]> git.ipfire.org Git - thirdparty/gnutls.git/log
thirdparty/gnutls.git
8 years agotests: windows: warning: function declaration isn't a prototype
Alon Bar-Lev [Fri, 25 Aug 2017 21:16:03 +0000 (00:16 +0300)] 
tests: windows: warning: function declaration isn't a prototype

Signed-off-by: Alon Bar-Lev <alon.barlev@gmail.com>
8 years agotests: warning: implicit declaration of function
Alon Bar-Lev [Fri, 25 Aug 2017 20:45:44 +0000 (23:45 +0300)] 
tests: warning: implicit declaration of function

Signed-off-by: Alon Bar-Lev <alon.barlev@gmail.com>
8 years agom4: updated ax_code_coverage.m4 [ci skip]
Nikos Mavrogiannopoulos [Thu, 24 Aug 2017 15:03:17 +0000 (17:03 +0200)] 
m4: updated ax_code_coverage.m4 [ci skip]

This version fixes a bug which prevented including the branch coverage
into output.

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agofuzzer: Enhance code coverage of gnutls_base64_encoder_fuzzer
Tim Rühsen [Mon, 21 Aug 2017 13:19:25 +0000 (15:19 +0200)] 
fuzzer: Enhance code coverage of gnutls_base64_encoder_fuzzer

Signed-off-by: Tim Rühsen <tim.ruehsen@gmx.de>
8 years agofuzzer: Add script 'view-coverage'
Tim Rühsen [Mon, 21 Aug 2017 13:16:55 +0000 (15:16 +0200)] 
fuzzer: Add script 'view-coverage'

This helper script is for viewing the code coverage of
single (or combined) fuzzers running with all his corpora.

It helps optimizing the code coverage by hand-crafting corpora
and/or dictionaries.

Signed-off-by: Tim Rühsen <tim.ruehsen@gmx.de>
8 years agofuzzer: Change CFLAGS -O0 to -O1 in fuzz/README.md
Tim Rühsen [Mon, 21 Aug 2017 12:22:58 +0000 (14:22 +0200)] 
fuzzer: Change CFLAGS -O0 to -O1 in fuzz/README.md

Signed-off-by: Tim Rühsen <tim.ruehsen@gmx.de>
8 years agofuzzer: Update corpora from oss-fuzz
Tim Rühsen [Mon, 21 Aug 2017 12:20:54 +0000 (14:20 +0200)] 
fuzzer: Update corpora from oss-fuzz

Signed-off-by: Tim Rühsen <tim.ruehsen@gmx.de>
8 years agotlslite: updated to latest version
Nikos Mavrogiannopoulos [Thu, 24 Aug 2017 13:29:19 +0000 (15:29 +0200)] 
tlslite: updated to latest version

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agocerttool: do not ask about RSA encryption in non-RSA keys
Nikos Mavrogiannopoulos [Wed, 23 Aug 2017 08:20:05 +0000 (10:20 +0200)] 
certtool: do not ask about RSA encryption in non-RSA keys

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agofuzz: work-around libtool file name
Nikos Mavrogiannopoulos [Tue, 22 Aug 2017 14:17:54 +0000 (16:17 +0200)] 
fuzz: work-around libtool file name

fuzzers utilize argv[0] to discover the name the reproducers are stored
in. However libtool creates a script which later runs the executable.
Try to detect that situation and use the right paths.

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agodh params: document DH param setting functions as deprecated
Nikos Mavrogiannopoulos [Tue, 22 Aug 2017 06:48:03 +0000 (08:48 +0200)] 
dh params: document DH param setting functions as deprecated

They are no longer useful after the RFC7919 DH parameter negotiation.

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agotests: introduced unit test of gnutls_memset()
Nikos Mavrogiannopoulos [Tue, 15 Aug 2017 08:03:54 +0000 (10:03 +0200)] 
tests: introduced unit test of gnutls_memset()

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agofuzz: removed -static ldflag completely
Nikos Mavrogiannopoulos [Tue, 22 Aug 2017 05:27:03 +0000 (07:27 +0200)] 
fuzz: removed -static ldflag completely

It is not necessary for building the fuzzer, and was causing
issues in MacOSX systems.

Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
8 years ago.gitlab-ci.yml: use the same flags in the tags and non-tags windows builds gnutls_3_6_0_1
Nikos Mavrogiannopoulos [Mon, 21 Aug 2017 07:47:59 +0000 (09:47 +0200)] 
.gitlab-ci.yml: use the same flags in the tags and non-tags windows builds

Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
8 years agotests: p11-kit-trust is not compiled in windows
Nikos Mavrogiannopoulos [Mon, 21 Aug 2017 07:46:07 +0000 (09:46 +0200)] 
tests: p11-kit-trust is not compiled in windows

Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
8 years agofuzz: temporarily disable -static build of fuzz/ in MacOSX gnutls_3_6_0
Nikos Mavrogiannopoulos [Mon, 21 Aug 2017 06:35:07 +0000 (08:35 +0200)] 
fuzz: temporarily disable -static build of fuzz/ in MacOSX

This allows running the MacOSX CI tests on travis.

Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
8 years agodoc update
Nikos Mavrogiannopoulos [Mon, 21 Aug 2017 06:26:57 +0000 (08:26 +0200)] 
doc update

Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
8 years agotests: verify the output size of gnutls_x509_privkey_export
Nikos Mavrogiannopoulos [Mon, 21 Aug 2017 05:56:58 +0000 (07:56 +0200)] 
tests: verify the output size of gnutls_x509_privkey_export

That is, make sure that gnutls_x509_privkey_export() and
gnutls_x509_privkey_export2() agrees with the strlen()
value on the data.

Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
8 years ago.travis.yml: print failed log files in fuzz after failure
Nikos Mavrogiannopoulos [Sun, 20 Aug 2017 18:46:31 +0000 (20:46 +0200)] 
.travis.yml: print failed log files in fuzz after failure

Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
8 years agohooks.m4: reduce the gap between minor soversion of 3.5.x and 3.6.0
Nikos Mavrogiannopoulos [Sun, 20 Aug 2017 17:43:52 +0000 (19:43 +0200)] 
hooks.m4: reduce the gap between minor soversion of 3.5.x and 3.6.0

Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
8 years agotests: make mini-record more friendly for OSes with limited buffers
Nikos Mavrogiannopoulos [Sun, 20 Aug 2017 07:24:19 +0000 (09:24 +0200)] 
tests: make mini-record more friendly for OSes with limited buffers

Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
8 years agopull/push backends: ECONNRESET is translated to GNUTLS_E_PREMATURE_TERMINATION
Nikos Mavrogiannopoulos [Sun, 20 Aug 2017 07:18:05 +0000 (09:18 +0200)] 
pull/push backends: ECONNRESET is translated to GNUTLS_E_PREMATURE_TERMINATION

This returns a more reasonable error code on platforms where
this errno is set.

Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
8 years agotests: gnutls_x509_privkey_import: address issue on error path
Nikos Mavrogiannopoulos [Sun, 20 Aug 2017 07:05:02 +0000 (09:05 +0200)] 
tests: gnutls_x509_privkey_import: address issue on error path

Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
8 years agosed: use it in a portable way in makefiles
Nikos Mavrogiannopoulos [Sat, 19 Aug 2017 22:18:44 +0000 (00:18 +0200)] 
sed: use it in a portable way in makefiles

Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
8 years agoconfigure: disable hardware acceleration on aarch64/ilp32 mode
Nikos Mavrogiannopoulos [Sat, 19 Aug 2017 21:33:46 +0000 (23:33 +0200)] 
configure: disable hardware acceleration on aarch64/ilp32 mode

Our included assembly code for aarch64 is not suitable for that
data mode.

Resolves #252

Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
8 years agocreate_tls_random: avoid warning in fuzzying mode
Nikos Mavrogiannopoulos [Sat, 19 Aug 2017 11:39:28 +0000 (13:39 +0200)] 
create_tls_random: avoid warning in fuzzying mode

Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
8 years agoconfigure.ac: removed conditional FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION
Nikos Mavrogiannopoulos [Sat, 19 Aug 2017 06:58:37 +0000 (08:58 +0200)] 
configure.ac: removed conditional FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION

Instead rely only on the definition, to make fuzzying mode to be
enabled even if --enable-fuzzer-target is not specified, but defined
b the compiler.

Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
8 years agornd-fuzzer: use ifdef instead of conditional compilation
Nikos Mavrogiannopoulos [Sat, 19 Aug 2017 06:56:28 +0000 (08:56 +0200)] 
rnd-fuzzer: use ifdef instead of conditional compilation

This allows compiling in fuzzying mode even when --enable-fuzzer-target
is not specified on configure, but the definition is present.

Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
8 years agofuzzer: Update base64 fuzzers + corpora
Tim Rühsen [Fri, 18 Aug 2017 19:39:13 +0000 (21:39 +0200)] 
fuzzer: Update base64 fuzzers + corpora

Signed-off-by: Tim Rühsen <tim.ruehsen@gmx.de>
8 years agofuzzer: Fix include path in run-clang.sh [skip ci]
Tim Rühsen [Fri, 18 Aug 2017 19:32:28 +0000 (21:32 +0200)] 
fuzzer: Fix include path in run-clang.sh [skip ci]

Signed-off-by: Tim Rühsen <tim.ruehsen@gmx.de>
8 years agognutls_x509_privkey_export: use _gnutls_copy_string on PEM data
Nikos Mavrogiannopoulos [Fri, 18 Aug 2017 13:43:43 +0000 (15:43 +0200)] 
gnutls_x509_privkey_export: use _gnutls_copy_string on PEM data

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agoCorrected argument names of functions to correspond to declaration
Nikos Mavrogiannopoulos [Fri, 18 Aug 2017 11:05:34 +0000 (13:05 +0200)] 
Corrected argument names of functions to correspond to declaration

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agolib: use casts and be explicit on intentional enumeration use
Nikos Mavrogiannopoulos [Fri, 18 Aug 2017 10:57:07 +0000 (12:57 +0200)] 
lib: use casts and be explicit on intentional enumeration use

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agognutls-cli-debug: do not run non-FIPS cipher tests when in FIPS mode
Nikos Mavrogiannopoulos [Fri, 18 Aug 2017 11:56:04 +0000 (13:56 +0200)] 
gnutls-cli-debug: do not run non-FIPS cipher tests when in FIPS mode

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agodoc update
Nikos Mavrogiannopoulos [Fri, 18 Aug 2017 10:52:20 +0000 (12:52 +0200)] 
doc update

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agodoc update
Nikos Mavrogiannopoulos [Fri, 18 Aug 2017 10:47:12 +0000 (12:47 +0200)] 
doc update

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agotests: added basic test for the operation of gnutls-cli-debug
Nikos Mavrogiannopoulos [Fri, 18 Aug 2017 09:51:53 +0000 (11:51 +0200)] 
tests: added basic test for the operation of gnutls-cli-debug

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agotests: verify the presence of GNUTLS_SFLAGS_RFC7919 flag in server and client mode
Nikos Mavrogiannopoulos [Fri, 18 Aug 2017 09:44:55 +0000 (11:44 +0200)] 
tests: verify the presence of GNUTLS_SFLAGS_RFC7919 flag in server and client mode

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agognutls-cli-debug: check whether RFC7919 is supported
Nikos Mavrogiannopoulos [Fri, 18 Aug 2017 09:34:46 +0000 (11:34 +0200)] 
gnutls-cli-debug: check whether RFC7919 is supported

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agognutls_session_get_flags: introduced GNUTLS_SFLAGS_RFC7919
Nikos Mavrogiannopoulos [Fri, 18 Aug 2017 09:31:52 +0000 (11:31 +0200)] 
gnutls_session_get_flags: introduced GNUTLS_SFLAGS_RFC7919

This allows checking whether the DHE parameters used were negotiated
using RFC7919.

