Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | Merge pull request #2589 from reaperhulk/dict-dict-dict | Alex Gaynor | 2015-12-27 | 1 | -2/+28 | |
|\ | | | | | add a comment and a dict we need in #2582 | |||||
| * | add a comment and a dict we need in #2582 | Paul Kehrer | 2015-12-26 | 1 | -2/+28 | |
| | | ||||||
* | | Simplify code slightly by adding a new binding | Alex Gaynor | 2015-12-26 | 1 | -4/+1 | |
|/ | ||||||
* | unused import | Alex Gaynor | 2015-12-26 | 1 | -1/+0 | |
| | ||||||
* | A handful of small cleanups and simplifications | Alex Gaynor | 2015-12-26 | 2 | -6/+4 | |
| | ||||||
* | add invaliditydate class for crl entry extensions | Paul Kehrer | 2015-12-26 | 1 | -1/+3 | |
| | ||||||
* | switch CRLReason to use a class | Paul Kehrer | 2015-12-26 | 1 | -1/+1 | |
| | ||||||
* | start switching the CRL entry extensions to be full-fledged classes | Paul Kehrer | 2015-12-25 | 1 | -1/+1 | |
| | | | | first up: CertificateIssuer | |||||
* | Merge pull request #2574 from reaperhulk/rename-crlextension | Alex Gaynor | 2015-12-25 | 1 | -6/+6 | |
|\ | | | | | rename CRLExtensionOID to CRLEntryExtensionOID | |||||
| * | rename CRLExtensionOID to CRLEntryExtensionOID | Paul Kehrer | 2015-12-25 | 1 | -6/+6 | |
| | | ||||||
* | | X509_REVOKED_dup isn't available everywhere, we get to define our own | Paul Kehrer | 2015-12-25 | 1 | -1/+3 | |
| | | ||||||
* | | support revoked certificates in CertificateRevocationListBuilder | Paul Kehrer | 2015-12-25 | 1 | -0/+9 | |
|/ | ||||||
* | RevokedCertificateBuilder | Paul Kehrer | 2015-12-25 | 1 | -2/+19 | |
| | ||||||
* | add create_x509_revoked_certificate to x509backend interface | Paul Kehrer | 2015-12-25 | 1 | -0/+3 | |
| | ||||||
* | use _create_x509_extensions in create_x509_crl | Paul Kehrer | 2015-12-25 | 1 | -20/+8 | |
| | ||||||
* | add extension support to the CRLBuilder | Paul Kehrer | 2015-12-25 | 1 | -1/+41 | |
| | ||||||
* | a different approach to refactoring the x509 extension addition | Paul Kehrer | 2015-12-24 | 1 | -21/+24 | |
| | ||||||
* | don't reuse a variable, it's confusing | Paul Kehrer | 2015-12-24 | 1 | -4/+6 | |
| | ||||||
* | refactor x509 extension creation to make it a bit more reusable | Paul Kehrer | 2015-12-24 | 1 | -38/+39 | |
| | | | | | Unfortunately X509 certs and CSRs add extensions differently, so we can't reuse quite as much as we'd like to... | |||||
* | CertificateRevocationListBuilder | Paul Kehrer | 2015-12-24 | 1 | -1/+67 | |
| | | | | | RSA keys only. Currently does not support CRL extensions or CRLEntry extensions. | |||||
* | coverage | Paul Kehrer | 2015-12-24 | 1 | -1/+1 | |
| | ||||||
* | add create_x509_crl interface | Paul Kehrer | 2015-12-24 | 1 | -0/+3 | |
| | ||||||
* | please the great flake8 in the sky | Alex Gaynor | 2015-12-24 | 1 | -3/+1 | |
| | ||||||
* | full indexing support + testsg | Alex Gaynor | 2015-12-24 | 1 | -4/+12 | |
| | ||||||
* | Make indexing a CRL O(1) instead of O(n). | Alex Gaynor | 2015-12-24 | 1 | -2/+5 | |
| | | | | This drops support for slicing, if that's important someone say something and I can add it back | |||||
* | Simplify implementation of CRL indexing and iteration. | Alex Gaynor | 2015-12-24 | 1 | -13/+8 | |
| | | | | No longer allocates a list just to iterate over it. | |||||
