platform/upstream/openconnect.git
14 years agoAdmit --useragent option
David Woodhouse [Tue, 4 Aug 2009 19:18:03 +0000 (20:18 +0100)]
Admit --useragent option

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
14 years agoAdmit CSD support
David Woodhouse [Tue, 4 Aug 2009 19:17:26 +0000 (20:17 +0100)]
Admit CSD support

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
14 years agoMerge branch 'master' of git://git.infradead.org/~ediap/openconnect-csd2
David Woodhouse [Tue, 4 Aug 2009 19:14:06 +0000 (20:14 +0100)]
Merge branch 'master' of git://git.infradead.org/~ediap/openconnect-csd2

14 years agoSupport cookies in a CSD way
Antonio Borneo [Sun, 2 Aug 2009 18:26:43 +0000 (20:26 +0200)]
Support cookies in a CSD way

Signed-off-by: Antonio Borneo <borneo.antonio@gmail.com>
14 years agoUse common implementation for get_cert_XYZ_fingerprint() functions
Adam Piątyszek [Sun, 2 Aug 2009 18:24:58 +0000 (20:24 +0200)]
Use common implementation for get_cert_XYZ_fingerprint() functions

Specialized functions get_gert_md5_fingerprint() and
get_cert_sha1_fingerprint() call get_cert_fingerprint() function.

Signed-off-by: Adam Piątyszek <ediap@users.sourceforge.net>
14 years agoPass MD5 fingerprints of client/server certificates to the CSD script
Adam Piątyszek [Sun, 2 Aug 2009 17:20:32 +0000 (19:20 +0200)]
Pass MD5 fingerprints of client/server certificates to the CSD script

Signed-off-by: Adam Piątyszek <ediap@users.sourceforge.net>
14 years agoCode refactoring (get_cert_fingerprint -> get_cert_sha1_fingerprint)
Adam Piątyszek [Sun, 2 Aug 2009 17:32:08 +0000 (19:32 +0200)]
Code refactoring (get_cert_fingerprint -> get_cert_sha1_fingerprint)

Signed-off-by: Adam Piątyszek <ediap@users.sourceforge.net>
14 years agoMinor fixes of quotation marks in CSD script arguments
Adam Piątyszek [Tue, 21 Jul 2009 09:53:05 +0000 (11:53 +0200)]
Minor fixes of quotation marks in CSD script arguments

Signed-off-by: Adam Piątyszek <ediap@users.sourceforge.net>
14 years agoFix most arguments to csd script
David Woodhouse [Tue, 21 Jul 2009 09:19:48 +0000 (10:19 +0100)]
Fix most arguments to csd script

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
14 years agoquick hack to handle refresh
David Woodhouse [Tue, 21 Jul 2009 08:52:49 +0000 (09:52 +0100)]
quick hack to handle refresh

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
14 years agoFix double free of stuburl
David Woodhouse [Tue, 21 Jul 2009 08:52:28 +0000 (09:52 +0100)]
Fix double free of stuburl

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
14 years agoUse redirect handling for form action and csd
David Woodhouse [Tue, 21 Jul 2009 08:20:14 +0000 (09:20 +0100)]
Use redirect handling for form action and csd

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
14 years agoDelete CSD script after authentication, use CSD only once
David Woodhouse [Tue, 21 Jul 2009 08:16:02 +0000 (09:16 +0100)]
Delete CSD script after authentication, use CSD only once

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
14 years agofix csd script running
David Woodhouse [Tue, 21 Jul 2009 08:06:41 +0000 (09:06 +0100)]
fix csd script running

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
14 years agoRemove leading '/' from csd_stuburl and csd_waiturl strings
Adam Piątyszek [Tue, 4 Aug 2009 12:05:40 +0000 (14:05 +0200)]
Remove leading '/' from csd_stuburl and csd_waiturl strings

This was necessary, because of connection errors when using:
"xxx.yyy.com//CACHE/sdesktop/install/binaries/sfinst"
FIXME: this should be implemented in a more generic way!

Signed-off-by: Adam Piątyszek <ediap@users.sourceforge.net>
14 years agoDo not overwrite the csd_token and csd_ticket strings
Adam Piątyszek [Tue, 4 Aug 2009 12:04:22 +0000 (14:04 +0200)]
Do not overwrite the csd_token and csd_ticket strings

Signed-off-by: Adam Piątyszek <ediap@users.sourceforge.net>
14 years agoDouble the buffer size to 128KB
Adam Piątyszek [Tue, 4 Aug 2009 12:02:49 +0000 (14:02 +0200)]
Double the buffer size to 128KB

The downloaded CSD package has almost 69KB, so 64KB was not enough.

