00:00
cd6acf1200
Allow passing in related certificates used to build the chain.
Love Hörnquist Åstrand
2006-03-28 04:38:14 +00:00
27a38bba47
x
Love Hörnquist Åstrand
2006-03-28 03:48:58 +00:00
6f2f155e73
(check_altName): Print the othername oid.
Love Hörnquist Åstrand
2006-03-28 03:48:21 +00:00
2832b00b67
Manual page claims RSA_public_decrypt will return -1 on error, lets check for that
Love Hörnquist Åstrand
2006-03-28 03:46:54 +00:00
6af8c899ad
x
Love Hörnquist Åstrand
2006-03-28 00:04:44 +00:00
8c6b7f98ff
Add id-pkinit-ms-san.
Love Hörnquist Åstrand
2006-03-28 00:03:34 +00:00
905242765a
(log_patype): Add case for KRB5_PADATA_PA_PK_OCSP_RESPONSE.
Love Hörnquist Åstrand
2006-03-27 22:54:50 +00:00
ab4ac9ff66
x
Love Hörnquist Åstrand
2006-03-27 22:52:29 +00:00
2dbb33653c
(PADATA-TYPE): Add KRB5-PADATA-PA-PK-OCSP-RESPONSE
Love Hörnquist Åstrand
2006-03-27 22:52:11 +00:00
7f803fd58d
(_hx509_pbe_decrypt): also try the empty password
Love Hörnquist Åstrand
2006-03-27 22:10:36 +00:00
f4e25d6573
(match_localkeyid): no need to add back the cert to the cert pool, its already there.
Love Hörnquist Åstrand
2006-03-27 22:09:28 +00:00
201f534ca1
Pass on flags, unbreaks last commit.
Love Hörnquist Åstrand
2006-03-27 21:40:56 +00:00
3c795c81d6
x
Love Hörnquist Åstrand
2006-03-27 21:35:22 +00:00
381c1b5a04
Add REQUIRE_SIGNER
Love Hörnquist Åstrand
2006-03-27 21:34:58 +00:00
e3ef13ddb4
(hx509_cert_free): ok to free NULL
Love Hörnquist Åstrand
2006-03-27 21:34:13 +00:00
72e10b58e9
Add new error code SIGNATURE_WITHOUT_SIGNER.
Love Hörnquist Åstrand
2006-03-27 21:33:19 +00:00
f0997e90dc
(_hx509_name_ds_cmp): make DirectoryString case insenstive (hx509_name_to_string): less spacing
Love Hörnquist Åstrand
2006-03-27 21:32:26 +00:00
fbd84cf005
Check for signature error, check consitency of error
Love Hörnquist Åstrand
2006-03-27 21:04:28 +00:00
ca56604415
Spelling
Love Hörnquist Åstrand
2006-03-27 15:44:04 +00:00
a615263222
x
Love Hörnquist Åstrand
2006-03-27 12:51:09 +00:00
abfe7761c2
Add hx509 when using PK-INIT.
Love Hörnquist Åstrand
2006-03-27 12:49:30 +00:00
33790dc4b8
x
Love Hörnquist Åstrand
2006-03-27 04:52:54 +00:00
63170a411d
x
Love Hörnquist Åstrand
2006-03-27 04:35:41 +00:00
28ef233497
(file_init): leak less memory
Love Hörnquist Åstrand
2006-03-27 04:26:37 +00:00
6e3958b47e
(_hx509_collector_alloc): handle errors
Love Hörnquist Åstrand
2006-03-27 04:26:05 +00:00
d275b39ee1
Use ticket flags definition, might fix Mac OS X Kerberos.app problems.
Love Hörnquist Åstrand
2006-03-27 04:22:23 +00:00
f024392e81
Switch to hx509.
Love Hörnquist Åstrand
2006-03-26 23:55:17 +00:00
c4c31576fe
(_hx509_private_key_assign_key_file): ask for password if nothing matches.
Love Hörnquist Åstrand
2006-03-26 23:54:18 +00:00
7542d311ee
Expose more of the hx509_query interface.
Love Hörnquist Åstrand
2006-03-26 23:51:10 +00:00
099a14e094
hx509_certs_find is now exposed.
Love Hörnquist Åstrand
2006-03-26 23:49:04 +00:00
a27d1186bf
(hx509_certs_free): allow free-ing NULL (hx509_certs_find): expose (hx509_get_one_cert): new function
Love Hörnquist Åstrand
2006-03-26 23:43:37 +00:00
12096c0f04
Remove hx509_query, its exposed now.
