|
|
|
@23e98b3
|
5 years |
fiona.klute |
Implement ssl_engine_set as introduced by mod_ssl in Apache 2.4.33
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@235e109
|
5 years |
fiona.klute |
Unify initialization of mod_gnutls connection context
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@fe21671
|
5 years |
thomas2.klute |
ssl_engine_disable(): Remove mod_gnutls filters, not first in chain
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@1de1026
|
5 years |
thomas2.klute |
mgs_get_ocsp_response(): Separate mgs_srvconf_rec* variable for …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@994a5fb
|
5 years |
thomas2.klute |
Do not reconfigure OCSP status callback on each connection
The …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@2a912c3
|
5 years |
thomas2.klute |
Release version 0.8.3
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
mod_gnutls/0.8.3
|
|
|
@54d07a1
|
5 years |
thomas2.klute |
Do not announce (unused) session ticket support on proxy connections
…
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@265159d
|
5 years |
thomas2.klute |
Send SNI for proxy connections
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@321912b
|
5 years |
thomas2.klute |
Test suite: Start OCSP responder from runtests if config exists
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@ee94de5
|
5 years |
thomas2.klute |
Test suite: Clean up for current GnuPG versions
Newer GnuPG versions …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@acea635
|
5 years |
thomas2.klute |
Test suite: Wait for Apache shutdown before "distclean" check
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@1872744
|
5 years |
thomas2.klute |
Test suite: Rename bash function backend_apache to apache_service
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@b28158c
|
5 years |
thomas2.klute |
Test suite: Start proxy backend server from runtests if config exists
…
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@c9e4709
|
5 years |
thomas2.klute |
Test suite: Use dir argument instead of "testdir" env in backend_apache
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@967bf9b
|
5 years |
thomas2.klute |
Test suite: Prevent duplicate "Listen" on OCSP_PORT
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@97d7c63
|
5 years |
thomas2.klute |
Test suite: Port config for proxy backend in Makefile and Apache …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@e00d91a
|
5 years |
thomas2.klute |
Test suite: Use TEST_LOCK instead of constant TEST_PID in runtests
…
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@94430e6
|
5 years |
thomas2.klute |
Test suite: Run a separate Apache instance for the OCSP responder
…
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@a09df8c
|
5 years |
thomas2.klute |
Handbook: Update RFC reference for SNI
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@2ae1c3c
|
6 years |
thomas2.klute |
Update changelog with changes since 0.8.2
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@98cf33f
|
6 years |
thomas2.klute |
Rewrite SNI handler to accept long names and ignore unknown name types …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@017ef2d
|
6 years |
thomas2.klute |
Cleanup of post client hello and SNI handling functions
* Get module …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@cebb74a
|
6 years |
thomas2.klute |
Remove broken SNI/session resumption workaround
By specification, the …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@e389b85
|
6 years |
thomas2.klute |
Remove obsolete global GnuTLS (de)init calls
These calls have been …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@732c5733
|
6 years |
thomas2.klute |
Fix description of environment variable "SSL_CLIENT_I_DN" (issuer DN)
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@cdc6e4a
|
6 years |
thomas2.klute |
Choose flock or PID wait based on availability, not file parameter presence
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@b8b1990
|
6 years |
thomas2.klute |
Use fixed DH parameters for tests that log DH prime length in CGI …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@f4deac5
|
6 years |
thomas2.klute |
Warn users about OpenPGP deprecation
OpenPGP support has been …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@bd6591f
|
6 years |
thomas2.klute |
Update documentation of the GnuTLSDHFile option
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@a2b4ab6
|
6 years |
thomas2.klute |
Use GnuTLS known DH parameters
If the user does not configure the DH …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@92ac36e
|
6 years |
thomas2.klute |
Remove dead code in DH parameters setup
The dh_params variable in …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@439005a
|
6 years |
thomas2.klute |
Skip OpenPGP test if GnuTLS was compiled without OpenPGP support
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@4f7edd5
|
6 years |
thomas2.klute |
Remove log for mutex creation errors (core logs them at emergency level)
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@f2a44d1
|
6 years |
thomas2.klute |
