source: mod_gnutls/src/gnutls_config.c

Revision Log Mode:


Copied or renamed
Diff Rev Age Author Log Message
(edit) @4e388b0   17 months fiona.klute Consistently use strcasecmp() instead of mixing in apr_strnatcasecmp() debian/master
(edit) @6d8c00c   17 months fiona.klute Include apr_strings.h only where needed debian/master
(edit) @60868d2   18 months fiona.klute Default to NORMAL for the GnuTLS priority settings This simplifies … debian/master
(edit) @adceac0   19 months fiona.klute Remove unneeded server variables "cert_cn" and "cert_san" "cert_san" … debian/master
(edit) @eced11a   23 months fiona.klute Remove server variable ocsp_cache_enable There is no need to … debian/master
(edit) @babdb29   23 months fiona.klute Initialize and clean up the OCSP cache, following session cache patterns debian/master
(edit) @d036f96   2 years fiona.klute Add configuration directive GnuTLSOCSPCache (no-op for now) First … debian/master
(edit) @ce5f776   2 years fiona.klute Move config and post_config of a cache instance to separate functions … debian/master
(edit) @f52f1b4   2 years fiona.klute Allow GnuTLSCacheTimeout in virtual host config I'm not sure if … debian/master
(edit) @b94aee2   2 years fiona.klute Remove internal cache type enum The cache type is now transparently … debian/master
(edit) @6bbd378   2 years fiona.klute Remove special handling for APR memcache and leftover includes debian/master
(edit) @de1ceab   2 years fiona.klute Replace internal cache implementation with mod_socache Massively … debian/master
(edit) @0470e44   2 years fiona.klute Support common socache "type:config" style for GnuTLSCache directive debian/master
(edit) @7921dc7   2 years fiona.klute Remove OpenPGP authentication OpenPGP authentication was removed from … debian/master
(edit) @2246a84   2 years fiona.klute Make automatic OCSP cache updates and fuzz time configurable debian/master
(edit) @0e3f8c6   2 years fiona.klute Create module-wide singleton watchdog during post_config debian/master
(edit) @3c123cd   2 years fiona.klute Update my name, prepare changelog for the next release debian/masterdebian/stretch-backportsupstream
(edit) @a2b4ab6   3 years thomas2.klute Use GnuTLS known DH parameters If the user does not configure the DH … debian/masterdebian/stretch-backportsupstream
(edit) @104e881   3 years thomas2.klute General comment updates for Doxygen compatibility Mostly /* */ vs. … debian/masterdebian/stretch-backportsupstream
(edit) @e1c094c   3 years thomas2.klute Replace GnuTLSOCSPGraceTime with GnuTLSOCSPCacheTimeout Configuring a … debian/masterdebian/stretch-backportsupstream
(edit) @b888e8b   3 years thomas2.klute New directive GnuTLSOCSPCheckNonce Some CAs refuse to send nonces in … debian/masterdebian/stretch-backportsupstream
(edit) @c39ae1a   3 years thomas2.klute Initialize OCSP timeouts with an "unset" value The configuration … debian/masterdebian/stretch-backportsupstream
(edit) @0a02378   3 years thomas2.klute Style fixes for OCSP related time differences * Consistently use … debian/masterdebian/stretch-backportsupstream
(edit) @333bbc7   3 years thomas2.klute Configurable OCSP socket timeout Stalled OCSP requests must time out … debian/masterdebian/stretch-backportsupstream
(edit) @c6dda6d   3 years thomas2.klute Rate limit OCSP requests Retries after failed OCSP requests must be … debian/masterdebian/stretch-backportsupstream
(edit) @d26fa55   3 years thomas2.klute Allow GnuTLSOCSPGraceTime in virtual host context mgs_set_timeout … debian/masterdebian/stretch-backportsupstream
(edit) @4d4a406   4 years thomas2.klute New config option: GnuTLSOCSPStapling This flag option … debian/masterdebian/stretch-backportsupstream
