radsecproxy.git
10 years agoHave the library depend on radsec.sym. libradsec
Linus Nordberg [Fri, 17 May 2013 08:53:36 +0000 (10:53 +0200)]
Have the library depend on radsec.sym.

10 years agoMerge branch 'libradsec-add-avp-2' into libradsec
Linus Nordberg [Fri, 17 May 2013 08:50:11 +0000 (10:50 +0200)]
Merge branch 'libradsec-add-avp-2' into libradsec

Conflicts:
lib/Makefile.am

10 years agoDon't provide bogus info in an error.
Linus Nordberg [Fri, 17 May 2013 08:44:11 +0000 (10:44 +0200)]
Don't provide bogus info in an error.

10 years agoMove PSK example configuration to a separate file.
Linus Nordberg [Fri, 17 May 2013 08:41:50 +0000 (10:41 +0200)]
Move PSK example configuration to a separate file.

10 years agoFix typo.
Linus Nordberg [Wed, 15 May 2013 13:44:52 +0000 (15:44 +0200)]
Fix typo.

10 years agoDon't crash on reading invalid messages.
Linus Nordberg [Wed, 15 May 2013 09:57:09 +0000 (11:57 +0200)]
Don't crash on reading invalid messages.

Also, invoke disconnected callback and close connection in error
cases.

10 years agoWhitespace changes in license headers.
Linus Nordberg [Thu, 9 May 2013 07:50:11 +0000 (09:50 +0200)]
Whitespace changes in license headers.

10 years agoUpdate copyright years.
Linus Nordberg [Thu, 9 May 2013 07:49:37 +0000 (09:49 +0200)]
Update copyright years.

10 years agoInclude stdlib.h everywhere we call (m|c)alloc.
Linus Nordberg [Thu, 9 May 2013 07:32:31 +0000 (09:32 +0200)]
Include stdlib.h everywhere we call (m|c)alloc.

10 years agoUse malloc+memcpy rather than calloc+strcpy in rs_strdup.
Linus Nordberg [Thu, 9 May 2013 06:59:00 +0000 (08:59 +0200)]
Use malloc+memcpy rather than calloc+strcpy in rs_strdup.

For effiency (but triggered by calloc needing unistd.h on Darwin).

10 years agoRevert "Bump library interface revision."
Linus Nordberg [Wed, 8 May 2013 21:10:11 +0000 (23:10 +0200)]
Revert "Bump library interface revision."

So there were two things wrong with that commit.

1. Library interface revision should be bumped only immediately before
a public release.

2. Given the changes in the library, it should change to 0:1:0 since
the interface didn't change (including not being extended).

This reverts commit b9e967b3cde6af41cd0e863e9ff073897019625a.

Conflicts:
lib/Makefile.am

10 years agoExport rs_packet_add_avp() and set library revision. libradsec-add-avp-2
Linus Nordberg [Wed, 8 May 2013 21:03:51 +0000 (23:03 +0200)]
Export rs_packet_add_avp() and set library revision.

Correct library revision is 1:0:1, given that the last "released"
library was 0:0:0. (The current 1:0:0 is wrong.)

10 years agoClarify and reformat comments on how to use Libtool's -version-info.
Linus Nordberg [Wed, 8 May 2013 20:42:00 +0000 (22:42 +0200)]
Clarify and reformat comments on how to use Libtool's -version-info.

10 years agoPass make distcheck.
Linus Nordberg [Wed, 8 May 2013 20:18:27 +0000 (22:18 +0200)]
Pass make distcheck.

10 years agoDon't include tests in SUBIDRS after all.
Linus Nordberg [Wed, 8 May 2013 20:17:32 +0000 (22:17 +0200)]
Don't include tests in SUBIDRS after all.

It requires a running radius server. That's not a nice thing to
require for something like distcheck.