Test suite: Set DefaultRuntimeDir? for all Apache instances
According …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@342e11d
|
6 years |
thomas2.klute |
Test suite: Remove unnecessary TEST_IP handling for proxy back-end …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@339a49d
|
6 years |
thomas2.klute |
Test suite: List .bash in TEST_EXTENSIONS
This way the test harness …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@4fb510d
|
6 years |
thomas2.klute |
Test suite: Add generic function to wait for a command to succeed
The …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@5f3222b
|
6 years |
thomas2.klute |
Test suite: Use "caller" builtin and BASH_COMMAND for error traces
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@0b83b21
|
6 years |
thomas2.klute |
Remove two left-over function declarations for Lua auth handling
…
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@b0e4ce6
|
6 years |
thomas2.klute |
configure.ac: Log values of CFLAGS and LDFLAGS for GnuTLS
Convenience …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@6135393
|
6 years |
thomas2.klute |
Do not treat warnings about deprecated declarations as errors
GnuTLS …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@37beb92
|
6 years |
thomas2.klute |
Test suite: Do not explicitly set the mutex type to "default"
The …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@fb4da99
|
6 years |
thomas2.klute |
Test suite: Log the HTTPD build configuration if VERBOSE is enabled
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@4ae5b82
|
6 years |
thomas2.klute |
Check if flock supports --verbose
Some old versions of flock do not …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@6c030c1
|
6 years |
thomas2.klute |
Test suite: Make timeouts for server locks and HTTPS requests …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@bbfcbb5
|
6 years |
thomas2.klute |
Test suite: Log if a process to be stopped by PID file is not running
…
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@8184ad0
|
6 years |
thomas2.klute |
Test suite: Run flock with "--verbose" to log timeouts
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@26ae700
|
6 years |
thomas2.klute |
Test suite: Remove NameVirtualHost? directives
According to the Apache …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@d39ea18
|
6 years |
thomas2.klute |
Test suite: Do not continue test case if Apache instance fails to …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@0202d6b
|
6 years |
thomas2.klute |
Release version 0.8.2
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
mod_gnutls/0.8.2
|
|
|
@10d9053
|
6 years |
thomas2.klute |
Test suite, gen_ocsp_index.c: Handle serial as fixed order byte array
…
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@0a12ff8
|
6 years |
thomas2.klute |
Test suite: Ensure CRLF line ends in HTTP headers
Debian Sid updated …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@154db29
|
6 years |
thomas2.klute |
Release version 0.8.1
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
mod_gnutls/0.8.1
|
|
|
@5ac4bbe
|
6 years |
thomas2.klute |
Use APR_SIZE_T_FMT macro for portable apr_size_t formatting
The size …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@677754f
|
6 years |
thomas2.klute |
Release version 0.8.0
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
mod_gnutls/0.8.0
|
|
|
@c22af3a
|
6 years |
thomas2.klute |
Handbook: List Berkeley DB and GDBM as equal options for DBM caches
…
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@251edfe
|
6 years |
thomas2.klute |
Mention Doxygen documentation in README
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@08b821a
|
6 years |
thomas2.klute |
gnutls_io.c: API documentation
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@e0e0b0f
|
6 years |
thomas2.klute |
Include memcached cache functions in Doxygen documentation, if enabled
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@104e881
|
6 years |
thomas2.klute |
General comment updates for Doxygen compatibility
Mostly /* */ vs. …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@14548b9
|
6 years |
thomas2.klute |
Update comments in gnutls_cache.(c|h) to work with Doxygen
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@d4d066f
|
6 years |
thomas2.klute |
Enable automatic brief descriptions in Doxygen documentation
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@9a18e30
|
6 years |
thomas2.klute |
Support basic Doxygen calls
Doxygen targets are included in the …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@e1c094c
|
6 years |
thomas2.klute |
Replace GnuTLSOCSPGraceTime with GnuTLSOCSPCacheTimeout
Configuring a …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@b26a792
|
6 years |
thomas2.klute |
Beta release version 0.8.0-beta
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
mod_gnutls/0.8.0-beta
|
|
|
@b888e8b
|
6 years |
thomas2.klute |
New directive GnuTLSOCSPCheckNonce
Some CAs refuse to send nonces in …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@b34a67e
|
6 years |
thomas2.klute |