(edit) @70d014b   4 years thomas2.klute Remove FIXME comment about releasing config structures: Done! debian/masterdebian/stretch-backportsupstream
(edit) @b8700b0   4 years thomas2.klute Deinit proxy credentials on config pool cleanup debian/masterdebian/stretch-backportsupstream
(edit) @7e7d328   4 years thomas2.klute Deinit PGP certificate on config pool cleanup debian/masterdebian/stretch-backportsupstream
(edit) @44e8944   4 years thomas2.klute Allocate memory for X.509 and PGP certificates only when needed debian/masterdebian/stretch-backportsupstream
(edit) @eee1432   4 years thomas2.klute Bind temporary pool in mgs_load_files() to ptemp scope Pool 'spool' … debian/masterdebian/stretch-backportsupstream
(edit) @45b7b83   4 years thomas2.klute Deinit PGP private key and keyring on config pool cleanup debian/masterdebian/stretch-backportsupstream
(edit) @db9ef68   4 years thomas2.klute Deinit client CA list on config pool cleanup debian/masterdebian/stretch-backportsupstream
(edit) @81433f1   4 years thomas2.klute Reformat mgs_load_files() This commit changes only whitespace and … debian/masterdebian/stretch-backportsupstream
(edit) @e2ba939   4 years thomas2.klute Prevent memory leaks in post_conf hook Valgrind indicated memory … debian/masterdebian/stretch-backportsupstream
(edit) @cc74801e   4 years thomas2.klute Move generated vhost-wide OCSP config into a private structure debian/masterdebian/stretch-backportsupstream
(edit) @d6834e0   4 years thomas2.klute OCSP refresh mutex: Prevent parallel requests Add a global mutex … debian/masterdebian/stretch-backportsupstream
(edit) @aa68232   4 years thomas2.klute Move global cache mutex into the private cache struct debian/masterdebian/stretch-backportsupstream
(edit) @e809fb3   4 years thomas2.klute Use generic cache functions for OCSP response caching With this, OCSP … debian/masterdebian/stretch-backportsupstream
(edit) @70a1e5a   4 years thomas2.klute Introduce OCSP caching grace time A cached OCSP response must be … debian/masterdebian/stretch-backportsupstream
(edit) @c005645   4 years thomas2.klute Mutex for DBM cache access I noticed that with a DBM cache enabled … debian/masterdebian/stretch-backportsupstream
(edit) @8913410   4 years thomas2.klute Update copyright headers debian/masterdebian/stretch-backportsupstream
(edit) @fd6bb19   4 years thomas2.klute Extract OCSP access URI from the server certificate debian/masterdebian/stretch-backportsupstream
(edit) @fad7695   4 years thomas2.klute Store OCSP trust list in server config This avoids recreating the … debian/masterdebian/stretch-backportsupstream
(edit) @94cb972   4 years thomas2.klute Minimal OCSP stapling implementation using externally provided … debian/masterdebian/stretch-backportsupstream
(edit) @9ca1f21   5 years thomas2.klute Allow loading more than one PKCS #11 module using GnuTLSP11Module … debian/masterdebian/stretch-backportsjessie-backportsupstream
(edit) @176047e   5 years thomas2.klute Use AP_INIT_FLAG for On/Off? config directives Letting the Apache … debian/masterdebian/stretch-backportsjessie-backportsupstream
(edit) @7764015   5 years thomas2.klute Update GnuTLSP11Module documentation for stricter semantics debian/masterdebian/stretch-backportsjessie-backportsupstream
(edit) @e021722   5 years thomas2.klute Update copyright headers for Nikos Mavrogiannopoulos' PKCS #11 patch … debian/masterdebian/stretch-backportsjessie-backportsupstream
(edit) @e391197   5 years thomas2.klute Update copyright headers for C source debian/masterdebian/stretch-backportsjessie-backportsupstream
(edit) @a2e3c33   5 years thomas2.klute Rename option SSLProxyEngine to GnuTLSProxyEngine This matches the … debian/masterdebian/stretch-backportsjessie-backportsupstream