Love Hörnquist Åstrand
2006-03-26 23:39:08 +00:00
e0955cb5ba
Add hx509_query.
Love Hörnquist Åstrand
2006-03-26 23:33:55 +00:00
8c24e62151
Rename id-pksan to id-pkinit-san
Love Hörnquist Åstrand
2006-03-26 23:13:26 +00:00
a113ec2ba4
Add pkinit-san.
Love Hörnquist Åstrand
2006-03-26 23:12:54 +00:00
372189d4a1
x
Love Hörnquist Åstrand
2006-03-24 23:01:33 +00:00
137d218e79
(log_patypes): log the patypes requested by the client
Love Hörnquist Åstrand
2006-03-24 22:50:02 +00:00
e23391e667
x
Love Hörnquist Åstrand
2006-03-23 19:38:10 +00:00
c01934528b
Spelling.
Love Hörnquist Åstrand
2006-03-23 19:36:31 +00:00
a603f569c3
(_krb5_pk_rd_pa_reply): pass down the req_buffer in the w2k case too. From Douglas E. Engert.
Love Hörnquist Åstrand
2006-03-23 17:19:14 +00:00
1bb14914c1
(gss_init): add missing ; from Ted Percival
Love Hörnquist Åstrand
2006-03-23 16:53:26 +00:00
3d2c2ccee8
Add undocument flags and spelling, from Ted Percival <Ted.Percival@quest.com>
Love Hörnquist Åstrand
2006-03-23 16:41:09 +00:00
5a9da5632c
(_krb5_mk_req_internal): Indent and remove unused code block.
Love Hörnquist Åstrand
2006-03-19 20:33:13 +00:00
4740e4a03a
(_krb5_mk_req_internal): on failure, goto error handling. Fixes Coverity NetBSD CID 2591 by catching a failing krb5_copy_keyblock()
Love Hörnquist Åstrand
2006-03-19 20:30:34 +00:00
4e8e0a32a2
(krb5_rd_priv): reset outdata before returning error or success
Love Hörnquist Åstrand
2006-03-18 22:15:57 +00:00
ddaa580f35
(krb5_rd_safe): reset outdata before returning error or success
Love Hörnquist Åstrand
2006-03-18 22:15:28 +00:00
544071b438
(krb5_read_message): reset out data before return error or success, fixes many Coverity bugs.
Love Hörnquist Åstrand
2006-03-18 22:13:45 +00:00
08687cb067
(krb5_free_addresses): reset val,len in address when free-ing. Fixes Coverity NetBSD bug #2605 (krb5_parse_address): reset val,len before possibly return errors Fixes Coverity NetBSD bug #2605
Love Hörnquist Åstrand
2006-03-17 22:12:13 +00:00
a1143ef753
x
Love Hörnquist Åstrand
2006-03-08 12:30:54 +00:00
5be7181d53
(init_generate): Nothing in the generated files needs timegm(), so no need to provide a prototype for it.
Love Hörnquist Åstrand
2006-03-08 12:29:34 +00:00
8c024240f3
x
Love Hörnquist Åstrand
2006-03-07 19:42:39 +00:00
e1bd6f1007
(recv_loop): it should never happen, but make sure nbytes > 0
Love Hörnquist Åstrand
2006-03-07 19:39:59 +00:00
ac1c623242
(add_addrs): handle the case where addr->len == 0 and n == 0, then realloc might return NULL.
Love Hörnquist Åstrand
2006-03-07 19:38:09 +00:00
203072d917
(decrypt_*): handle the case where the plaintext is 0 bytes long, realloc might then return NULL.
Love Hörnquist Åstrand
2006-03-07 19:34:55 +00:00
2b07dd8731
x
Love Hörnquist Åstrand
2006-03-07 09:28:20 +00:00
337cf04f82
EVP interface depends on dlopen, add it to LIBFLAGS
Love Hörnquist Åstrand
2006-03-07 09:28:00 +00:00
cd53d482ff
x
Love Hörnquist Åstrand
2006-03-06 12:54:07 +00:00
5cca9c04e6
Drop krb5_string_to_key_derived.
Love Hörnquist Åstrand
2006-02-28 15:02:37 +00:00
b9b27743b2
Remove krb5_string_to_key_derived.
Love Hörnquist Åstrand
2006-02-28 15:01:22 +00:00