10 years agoInitial RPM packaging
Linus Nordberg [Wed, 8 May 2013 19:42:17 +0000 (21:42 +0200)]
Initial RPM packaging

Adapted from
commit 8ff4e9ab2308fc6ee1e9b140d85ba45eff5287ce
Author: Sam hartman <hartmans@painless-security.com>
Date:   Mon Oct 10 15:25:11 2011 +0100

Conflicts:
lib/Makefile.am
lib/configure.ac

10 years agoAdd a few bits to README.
Linus Nordberg [Wed, 8 May 2013 19:17:54 +0000 (21:17 +0200)]
Add a few bits to README.

10 years agoExit tests with number of failures.
Linus Nordberg [Wed, 8 May 2013 18:28:17 +0000 (20:28 +0200)]
Exit tests with number of failures.

Now 'make check' really fails when a test fails.

10 years agoAdd 'tests' to SUBDIRS to make 'make check' work.
Linus Nordberg [Wed, 8 May 2013 18:23:06 +0000 (20:23 +0200)]
Add 'tests' to SUBDIRS to make 'make check' work.

10 years agoConstify the MD5 implementation.
Linus Nordberg [Wed, 8 May 2013 18:21:18 +0000 (20:21 +0200)]
Constify the MD5 implementation.

10 years agoAdd rs_packet_add_avp() and use it.
Linus Nordberg [Wed, 8 May 2013 15:08:14 +0000 (17:08 +0200)]
Add rs_packet_add_avp() and use it.

rs_packet_create_authn_request() now uses rs_packet_add_avp() instead
of rs_packet_append_avp() which makes it possible to create a
authentication packet without knowing the shared secret.

Calling rs_packet_add_avp() on a packet is incompatible with using
rs_packet_append_avp() on the same packet but since
rs_packet_create_authn_request() adds attribute-value pairs for user
name and password only if those arguments are supplied, code that
doesn't use user name and password (i.e. mech_eap) should still be
fine.

10 years agoPush an error on the error stack when returning !RSE_OK.
Linus Nordberg [Wed, 8 May 2013 15:10:10 +0000 (17:10 +0200)]
Push an error on the error stack when returning !RSE_OK.

10 years agoRevive RSE_MAX.
Linus Nordberg [Wed, 8 May 2013 15:05:57 +0000 (17:05 +0200)]
Revive RSE_MAX.

It's being used after all.

10 years agoAdd an assert in error handling code.
Linus Nordberg [Wed, 8 May 2013 13:00:00 +0000 (15:00 +0200)]
Add an assert in error handling code.

10 years agoRemove an unused error code and unusued RSE_MAX.
Linus Nordberg [Wed, 8 May 2013 10:00:00 +0000 (12:00 +0200)]
Remove an unused error code and unusued RSE_MAX.

Also, remove unused file attr.c.

10 years agoFollow API change in tests.
Linus Nordberg [Mon, 6 May 2013 10:01:00 +0000 (12:01 +0200)]
Follow API change in tests.

10 years agoRevert "Add formal argument 'secret' to two public functions."
Linus Nordberg [Mon, 6 May 2013 10:00:00 +0000 (12:00 +0200)]
Revert "Add formal argument 'secret' to two public functions."

This reverts commit 09d1cff2418a900b587b2113f508984f2417cc11.

Conflicts:
lib/include/radsec/request.h

10 years agoAdd and fix RADIUS attributes (4b9e4cb1, e4b6e972).
Sam Hartman [Wed, 19 Sep 2012 00:50:12 +0000 (20:50 -0400)]
Add and fix RADIUS attributes (4b9e4cb1e4b6e972).

Fix capitalization in abfab dictionary
Update to IETF RADIUS attributes

draft-ietf-abfab-gss-eap has been approved; include IANA-issued
standard radius attributes for Moonshot.
Fix capitalization in abfab dictionary

10 years agoBuild include before building '.'
Linus Nordberg [Tue, 7 May 2013 08:09:53 +0000 (10:09 +0200)]
Build include before building '.'

Patch by Sam Hartman (ff1af013 in moonshot).

10 years agoUse CUnit for tests.
Linus Nordberg [Mon, 6 May 2013 18:30:47 +0000 (20:30 +0200)]
Use CUnit for tests.

cgreen didn't seem properly maintained. CUnit seems to be widely used.

