@37beb92
4 years
thomas2.klute
Test suite: Do not explicitly set the mutex type to "default"
The …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@fb4da99
4 years
thomas2.klute
Test suite: Log the HTTPD build configuration if VERBOSE is enabled
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@4ae5b82
4 years
thomas2.klute
Check if flock supports --verbose
Some old versions of flock do not …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@6c030c1
4 years
thomas2.klute
Test suite: Make timeouts for server locks and HTTPS requests …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@bbfcbb5
4 years
thomas2.klute
Test suite: Log if a process to be stopped by PID file is not running
…
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@8184ad0
4 years
thomas2.klute
Test suite: Run flock with "--verbose" to log timeouts
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@26ae700
4 years
thomas2.klute
Test suite: Remove NameVirtualHost? directives
According to the Apache …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@d39ea18
4 years
thomas2.klute
Test suite: Do not continue test case if Apache instance fails to …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@0202d6b
4 years
thomas2.klute
Release version 0.8.2
asyncio debian/master debian/stretch-backports proxy-ticket upstream
mod_gnutls/0.8.2
@10d9053
4 years
thomas2.klute
Test suite, gen_ocsp_index.c: Handle serial as fixed order byte array
…
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@0a12ff8
4 years
thomas2.klute
Test suite: Ensure CRLF line ends in HTTP headers
Debian Sid updated …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@154db29
4 years
thomas2.klute
Release version 0.8.1
asyncio debian/master debian/stretch-backports proxy-ticket upstream
mod_gnutls/0.8.1
@5ac4bbe
4 years
thomas2.klute
Use APR_SIZE_T_FMT macro for portable apr_size_t formatting
The size …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@677754f
4 years
thomas2.klute
Release version 0.8.0
asyncio debian/master debian/stretch-backports proxy-ticket upstream
mod_gnutls/0.8.0
@c22af3a
4 years
thomas2.klute
Handbook: List Berkeley DB and GDBM as equal options for DBM caches
…
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@251edfe
4 years
thomas2.klute
Mention Doxygen documentation in README
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@08b821a
4 years
thomas2.klute
gnutls_io.c: API documentation
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@e0e0b0f
4 years
thomas2.klute
Include memcached cache functions in Doxygen documentation, if enabled
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@104e881
4 years
thomas2.klute
General comment updates for Doxygen compatibility
Mostly /* */ vs. …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@14548b9
4 years
thomas2.klute
Update comments in gnutls_cache.(c|h) to work with Doxygen
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@d4d066f
4 years
thomas2.klute
Enable automatic brief descriptions in Doxygen documentation
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@9a18e30
4 years
thomas2.klute
Support basic Doxygen calls
Doxygen targets are included in the …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@e1c094c
4 years
thomas2.klute
Replace GnuTLSOCSPGraceTime with GnuTLSOCSPCacheTimeout
Configuring a …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@b26a792
4 years
thomas2.klute
Beta release version 0.8.0-beta
asyncio debian/master debian/stretch-backports proxy-ticket upstream
mod_gnutls/0.8.0-beta
@b888e8b
4 years
thomas2.klute
New directive GnuTLSOCSPCheckNonce
Some CAs refuse to send nonces in …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@b34a67e
4 years
thomas2.klute
Handbook: Add example ocsptool command for response file creation
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@3475e62
4 years
thomas2.klute
Remove EXPERIMENTAL mark for OCSP from internal documentation
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@c39ae1a
4 years
thomas2.klute
Initialize OCSP timeouts with an "unset" value
The configuration …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@0cd8f3d
4 years
thomas2.klute
Update OCSP stapling documentation
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@444e6ed
4 years
thomas2.klute
Fix documentation of GnuTLSCacheTimeout
GnuTLSCacheTimeout has …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@ef107fd
4 years
thomas2.klute
Remove TODO for OCSP requests without nonces
Ideally all OCSP …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@0a02378
4 years
thomas2.klute
Style fixes for OCSP related time differences
* Consistently use …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@333bbc7
4 years
thomas2.klute
Configurable OCSP socket timeout
Stalled OCSP requests must time out …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@c6dda6d
4 years
thomas2.klute
Rate limit OCSP requests
