Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | somewhat improved plain tcp syslog reliability | Rainer Gerhards | 2008-06-09 | 5 | -1/+54 | |
| | | | | | | ...by doing a connection check before sending. Credits to Martin Schuette for providing the idea. Details are available at http://blog.gerhards.net/2008/06/reliable-plain-tcp-syslog-once-again.html | |||||
* | fixed a bug with the new property replacer option | Rainer Gerhards | 2008-06-07 | 1 | -1/+1 | |
| | | | | | there was a copy&paste error in the timereported property - thanks to Elizabeth for reporting it | |||||
* | added new property replacer option "time-subseconds" | Rainer Gerhards | 2008-06-06 | 4 | -1/+70 | |
| | | | | enables to query just the subsecond part of a high-precision timestamp | |||||
* | preparing 3.19.6v3.19.6 | Rainer Gerhards | 2008-06-06 | 1 | -1/+1 | |
| | ||||||
* | enhanced property replacer to support multiple regex matches | Rainer Gerhards | 2008-06-04 | 1 | -5/+28 | |
| | ||||||
* | bugfix: off-by-one bug during certificate check | Rainer Gerhards | 2008-06-04 | 1 | -2/+4 | |
| | ||||||
* | bugfix: part of permittedPeer structure was not correctly initialized | Rainer Gerhards | 2008-06-03 | 1 | -2/+1 | |
| | | | | thanks to varmojfekoj for spotting this | |||||
* | capability for replacement text in no match regex case added | Rainer Gerhards | 2008-05-30 | 1 | -13/+18 | |
| | | | | | | implemented in property replacer: if a regular expression does not match, it can now either return "**NO MATCH** (default, as before), a blank property or the full original property text | |||||
* | enhanced property replacer's regex to support submatches | Rainer Gerhards | 2008-05-29 | 1 | -7/+21 | |
| | | | | | | | - enabled Posix ERE expressions inside the property replacer (previously BRE was permitted only) - provided ability to specify that a regular expression submatch shall be used inside the property replacer | |||||
* | Merge branch 'ietf-tls' | Rainer Gerhards | 2008-05-27 | 7 | -57/+1088 | |
|\ | ||||||
| * | implemented wildcards inside certificate name check authentication | Rainer Gerhards | 2008-05-27 | 4 | -7/+311 | |
| | | ||||||
| * | client now provides cert even if it is not signed by one of the server's ↵ | Rainer Gerhards | 2008-05-27 | 3 | -10/+170 | |
| | | | | | | | | trusted CAs (gtls) | |||||
| * | protected gtls error string function by a mutex. | Rainer Gerhards | 2008-05-26 | 1 | -1/+7 | |
| | | | | | | | | | | Without it, we could have a race condition in extreme cases. This was very remote, but now can no longer happen. | |||||
| * | fixed fingerprint generator | Rainer Gerhards | 2008-05-26 | 1 | -2/+1 | |
| | | | | | | | | fixed problem introduced earlier today | |||||
| * | fixed wrong cert expiration date check | Rainer Gerhards | 2008-05-26 | 1 | -1/+1 | |
| | | ||||||
| * | added certificate validity date check (gtls) | Rainer Gerhards | 2008-05-26 | 2 | -10/+58 | |
| | | ||||||
| * | added gtls name authentication based on common name (inside DN) | Rainer Gerhards | 2008-05-26 | 2 | -7/+100 | |
| | | | | | | | | also changed fingerprint gtls auth mode to new format fingerprint | |||||
| * | added capability to auto-configure tls auth rule for client connecting to server | Rainer Gerhards | 2008-05-26 | 2 | -13/+52 | |
| | | | | | | | | must match hostname in send action | |||||
| * | improved gtls error reporting | Rainer Gerhards | 2008-05-26 | 1 | -2/+11 | |
| | | ||||||
| * | checking if client provided a cert and complain if not | Rainer Gerhards | 2008-05-23 | 1 | -1/+3 | |
| | | ||||||
| * | added x509/name authentication (so far based on dnsName only) | Rainer Gerhards | 2008-05-22 | 1 | -58/+137 | |
| | | ||||||
| * | added code to pull the subjectAltName - dNSName | Rainer Gerhards | 2008-05-21 | 2 | -3/+23 | |
| | | ||||||
| * | fixed invalid prototype | Rainer Gerhards | 2008-05-21 | 1 | -1/+1 | |
| | | ||||||
| * | implemented x509/certvalid "authentication" | Rainer Gerhards | 2008-05-21 | 4 | -4/+276 | |
| | | ||||||
* | | bugfix: sender information (fromhost et al) was missing in imudp | Rainer Gerhards | 2008-05-21 | 1 | -1/+1 | |
| | | | | | | | | thanks to sandiso for reporting this bug | |||||
* | | Merge branch 'ietf-tls' | Rainer Gerhards | 2008-05-21 | 12 | -23/+398 | |
|\| | | | | | | | | | | | Conflicts: ChangeLog | |||||
| * | re-enabled anon mode (failed if client did not provide cert) | Rainer Gerhards | 2008-05-21 | 1 | -3/+6 | |
| | | ||||||
