Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | Set default cert expiry to <39 months | Maximilian Hils | 2015-11-04 | 1 | -1/+2 |
| | | | This sould fix mitmproxy/mitmproxy#815 | ||||
* | python3++ | Maximilian Hils | 2015-09-20 | 1 | -3/+3 |
| | |||||
* | python3++ | Maximilian Hils | 2015-09-20 | 1 | -5/+6 |
| | |||||
* | python3++ | Maximilian Hils | 2015-09-18 | 1 | -20/+20 |
| | |||||
* | properly handle SNI IPs | Maximilian Hils | 2015-09-18 | 1 | -2/+9 |
| | | | | | | fixes mitmproxy/mitmproxy#772 We must use the ipaddress package here, because that's what cryptography uses. If we opt for something else, we have nasty namespace conflicts. | ||||
* | add distinct error for cert verification issues | Maximilian Hils | 2015-07-24 | 1 | -2/+0 |
| | |||||
* | remove certffi | Maximilian Hils | 2015-06-26 | 1 | -6/+0 |
| | |||||
* | mark unused variables and arguments | Thomas Kriechbaumer | 2015-06-18 | 1 | -1/+1 |
| | |||||
* | Adjust pep8 parameters, reformat | Aldo Cortesi | 2015-05-30 | 1 | -18/+57 |
| | |||||
* | Satisfy autobots. | Aldo Cortesi | 2015-05-28 | 1 | -1/+2 |
| | |||||
* | Merge branch 'Kriechi-cleanup' | Aldo Cortesi | 2015-05-28 | 1 | -23/+45 |
|\ | |||||
| * | cleanup code with autopep8 | Thomas Kriechbaumer | 2015-05-27 | 1 | -24/+32 |
| | | | | | | | | run the following command: $ autopep8 -i -r -a -a . | ||||
* | | update TLS defaults: signature hash and DH params | Thomas Kriechbaumer | 2015-05-27 | 1 | -11/+21 |
|/ | | | | | * SHA1 is deprecated (use SHA256) * increase RSA key to 2048 bits * increase DH params to 4096 bits (LogJam attack) | ||||
* | fix code smell | Maximilian Hils | 2015-04-09 | 1 | -2/+2 |
| | |||||
* | ...two years is not enough. | Maximilian Hils | 2015-02-17 | 1 | -2/+2 |
| | |||||
* | 5 years is enough... | Aldo Cortesi | 2015-02-17 | 1 | -1/+1 |
| | |||||
* | By popular demand, bump dummy cert expiry to 5 years | Aldo Cortesi | 2015-02-17 | 1 | -1/+1 |
| | | | | fixes #52 | ||||
* | clean up code | Maximilian Hils | 2014-10-09 | 1 | -36/+37 |
| | |||||
* | CertStore: add support for cert chains | Maximilian Hils | 2014-10-08 | 1 | -29/+41 |
| | |||||
* | Merge pull request #34 from bbaetz/master | Aldo Cortesi | 2014-09-07 | 1 | -4/+4 |
|\ | | | | | Change the criticality of a number of X509 extentions, to match | ||||
| * | Change the criticality of a number of X509 extentions, to match | Bradley Baetz | 2014-03-20 | 1 | -4/+4 |
| | | | | | | | | | | | | the RFCs and real-world CAs/certs. This improve compatability with older browsers/clients. | ||||
* | | make inequality comparison work | Maximilian Hils | 2014-09-04 | 1 | -0/+3 |
| | | |||||
* | | minor cleanups | Maximilian Hils | 2014-08-16 | 1 | -12/+3 |
| | | |||||
* | | certstore: add support for asterisk form to DNTree replacement | Maximilian Hils | 2014-07-19 | 1 | -1/+18 |
| | | |||||
* | | temporarily replace DNTree with a simpler cert lookup mechanism, fix ↵ | Maximilian Hils | 2014-07-18 | 1 | -46/+53 |
| | | | | | | | | mitmproxy/mitmproxy#295 | ||||
* | | mark nsCertType non-critical, fix #39 | Maximilian Hils | 2014-06-29 | 1 | -1/+1 |
| | | |||||
* | | Update certutils.py | Maximilian Hils | 2014-04-25 | 1 | -1/+1 |
|/ | | | refs mitmproxy/mitmproxy#200 | ||||