(edit) @87f1ed2   5 years thomas2.klute Allow loading of an additional PKCS #11 provider library When using … debian/masterdebian/stretch-backportsjessie-backportsupstream
(edit) @4133f2d   5 years thomas2.klute Unify argument handling in mgs_set_priorities Just store the argument … debian/masterdebian/stretch-backportsjessie-backportsupstream
(edit) @2cde026d   5 years thomas2.klute Merge branch 'new-gnutls-api' Merge my TLS proxy implementation with … debian/masterdebian/stretch-backportsjessie-backportsupstream
(edit) @f030883   5 years thomas2.klute Set GnuTLS priorities for proxy connections separately Until now, … debian/masterdebian/stretch-backportsjessie-backportsupstream
(edit) @d04f7da   5 years thomas2.klute Version guards for gnutls_privkey_import_openpgp_raw workaround The … debian/masterdebian/stretch-backportsjessie-backportsupstream
(edit) @2cde8111   5 years thomas2.klute Workarounds for OpenPGP key handling Commit … debian/masterdebian/stretch-backportsjessie-backportsupstream
(edit) @259e835   5 years thomas2.klute Merge branch 'master' into new-gnutls-api Branch 'master' at this … debian/masterdebian/stretch-backportsjessie-backportsupstream
(edit) @1d9cfaf   5 years thomas2.klute gnutls_config.c: Backport function signature changes from master … debian/masterdebian/stretch-backportsjessie-backportsupstream
(edit) @809c422   5 years thomas2.klute TLS proxy: Add support for CRLs to back end server verification When … debian/masterdebian/stretch-backportsjessie-backportsupstream
(edit) @0de1839   5 years thomas2.klute Support X.509 auth for TLS proxy connections This commit adds support … debian/masterdebian/stretch-backportsjessie-backportsupstream
(edit) @7314438   5 years thomas2.klute Fix whitespace problems detected by git debian/masterdebian/stretch-backportsjessie-backportsupstream
(edit) @beb14d9   5 years thomas2.klute Proof of concept: Support for proxy back end connections using TLS … debian/masterdebian/stretch-backportsjessie-backportsupstream
(edit) @031acac   6 years nmav Use the new (3.1.3+) GnuTLS APIs to obtain private keys. This allows … debian/masterdebian/stretch-backportsjessie-backportsupstream
(edit) @fd82e59   6 years dkg use strict compiler arguments by default (-Wall -Werror -Wextra) … debian/masterdebian/stretch-backportsjessie-backportsupstream
(edit) @2aaf4f5   6 years dkg implement GnuTLSExportCertificates control over max exported cert size … debian/masterdebian/stretch-backportsjessie-backportsupstream
(edit) @55dc3f0   6 years dkg Make Apache 2.4 display the correct module in error logs debian/masterdebian/stretch-backportsjessie-backportsupstream
(edit) @671b64f   6 years dkg remove all trailing whitespace debian/masterdebian/stretch-backportsjessie-backportsupstream
(edit) @cf2b905   6 years dkg MSVA: document and parse GnuTLSClientVerifyMethod directive The … debian/masterdebian/stretch-backportsjessie-backportsupstream
(edit) @7d1ab49   7 years dkg restore GnuTLSExportCertificate directive It looks to me like this … debian/masterdebian/stretch-backportsjessie-backportsmsvaupstream
(edit) @929d313   7 years dkg avoid use-after-free in mgs_set_key_file() debian/masterdebian/stretch-backportsjessie-backportsmsvaupstream
(edit) @480aba1   7 years dkg correct context terminology for GnuTLSCache configurations "global … debian/masterdebian/stretch-backportsjessie-backportsmsvaupstream
(edit) @040387c   7 years dkg server-wide settings should be defaults unless overridden in a vhost … debian/masterdebian/stretch-backportsjessie-backportsmsvaupstream
(edit) @8400c2e   7 years dkg properly document the GnuTLSCache directive debian/masterdebian/stretch-backportsjessie-backportsmsvaupstream
