|
|
|
@4261999
|
8 years |
thomas2.klute |
gnutls_io_input_read: Retry gnutls_record_recv if necessary
While …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@398d1a0
|
8 years |
thomas2.klute |
Improved logging for gnutls_io_input_read
* Log if something tried to …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@4fefa39
|
8 years |
thomas2.klute |
src/gnutls_io.c: Reformat gnutls_io_filter_error for readability
No …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@beb14d9
|
8 years |
thomas2.klute |
Proof of concept: Support for proxy back end connections using TLS
…
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@c1ef069
|
8 years |
thomas2.klute |
Record if a connection is a proxy connection
When handling a proxy …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@5342265
|
8 years |
thomas2.klute |
Close last for loop in mgs_find_sni_server
The closing brace for the …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@07d548d
|
8 years |
thomas2.klute |
Properly use SSLProxyEngine option
ssl_proxy_enable now checks if …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@accbb83
|
8 years |
thomas2.klute |
mod_gnutls.c: Whitespace and line break fixes
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@c4ba9722
|
8 years |
thomas2.klute |
Add myself to list of contributors
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@c782c1f
|
8 years |
thomas2.klute |
Don't do global deinit when disabling TLS for a proxy back end …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@e8acf05
|
8 years |
thomas2.klute |
Enable/disable TLS per connection in ssl_engine_disable
Previously, …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@e4b58b6
|
8 years |
thomas2.klute |
Check error codes during GnuTLS connection init
These calls shouldn't …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@3d361b8
|
8 years |
thomas2.klute |
Check if filters exist before removing them in ssl_engine_disable
…
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@64dadf8
|
8 years |
thomas2.klute |
Use proper GNUTLS_ENABLED_* macros in SSL proxy functions
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@c32240f
|
8 years |
dkg |
switch from --long-arg=foo to --long-arg foo for certtool in test …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@fd82e59
|
9 years |
dkg |
use strict compiler arguments by default (-Wall -Werror -Wextra)
…
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@8a30d35
|
9 years |
dkg |
avoid deprecated form of AM_INIT_AUTOMAKE
without this change, we …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@765cac2
|
9 years |
dkg |
clean up MGS_SIDE abuse of apr_pstrcat
We were allocating twice as …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@2aaf4f5
|
9 years |
dkg |
implement GnuTLSExportCertificates control over max exported cert size …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@999cdec
|
9 years |
dkg |
GnuTLSExportCertificates should control maximum size of exported certs …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@04f48a2
|
9 years |
dkg |
trim down the readme so that we have one place for documentation.
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@8232c8b
|
9 years |
dkg |
removing dia ORM renderings; avoiding synchronization issues
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@a8df590
|
9 years |
dkg |
clean up testing directory properly
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@55dc3f0
|
9 years |
dkg |
Make Apache 2.4 display the correct module in error logs
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@1a99240
|
9 years |
dkg |
removing certtool templates that will be regenerated
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
mod_gnutls/0.6
|
|
|
@460c048
|
9 years |
dkg |
preparing version 0.6 release
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@83eafed
|
9 years |
dkg |
avoid a very unlikely NULL dereference
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@bce7907
|
9 years |
dkg |
updated documentation to refer to the project website.
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@2de1320
|
9 years |
dkg |
drop the -PKIX suffix in the session description
(this tracks changes …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@4ec9183
|
9 years |
dkg |
Include GnuTLS version as additional version component in Server …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@1830668
|
9 years |
dkg |
fix PKG_CHECK_MODULES autoconf macro
…
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@ba7d1c5
|
9 years |
dkg |
Use older priority string for compatibility
This lets the test at …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@46de753
|
9 years |
dkg |
fix build against GnuTLS 2.12.x
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@ac32bb5
|
9 years |
dkg |
document SSL_CLIENT_CERT_TYPE
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@5409165
|
9 years |
dkg |
correct GnuTLSPriorities documentation
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@6cfb4b4
|
9 years |
dkg |
replacing manual.mdwn with mod_gnutls_manual.mdwn
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@5a3ab3c
|
9 years |
dkg |
README.ENV is now subsumed into docs/mod_gnutls_manual.mdwn
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@671b64f
|
9 years |
dkg |
remove all trailing whitespace
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@9720026
|
9 years |
dkg |
silly newline cleanup
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@5674676
|
9 years |
dkg |
add SSL_DH_PRIME_BITS to expose the size of the DH modulus to CGI
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@9717fe4
|
9 years |
dkg |
test mod_status output
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@b4739cd
|
9 years |
dkg |
display some information in mod_status
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@37b52ea
|
9 years |
dkg |
do not fail if the msva homedir already exists
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@b55bf71
|
9 years |
dkg |
accept the e-mail address in the cert Subject if no sAN e-mail is present
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@a01f8ab
|
9 years |
dkg |
upgrade to libmsv 0.1 API
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@832182b
|
9 years |
dkg |
extracting the user ID from a certificate cleanly.