Signed-off-by: Adam Piątyszek <ediap@users.sourceforge.net>
14 years agoFix default useragent string
David Woodhouse [Tue, 4 Aug 2009 11:17:36 +0000 (12:17 +0100)]
Fix default useragent string

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
14 years agoSelect User-Agent field
Antonio Borneo [Tue, 4 Aug 2009 11:15:41 +0000 (12:15 +0100)]
Select User-Agent field

Cisco device logs User-Agent: string, as explained in
http://www.cisco.com/en/US/docs/security/vpn_client/anyconnect/anyconnect23/release/notes/anyconnect23rn.html#wp908512
This patch let you change OpenConnect default User-Agent: string from
command line.

e.g. --useragent 'Cisco AnyConnect VPN Agent for Windows 2.2.0133'

Signed-off-by: Antonio Borneo <borneo.antonio@gmail.com>
Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoFirst attempt at CSD support
David Woodhouse [Mon, 20 Jul 2009 22:24:08 +0000 (23:24 +0100)]
First attempt at CSD support

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoAllow parse_xml_response to redirect
David Woodhouse [Mon, 20 Jul 2009 12:38:30 +0000 (13:38 +0100)]
Allow parse_xml_response to redirect

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoAdd mailing list
David Woodhouse [Mon, 20 Jul 2009 12:07:53 +0000 (13:07 +0100)]
Add mailing list

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoTag version 2.01 v2.01
David Woodhouse [Wed, 24 Jun 2009 17:30:34 +0000 (18:30 +0100)]
Tag version 2.01

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoUpdate changelog
David Woodhouse [Wed, 24 Jun 2009 17:29:50 +0000 (18:29 +0100)]
Update changelog

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoDon't clear vpninfo->dtls_cipher on CSTP reconnect
David Woodhouse [Tue, 23 Jun 2009 21:42:19 +0000 (22:42 +0100)]
Don't clear vpninfo->dtls_cipher on CSTP reconnect

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoDon't free certs while building chain
David Woodhouse [Tue, 16 Jun 2009 16:03:06 +0000 (17:03 +0100)]
Don't free certs while building chain

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoFix install target
David Woodhouse [Tue, 16 Jun 2009 14:03:42 +0000 (15:03 +0100)]
Fix install target

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoMention FreeBSD port
David Woodhouse [Tue, 16 Jun 2009 08:20:31 +0000 (09:20 +0100)]
Mention FreeBSD port

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoGive up permanently when no DTLS cipher; don't keep complaining
David Woodhouse [Wed, 10 Jun 2009 17:02:37 +0000 (18:02 +0100)]
Give up permanently when no DTLS cipher; don't keep complaining

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoDon't add duplicate certs
David Woodhouse [Thu, 4 Jun 2009 10:52:24 +0000 (11:52 +0100)]
Don't add duplicate certs

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoUse SSL_CTX_use_certificate_chain_file() to load extra certs too
David Woodhouse [Thu, 4 Jun 2009 10:45:07 +0000 (11:45 +0100)]
Use SSL_CTX_use_certificate_chain_file() to load extra certs too

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoTag version 2.00 v2.00
David Woodhouse [Wed, 3 Jun 2009 12:05:24 +0000 (13:05 +0100)]
Tag version 2.00

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoUpdate web page with tag
David Woodhouse [Wed, 3 Jun 2009 12:04:27 +0000 (13:04 +0100)]
Update web page with tag

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoAdd missing </LI> tags to changelog
David Woodhouse [Wed, 3 Jun 2009 11:32:52 +0000 (12:32 +0100)]
Add missing </LI> tags to changelog

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoUpdate changelog
David Woodhouse [Wed, 3 Jun 2009 11:08:01 +0000 (12:08 +0100)]
Update changelog

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoFix documentation for --servercert option
David Woodhouse [Wed, 3 Jun 2009 10:16:25 +0000 (11:16 +0100)]
Fix documentation for --servercert option

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoClean up Makefile detection of gtk/gconf, check for openssl includes
David Woodhouse [Wed, 3 Jun 2009 09:47:10 +0000 (10:47 +0100)]
Clean up Makefile detection of gtk/gconf, check for openssl includes

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoClean up warning seen on MacOS build
David Woodhouse [Wed, 3 Jun 2009 09:46:42 +0000 (10:46 +0100)]
Clean up warning seen on MacOS build

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoFix printf format for st_size
David Woodhouse [Wed, 3 Jun 2009 08:40:06 +0000 (09:40 +0100)]
Fix printf format for st_size

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoRemove GNUism from Makefile by printing new version in version.sh
David Woodhouse [Wed, 3 Jun 2009 08:37:09 +0000 (09:37 +0100)]
Remove GNUism from Makefile by printing new version in version.sh

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoClean up version.sh
David Woodhouse [Wed, 3 Jun 2009 08:05:09 +0000 (09:05 +0100)]
Clean up version.sh

