Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
| * | | | implemented wildcards inside certificate name check authentication | Rainer Gerhards | 2008-05-27 | 4 | -7/+311 | |
| | | | | ||||||
| * | | | client now provides cert even if it is not signed by one of the server's ↵ | Rainer Gerhards | 2008-05-27 | 3 | -10/+170 | |
| | | | | | | | | | | | | | | | | trusted CAs (gtls) | |||||
| * | | | protected gtls error string function by a mutex. | Rainer Gerhards | 2008-05-26 | 2 | -1/+10 | |
| | | | | | | | | | | | | | | | | | | | | Without it, we could have a race condition in extreme cases. This was very remote, but now can no longer happen. | |||||
| * | | | fixed fingerprint generator | Rainer Gerhards | 2008-05-26 | 1 | -2/+1 | |
| | | | | | | | | | | | | | | | | fixed problem introduced earlier today | |||||
| * | | | fixed wrong cert expiration date check | Rainer Gerhards | 2008-05-26 | 1 | -1/+1 | |
| | | | | ||||||
| * | | | added certificate validity date check (gtls) | Rainer Gerhards | 2008-05-26 | 2 | -10/+58 | |
| | | | | ||||||
| * | | | added gtls name authentication based on common name (inside DN) | Rainer Gerhards | 2008-05-26 | 3 | -7/+101 | |
| | | | | | | | | | | | | | | | | also changed fingerprint gtls auth mode to new format fingerprint | |||||
| * | | | added capability to auto-configure tls auth rule for client connecting to server | Rainer Gerhards | 2008-05-26 | 2 | -13/+52 | |
| | | | | | | | | | | | | | | | | must match hostname in send action | |||||
| * | | | improved gtls error reporting | Rainer Gerhards | 2008-05-26 | 2 | -7/+26 | |
| | | | | ||||||
| * | | | checking if client provided a cert and complain if not | Rainer Gerhards | 2008-05-23 | 1 | -1/+3 | |
| | | | | ||||||
| * | | | updated TLS documentation with HOWTO on certificate generation | Rainer Gerhards | 2008-05-23 | 1 | -11/+113 | |
| | | | | ||||||
| * | | | changed config directive name to reflect different use | Rainer Gerhards | 2008-05-22 | 3 | -25/+23 | |
| | | | | | | | | | | | | | | | | | | | | | | | | $ActionSendStreamDriverCertFingerprint is now $ActionSendStreamDriverPermittedPeer and can be used both for fingerprint and name authentication (similar to the input side) | |||||
| * | | | added x509/name authentication (so far based on dnsName only) | Rainer Gerhards | 2008-05-22 | 1 | -58/+137 | |
| | | | | ||||||
| * | | | added code to pull the subjectAltName - dNSName | Rainer Gerhards | 2008-05-21 | 2 | -3/+23 | |
| | | | | ||||||
| * | | | fixed invalid prototype | Rainer Gerhards | 2008-05-21 | 1 | -1/+1 | |
| | | | | ||||||
| * | | | implemented x509/certvalid "authentication" | Rainer Gerhards | 2008-05-21 | 5 | -7/+286 | |
| | | | | ||||||
* | | | | bugfix: sender information (fromhost et al) was missing in imudp | Rainer Gerhards | 2008-05-21 | 2 | -1/+3 | |
| | | | | | | | | | | | | | | | | thanks to sandiso for reporting this bug | |||||
* | | | | Merge branch 'beta' | Rainer Gerhards | 2008-05-21 | 2 | -1/+5 | |
|\ \ \ \ | | |/ / | |/| | | | | | | | | | | | | | | Conflicts: ChangeLog | |||||
| * | | | bugfix: imklog went into an endless loop if a PRI value was inside | Rainer Gerhards | 2008-05-21 | 2 | -1/+6 | |
| | | | | | | | | | | | | | | | | | | | | | | | | a kernel log message This is an unusual case under Linux, and a frequent one under BSD | |||||
* | | | | bumping version number | Rainer Gerhards | 2008-05-21 | 3 | -2/+4 | |
| | | | | ||||||
* | | | | finalizing v3.19.3v3.19.3 | Rainer Gerhards | 2008-05-21 | 2 | -2/+2 | |
| | | | | ||||||
* | | | | Merge branch 'ietf-tls' | Rainer Gerhards | 2008-05-21 | 26 | -112/+742 | |
|\ \ \ \ | | |/ / | |/| | | | | | | | | | | | | | | Conflicts: ChangeLog | |||||
| * | | | added some forgotten doc | Rainer Gerhards | 2008-05-21 | 2 | -12/+27 | |
| | | | | ||||||
| * | | | added new transport auth methods to doc set | Rainer Gerhards | 2008-05-21 | 5 | -9/+86 | |
| | | | | ||||||
| * | | | re-enabled anon mode (failed if client did not provide cert) | Rainer Gerhards | 2008-05-21 | 2 | -4/+7 | |
| | | | | ||||||
| * | | | changed default GnuTLS key material to more reasonable values | Rainer Gerhards | 2008-05-20 | 5 | -57/+55 | |
| | | | | | | | | | | | | | | | | | | | | We now also provide everything to sign with a common CA. NOTE: none of this is for production use! | |||||
| * | | | first implementation of TLS server client authentication check | Rainer Gerhards | 2008-05-19 | 16 | -58/+347 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | The TLS server now checks the client fingerprint. This works, but is highly experimental. Needs to be refined for practice. Also: - implemented permittedPeers helper construct to store names - changed omfwd implementation to use new permittedPeers | |||||