Retries after failed OCSP requests must be …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@d26fa55
5 years
thomas2.klute
Allow GnuTLSOCSPGraceTime in virtual host context
mgs_set_timeout …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@3f0b470
5 years
thomas2.klute
Macro for the OCSP socket timeout
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@4bc17ae
5 years
thomas2.klute
Alpha release version 0.8.0-alpha
asyncio debian/master debian/stretch-backports proxy-ticket upstream
mod_gnutls/0.8.0-alpha
@8a0da86
5 years
thomas2.klute
Adjust log levels for OCSP cache updates
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@9c456a9
5 years
thomas2.klute
Clean up cache logging
* Demote ordinary cache store/fetch operations …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@df49a2d
5 years
thomas2.klute
Handbook: Sort options into subsections
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@c3c96ca
5 years
thomas2.klute
Handbook: Update and simplify description of GnuTLSPriorities
The …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@fc124e9
5 years
thomas2.klute
Handbook: Update configuration examples
* Replaced old example …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@743e31f
5 years
thomas2.klute
Documentation: Use "TLS" as the generic term instead of "SSL"
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@e9ef72c
5 years
thomas2.klute
Disable GnuTLSSessionTickets by default as described in handbook
The …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@5a5032f
5 years
thomas2.klute
Documentation for OCSP stapling options
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@4c529de
5 years
thomas2.klute
Update Apache and GnuTLS version dependencies
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@3725f2d
5 years
thomas2.klute
Disable OCSP test for GnuTLS 3.5.0
Since 3.5.1 has been released, …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@f1147b6
5 years
thomas2.klute
OCSP post config: Ensure OCSP URI or response file are set
If the …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@ef06c74
5 years
thomas2.klute
Compatibility code for GCC version < 5
The builtin_add_overflow() …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@ac3f500
5 years
thomas2.klute
Compatibility code for GnuTLS version < 3.4
* gnutls_memset() is not …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@87d507b
5 years
thomas2.klute
Overwrite session ticket key before releasing it
Private key material …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@78b75b3
5 years
thomas2.klute
Restore GnuTLSOCSPResponseFile option
Using an externally updated …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@a784735
5 years
thomas2.klute
Test 27_OCSP_server: Check if gnutls-cli received a stapled OCSP response
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@4d4a406
5 years
thomas2.klute
New config option: GnuTLSOCSPStapling
This flag option …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@70d014b
5 years
thomas2.klute
Remove FIXME comment about releasing config structures: Done!
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@b8700b0
5 years
thomas2.klute
Deinit proxy credentials on config pool cleanup
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@02eabe7
5 years
thomas2.klute
TLS Proxy: Fix memory leak while logging certificate status
The …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@f265001
5 years
thomas2.klute
Bind temporary pool in load_proxy_x509_credentials() to ptemp scope
…
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@7e7d328
5 years
thomas2.klute
Deinit PGP certificate on config pool cleanup
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@44e8944
5 years
thomas2.klute
Allocate memory for X.509 and PGP certificates only when needed
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@eee1432
5 years
thomas2.klute
Bind temporary pool in mgs_load_files() to ptemp scope
Pool 'spool' …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@45b7b83
5 years
thomas2.klute
Deinit PGP private key and keyring on config pool cleanup
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@db9ef68
5 years
thomas2.klute
Deinit client CA list on config pool cleanup
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@81433f1
5 years
thomas2.klute
Reformat mgs_load_files()
This commit changes only whitespace and …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@e2ba939
5 years
thomas2.klute
Prevent memory leaks in post_conf hook
Valgrind indicated memory …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@317b569
5 years
thomas2.klute
Make the response validity period of the test responder configurable
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@894efd0
5 years
thomas2.klute
Check OCSP response nonce
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@82745d1
5 years
thomas2.klute
Fix memory usage issues