10 years agoBump library interface revision.
Linus Nordberg [Mon, 6 May 2013 12:45:33 +0000 (14:45 +0200)]
Bump library interface revision.

Commit edf4c047 claimed it did this but didn't really do it.

    Should really have been done as part of bumping the library version
    (0.0.2.dev in configure.ac).

10 years agoBump version to 0.0.4.dev to keep ahead of moonshot.
Linus Nordberg [Mon, 6 May 2013 12:35:12 +0000 (14:35 +0200)]
Bump version to 0.0.4.dev to keep ahead of moonshot.

11 years agoImprove documentation.
Linus Nordberg [Tue, 29 Jan 2013 14:27:26 +0000 (15:27 +0100)]
Improve documentation.

11 years agoRemove dead code.
Linus Nordberg [Mon, 28 Jan 2013 15:22:14 +0000 (16:22 +0100)]
Remove dead code.

11 years agoUpdate HACKING with a rough road map.
Linus Nordberg [Fri, 25 Jan 2013 08:58:26 +0000 (09:58 +0100)]
Update HACKING with a rough road map.

11 years agoAdd PSK example in examples/client.conf.
Linus Nordberg [Thu, 24 Jan 2013 16:33:08 +0000 (17:33 +0100)]
Add PSK example in examples/client.conf.

11 years agoDo the test for PSK properly.
Linus Nordberg [Thu, 24 Jan 2013 16:32:18 +0000 (17:32 +0100)]
Do the test for PSK properly.

Fixes 823ea9ba.

11 years agoAdd two helper functions to conn.[ch].
Linus Nordberg [Thu, 24 Jan 2013 16:31:49 +0000 (17:31 +0100)]
Add two helper functions to conn.[ch].

11 years agoOrder functions properly in conn.c.
Linus Nordberg [Thu, 24 Jan 2013 16:22:14 +0000 (17:22 +0100)]
Order functions properly in conn.c.

11 years agoDon't verify server certificate if we're using PSK.
Linus Nordberg [Thu, 24 Jan 2013 15:51:36 +0000 (16:51 +0100)]
Don't verify server certificate if we're using PSK.

11 years agoAdd missing key files to demoCA.
Linus Nordberg [Thu, 24 Jan 2013 11:44:19 +0000 (12:44 +0100)]
Add missing key files to demoCA.

11 years agoRename rs_packet_flags members.
Linus Nordberg [Thu, 24 Jan 2013 07:32:23 +0000 (08:32 +0100)]
Rename rs_packet_flags members.

Uppercase to make them appear as the constants they are, as opposed to
variables.

Remove 'flag' suffix, typically used for variables.

Spell out HEADER.

11 years agoNew demo CA for tests.
Linus Nordberg [Wed, 23 Jan 2013 17:26:12 +0000 (18:26 +0100)]
New demo CA for tests.

Update examples config file accordingly.

11 years agoHandle case where config hasn't yet been read better.
Linus Nordberg [Wed, 23 Jan 2013 15:18:26 +0000 (16:18 +0100)]
Handle case where config hasn't yet been read better.

Don't segfault is a good start.

11 years agoAdd some info on usage modes.
Linus Nordberg [Wed, 23 Jan 2013 11:21:06 +0000 (12:21 +0100)]
Add some info on usage modes.

11 years agoAdd docstrings and a comment.
Linus Nordberg [Tue, 22 Jan 2013 14:52:09 +0000 (15:52 +0100)]
Add docstrings and a comment.

11 years agoRemove unnecessary #includes.
Linus Nordberg [Tue, 22 Jan 2013 14:46:11 +0000 (15:46 +0100)]
Remove unnecessary #includes.

11 years agoWhitespace.
Linus Nordberg [Tue, 22 Jan 2013 14:45:47 +0000 (15:45 +0100)]
Whitespace.

11 years agoCompile with -Werror.
Linus Nordberg [Tue, 22 Jan 2013 14:45:33 +0000 (15:45 +0100)]
Compile with -Werror.