* | coverage fix | Alex Gaynor | 2015-12-24 | 1 | -8/+7 | |
| | ||||||
* | Improve the performance of len(crl) | Alex Gaynor | 2015-12-23 | 1 | -3/+6 | |
| | ||||||
* | fix a potential memory issue when retaining revoked certs from a CRL | Paul Kehrer | 2015-12-23 | 1 | -2/+13 | |
| | ||||||
* | CRLNumber needs to be a class for reasons. | Paul Kehrer | 2015-12-22 | 1 | -1/+1 | |
| | ||||||
* | add support for parsing AuthorityInfoAccess and IssuerAltName CRL exts | Paul Kehrer | 2015-12-22 | 1 | -0/+4 | |
| | | | | Expand the CRL extensions test to check the value | |||||
* | support parsing CRL extensions in the OpenSSL backend | Paul Kehrer | 2015-12-21 | 1 | -1/+18 | |
| | ||||||
* | add a CRL public_bytes method | Paul Kehrer | 2015-12-20 | 1 | -0/+14 | |
| | ||||||
* | support CRLs with no revoked certificates | Paul Kehrer | 2015-12-20 | 1 | -7/+6 | |
| | ||||||
* | Change password callback to use userdata pointer | Christian Heimes | 2015-12-20 | 1 | -33/+48 | |
| | | | | | | | | | Instead of a closure the pem_password_cb now uses the void *userdata argument to exchange data with the callback function. It's a necessary step to port all callbacks to new static callbacks. See: #2477 Signed-off-by: Christian Heimes <christian@python.org> | |||||
* | X509_set_subject_name and X509_set_issuer_name copy the object | Paul Kehrer | 2015-12-15 | 1 | -2/+2 | |
| | | | | | So we need to register our own copy for gc. This fixes a memory leak reported by Wulf. | |||||
* | fix the comment so that it is no longer nonsense | Paul Kehrer | 2015-12-03 | 1 | -1/+1 | |
| | ||||||
* | expose tbs_certrequest_bytes and signature on CertificateSigningRequest | Paul Kehrer | 2015-12-03 | 1 | -0/+15 | |
| | ||||||
* | move _encode_name_constraints and _encode_general_subtrees | Paul Kehrer | 2015-12-02 | 1 | -36/+36 | |
| | ||||||
* | implement support for encoding name constraints | Paul Kehrer | 2015-12-02 | 1 | -0/+37 | |
| | ||||||
* | add tbsCertList and signature interfaces to CRLs | Erik Trauschke | 2015-11-19 | 1 | -0/+15 | |
| | ||||||
* | rename tbs_certificate to tbs_certificate_bytes, add a comment | Paul Kehrer | 2015-11-03 | 1 | -1/+2 | |
| | ||||||
* | add support for Certificate signature and tbs_certificate | Paul Kehrer | 2015-11-03 | 1 | -0/+14 | |
| | ||||||
* | flake8 | Alex Gaynor | 2015-11-01 | 1 | -2/+2 | |
| | ||||||
* | corrected a few typos in comments | Alex Gaynor | 2015-11-01 | 1 | -3/+3 | |
| | ||||||
* | please flake8 | Alex Gaynor | 2015-10-29 | 1 | -1/+1 | |
| | ||||||
* | Error cleanly if the public and private keys to an ECDH key exchange are on ↵ | Alex Gaynor | 2015-10-28 | 1 | -0/+5 | |
| | | | | different curves | |||||
* | Merge pull request #2435 from reaperhulk/fix-2407 | Alex Gaynor | 2015-10-27 | 1 | -6/+8 | |
|\ | | | | | encode countryName with PrintableString | |||||
| * | update comment to include a bit more detail | Paul Kehrer | 2015-10-27 | 1 | -2/+2 | |
| | | ||||||
| * | encode countryName with PrintableString | Paul Kehrer | 2015-10-20 | 1 | -6/+8 | |
| | | | | | | | | | | | | | | This commit adds a dependency on asn1crypto for testing purposes to parse the certificate and confirm that countryName is encoded with PrintableString while other fields are UTF8String. This is a test only dep. |