Handbook: Add example ocsptool command for response file creation
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@3475e62
|
6 years |
thomas2.klute |
Remove EXPERIMENTAL mark for OCSP from internal documentation
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@c39ae1a
|
6 years |
thomas2.klute |
Initialize OCSP timeouts with an "unset" value
The configuration …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@0cd8f3d
|
6 years |
thomas2.klute |
Update OCSP stapling documentation
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@444e6ed
|
6 years |
thomas2.klute |
Fix documentation of GnuTLSCacheTimeout
GnuTLSCacheTimeout has …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@ef107fd
|
6 years |
thomas2.klute |
Remove TODO for OCSP requests without nonces
Ideally all OCSP …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@0a02378
|
6 years |
thomas2.klute |
Style fixes for OCSP related time differences
* Consistently use …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@333bbc7
|
6 years |
thomas2.klute |
Configurable OCSP socket timeout
Stalled OCSP requests must time out …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@c6dda6d
|
6 years |
thomas2.klute |
Rate limit OCSP requests
Retries after failed OCSP requests must be …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@d26fa55
|
6 years |
thomas2.klute |
Allow GnuTLSOCSPGraceTime in virtual host context
mgs_set_timeout …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@3f0b470
|
6 years |
thomas2.klute |
Macro for the OCSP socket timeout
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@4bc17ae
|
7 years |
thomas2.klute |
Alpha release version 0.8.0-alpha
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
mod_gnutls/0.8.0-alpha
|
|
|
@8a0da86
|
7 years |
thomas2.klute |
Adjust log levels for OCSP cache updates
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@9c456a9
|
7 years |
thomas2.klute |
Clean up cache logging
* Demote ordinary cache store/fetch operations …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@df49a2d
|
7 years |
thomas2.klute |
Handbook: Sort options into subsections
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@c3c96ca
|
7 years |
thomas2.klute |
Handbook: Update and simplify description of GnuTLSPriorities
The …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@fc124e9
|
7 years |
thomas2.klute |
Handbook: Update configuration examples
* Replaced old example …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@743e31f
|
7 years |
thomas2.klute |
Documentation: Use "TLS" as the generic term instead of "SSL"
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@e9ef72c
|
7 years |
thomas2.klute |
Disable GnuTLSSessionTickets by default as described in handbook
The …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@5a5032f
|
7 years |
thomas2.klute |
Documentation for OCSP stapling options
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@4c529de
|
7 years |
thomas2.klute |
Update Apache and GnuTLS version dependencies
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@3725f2d
|
7 years |
thomas2.klute |
Disable OCSP test for GnuTLS 3.5.0
Since 3.5.1 has been released, …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@f1147b6
|
7 years |
thomas2.klute |
OCSP post config: Ensure OCSP URI or response file are set
If the …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@ef06c74
|
7 years |
thomas2.klute |
Compatibility code for GCC version < 5
The builtin_add_overflow() …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@ac3f500
|
7 years |
thomas2.klute |
Compatibility code for GnuTLS version < 3.4
* gnutls_memset() is not …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@87d507b
|
7 years |
thomas2.klute |
Overwrite session ticket key before releasing it
Private key material …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@78b75b3
|
7 years |
thomas2.klute |
Restore GnuTLSOCSPResponseFile option
Using an externally updated …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@a784735
|
7 years |
thomas2.klute |
Test 27_OCSP_server: Check if gnutls-cli received a stapled OCSP response
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@4d4a406
|
7 years |
thomas2.klute |
New config option: GnuTLSOCSPStapling
This flag option …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@70d014b
|
7 years |
thomas2.klute |
Remove FIXME comment about releasing config structures: Done!
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@b8700b0
|
7 years |
thomas2.klute |
Deinit proxy credentials on config pool cleanup
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@02eabe7
|
7 years |
thomas2.klute |
TLS Proxy: Fix memory leak while logging certificate status
The …
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@f265001
|
7 years |
thomas2.klute |
Bind temporary pool in load_proxy_x509_credentials() to ptemp scope
…
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|
@7e7d328
|
7 years |
thomas2.klute |
Deinit PGP certificate on config pool cleanup
asynciodebian/masterdebian/stretch-backportsmainproxy-ticketupstream
|
|
|