(edit) @3b4c0d0   7 years neuromancer * Added Comments to Header Structures * Refactored the following: … debian/masterdebian/stretch-backportsjessie-backportsmsvaupstream
(edit) @33826c5   9 years neuromancer mod_proxy support debian/masterdebian/stretch-backportsjessie-backportsmsvaupstream
(edit) @e183628   9 years neuromancer Updated Copyright Headers & Formatting debian/masterdebian/stretch-backportsjessie-backportsmsvaupstream
(edit) @443b18e   9 years neuromancer Remove Legacy LUA Code debian/masterdebian/stretch-backportsjessie-backportsmsvaupstream
(edit) @b59327c   9 years nmav GnuTLSCache can now take a single argument (none). debian/masterdebian/stretch-backportsjessie-backportsmsvaupstream
(edit) @e02dd8c   9 years nmav indented code debian/masterdebian/stretch-backportsjessie-backportsmsvaupstream
(edit) @d8c7cf4   10 years nmav Only allow two options for DB. Berkeley DB and gdbm. The other options … debian/masterdebian/stretch-backportsjessie-backportsmsvaupstream
(edit) @771ca63   10 years nmav The GnuTLSCache variable now can be given the specific option "sdbm" … debian/masterdebian/stretch-backportsjessie-backportsmsvaupstream
(edit) @bca274d   10 years nmav Session tickets are enabled by default. debian/masterdebian/stretch-backportsjessie-backportsmsvaupstream
(edit) @ae233c2   10 years nmav Added option to turn on/off session tickets. debian/masterdebian/stretch-backportsjessie-backportsmsvaupstream
(edit) @03a9a6b   10 years nmav Force SDBM. debian/masterdebian/stretch-backportsjessie-backportsmsvaupstream
(edit) @7ef38d4   11 years nmav if private key import fails try as pkcs8 key. debian/masterdebian/stretch-backportsjessie-backportsmsvaupstream
(edit) @8663ace   11 years nmav removed limit on ca certificates' number debian/masterdebian/stretch-backportsjessie-backportsmsvaupstream
(edit) @787dab7   12 years nmav added option to disable srp (for distributions that disable it in gnutls) debian/masterdebian/stretch-backportsjessie-backportsmsvaupstream
(edit) @2b3a248   12 years nmav more changes for openpgp support. Seems to be at a workable state. debian/masterdebian/stretch-backportsjessie-backportsmsvaupstream
(edit) @e5bbda4   12 years nmav Initial support for openpgp keys debian/masterdebian/stretch-backportsjessie-backportsmsvaupstream
(edit) @5e81262   12 years nmav Added support for sending more than one certificate. debian/masterdebian/stretch-backportsjessie-backportsmsvaupstream
(edit) @b077bdd   12 years nmav added more error checks. debian/masterdebian/stretch-backportsjessie-backportsmsvaupstream
(edit) @a3c97d1   12 years nmav better handling of RSAFile and DHFile debian/masterdebian/stretch-backportsjessie-backportsmsvaupstream
(edit) @e239d1a   12 years nmav No more defaults for dhparams, rsaparams. Check for GnuTLSPriorities. debian/masterdebian/stretch-backportsjessie-backportsmsvaupstream
(edit) @fd73a08   12 years nmav Added support for subject alternative names. (untested) debian/masterdebian/stretch-backportsjessie-backportsmsvaupstream
(edit) @7bebb42   12 years nmav upgraded to 0.4.0 debian/masterdebian/stretch-backportsjessie-backportsmsvaupstream
(edit) @836c2f9   15 years chip start the CA Certificate code. debian/masterdebian/stretch-backportsjessie-backportsmsvaupstream
(edit) @84cb5b2   15 years chip - add lua to do client verification - only use gcrypt locking when … debian/masterdebian/stretch-backportsjessie-backportsmsvaupstream
(edit) @c301152   15 years chip - move hooks to gnutls_hooks.c - use 'mgs_' as the prefix for all … debian/masterdebian/stretch-backportsjessie-backportsmsvaupstream
Note: See TracRevisionLog for help on using the revision log.