318ad7f355
Version set to 1.0-alpha10
1.0-alpha10
2016-08-23 14:53:27 +02:00
ef2042253c
When server certificate has no subjectAltName(2), compare host name against Common Name
2016-08-23 14:29:47 +02:00
9b997408a1
Switched to Schannel to do the TLS
2016-08-23 13:53:23 +02:00
5720524abe
Version set to 1.0-alpha9
1.0-alpha9
2016-08-18 06:33:02 +02:00
1f1b9b1084
GUI boots with a predefined configuration on new profiles now
...
(closes #10 )
2016-08-18 06:31:16 +02:00
076c6b77d7
GUI updated to show "<Your Provider>" when provider ID is blank
2016-08-18 06:30:02 +02:00
92460c571f
Initial focus changed to the first non-mouse-wheel-capturing control to allow initial scrolling of the configuration dialog using mouse wheel
2016-08-17 16:42:19 +02:00
b79a2f26f6
Support for read-only lock added to GUI
2016-08-17 16:27:43 +02:00
373c83dbbe
Provider identity and help-desk is configurable via GUI now
2016-08-17 15:56:11 +02:00
543dada025
Provider and method lists are arrays now, to allow random access for configuration dialog coming-up
2016-08-17 14:47:15 +02:00
ce22ec3bfa
wxEAPCredentialsPanelPassBase >> wxEAPCredentialsPassPanelBase
2016-08-17 13:48:14 +02:00
a04647b7b5
Version set to 1.0-alpha8
1.0-alpha8
2016-08-17 11:51:36 +02:00
df1d431bd0
- TLS revised (again)
...
- TLS Session resumption issues resolved
- Credential prompt has "Remember" checkbox initially selected when credentials originate from Windows Credential Manager
- Last authentication attempt failure notice is more general and no longer insinuate user credentials are the likely cause of the failure
- Additional log messages added
2016-08-17 11:50:34 +02:00
16527c8124
Client explicitly refuses to accept change cipher spec if no or NULL cipher was proposed now
2016-08-17 09:32:43 +02:00
69e6b775f8
Hello requests are no longer included in the handshake hashing (as per RFC)
2016-08-17 09:29:55 +02:00
c69316071f
Support for encrypted change cipher spec messages added
2016-08-17 09:26:46 +02:00
a02d1e7094
Explicit checks on server certificate chain added:
...
- Certificate can not be self-signed: Cannot check trust against configured root CAs when server certificate is self-signed
- Server can provide full certificate chain up-to and including root CA. Importing root CA to the store for certificate chain validation would implicitly trust this certificate chain. Thus, we skip all self-signed certificates on import.
2016-08-17 09:22:38 +02:00
078636eb14
make_change_chiper_spec() removed as this message can simply be created using make_message()
2016-08-17 09:09:42 +02:00
cabae26e0b
Flags describing handshake messages received assembled in a boolean table of flags
2016-08-17 09:01:11 +02:00
7376693838
Additional constants
2016-08-17 08:34:25 +02:00
a5b3914a09
Comments and some minor clean-up
2016-08-16 22:27:30 +02:00
8beb7bd27a
Version set to 1.0-alpha7
1.0-alpha7
2016-08-16 16:59:03 +02:00
00dd1277c5
Switched to the new key import method, as the old one had issues with PROV_RSA_AES crystallographic provider
2016-08-16 16:55:18 +02:00
e9839706b6
TLS clean-up
2016-08-16 16:44:19 +02:00
f5b03bc0bf
Annotation update
2016-08-16 10:39:42 +02:00
c953fb8db4
Version set to 1.0-alpha6
1.0-alpha6
2016-08-16 01:00:41 +02:00
db27355e46
Some last compiler warnings resolved
2016-08-16 00:58:22 +02:00
85d7c3d4ec
Support for TLS 1.2 added
2016-08-16 00:47:47 +02:00
d68fd6ce08
Support for TLS 1.1 finished
2016-08-15 22:49:45 +02:00
82e910fea4
Late pad-checking added to prevent [Canvel, B] attack
2016-08-15 22:48:08 +02:00
7fa3289e3d
Incorrect parameter reference fixed
2016-08-15 22:45:54 +02:00
de802b7a28
Byte-enums redefined & code clean-up
2016-08-15 21:01:38 +02:00
67fe27f6fd
Support for stream ciphers added
2016-08-15 19:04:56 +02:00
c8cfe4da42
TLS version no longer static, thou still fixed to TLS 1.0
2016-08-15 19:04:21 +02:00
3267b7f53d
Missing credential storage added
2016-08-15 18:36:01 +02:00
7b3ecda484
Clean-up
2016-08-15 18:35:15 +02:00
d8ccf7cbc0
Credential management revised
2016-08-15 17:33:10 +02:00
4dc7083028
wxEAPProviderLockedPanelBase renamed to wxEAPGeneralNotePanel to accommodate general use later
2016-08-15 16:53:42 +02:00
e34d2ba275
Prefast declaration update
2016-08-15 15:10:42 +02:00
3d6849a523
Peer correctly returns providers configuration instead of method configuration in method_tls::get_result()
2016-08-15 14:13:14 +02:00
217c3dd090
Issue with TLS credentials panel resetting PAP credentials in TTLS fixed
2016-08-15 14:05:14 +02:00
e807336e7b
The TLS phase can be determined from flags alone, therefore m_phase member eliminated
2016-08-15 10:40:27 +02:00
95426cde7c
Clean-up
2016-08-15 10:09:01 +02:00
92c62c53d7
16B PAP password padding added (RFC 5281)
2016-08-15 05:40:23 +02:00
99aa53726d
- PPP authentication EAP response packet is correctly formed now
...
- MS-MPPE-Send-Key/MS-MPPE-Recv-Key sorted out
2016-08-14 21:04:19 +02:00
95e2f7e01b
Encryption/decryption revised
...
- Number of memory copying reduced
- HMAC verification of server packets added
- Handshake hashing simplified
2016-08-14 18:51:18 +02:00
735d669887
Check for "change cipher spec" before server "finished" message added
2016-08-14 16:32:28 +02:00
a8db309a76
Wrong HMAC byte order issue fixed
2016-08-14 16:31:38 +02:00
7b94f01aa7
method_tls::create_key() optimization
2016-08-14 16:31:07 +02:00
12beee54ad
Ambiguous variable name changed
2016-08-14 16:24:07 +02:00