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@140d237
|
9 years |
dkg |
added a monkeysphere-validated test
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@5c0d491
|
9 years |
dkg |
MSVA: successful communication between apache and the agent
This is …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@07889ab
|
9 years |
dkg |
MSVA: some initial framework
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@e3cbda4
|
9 years |
dkg |
MSVA: include in test framework
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@cf2b905
|
9 years |
dkg |
MSVA: document and parse GnuTLSClientVerifyMethod directive
The …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@fa45dcb
|
9 years |
dkg |
MSVA: ./configure now supports --enable-msva
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@6870585
|
9 years |
dkg |
Do not request X.509 certs when we are expecting OpenPGP
Apparently …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@925318f
|
9 years |
dkg |
simplify OpenPGP User ID for server in test suite
Our test suite …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@c25fc5d
|
9 years |
dkg |
OpenPGP certificate needs either sign or encrypt capabilities
GnuTLS …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@dee490f
|
9 years |
dkg |
update tests for apache 2.4
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@74212ee
|
9 years |
dkg |
update test since SSL_CLIENT_CERT is not exported to the environment …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@6bb2474
|
10 years |
dkg |
Changed Default Export Of Full PEM Certificates To FALSE
This matches …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@70e7652
|
10 years |
dkg |
remove old versions of documentation now that we can generate them …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@2b16350
|
10 years |
dkg |
clean up documentation, list GnuTLSEnable as the first option
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@e7527b9
|
10 years |
dkg |
automate generation of other manual formats.
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@4ee45a1
|
10 years |
dkg |
Used pandoc to convert from html to markdown
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainproxy-ticketupstream
|
|
|
@6f76e16
|
10 years |
dkg |
Do not compare ephemeral output from gnutls-cli failures
The original …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@b1c2b01
|
10 years |
dkg |
avoid a segfault if no X.509 certificates are present during vhost_cb
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@834d926
|
10 years |
dkg |
add basic test with OpenPGP-certified credentials
This test is …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@3e800f9
|
10 years |
dkg |
test suite: OpenPGP certificates and secrets
Make ASCII-armored …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@7d1ab49
|
10 years |
dkg |
restore GnuTLSExportCertificate directive
It looks to me like this …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@6ef3afc
|
10 years |
dkg |
added tests that cover passing environment variables to the CGI script
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@adb7135
|
10 years |
dkg |
add basic test to check for client-cert verification.
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@25e6b32
|
10 years |
dkg |
remove obsolete mgs_handle_t.rsa_params -- RSA-EXPORT is not supported …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@c0dd3ab
|
10 years |
dkg |
avoid invoking gnutls_transport_get_ptr on a NULL session
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@f9eab65
|
10 years |
dkg |
add two tests that detail expected vhost selection for clients who do …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@cf51bf9
|
10 years |
dkg |
added a test to verify that SNI works
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@b668622
|
10 years |
dkg |
Do not override the configured GnuTLS priority string.
This fixes …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@c5bf40b
|
10 years |
dkg |
added test that should fail due to protocol priority mismatch
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@8985a6b
|
10 years |
dkg |
allow certificate use for clients without SNI
The test removed here …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@a4006d3
|
10 years |
dkg |
make basic test without SNI from the client
This should use the …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@032ff02
|
10 years |
dkg |
parameterize mod_gnutls.h.in so that MOD_GNUTLS_VERSION and …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@9ecd212
|
10 years |
dkg |
avoid embedding extra/unnecessary newlines in logs
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@932b68e
|
10 years |
dkg |
Check for the version of GnuTLS we built against
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@cb5188f
|
10 years |
dkg |
fatal library initialization error logs should be at APLOG_EMERG
…
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@421ef1c
|
10 years |
dkg |
deal responsibly with grave failures in pre_config hook
If a …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@929d313
|
10 years |
dkg |
avoid use-after-free in mgs_set_key_file()
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@480aba1
|
10 years |
dkg |
correct context terminology for GnuTLSCache configurations
"global …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@0367e02
|
10 years |
dkg |
test to ensure that cache directives are only global
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@040387c
|
10 years |
dkg |
server-wide settings should be defaults unless overridden in a vhost
…
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@32538ff
|
10 years |
dkg |
demonstrate failure with server-wide setting of GnuTLS priorities
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@4b53371
|
10 years |
dkg |
initial testing framework, with one simple test.
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@375939d
|
10 years |
dkg |
tell git to explicitly ignore configuration and build byproducts
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@2d0f6cf
|
10 years |
dkg |
initialize members by name, for better clarity
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@8400c2e
|
10 years |
dkg |
properly document the GnuTLSCache directive
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@369f47a
|
10 years |
dkg |
avoid calling gnutls_srp_server_get_username() unless SRP is configured
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@b8df283
|
10 years |
dkg |
use gnutls_datum_t instead of the deprecated gnutls_datum
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@2b76a9c
|
10 years |
dkg |
X.509 certificates are ordered EE first (see …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@303dc6e
|
10 years |
dkg |
manual cleanup and clarification
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@dab7a25
|
10 years |
dkg |
rip out remaining references to obsolete "export" encryption
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@6055aff
|
10 years |
dkg |
warn if the server hostname cannot be found in the certificate
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@e2b936e
|
10 years |
dkg |
no longer using first_run since 31645b2ad; remove it
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@422f5b7
|
10 years |
dkg |
report an error if the attempt to chown the dbm session cache fails
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|
@198b9f0
|
10 years |
dkg |
try to record a surmise of the expected C coding conventions for emacs …
asynciodebian/masterdebian/stretch-backportsjessie-backportsmainmsvaproxy-ticketupstream
|
|
|