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agognutls_auth_*: check cs parameter for validity prior to use
Nikos Mavrogiannopoulos [Fri, 18 Aug 2017 09:22:11 +0000 (11:22 +0200)] 
gnutls_auth_*: check cs parameter for validity prior to use

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agocerttool: simplified certificate PEM printing
Nikos Mavrogiannopoulos [Fri, 18 Aug 2017 09:16:50 +0000 (11:16 +0200)] 
certtool: simplified certificate PEM printing

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agognutls-cli: fixed bounds check on benchmark-tls
Nikos Mavrogiannopoulos [Fri, 18 Aug 2017 09:14:16 +0000 (11:14 +0200)] 
gnutls-cli: fixed bounds check on benchmark-tls

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agolib: removed legacy debugging code
Nikos Mavrogiannopoulos [Fri, 18 Aug 2017 08:44:21 +0000 (10:44 +0200)] 
lib: removed legacy debugging code

That code was code from the initial versions of gnutls. It was neither
used nor updated for long time.

Relates #248

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agofuzz: added missing files into dist [ci skip]
Nikos Mavrogiannopoulos [Fri, 18 Aug 2017 08:35:03 +0000 (10:35 +0200)] 
fuzz: added missing files into dist [ci skip]

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agotests: added missing files in dist [ci skip]
Nikos Mavrogiannopoulos [Fri, 18 Aug 2017 08:06:36 +0000 (10:06 +0200)] 
tests: added missing files in dist [ci skip]

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agotests: do not suppress stderr errors on servers startup
Nikos Mavrogiannopoulos [Fri, 18 Aug 2017 08:05:36 +0000 (10:05 +0200)] 
tests: do not suppress stderr errors on servers startup

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agodoc update
Nikos Mavrogiannopoulos [Thu, 17 Aug 2017 15:41:34 +0000 (17:41 +0200)] 
doc update

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agoabi-check: added check for 3.6.0 ABI compatibility
Nikos Mavrogiannopoulos [Fri, 18 Aug 2017 06:39:50 +0000 (08:39 +0200)] 
abi-check: added check for 3.6.0 ABI compatibility

Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
8 years agognutls_x509_crl_get_issuer_dn: removed unnecessary const
Nikos Mavrogiannopoulos [Fri, 18 Aug 2017 06:38:48 +0000 (08:38 +0200)] 
gnutls_x509_crl_get_issuer_dn: removed unnecessary const

Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
8 years agocerttool: fixed documentation of sign-params
Nikos Mavrogiannopoulos [Thu, 17 Aug 2017 09:27:24 +0000 (11:27 +0200)] 
certtool: fixed documentation of sign-params

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agoREADME.md: mention lockfile-progs dependency
Nikos Mavrogiannopoulos [Thu, 17 Aug 2017 08:50:56 +0000 (10:50 +0200)] 
README.md: mention lockfile-progs dependency

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agotests: tls-neg-ext4-key: explicitly restrict to TLS 1.2, 1.1 and 1.0
Nikos Mavrogiannopoulos [Thu, 17 Aug 2017 08:02:47 +0000 (10:02 +0200)] 
tests: tls-neg-ext4-key: explicitly restrict to TLS 1.2, 1.1 and 1.0

This allows testing all signature types used in the protocol.

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agosign APIs: introduce RSA-RAW signing algorithm
Nikos Mavrogiannopoulos [Thu, 17 Aug 2017 07:59:53 +0000 (09:59 +0200)] 
sign APIs: introduce RSA-RAW signing algorithm

This ensures that there is a signing algorithm for all the operations
we support. Previously, we required GNUTLS_SIGN_UNKNOWN to be acceptable
by signing functions to accomodate for raw RSA operations. Now we make
that explicit and in the process clean-up the API.

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agoremoved devel/fuzz; functionality moved to fuzz/ [ci skip]
Nikos Mavrogiannopoulos [Thu, 17 Aug 2017 08:09:13 +0000 (10:09 +0200)] 
removed devel/fuzz; functionality moved to fuzz/ [ci skip]

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agofuzzer: Add 'make -C fuzz coverage' [ci skip]
Tim Rühsen [Fri, 11 Aug 2017 19:42:02 +0000 (21:42 +0200)] 
fuzzer: Add 'make -C fuzz coverage' [ci skip]

This reports how much code is covered by fuzzing.

Signed-off-by: Tim Rühsen <tim.ruehsen@gmx.de>
8 years ago_gnutls_recv_server_certificate_status: use the same type in subtracted values
Nikos Mavrogiannopoulos [Mon, 14 Aug 2017 06:46:03 +0000 (08:46 +0200)] 
_gnutls_recv_server_certificate_status: use the same type in subtracted values

This ensures that there are no issues with subtracting those values.
Note that the second is read from an uint24_t and thus it is always
positive regardless its type.