* | create dhparam file if it doesn't exist, fix mitmproxy/mitmproxy#235 | Maximilian Hils | 2014-03-11 | 1 | -0/+7 |
| | |||||
* | Certificate flags | Aldo Cortesi | 2014-03-10 | 1 | -0/+7 |
| | |||||
* | Support Ephemeral Diffie-Hellman | Aldo Cortesi | 2014-03-07 | 1 | -5/+19 |
| | |||||
* | CertStore: cope with certs that have no common name | Aldo Cortesi | 2014-03-05 | 1 | -3/+4 |
| | |||||
* | Much more sophisticated certificate store | Aldo Cortesi | 2014-03-05 | 1 | -12/+75 |
| | | | | | | | - Handle wildcard lookup - Handle lookup of SANs - Provide hooks for registering override certs and keys for specific domains (including wildcard specifications) | ||||
* | Beef up CertStore, add DH params. | Aldo Cortesi | 2014-03-04 | 1 | -72/+85 |
| | |||||
* | Minor improvement to CertStore interface | Aldo Cortesi | 2014-03-02 | 1 | -5/+4 |
| | |||||
* | move StateObject back into libmproxy | Maximilian Hils | 2014-01-31 | 1 | -11/+1 |
| | |||||
* | remove subclassing of tuple in tcp.Address, move StateObject into netlib | Maximilian Hils | 2014-01-30 | 1 | -1/+11 |
| | |||||
* | add tcp.Address to unify ipv4/ipv6 address handling | Maximilian Hils | 2014-01-28 | 1 | -1/+1 |
| | |||||
* | Make certificate not-before time 48 hours. | Aldo Cortesi | 2014-01-08 | 1 | -1/+1 |
| | | | | Fixes #200 | ||||
* | Domain checks for persistent cert store is now irrelevant. | Aldo Cortesi | 2013-12-08 | 1 | -14/+0 |
| | | | | | We no longer store these on disk, so we don't care about path components. | ||||
* | Merge pull request #22 from fictivekin/custom-o-cn | Aldo Cortesi | 2013-12-07 | 1 | -6/+9 |
|\ | | | | | allow specification of o, cn, expiry | ||||
| * | allow specification of o, cn, expiry | Sean Coates | 2013-10-07 | 1 | -6/+9 |
| | | |||||
* | | remove tempfile and shutil imports because they're not actually used | Sean Coates | 2013-10-07 | 1 | -1/+1 |
|/ | |||||
* | Don't create a certificate request when creating a dummy cert | Paul | 2013-09-24 | 1 | -10/+2 |
| | |||||
* | Revamp dummy cert generation. | Aldo Cortesi | 2013-08-12 | 1 | -32/+13 |
| | | | | We no longer use on-disk storage - we just keep the certs in memory. | ||||
* | always read files in binary mode | Maximilian Hils | 2013-06-16 | 1 | -6/+6 |
| | |||||
* | Add a request_client_cert argument to server SSL conversion. | Aldo Cortesi | 2013-05-13 | 1 | -3/+0 |
| | | | | | | | | | | By default, we now do not request the client cert. We're supposed to be able to do this with no negative effects - if the client has no cert to present, we're notified and proceed as usual. Unfortunately, Android seems to have a bug (tested on 4.2.2) - when an Android client is asked to present a certificate it does not have, it hangs up, which is frankly bogus. Some time down the track we may be able to make the proper behaviour the default again, but until then we're conservative. | ||||
* | extensions aren't supported in v1, set to v3 (value=2) if using them. | Tim Becker | 2013-04-19 | 1 | -0/+1 |
| | |||||
* | Housekeeping and cleanup, some minor argument name changes. | Aldo Cortesi | 2013-02-24 | 1 | -1/+0 |
| | |||||
* | More accurate description of an HTTP read error, make pyflakes happy. | Aldo Cortesi | 2013-02-24 | 1 | -1/+1 |
| | |||||
* | Beef up client certificate handling substantially. | Aldo Cortesi | 2013-01-20 | 1 | -3/+3 |
| |