summaryrefslogtreecommitdiffstats
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | | | | added support for EGAIN while trying to receive data on gTLS sessionRainer Gerhards2008-06-246-31/+143
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This maps to bugzilla bug 83: http://bugzilla.adiscon.com/show_bug.cgi?id=83 This is the first test version, posted to user for repro of the problem. It contains code to handle the case, HOWEVER, I have not been able to test it in a scenario where a retry actually happens while receiving (I dont't get this in my environment). So I assume it is buggy and will probably not work.
| * | | | | | disabled compile warnings caused by third-party librariesRainer Gerhards2008-06-239-1/+28
| | | | | | |
| * | | | | | changed Rcv-Interface in tcpsrv subsystemRainer Gerhards2008-06-237-38/+56
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | It is now iRet based. This enables us to communicate more in-depth information to the upper peers. This is needed to handle the EGAIN case on rcv (not yet implemented)
| * | | | | | disabled in-depth GnuTLS debugging aidRainer Gerhards2008-06-231-0/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is a debug aid, only. Note that it may reveal sensitive information, so it should never be active in production code. Currently, this is a compile-time switch and requires code changes to (de)activate.
| * | | | | | added some develop environmet files to .gitignoreRainer Gerhards2008-06-231-0/+7
| | | | | | |
| * | | | | | added tls server docRainer Gerhards2008-06-231-0/+118
| | | | | | |
| * | | | | | improved TLS docRainer Gerhards2008-06-203-40/+44
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | also changed samples to 2048 bit keys, because 1024 will soon no longer be considered secure.
| * | | | | | bugfix: some error states were swappedRainer Gerhards2008-06-202-6/+29
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | ... in gnutls code, resulting in some hard too understand error messages. Also genereally improved certificate error messages a bit. Also, added GnuTLS debugging support.
| * | | | | | added doc on how to generate certficatesRainer Gerhards2008-06-195-1/+349
| | | | | | | | | | | | | | | | | | | | | | | | | | | | with gnutls for both the CA and individual machines
| * | | | | | begun step-by-step guide for TLS protected syslogRainer Gerhards2008-06-1815-55/+209
| | | | | | |
| * | | | | | updated status to reflect 3.17.4 releaseRainer Gerhards2008-06-162-3/+4
| | | | | | |
| * | | | | | Merge branch 'beta'Rainer Gerhards2008-06-161-1/+1
| |\ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Conflicts: ChangeLog configure.ac doc/manual.html
| * | | | | | | added .gitignore for testsRainer Gerhards2008-06-161-0/+3
| | | | | | | |
| * | | | | | | begun building a testbenchRainer Gerhards2008-06-1314-20/+336
| | | | | | | |
| * | | | | | | bugfix: restored accidently deleted version lineRainer Gerhards2008-06-131-0/+1
| | | | | | | |
| * | | | | | | added a few more .gitignore rules to serve my environmentRainer Gerhards2008-06-131-0/+2
| | | | | | | |
| * | | | | | | Merge branch 'beta'Rainer Gerhards2008-06-125-10/+19
| |\ \ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Conflicts: ChangeLog configure.ac doc/manual.html plugins/imklog/linux.c
| * | | | | | | | bumped version numberRainer Gerhards2008-06-113-2/+4
| | | | | | | | |
| * | | | | | | | updated statusv3.19.7Rainer Gerhards2008-06-111-4/+4
| | | | | | | | |
| * | | | | | | | preparing for 3.19.7 releaseRainer Gerhards2008-06-111-1/+4
| | | | | | | | |
| * | | | | | | | Remove .cvsignore files, add .gitignore.Michael Biebl2008-06-1116-89/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Signed-off-by: Rainer Gerhards <rgerhards@adiscon.com>
| * | | | | | | | Fix linker flags for librsyslog and rsyslogdMichael Biebl2008-06-112-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Use $(dl_libs) and $(rt_libs) instead of -ldl and -lrt. This ensures that rsyslog can be successfully built on *BSD. Don't like rsyslogd against $(dl_libs) and $(rt_libs) anymore. This functionality is now in librsyslog. Signed-off-by: Rainer Gerhards <rgerhards@adiscon.com>
| * | | | | | | | fixed syntax error (typo in var name) and cleaupRainer Gerhards2008-06-103-9/+5
| | | | | | | | |
| * | | | | | | | made rsyslog tickless in the (usual and default) case that repeatedRainer Gerhards2008-06-093-11/+22
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | message reduction is turned off. More info: http://blog.gerhards.net/2008/06/coding-to-save-environment.html
| * | | | | | | | somewhat improved plain tcp syslog reliabilityRainer Gerhards2008-06-0910-13/+94
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | ...by doing a connection check before sending. Credits to Martin Schuette for providing the idea. Details are available at http://blog.gerhards.net/2008/06/reliable-plain-tcp-syslog-once-again.html
| * | | | | | | | fixed a bug with the new property replacer optionRainer Gerhards2008-06-072-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | there was a copy&paste error in the timereported property - thanks to Elizabeth for reporting it
| * | | | | | | | added new property replacer option "time-subseconds"Rainer Gerhards2008-06-068-2/+80
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | enables to query just the subsecond part of a high-precision timestamp
| * | | | | | | | added doc on suggested TLS deploymentRainer Gerhards2008-06-062-3/+146
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | (rough picture, actual configuration sample still missing).