11 years agoRemove incorrect build instruction from HACKING.
Linus Nordberg [Tue, 22 Jan 2013 13:14:07 +0000 (14:14 +0100)]
Remove incorrect build instruction from HACKING.

11 years agoAdd md5.[ch] for when we are configured without OpenSSL.
Linus Nordberg [Tue, 22 Jan 2013 13:11:32 +0000 (14:11 +0100)]
Add md5.[ch] for when we are configured without OpenSSL.

This is Solar Designers implementation from
http://openwall.info/wiki/people/solar/software/public-domain-source-code/md5 .

RS_MD5Transform goes away since it's not in md5.h. It's not used in
lib/radius/.

Might want to move this into lib/radius/ if we end up not using it in
lib/.

11 years agoRevive radsecproxy.h and hostport_types.h and move rsp_* into radsecproxy/.
Linus Nordberg [Tue, 22 Jan 2013 10:01:59 +0000 (11:01 +0100)]
Revive radsecproxy.h and hostport_types.h and move rsp_* into radsecproxy/.

11 years agoClean up top dir.
Linus Nordberg [Tue, 22 Jan 2013 09:36:57 +0000 (10:36 +0100)]
Clean up top dir.

11 years agoMerge branch 'libradsec-new-client' into libradsec
Linus Nordberg [Mon, 21 Jan 2013 10:02:17 +0000 (11:02 +0100)]
Merge branch 'libradsec-new-client' into libradsec

11 years agoUpdate README and HACKING. libradsec-new-client
Linus Nordberg [Mon, 21 Jan 2013 09:50:53 +0000 (10:50 +0100)]
Update README and HACKING.

Whitespace fixes.
Say Debian instead of Ubuntu.
Update versions of library dependencies.

HACKING:
Revive the "fully reentrant" design goal.
Admit that we don't implement a server API.

11 years agoFix a doc comment.
Linus Nordberg [Wed, 16 Jan 2013 14:39:53 +0000 (15:39 +0100)]
Fix a doc comment.

11 years agoDefine WITHOUT_OPENSSL if we don't have openssl.
Linus Nordberg [Wed, 19 Dec 2012 14:45:42 +0000 (15:45 +0100)]
Define WITHOUT_OPENSSL if we don't have openssl.

This is for radius/client.h.

We will want an alternative way of getting MD5. Include md5.[ch] from
FreeBSD? Link with libnettle?

11 years agoFix typos.
Linus Nordberg [Wed, 19 Dec 2012 11:15:15 +0000 (12:15 +0100)]
Fix typos.

#error messages.

11 years agoRemove generated autotools files.
Linus Nordberg [Wed, 19 Dec 2012 09:49:24 +0000 (10:49 +0100)]
Remove generated autotools files.

11 years agoRename COPYING -> LICENSE.
Linus Nordberg [Wed, 19 Dec 2012 09:41:57 +0000 (10:41 +0100)]
Rename COPYING -> LICENSE.

And distribute LICENSE and HACKING.

11 years agoRemove the option to use GPLv2 as the license.
Linus Nordberg [Tue, 18 Dec 2012 13:40:35 +0000 (14:40 +0100)]
Remove the option to use GPLv2 as the license.

This follows the changes to the upstream radsecproxy repository.
Also, Stig Venaas is removed from all copyright, replaced by UNINETT.

Add JANET as copyright holder (avp.c).

11 years agoConfig docu.
Linus Nordberg [Tue, 18 Dec 2012 12:24:59 +0000 (13:24 +0100)]
Config docu.

11 years agoWhitespace.
Linus Nordberg [Tue, 18 Dec 2012 12:24:45 +0000 (13:24 +0100)]
Whitespace.

11 years agoInclude <sys/types.h> for Junos.
Linus Nordberg [Tue, 18 Dec 2012 07:40:00 +0000 (08:40 +0100)]
Include <sys/types.h> for Junos.

Fix from Luke Howard.

11 years agoWhitespace.
Linus Nordberg [Mon, 17 Dec 2012 15:11:42 +0000 (16:11 +0100)]
Whitespace.

