Age | Commit message (Collapse) | Author |
|
svn path=/branches/tk274/; revision=4714
|
|
svn path=/branches/tk274/; revision=4713
|
|
I see what the ROA code looks like.
svn path=/branches/tk274/; revision=4712
|
|
svn path=/branches/tk274/; revision=4711
|
|
svn path=/branches/tk274/; revision=4710
|
|
svn path=/branches/tk274/; revision=4709
|
|
ugly, still needs work, but appears to return correct results.
svn path=/branches/tk274/; revision=4708
|
|
vary, but general approach should work for many (most? all?) other
extensions.
svn path=/branches/tk274/; revision=4707
|
|
linking against libssl, only libcrypto. Internal documentation almost
matches current reality. A few deliberate harmless compilation
warnings to remind me of loose ends that still want cleaning up.
svn path=/branches/tk274/; revision=4706
|
|
Replaced old factory functions with proper (well, I hope they're
proper) class __new__() and __init__() methods as appropriate, whack
PyTypeObject structures to make it possible to subclass these classes,
etcetera. Doc strings for classes and methods are still horribly out
of date, but at least it all shows up properly now.
Caveat: This is a major change and has not yet been heavily tested.
It seems to work, but splitting the old factory functions into
__new__() and __init__() methods exposed some corner cases which I may
or may not have handled correctly.
svn path=/branches/tk274/; revision=4705
|
|
svn path=/branches/tk274/; revision=4704
|
|
svn path=/branches/tk274/; revision=4703
|
|
code still served was to support selection of an (optional) encryption
algorithm for new RSA private keys; since none of the two dozen
algorithms supported by that code were anything one would choose this
year, I converted the whole mess just to use AES-256-CBC as the one
supported encryption algorithm. Fix this if anything ever cares.
svn path=/branches/tk274/; revision=4702
|
|
Since we can't get rid of them yet, fix them to pass the digest length
along to OpenSSL for checking.
svn path=/branches/tk274/; revision=4701
|
|
svn path=/branches/tk274/; revision=4700
|
|
method documentation. Most of the existing method documentation needs
editing to for this to be fully useful, but it's a start.
svn path=/branches/tk274/; revision=4699
|
|
svn path=/branches/tk274/; revision=4698
|
|
svn path=/branches/tk274/; revision=4697
|
|
swacks of code which either haven't been used in RPKI for years or
have never been used in RPKI at all, and which, in either case, I'd
rather not have to maintain: SSL/TLS, MD2, RIPEMD160, HMAC. There's
almost certainly more to prune, but this was the lowest-hanging fruit.
svn path=/branches/tk274/; revision=4696
|
|
svn path=/branches/tk274/; revision=4695
|
|
rpki.x509 module.
svn path=/branches/tk274/; revision=4694
|
|
svn path=/branches/tk274/; revision=4693
|
|
svn path=/branches/tk274/; revision=4692
|
|
svn path=/branches/tk274/; revision=4691
|
|
svn path=/branches/tk274/; revision=4690
|
|
class to use POW instead of POW.pkix.
svn path=/branches/tk274/; revision=4689
|
|
RDNs, for compatability with other X.509-aware Python code that uses
this encoding. We don't really expect to see multi-value RDNs in
RPKI, nor do we fully support them yet; for the moment, the goal is
just to get to a point where we can rewrite the rpki.x509 subject and
issuer name functions to use POW rather than POW.pkix.
svn path=/branches/tk274/; revision=4688
|
|
svn path=/branches/tk274/; revision=4687
|
|
the bug fixed in [4684].
svn path=/branches/tk274/; revision=4686
|
|
numeric OIDs.
svn path=/branches/tk274/; revision=4685
|
|
svn path=/branches/tk274/; revision=4684
|
|
svn path=/branches/tk274/; revision=4683
|
|
svn path=/branches/tk274/; revision=4682
|
|
svn path=/branches/tk274/; revision=4681
|
|
mode.
svn path=/branches/tk274/; revision=4680
|
|
svn path=/branches/tk274/; revision=4679
|
|
consequence, non-loopback users of yamlconf output will need to call
"rpkic update_bpki" before starting daemons.
svn path=/branches/tk274/; revision=4678
|
|
technically correct, but there are already enough violations of the
naming scheme that one more won't matter.
svn path=/branches/tk274/; revision=4677
|
|
useful. Add rpki.sql.cache_reference decorator, to give the garbage
collector some guidance about linkages between active objects now that
the SQL cache uses weak references. Other minor cleanup.
svn path=/branches/tk274/; revision=4676
|
|
svn path=/branches/tk274/; revision=4675
|
|
svn path=/branches/tk274/; revision=4674
|
|
svn path=/branches/tk274/; revision=4673
|
|
svn path=/branches/tk274/; revision=4672
|
|
svn path=/branches/tk274/; revision=4671
|
|
svn path=/branches/tk274/; revision=4670
|
|
svn path=/branches/tk274/; revision=4669
|
|
scripts.
svn path=/branches/tk274/; revision=4668
|
|
configurations, to avoid warnings about it being tainted. This is
really a conflict between needing to support rootd and wanting to make
the configuration clean when not running rootd: either we add an extra
directory level to the publication structure which we don't use when
not running rootd, or we move root.cer somewhere else. Since the
latter is simpler except for test configurations which are already
generated for us by programs, we do the latter.
svn path=/branches/tk274/; revision=4667
|
|
check for missing databases and clean existing databases if found.
Dump SQL to files at end of run.
svn path=/branches/tk274/; revision=4666
|
|
svn path=/branches/tk274/; revision=4665
|