Commit message (Collapse) | Author | Age | |
---|---|---|---|
* | Avoid requesting certificate from client when we already have it. Patch by ↵ | Nikos Mavrogiannopoulos | 2009-06-30 |
| | | | | AlainKnaff. | ||
* | Applied patch by AlainKnaff to correctly verify certificates per directory. ↵ | Nikos Mavrogiannopoulos | 2009-06-30 |
| | | | | | | | Patch by AlainKnaff. Solves: http://issues.outoforder.cc/view.php?id=93 | ||
* | set srp username to empty string. Solves ↵ | Nikos Mavrogiannopoulos | 2009-06-30 |
| | | | | http://issues.outoforder.cc/view.php?id=92 | ||
* | Try to avoid bug http://issues.outoforder.cc/view.php?id=102 | Nikos Mavrogiannopoulos | 2009-06-30 |
| | |||
* | Allow openpgp certificates that have infinite expiration time. Suggestion by ↵ | Nikos Mavrogiannopoulos | 2009-06-30 |
| | | | | MattLoar at http://issues.outoforder.cc/view.php?id=96. | ||
* | Applied patch to allow building with Apache 2.4. Patch by Arfrever Frehtes ↵ | Nikos Mavrogiannopoulos | 2009-06-30 |
| | | | | Taifersar Arahesis <arfrever.fta@gmail.com>. | ||
* | do not try to send empty packs using TLS. This this has a special meaning ↵ | Nikos Mavrogiannopoulos | 2009-06-13 |
| | | | | and could result in clients closing connections. | ||
* | if private key import fails try as pkcs8 key. | Nikos Mavrogiannopoulos | 2009-05-21 |
| | |||
* | removed limit on ca certificates' number | Nikos Mavrogiannopoulos | 2009-01-24 |
| | |||
* | Added patch to fix issue with mod_proxy. Investigation and patch by Alain Knaff. | Nikos Mavrogiannopoulos | 2009-01-04 |
| | | | | | | | | | | | | | It seems that the reason for this behavior is that the mgs_hook_pre_connection is being called both for incoming and outgoing (mod_proxy) connections. The attached patch (mod_proxy.patch) tries to find out in which case we are, and returns OK without doing anything if it is an outgoing connection. The method of telling both cases apart (namely, checking whether remote address' hostname is set) may seem somewhat hackish, but it does work, even if HostnameLookups is set to On. If ever there is a problem with this method, we might need to check local port instead (whether it is 443), but that would break if a non-standard https port was used. | ||
* | APLOG_EMERG was replaced with APLOG_STARTUP for startup messages. | Nikos Mavrogiannopoulos | 2008-11-02 |
| | |||
* | increased max handshake tries | Nikos Mavrogiannopoulos | 2008-10-16 |
| | |||
* | Allow openpgp-only sites | Nikos Mavrogiannopoulos | 2008-10-01 |
| | |||
* | better logging | Nikos Mavrogiannopoulos | 2008-10-01 |
| | |||
* | updated README file to account for openpgp keys --patch by Jack Bates | Nikos Mavrogiannopoulos | 2008-10-01 |
| | |||
* | use memmove instead of memcpy because buffers might overlap. | Nikos Mavrogiannopoulos | 2008-09-14 |
| | |||
* | added check for invalid context | Nikos Mavrogiannopoulos | 2008-09-14 |
| | |||
* | depend on main libgnutls library (and gnutls 2.4.x) | Nikos Mavrogiannopoulos | 2008-06-29 |
| | |||
* | send database store failure as DEBUG | Nikos Mavrogiannopoulos | 2008-03-05 |
| | |||
* | corrected SRP enable flag, and corrected the DBM hook support. It now free ↵ | Nikos Mavrogiannopoulos | 2008-03-03 |
| | | | | data needed by some DBM providers. | ||
* | added option to disable srp (for distributions that disable it in gnutls) | Nikos Mavrogiannopoulos | 2008-02-20 |
| | |||
* | prepare for an alpha release | Nikos Mavrogiannopoulos | 2008-01-24 |
| | |||
* | (no commit message) | Nikos Mavrogiannopoulos | 2007-12-16 |
| | |||
* | more changes for openpgp support. Seems to be at a workable state. | Nikos Mavrogiannopoulos | 2007-12-16 |
| | |||
* | print error if preconfiguration fails | Nikos Mavrogiannopoulos | 2007-12-15 |
| | |||
* | Initial support for openpgp keys | Nikos Mavrogiannopoulos | 2007-12-15 |
| | |||
* | (no commit message) | Nikos Mavrogiannopoulos | 2007-12-10 |
| | |||
* | (no commit message) | Nikos Mavrogiannopoulos | 2007-12-10 |
| | |||
* | (no commit message) | Nikos Mavrogiannopoulos | 2007-12-09 |
| | |||
* | Do not allow resuming sessions on different servers. | Nikos Mavrogiannopoulos | 2007-12-09 |
| | |||
* | Corrected bug which did not allow the TLS session cache to be used. | Nikos Mavrogiannopoulos | 2007-12-09 |
| | |||
* | Added support for sending more than one certificate. | Nikos Mavrogiannopoulos | 2007-12-08 |
| | |||
* | added more error checks. | Nikos Mavrogiannopoulos | 2007-12-03 |
| | |||
* | better handling of RSAFile and DHFile | Nikos Mavrogiannopoulos | 2007-12-03 |
| | |||
* | report the missing GnuTLSPriorities for the gnutls enabled hosts only. | Nikos Mavrogiannopoulos | 2007-12-02 |
| | |||
* | No more defaults for dhparams, rsaparams. Check for GnuTLSPriorities. | Nikos Mavrogiannopoulos | 2007-12-02 |
| | |||
* | The compatibility mode can now be enabled only using the GnuTLSPriorities ↵ | Nikos Mavrogiannopoulos | 2007-12-02 |
| | | | | string. | ||
* | (no commit message) | Nikos Mavrogiannopoulos | 2007-12-02 |
| | |||
* | added SSL_SERVER/CLIENT_S_TYPE | Nikos Mavrogiannopoulos | 2007-12-02 |
| | |||
* | export the alternative names of the certificate | Nikos Mavrogiannopoulos | 2007-12-02 |
| | |||
* | added SSL_SERVER_M_SERIAL environment variable | Nikos Mavrogiannopoulos | 2007-12-02 |
| | |||
* | more fixes for subject alternative name. | Nikos Mavrogiannopoulos | 2007-12-02 |
| | |||
* | some fixes in alternative name support | Nikos Mavrogiannopoulos | 2007-12-02 |
| | |||
* | Added support for subject alternative names. (untested) | Nikos Mavrogiannopoulos | 2007-12-01 |
| | |||
* | upgraded to 0.4.0 | Nikos Mavrogiannopoulos | 2007-11-28 |
| | |||
* | Put a limit on the number of times we try to handshake. | Paul Querna | 2005-09-25 |
| | |||
* | start the CA Certificate code. | Paul Querna | 2005-05-24 |
| | |||
* | - add lua to do client verification | Paul Querna | 2005-05-17 |
| | | | | | - only use gcrypt locking when required to | ||
* | Refactor finding the correct server record to fix resumed sessions.0.2.00.2.x | Paul Querna | 2005-04-25 |
| | |||
* | apr_table_setn doesn't copy the data. oops. | Paul Querna | 2005-04-24 |
| |