11 years agoAdd formal argument 'secret' to two public functions.
Linus Nordberg [Mon, 17 Dec 2012 15:11:14 +0000 (16:11 +0100)]
Add formal argument 'secret' to two public functions.

The functions are rs_packet_create_authn_request() and
rs_request_create_authn().

Attributes of type PW_USER_PASSWORD are supposed to be MD5
obfuscated (see vp2data_any()).

NOTE: This is a non-backward compatible API change.

11 years agoExample code: Print a little bit more helpful information on failure.
Linus Nordberg [Mon, 17 Dec 2012 15:07:16 +0000 (16:07 +0100)]
Example code: Print a little bit more helpful information on failure.

11 years agoExample code: Don't create rs_error on failing context creation.
Linus Nordberg [Mon, 17 Dec 2012 15:05:55 +0000 (16:05 +0100)]
Example code: Don't create rs_error on failing context creation.

We don't export err_create() and the error is ENOMEM nowadays.

11 years agoDocu: Fix libevent url.
Linus Nordberg [Mon, 17 Dec 2012 15:04:30 +0000 (16:04 +0100)]
Docu: Fix libevent url.

11 years agoDocu: Remove dependency on libradius.
Linus Nordberg [Mon, 17 Dec 2012 15:03:12 +0000 (16:03 +0100)]
Docu: Remove dependency on libradius.

11 years agoFix language.
Linus Nordberg [Wed, 12 Dec 2012 10:04:31 +0000 (11:04 +0100)]
Fix language.

11 years agoMerge libradsec-new-client.
Linus Nordberg [Fri, 27 Apr 2012 15:00:17 +0000 (17:00 +0200)]
Merge libradsec-new-client.

11 years agoFix struct in6_addr undefined.
Linus Nordberg [Fri, 27 Apr 2012 14:58:03 +0000 (16:58 +0200)]
Fix struct in6_addr undefined.

Have lib/rsp_tlscommon.h include netinet/in.h since it's included by radsecproxy.h.

12 years agoVerify certificate CN against configured hostname.
Linus Nordberg [Thu, 26 Apr 2012 08:19:52 +0000 (10:19 +0200)]
Verify certificate CN against configured hostname.

NOTE: The subjectAltName check is not well tested.

12 years agoImplement cert verification.
Linus Nordberg [Thu, 26 Apr 2012 08:18:33 +0000 (10:18 +0200)]
Implement cert verification.

NOTE: Not used yet.

12 years agoHandle failing rs_context_create().
Linus Nordberg [Thu, 26 Apr 2012 08:17:24 +0000 (10:17 +0200)]
Handle failing rs_context_create().

12 years agoUse existing temporary variable conn.
Linus Nordberg [Thu, 26 Apr 2012 08:15:51 +0000 (10:15 +0200)]
Use existing temporary variable conn.

12 years agoAdd an error code.
Linus Nordberg [Thu, 26 Apr 2012 08:12:36 +0000 (10:12 +0200)]
Add an error code.

Also add error text for missing RSE_CRED.

12 years agoDon't resolve DNS names in rs_peer_set_address().
Linus Nordberg [Thu, 26 Apr 2012 08:10:33 +0000 (10:10 +0200)]
Don't resolve DNS names in rs_peer_set_address().

It simply stores (a copy of) hostname and service name in PEER.

12 years agoUse rs_strdup().
Linus Nordberg [Thu, 26 Apr 2012 08:08:59 +0000 (10:08 +0200)]
Use rs_strdup().

12 years agoAdd util.h and util.c.
Linus Nordberg [Thu, 26 Apr 2012 08:03:42 +0000 (10:03 +0200)]
Add util.h and util.c.

12 years agoFollow name change of rs_resolv().
Linus Nordberg [Thu, 26 Apr 2012 07:48:36 +0000 (09:48 +0200)]
Follow name change of rs_resolv().

12 years agoAdd missing radsec.h.
Linus Nordberg [Wed, 25 Apr 2012 15:45:24 +0000 (17:45 +0200)]
Add missing radsec.h.