* Use-after-free of the OCSP request in …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@16ad0eb
5 years
thomas2.klute
Perform OCSP request over HTTP
Finally the whole stack is there! …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@04addef
5 years
thomas2.klute
Test suite: Always lock authority PGP keyring
I've occasionally …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@0831437
5 years
thomas2.klute
Clarify the purpose of mgs_time2sz()
I've renamed the CTIME macro to …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@47a909e
5 years
thomas2.klute
Create OCSP requests when updating the cached response
Actually …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@6c44ed2
5 years
thomas2.klute
Test suite: Explicitly link gen_ocsp_index against libgnutls
This is …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@a372379
5 years
thomas2.klute
Store server certificate fingerprint in OCSP config
It's not like …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@cc74801e
5 years
thomas2.klute
Move generated vhost-wide OCSP config into a private structure
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@6b89353
5 years
thomas2.klute
Remove Lua bytecode variables from directory config structure
The …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@5559aa6
5 years
thomas2.klute
Rely on cache for OCSP response expiration
With fixed DBM cache …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@11e6205
5 years
thomas2.klute
dbm_cache_fetch(): Clear data size on allocation failure
Memory …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@b2e6406
5 years
thomas2.klute
Safe integer type conversion in mgs_filter_input()
Read sizes should …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@15b22cb
5 years
thomas2.klute
Allow compiling with clang
Needs just a minimal workaround for an …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@d6834e0
5 years
thomas2.klute
OCSP refresh mutex: Prevent parallel requests
Add a global mutex …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@aa68232
5 years
thomas2.klute
Move global cache mutex into the private cache struct
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@e809fb3
5 years
thomas2.klute
Use generic cache functions for OCSP response caching
With this, OCSP …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@3e22b82
5 years
thomas2.klute
Add generic store/fetch support to the memcached cache
Required to …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@70a1e5a
5 years
thomas2.klute
Introduce OCSP caching grace time
A cached OCSP response must be …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@f450ac9
5 years
thomas2.klute
Replace mgs_session_id2sz() with apr_(p?)escape_hex()
There's no need …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@d18afb8
5 years
thomas2.klute
Ensure that dbm_cache_fetch() does not return expired data
The cache …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@c6572ec
5 years
thomas2.klute
Apply default cache timeout to OCSP responses without nextUpdate
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@c55902b
5 years
thomas2.klute
Trigger cache expiration on fetch, small restructuring
In a situation …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@c005645
5 years
thomas2.klute
Mutex for DBM cache access
I noticed that with a DBM cache enabled …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@eb63377
5 years
thomas2.klute
Check only expiration time for OCSP responses from cache
Responses …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@366d1a1
5 years
thomas2.klute
Use nextUpdate field of OCSP response to set cache lifetime
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@08817d0
5 years
thomas2.klute
Check OCSP response before caching
Only verified responses should be …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@368e581
5 years
thomas2.klute
Update OCSP response cache only if response is missing or invalid
…
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@4bf4ce2
5 years
thomas2.klute
Use GCC builtins to catch overflows with mixed integer types
…
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@6b4136c
5 years
thomas2.klute
Store OCSP responses in DBM cache before use
This is not proper …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@2f932fa
5 years
thomas2.klute
Use gnutls_datum_t to pass DBM keys for GnuTLS sessions
The APR …
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@6814e48
5 years
thomas2.klute
Explain the different signatures of the dbm_cache functions
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@15245bf
5 years
thomas2.klute
Split dbm_cache_fetch() in generic and GnuTLS session specific parts
…
asyncio debian/master debian/stretch-backports proxy-ticket upstream
@1d1361f
5 years
thomas2.klute
Make dbm_cache_store() work outside connection context
asyncio debian/master debian/stretch-backports proxy-ticket upstream