| * | | | improved error messages and corrected fingerprint format | Rainer Gerhards | 2008-05-19 | 4 | -13/+32 | |
| | | | | ||||||
| * | | | regained netstream driver genericity; improved drivers | Rainer Gerhards | 2008-05-17 | 3 | -6/+56 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | - made action logic pass optional auth params only if they are actually configured - added new authMode and Fingerprint methods to ptcp netstream driver (keeping them once again generic) - added diagnostics messages when invalid auth modes were configured | |||||
| * | | | added first rough ability to authenticate the server against its certificate | Rainer Gerhards | 2008-05-16 | 8 | -23/+174 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is very experimental and needs some more work. It probably even segfaults - but the base code is there and running. The rest is refinement. While working on this, I did these two bugfixes: - bugfix: small mem leak in omfwd on exit (strmdriver name was not freed) - bugfix: $ActionSendStreamDriver had no effect | |||||
| * | | | Merge branch 'master' into ietf-tls | Rainer Gerhards | 2008-05-16 | 30 | -81/+257 | |
| |\ \ \ | ||||||
| * | | | | client provides x.509 and server prints fingerprint | Rainer Gerhards | 2008-05-15 | 2 | -6/+34 | |
| | | | | | ||||||
* | | | | | bugfix: missing linker options caused build to fail on some systems. | Tiziano Mueller | 2008-05-21 | 2 | -1/+3 | |
| | | | | | | | | | | | | | | | | | | | | Signed-off-by: Rainer Gerhards <rgerhards@adiscon.com> | |||||
* | | | | | bugfix: default syslog port was no longer used if none was configured. | varmojfekoj | 2008-05-21 | 2 | -1/+3 | |
| | | | | | | | | | | | | | | | | | | | | Signed-off-by: Rainer Gerhards <rgerhards@adiscon.com> | |||||
* | | | | | added some more info to project status page | Rainer Gerhards | 2008-05-16 | 1 | -5/+5 | |
| |/ / / |/| | | | ||||||
* | | | | bumped version number | Rainer Gerhards | 2008-05-16 | 2 | -1/+3 | |
| | | | | ||||||
* | | | | removed references to deleted filesv3.19.2 | Rainer Gerhards | 2008-05-16 | 1 | -4/+0 | |
| | | | | ||||||
* | | | | fixed potential uninitialzed var access (highly improbable) | Rainer Gerhards | 2008-05-16 | 1 | -0/+2 | |
| | | | | ||||||
* | | | | preparing for 3.19.2 | Rainer Gerhards | 2008-05-16 | 3 | -19/+50 | |
| | | | | ||||||
* | | | | Merge branch 'beta' | Rainer Gerhards | 2008-05-16 | 3 | -3/+23 | |
|\ \ \ \ | | |/ / | |/| | | | | | | | | | | | | | | | | | | Conflicts: ChangeLog rfc3195d.c | |||||
| * | | | Merge branch 'v3-stable' into beta | Rainer Gerhards | 2008-05-16 | 6 | -8/+28 | |
| |\ \ \ | | | |/ | | |/| | ||||||
| | * | | Merge branch 'v2-stable' into v3-stable | Rainer Gerhards | 2008-05-15 | 2 | -3/+13 | |
| | |\ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Conflicts: ChangeLog configure.ac | |||||
| | | * | | bumped version number | Rainer Gerhards | 2008-05-15 | 2 | -1/+3 | |
| | | | | | ||||||
| | | * | | finalizing 2.0.5 releasev2.0.5 | Rainer Gerhards | 2008-05-15 | 1 | -1/+1 | |
| | | | | | ||||||
| | | * | | updated ChangeLog (forgotten...) | Rainer Gerhards | 2008-05-07 | 1 | -0/+1 | |
| | | | | | ||||||
| | | * | | support for liblogging 0.7.1+ added | Rainer Gerhards | 2008-05-07 | 1 | -3/+3 | |
| | | | | | ||||||
| | * | | | bugfix: some whitespaces where incorrectly not ignored | Rainer Gerhards | 2008-05-14 | 3 | -0/+6 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | when parsing the config file. This is now corrected. Thanks to Michael Biebl for pointing out the problem. | |||||
| | * | | | fixed potential segfault due to invalid call to cfsysline | varmojfekoj | 2008-05-14 | 3 | -5/+9 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | thanks to varmojfekoj for the patch Signed-off-by: Rainer Gerhards <rgerhards@adiscon.com> | |||||
| * | | | | preparigng for 3.17.2 releasev3.17.2 | Rainer Gerhards | 2008-05-04 | 1 | -2/+2 | |
| | | | | | ||||||
* | | | | | added fromhost-ip properties and some bugfixes | Rainer Gerhards | 2008-05-16 | 19 | -32/+149 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | - bugfix: TCP input modules did incorrectly set fromhost property (always blank) - bugfix: imklog did not set fromhost property - added "fromhost-ip" property - added "RSYSLOG_DebugFormat" canned template - bugfix: hostname and fromhost were swapped when a persisted message (in queued mode) was read in |