Commit Graph

415 Commits

Author SHA1 Message Date
Nikos Mavrogiannopoulos
d9967aa63a doc update
Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
2019-02-22 08:47:00 +01:00
Nikos Mavrogiannopoulos
0d8fd8d2b6 doc update
Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
2019-02-22 08:45:49 +01:00
Nikos Mavrogiannopoulos
8ba3987f4c occtl: print the TLS session information, even if no DTLS channel
This ensures that the main process receives the TLS channel information
early and does not depend on DTLS channel establishment. Furthermore,
we refactor to make setup_dtls_psk_keys() fail early when no TLS channel
is available.

Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2019-01-19 20:09:53 +01:00
Nikos Mavrogiannopoulos
e0f847b984 worker: added safety check for selected DTLS ciphersuite prior to use
This avoids a crash when no DTLS ciphersuite is selected and adds a
test case for negotiation without DTLS.

Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2019-01-19 18:19:11 +01:00
Nikos Mavrogiannopoulos
cafd66d33d corrected typo
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2019-01-10 20:01:58 +01:00
Nikos Mavrogiannopoulos
dfc8f95ee8 released 0.12.2
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2019-01-10 19:55:15 +01:00
Nikos Mavrogiannopoulos
232de85d17 doc update
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2019-01-10 13:03:03 +01:00
Nikos Mavrogiannopoulos
579cfc0ead Added support for AES-256-CBC
This enables support for AES-256 for anyconnect clients which
do not support AES-GCM. Also prioritized the 256-bit ciphers
higher than the 128-bit ones.

Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2018-07-20 21:58:49 +02:00
Nikos Mavrogiannopoulos
68c16a56b1 NEWS: updated for release
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2018-05-12 11:23:03 +02:00
Nikos Mavrogiannopoulos
3dc6f95a6a released 0.12.1
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2018-05-12 08:17:22 +02:00
Nikos Mavrogiannopoulos
807ce345de main: create a sec-mod socket file independent of pid
That addresses the issue of not being able to run under systemd,
or under non-forking mode. Added test case to detect proper
operation.

Resolves #154

Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2018-05-11 22:04:28 +02:00
Nikos Mavrogiannopoulos
e1c3ed95b0 doc update [ci skip]
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2018-05-04 23:37:34 +02:00
Nikos Mavrogiannopoulos
094145bf54 configure: refuse to compile with known dependency issues
In particular require gnutls 3.5.5 which fixes cleanups in
gnutls_certificate_set_key(), or a recent version of
the 3.3.x branch. When forced to use a broken version work-around
issues (at the cost of a memory leak).

Resolves #152

Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2018-05-04 23:21:37 +02:00
Nikos Mavrogiannopoulos
66656388c6 bumped version
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2018-04-22 10:43:29 +02:00
Nikos Mavrogiannopoulos
d6332cd428 proc_table_update_ip: do not update IP if the previous IP is not found
That adds a safety net in case there is a mismatch of IPs, to prevent
adding two entries in the hashtable for the same IP.

Resolves #146

Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2018-04-02 23:04:39 +02:00
Nikos Mavrogiannopoulos
bd5ad4d7c3 doc update
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2018-04-01 13:31:59 +02:00
Nikos Mavrogiannopoulos
e09f54ea77 NEWS: document only entries which are not available in 0.11.x branch
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2018-03-22 08:46:26 +01:00
Nikos Mavrogiannopoulos
1aa3056849 doc update
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2018-03-21 12:55:04 +01:00
Nikos Mavrogiannopoulos
ecf9132495 doc update
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2018-03-06 20:42:33 +01:00
Nikos Mavrogiannopoulos
cc12fe7131 doc update
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2018-02-27 07:04:28 +01:00
Nikos Mavrogiannopoulos
5ebea1e475 doc update [ci skip]
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2018-02-22 19:59:12 +01:00
Nikos Mavrogiannopoulos
dbaecfa80e doc update
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2018-01-23 21:11:39 +01:00
Nikos Mavrogiannopoulos
8ebe287f1c doc update
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2018-01-17 20:50:54 +01:00
Nikos Mavrogiannopoulos
2559d68366 doc update
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2018-01-14 19:14:56 +01:00
Nikos Mavrogiannopoulos
f6a6f0bc34 bumped version
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2018-01-07 16:34:37 +01:00
Nikos Mavrogiannopoulos
4c4b60a5b6 doc update
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2018-01-07 11:43:37 +01:00
Nikos Mavrogiannopoulos
3bdd6bc7dc doc update
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2018-01-06 18:46:05 +01:00
Nikos Mavrogiannopoulos
8e3d89eca5 doc update [ci skip]
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2017-12-26 23:25:34 +01:00
Nikos Mavrogiannopoulos
97fb12de51 doc update
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2017-12-11 08:26:48 +01:00
Nikos Mavrogiannopoulos
289a250864 doc update
Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
2017-11-30 15:53:59 +01:00
Nikos Mavrogiannopoulos
b73c50ab2d doc update [ci skip]
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2017-10-21 19:59:26 +02:00
Nikos Mavrogiannopoulos
3d1598cfeb released 0.11.9
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2017-10-09 21:47:50 +02:00
Nikos Mavrogiannopoulos
edfff8d2b2 doc update
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2017-10-09 21:45:19 +02:00
Nikos Mavrogiannopoulos
4104160950 doc update
Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
2017-08-23 12:00:15 +02:00
Nikos Mavrogiannopoulos
aaf2c0265f doc update
Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
2017-08-23 11:59:53 +02:00
Nikos Mavrogiannopoulos
4fcea8ae06 doc update
Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
2017-08-23 09:19:01 +02:00
Nikos Mavrogiannopoulos
89ba65922a Avoid the use of the VERS-ALL priority string when gnutls < 3.3.24 is present
That priority string is only available on gnutls 3.3.24+ versions of gnutls.

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
2017-05-18 08:27:02 +02:00
Nikos Mavrogiannopoulos
954774d43e doc update
Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
2017-05-03 02:34:43 +02:00
Nikos Mavrogiannopoulos
a332788bd4 doc update
Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
2017-05-03 00:13:30 +02:00
Nikos Mavrogiannopoulos
373af80d60 doc update
Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
2017-04-28 17:20:29 +02:00
Nikos Mavrogiannopoulos
9dae1ecedc doc update
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2017-04-27 09:06:28 +02:00
Nikos Mavrogiannopoulos
03c81b190a doc update
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2017-04-23 19:09:39 +02:00
Nikos Mavrogiannopoulos
0d8ee5e6a9 config: increased the default max-ban-score to 8 wrong password attempts
This still prevents abuse, while allowing few more attempts than 5, which
are typically easily reached through software which remembers passwords.
At the same time increase the default ban time to 20 minutes.

Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2017-04-23 19:09:39 +02:00
Nikos Mavrogiannopoulos
5e7f416e72 doc update [ci skip]
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2017-04-14 17:24:23 +03:00
Nikos Mavrogiannopoulos
e135f8a54e doc update
Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
2017-04-14 16:39:00 +03:00
Nikos Mavrogiannopoulos
18fa25fea2 doc update
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2017-03-28 08:08:49 +02:00
Nikos Mavrogiannopoulos
fa00c52809 doc update 2017-03-20 09:28:01 +01:00
Nikos Mavrogiannopoulos
c1d86d5577 doc update
Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
2017-02-23 10:06:37 +01:00
Nikos Mavrogiannopoulos
d23215b584 bumped version 2017-02-12 10:19:02 +01:00
Nikos Mavrogiannopoulos
66f8b57af9 doc update 2017-01-29 15:54:54 +01:00