Resolves #245

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years ago_gnutls_proc_srp_client_kx: use same type in subtracted values
Nikos Mavrogiannopoulos [Mon, 14 Aug 2017 06:42:51 +0000 (08:42 +0200)] 
_gnutls_proc_srp_client_kx: use same type in subtracted values

This ensures that there are no issues with subtracting those values.
Note that the second is read from an uint16_t and thus it is always
positive regardless its type.

Resolves #244

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agofuzzer: Move regression corpora from tests/ to fuzz/
Tim Rühsen [Tue, 15 Aug 2017 10:34:25 +0000 (12:34 +0200)] 
fuzzer: Move regression corpora from tests/ to fuzz/

See fuzz/README.md for the corresponding paths.

Signed-off-by: Tim Rühsen <tim.ruehsen@gmx.de>
8 years agofuzzer: Suppress leak in libgmp <= 6.1.2
Tim Rühsen [Mon, 14 Aug 2017 10:34:00 +0000 (12:34 +0200)] 
fuzzer: Suppress leak in libgmp <= 6.1.2

Signed-off-by: Tim Rühsen <tim.ruehsen@gmx.de>
8 years agofuzzer: Suppress unsigned integer overflow in rnd-fuzzer.c
Tim Rühsen [Fri, 11 Aug 2017 16:31:35 +0000 (18:31 +0200)] 
fuzzer: Suppress unsigned integer overflow in rnd-fuzzer.c

Signed-off-by: Tim Rühsen <tim.ruehsen@gmx.de>
8 years agofuzzer: Initial check in for improved fuzzing
Tim Rühsen [Sat, 5 Aug 2017 18:49:19 +0000 (20:49 +0200)] 
fuzzer: Initial check in for improved fuzzing

Signed-off-by: Tim Rühsen <tim.ruehsen@gmx.de>
8 years agofuzzer: added a fuzzer target
Nikos Mavrogiannopoulos [Wed, 9 Aug 2017 06:24:59 +0000 (08:24 +0200)] 
fuzzer: added a fuzzer target

This allows to compile the library with flags which will add predictable
random generation and eliminate some crypto checks, in order for the
library to be used for testing (fuzzying).

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agoupdated auto-generated files
Nikos Mavrogiannopoulos [Tue, 15 Aug 2017 14:40:41 +0000 (16:40 +0200)] 
updated auto-generated files

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agognutls_x509_privkey_export: made a wrapper over gnutls_x509_privkey_export2()
Nikos Mavrogiannopoulos [Tue, 15 Aug 2017 14:39:36 +0000 (16:39 +0200)] 
gnutls_x509_privkey_export: made a wrapper over gnutls_x509_privkey_export2()

In addition, improved function description.

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agognutls-http-serv: use RSA-PSS key
Nikos Mavrogiannopoulos [Tue, 15 Aug 2017 11:23:39 +0000 (13:23 +0200)] 
gnutls-http-serv: use RSA-PSS key

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agodoc update
Nikos Mavrogiannopoulos [Tue, 15 Aug 2017 11:11:03 +0000 (13:11 +0200)] 
doc update

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agotests: use certtool to check RSA-PSS to RSA conversion
Nikos Mavrogiannopoulos [Tue, 15 Aug 2017 10:58:02 +0000 (12:58 +0200)] 
tests: use certtool to check RSA-PSS to RSA conversion

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agocerttool: introduced --to-rsa option
Nikos Mavrogiannopoulos [Tue, 15 Aug 2017 10:07:01 +0000 (12:07 +0200)] 
certtool: introduced --to-rsa option

This allows converting an RSA-PSS key to raw RSA.