| * | changed default GnuTLS key material to more reasonable values | Rainer Gerhards | 2008-05-20 | 1 | -1/+0 | |
| | | | | | | | | | | We now also provide everything to sign with a common CA. NOTE: none of this is for production use! | |||||
| * | first implementation of TLS server client authentication check | Rainer Gerhards | 2008-05-19 | 12 | -39/+209 | |
| | | | | | | | | | | | | | | The TLS server now checks the client fingerprint. This works, but is highly experimental. Needs to be refined for practice. Also: - implemented permittedPeers helper construct to store names - changed omfwd implementation to use new permittedPeers | |||||
| * | improved error messages and corrected fingerprint format | Rainer Gerhards | 2008-05-19 | 4 | -13/+32 | |
| | | ||||||
| * | regained netstream driver genericity; improved drivers | Rainer Gerhards | 2008-05-17 | 2 | -3/+47 | |
| | | | | | | | | | | | | | | | | | | - made action logic pass optional auth params only if they are actually configured - added new authMode and Fingerprint methods to ptcp netstream driver (keeping them once again generic) - added diagnostics messages when invalid auth modes were configured | |||||
| * | added first rough ability to authenticate the server against its certificate | Rainer Gerhards | 2008-05-16 | 6 | -5/+117 | |
| | | | | | | | | | | | | | | | | | | | | This is very experimental and needs some more work. It probably even segfaults - but the base code is there and running. The rest is refinement. While working on this, I did these two bugfixes: - bugfix: small mem leak in omfwd on exit (strmdriver name was not freed) - bugfix: $ActionSendStreamDriver had no effect | |||||
| * | Merge branch 'master' into ietf-tls | Rainer Gerhards | 2008-05-16 | 8 | -11/+70 | |
| |\ | ||||||
| * | | client provides x.509 and server prints fingerprint | Rainer Gerhards | 2008-05-15 | 2 | -6/+34 | |
| | | | ||||||
* | | | bugfix: missing linker options caused build to fail on some systems. | Tiziano Mueller | 2008-05-21 | 1 | -1/+1 | |
| |/ |/| | | | | | Signed-off-by: Rainer Gerhards <rgerhards@adiscon.com> | |||||
* | | fixed potential uninitialzed var access (highly improbable) | Rainer Gerhards | 2008-05-16 | 1 | -0/+2 | |
| | | ||||||
* | | Merge branch 'beta' | Rainer Gerhards | 2008-05-16 | 1 | -0/+2 | |
| | | | | | | | | | | | | | | Conflicts: ChangeLog rfc3195d.c | |||||
* | | added fromhost-ip properties and some bugfixes | Rainer Gerhards | 2008-05-16 | 6 | -11/+56 | |
| | | | | | | | | | | | | | | | | | | | | - bugfix: TCP input modules did incorrectly set fromhost property (always blank) - bugfix: imklog did not set fromhost property - added "fromhost-ip" property - added "RSYSLOG_DebugFormat" canned template - bugfix: hostname and fromhost were swapped when a persisted message (in queued mode) was read in | |||||
* | | added TODO item | Rainer Gerhards | 2008-05-15 | 1 | -1/+1 | |
| | | ||||||
* | | bugfix: TLS server went into an endless loop in some situations. | Rainer Gerhards | 2008-05-15 | 2 | -0/+10 | |
|/ | | | | Thanks to Michael Biebl for reporting the problem. | |||||
* | server's X509 cert fingerprint is obtained by client on connect | Rainer Gerhards | 2008-05-08 | 3 | -189/+50 | |
| | ||||||
* | added a bit of doc (at least something...) | Rainer Gerhards | 2008-05-08 | 3 | -1/+238 | |
| | ||||||
* | bugfix: gtls netstram driver did not specify threading model | Rainer Gerhards | 2008-05-08 | 1 | -3/+7 | |
| | | | | (could possibly lead to "interesting effects" ;)) | |||||
* | limited number of unavoidable compiler warnings when compiling with GnuTLS | Rainer Gerhards | 2008-05-07 | 1 | -2/+15 | |
| | ||||||
* | added missing includes (noticed under SuSe Linux) | Rainer Gerhards | 2008-05-06 | 2 | -0/+2 | |
| | ||||||
* | final touches for 3.19.0v3.19.0 | Rainer Gerhards | 2008-05-06 | 1 | -1/+0 | |
| | ||||||
* | Merge branch 'tls' | Rainer Gerhards | 2008-05-06 | 21 | -209/+550 | |
|\ | ||||||
| * | trying to remove compiler warnings | Rainer Gerhards | 2008-05-05 | 1 | -2/+2 | |
| | | ||||||
| * | support for different forwarding stream drivers added | Rainer Gerhards | 2008-05-05 | 3 | -3/+31 | |
| | | | | | | | | they can now be set on an action-by-action basis | |||||
| * | made default certificate file locations configurable | Rainer Gerhards | 2008-05-05 | 3 | -7/+87 | |
| | | | | | | | | | | | | - added $DefaultNetstreamDriverCAFile config directive - added $DefaultNetstreamDriverCertFile config directive - added $DefaultNetstreamDriverKeyFile config directive |