12 years agoPostpone resolving of DNS names of server.
Linus Nordberg [Wed, 25 Apr 2012 15:41:27 +0000 (17:41 +0200)]
Postpone resolving of DNS names of server.

We used to resolve DNS names when reading configuration.  We now do it
in event_init_socket() and cache the result in the connection object.

The imminent need for changing this is to keep host names around for
X509 certificate verification (CNAME and subjectAltName).  This will
also help later when we implement server failover (and later, when
people want to do more dynamic configuration, f.ex. NAPTR).

12 years agoUpdate HACKING.
Linus Nordberg [Wed, 25 Apr 2012 15:33:40 +0000 (17:33 +0200)]
Update HACKING.

12 years agoMissing response packet in rs_conn_receive_packet doesn't have to be a bug.
Linus Nordberg [Wed, 25 Apr 2012 13:23:06 +0000 (15:23 +0200)]
Missing response packet in rs_conn_receive_packet doesn't have to be a bug.

12 years agoFix a comment.
Linus Nordberg [Wed, 25 Apr 2012 13:22:36 +0000 (15:22 +0200)]
Fix a comment.

12 years agoConditionally compile TLS-PSK code (--enable-tls-psk).
Linus Nordberg [Mon, 23 Apr 2012 12:44:49 +0000 (14:44 +0200)]
Conditionally compile TLS-PSK code (--enable-tls-psk).

Also, allow for PSK-only configuration, i.e. don't barf on missing cert stuff.

12 years agoDon't say RADPROT_TLS when we mean RAD_TLS.
Linus Nordberg [Thu, 19 Apr 2012 09:23:06 +0000 (11:23 +0200)]
Don't say RADPROT_TLS when we mean RAD_TLS.

RADPROT_TLS is legacy from radsecproxy and will go away.
It happens to be defined to 1, the same as RAD_TLS, so it happens to work.

12 years agoUpdate copyright to JANET(UK)
Luke Howard [Fri, 30 Mar 2012 22:22:53 +0000 (09:22 +1100)]
Update copyright to JANET(UK)

12 years agoClarify comments about PSK string encoding.
Linus Nordberg [Wed, 1 Feb 2012 12:54:05 +0000 (13:54 +0100)]
Clarify comments about PSK string encoding.

12 years agoGet the test suite going again. libradsec-psk
Linus Nordberg [Tue, 31 Jan 2012 14:03:59 +0000 (15:03 +0100)]
Get the test suite going again.

12 years agoImplement TLS-PSK.
Linus Nordberg [Tue, 31 Jan 2012 12:15:20 +0000 (13:15 +0100)]
Implement TLS-PSK.

12 years agoFree the transport credentials struct.
Linus Nordberg [Thu, 26 Jan 2012 15:55:22 +0000 (16:55 +0100)]
Free the transport credentials struct.

12 years agoBump library interface revision.
Linus Nordberg [Tue, 24 Jan 2012 13:51:22 +0000 (14:51 +0100)]
Bump library interface revision.

Should really have been done as part of bumping the library version
(0.0.2.dev in configure.ac).

12 years agoBe user friendly in example program.
Linus Nordberg [Tue, 24 Jan 2012 12:17:40 +0000 (13:17 +0100)]
Be user friendly in example program.

12 years agoMove a comment, for clarification.
Linus Nordberg [Tue, 24 Jan 2012 12:17:12 +0000 (13:17 +0100)]
Move a comment, for clarification.

12 years agoAdd TLS PSK configuration options.
Linus Nordberg [Tue, 24 Jan 2012 12:16:26 +0000 (13:16 +0100)]
Add TLS PSK configuration options.

12 years agoCosmetic changes.
Linus Nordberg [Thu, 19 Jan 2012 08:11:48 +0000 (09:11 +0100)]
Cosmetic changes.

Language and typos in a README.

12 years agoCosmetic changes.
Linus Nordberg [Thu, 19 Jan 2012 08:10:07 +0000 (09:10 +0100)]
Cosmetic changes.

Better names of formal arguments in test program.