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agodoc update
Nikos Mavrogiannopoulos [Fri, 11 Aug 2017 14:37:21 +0000 (16:37 +0200)] 
doc update

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agoupdated auto-generated files
Nikos Mavrogiannopoulos [Fri, 11 Aug 2017 10:30:17 +0000 (12:30 +0200)] 
updated auto-generated files

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agotests: added unit tests for gnutls_privkey_import_ext4
Nikos Mavrogiannopoulos [Fri, 4 Aug 2017 13:51:34 +0000 (15:51 +0200)] 
tests: added unit tests for gnutls_privkey_import_ext4

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agognutls_privkey_import_ext4: introduced to allow signing with RSA-PSS or Ed25519 keys
Nikos Mavrogiannopoulos [Fri, 4 Aug 2017 13:00:46 +0000 (15:00 +0200)] 
gnutls_privkey_import_ext4: introduced to allow signing with RSA-PSS or Ed25519 keys

That function allows a signing callback which passes the signature
algorithm, providing all the information to callback for signing.
It also introduces GNUTLS_PRIVKEY_INFO_HAVE_SIGN_ALGO flag which
allows the library to query the private key of the supported
signature algorithms.

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agoreduce common asserts to assist in debugging the library
Nikos Mavrogiannopoulos [Tue, 15 Aug 2017 08:47:11 +0000 (10:47 +0200)] 
reduce common asserts to assist in debugging the library

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agodoc: algorithms.texi: include list of groups but skip compression methods
Nikos Mavrogiannopoulos [Tue, 15 Aug 2017 08:29:42 +0000 (10:29 +0200)] 
doc: algorithms.texi: include list of groups but skip compression methods

Compression methods are no longer relevant or supported, and groups
replace the elliptic curves.

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agodoc: improved elliptic curve and group documentation
Nikos Mavrogiannopoulos [Tue, 15 Aug 2017 08:27:19 +0000 (10:27 +0200)] 
doc: improved elliptic curve and group documentation

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
8 years agodoc: mention the AES-DRBG random generator [ci skip]
Nikos Mavrogiannopoulos [Mon, 14 Aug 2017 17:02:45 +0000 (19:02 +0200)] 
doc: mention the AES-DRBG random generator [ci skip]

Signed-off-by: Nikos Mavrogiannopoulos <nmav@gnutls.org>
9 years agotests: improved detection of 64-bit systems
Nikos Mavrogiannopoulos [Fri, 11 Aug 2017 10:40:14 +0000 (12:40 +0200)] 
tests: improved detection of 64-bit systems

We now use the ${ac_cv_sizeof_unsigned_long_int} variable which
gives the numbers used in the host system, not the build one.

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
9 years agotests: updated for new x86 host
Nikos Mavrogiannopoulos [Thu, 10 Aug 2017 08:51:26 +0000 (10:51 +0200)] 
tests: updated for new x86 host

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
9 years ago.gitlab-ci.yml: replaced the f23 x86 build with a f26 x86 build
Nikos Mavrogiannopoulos [Thu, 10 Aug 2017 07:37:07 +0000 (09:37 +0200)] 
.gitlab-ci.yml: replaced the f23 x86 build with a f26 x86 build

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
9 years agofuzz: explicitly initialize and deinitialize the library [ci skip]
Nikos Mavrogiannopoulos [Fri, 11 Aug 2017 09:09:39 +0000 (11:09 +0200)] 
fuzz: explicitly initialize and deinitialize the library [ci skip]

This enables the fuzzers to run even when statically linked.

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
9 years agohandshake: eliminated unnecessary function wrappers
Nikos Mavrogiannopoulos [Tue, 18 Jul 2017 11:08:31 +0000 (13:08 +0200)] 
handshake: eliminated unnecessary function wrappers

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
9 years agognutls_int.h: reduce memory occupied by ext_data
Nikos Mavrogiannopoulos [Tue, 18 Jul 2017 08:35:13 +0000 (10:35 +0200)] 
gnutls_int.h: reduce memory occupied by ext_data

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
9 years agognutls_int.h: reduced the maximum number of epoch states we keep
Nikos Mavrogiannopoulos [Tue, 18 Jul 2017 08:25:10 +0000 (10:25 +0200)] 
gnutls_int.h: reduced the maximum number of epoch states we keep

There was no need to keep 16 epochs, as we typically we have only
one or two active.