| * | | | | | | | bumping version numberRainer Gerhards2008-06-064-6/+8
| | | | | | | | |
| * | | | | | | | preparing 3.19.6v3.19.6Rainer Gerhards2008-06-062-2/+3
| | | | | | | | |
| * | | | | | | | enhanced property replacer to support multiple regex matchesRainer Gerhards2008-06-045-11/+61
| | | | | | | | |
| * | | | | | | | bugfix: removed some memory leaks in TLS codeRainer Gerhards2008-06-043-7/+23
| | | | | | | | |
| * | | | | | | | bugfix: off-by-one bug during certificate checkRainer Gerhards2008-06-042-2/+5
| | | | | | | | |
| * | | | | | | | bugfix: part of permittedPeer structure was not correctly initializedRainer Gerhards2008-06-032-2/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | thanks to varmojfekoj for spotting this
| * | | | | | | | bumped version numberRainer Gerhards2008-05-303-2/+4
| | | | | | | | |
| * | | | | | | | finalized 3.19.5v3.19.5Rainer Gerhards2008-05-302-5/+5
| | | | | | | | |
| * | | | | | | | capability for replacement text in no match regex case addedRainer Gerhards2008-05-305-18/+59
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | implemented in property replacer: if a regular expression does not match, it can now either return "**NO MATCH** (default, as before), a blank property or the full original property text
| * | | | | | | | enhanced property replacer's regex to support submatchesRainer Gerhards2008-05-295-14/+80
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | - enabled Posix ERE expressions inside the property replacer (previously BRE was permitted only) - provided ability to specify that a regular expression submatch shall be used inside the property replacer
| * | | | | | | | fixed typoIida, Masanari2008-05-281-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Typo caused confusion, because the database name is case sensitive, but case was used different in the sample and the database create script. Signed-off-by: Rainer Gerhards <rgerhards@adiscon.com>
| * | | | | | | | updated status documentRainer Gerhards2008-05-281-4/+4
| | | | | | | | |
| * | | | | | | | bumped version numberRainer Gerhards2008-05-273-2/+4
| | | | | | | | |
| * | | | | | | | finalized 3.19.4v3.19.4Rainer Gerhards2008-05-272-7/+14
| | | | | | | | |
| * | | | | | | | Merge branch 'ietf-tls'Rainer Gerhards2008-05-2712-96/+1248
| |\ \ \ \ \ \ \ \
| | * | | | | | | | implemented wildcards inside certificate name check authenticationRainer Gerhards2008-05-274-7/+311
| | | | | | | | | |
| | * | | | | | | | client now provides cert even if it is not signed by one of the server's ↵Rainer Gerhards2008-05-273-10/+170
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | trusted CAs (gtls)
| | * | | | | | | | protected gtls error string function by a mutex.Rainer Gerhards2008-05-262-1/+10
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Without it, we could have a race condition in extreme cases. This was very remote, but now can no longer happen.
| | * | | | | | | | fixed fingerprint generatorRainer Gerhards2008-05-261-2/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | fixed problem introduced earlier today
| | * | | | | | | | fixed wrong cert expiration date checkRainer Gerhards2008-05-261-1/+1
| | | | | | | | | |
| | * | | | | | | | added certificate validity date check (gtls)Rainer Gerhards2008-05-262-10/+58
| | | | | | | | | |
| | * | | | | | | | added gtls name authentication based on common name (inside DN)Rainer Gerhards2008-05-263-7/+101
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | also changed fingerprint gtls auth mode to new format fingerprint