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
9 years agognutls_int.h: removed unused variable from state
Nikos Mavrogiannopoulos [Tue, 18 Jul 2017 08:14:11 +0000 (10:14 +0200)] 
gnutls_int.h: removed unused variable from state

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
9 years agoextensions: simplified requirements from send callback
Nikos Mavrogiannopoulos [Fri, 14 Jul 2017 09:30:51 +0000 (11:30 +0200)] 
extensions: simplified requirements from send callback

The callback no longer needs to return the number of sent data;
they are now calculated by the caller.

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
9 years agoext/ecc: renamed Supported curves extension
Nikos Mavrogiannopoulos [Tue, 27 Jun 2017 09:42:25 +0000 (11:42 +0200)] 
ext/ecc: renamed Supported curves extension

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
9 years agognutls-serv: --require-client-cert no longer implies --verify-client-cert
Nikos Mavrogiannopoulos [Tue, 27 Jun 2017 09:01:08 +0000 (11:01 +0200)] 
gnutls-serv: --require-client-cert no longer implies --verify-client-cert

That is, it is now possible to require a client certificate without
verifying it.

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
9 years agoCONTRIBUTING.md: corrected typo [ci skip]
Nikos Mavrogiannopoulos [Thu, 10 Aug 2017 08:35:22 +0000 (10:35 +0200)] 
CONTRIBUTING.md: corrected typo [ci skip]

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
9 years agodoc update
Nikos Mavrogiannopoulos [Wed, 9 Aug 2017 14:59:15 +0000 (16:59 +0200)] 
doc update

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
9 years agoupdated auto-generated files
Nikos Mavrogiannopoulos [Wed, 9 Aug 2017 08:30:04 +0000 (10:30 +0200)] 
updated auto-generated files

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
9 years agoCONTRIBUTING.md: added section on symbol versioning
Nikos Mavrogiannopoulos [Wed, 9 Aug 2017 07:40:03 +0000 (09:40 +0200)] 
CONTRIBUTING.md: added section on symbol versioning

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
9 years agolibgnutls.map: separated symbols introduced in 3.6.0
Nikos Mavrogiannopoulos [Fri, 4 Aug 2017 09:06:18 +0000 (11:06 +0200)] 
libgnutls.map: separated symbols introduced in 3.6.0

This separation assists tools like rpm which can detect
the right version of the library to use, by using the
symbol version.

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
9 years agotests: added reproducer for private key import leak
Nikos Mavrogiannopoulos [Wed, 9 Aug 2017 08:21:06 +0000 (10:21 +0200)] 
tests: added reproducer for private key import leak

Issue found using oss-fuzz:
  https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=561

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
9 years agornd: use time_t for prng_reseed_time
Nikos Mavrogiannopoulos [Wed, 9 Aug 2017 11:18:33 +0000 (13:18 +0200)] 
rnd: use time_t for prng_reseed_time

This ensures that all time comparisons are done
under the same type.

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
9 years agognutls_x509_privkey_import_pkcs8: fixed memory leak on incorrect key import
Nikos Mavrogiannopoulos [Wed, 9 Aug 2017 08:20:36 +0000 (10:20 +0200)] 
gnutls_x509_privkey_import_pkcs8: fixed memory leak on incorrect key import

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
9 years agotests: added reproducer for memory leak in SRP server
Nikos Mavrogiannopoulos [Wed, 9 Aug 2017 07:58:17 +0000 (09:58 +0200)] 
tests: added reproducer for memory leak in SRP server

Issue found using oss-fuzz:
  https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=2859

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
9 years agognutls_srp_verifier: corrected memory leak
Nikos Mavrogiannopoulos [Wed, 9 Aug 2017 07:57:49 +0000 (09:57 +0200)] 
gnutls_srp_verifier: corrected memory leak

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
9 years agotests: added reproducer for memory leak in RSA-PSK
Nikos Mavrogiannopoulos [Wed, 9 Aug 2017 07:52:37 +0000 (09:52 +0200)] 
tests: added reproducer for memory leak in RSA-PSK

Issue found using oss-fuzz:
  https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=2863

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>
9 years agorsa-psk: corrected memory leak on invalid decrypt
Nikos Mavrogiannopoulos [Wed, 9 Aug 2017 07:52:21 +0000 (09:52 +0200)] 
rsa-psk: corrected memory leak on invalid decrypt

Signed-off-by: Nikos Mavrogiannopoulos <nmav@redhat.com>