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoRemove bashisms from version.sh
David Woodhouse [Tue, 2 Jun 2009 22:38:46 +0000 (23:38 +0100)]
Remove bashisms from version.sh

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoGrab focus on first widget which needs entry in the form
David Woodhouse [Tue, 2 Jun 2009 21:49:25 +0000 (22:49 +0100)]
Grab focus on first widget which needs entry in the form

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoAbort if certificate load fails, rather than continuing anyway
David Woodhouse [Tue, 2 Jun 2009 16:41:22 +0000 (17:41 +0100)]
Abort if certificate load fails, rather than continuing anyway

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoOnly save form entries if not cancelled.. and if they're non-NULL
David Woodhouse [Tue, 2 Jun 2009 16:35:47 +0000 (17:35 +0100)]
Only save form entries if not cancelled.. and if they're non-NULL

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoUse fingerprint for comparing certificates, not signature
David Woodhouse [Tue, 2 Jun 2009 16:26:28 +0000 (17:26 +0100)]
Use fingerprint for comparing certificates, not signature

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoupdate compatibility notes
David Woodhouse [Tue, 2 Jun 2009 12:20:21 +0000 (13:20 +0100)]
update compatibility notes

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agochangelog update
David Woodhouse [Tue, 2 Jun 2009 10:59:39 +0000 (11:59 +0100)]
changelog update

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoMore OpenSSL-0.9.7 compatibility
David Woodhouse [Tue, 2 Jun 2009 10:56:04 +0000 (11:56 +0100)]
More OpenSSL-0.9.7 compatibility

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoClean up certificate purpose workaround
David Woodhouse [Tue, 2 Jun 2009 10:54:41 +0000 (11:54 +0100)]
Clean up certificate purpose workaround

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoBuild against old OpenSSL without DTLS support (OSX, OpenBSD)
David Woodhouse [Tue, 2 Jun 2009 10:51:34 +0000 (11:51 +0100)]
Build against old OpenSSL without DTLS support (OSX, OpenBSD)

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoInclude <arpa/inet.h> for ntohl()
David Woodhouse [Mon, 1 Jun 2009 19:53:19 +0000 (20:53 +0100)]
Include <arpa/inet.h> for ntohl()

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoInclude appropriate headers for statfs() on FreeBSD and OSX
David Woodhouse [Mon, 1 Jun 2009 19:40:01 +0000 (20:40 +0100)]
Include appropriate headers for statfs() on FreeBSD and OSX

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoDiscard all but Legacy IP packets on VPN transmit
David Woodhouse [Mon, 1 Jun 2009 18:05:35 +0000 (19:05 +0100)]
Discard all but Legacy IP packets on VPN transmit

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoWeird tun prefix is only OpenBSD
David Woodhouse [Mon, 1 Jun 2009 17:58:57 +0000 (18:58 +0100)]
Weird tun prefix is only OpenBSD

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoHandle tun prefixing with AF_INET on BSD
David Woodhouse [Mon, 1 Jun 2009 17:41:46 +0000 (18:41 +0100)]
Handle tun prefixing with AF_INET on BSD

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoBuilds on OpenBSD
David Woodhouse [Mon, 1 Jun 2009 16:46:51 +0000 (17:46 +0100)]
Builds on OpenBSD

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoFix FSID handling on *BSD
David Woodhouse [Mon, 1 Jun 2009 16:41:47 +0000 (17:41 +0100)]
Fix FSID handling on *BSD

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoLink libcrypto
David Woodhouse [Mon, 1 Jun 2009 16:41:00 +0000 (17:41 +0100)]
Link libcrypto

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoAdd another missing <string.h>
David Woodhouse [Mon, 1 Jun 2009 16:23:30 +0000 (17:23 +0100)]
Add another missing <string.h>

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoMove ifr declaration inside Linux-only block
David Woodhouse [Mon, 1 Jun 2009 16:20:36 +0000 (17:20 +0100)]
Move ifr declaration inside Linux-only block

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoInclude <string.h> where needed
David Woodhouse [Mon, 1 Jun 2009 16:17:00 +0000 (17:17 +0100)]
Include <string.h> where needed

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agofix size_t printf format
David Woodhouse [Mon, 1 Jun 2009 16:16:14 +0000 (17:16 +0100)]
fix size_t printf format

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoNo need for bash
David Woodhouse [Mon, 1 Jun 2009 15:52:12 +0000 (16:52 +0100)]
No need for bash

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoInclude ctype.h for isspace()
David Woodhouse [Mon, 1 Jun 2009 15:47:26 +0000 (16:47 +0100)]
Include ctype.h for isspace()

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoMore include file fixes for OpenBSD
David Woodhouse [Mon, 1 Jun 2009 15:44:34 +0000 (16:44 +0100)]
More include file fixes for OpenBSD

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoRemove <sys/socket.h> from files which don't use it
David Woodhouse [Mon, 1 Jun 2009 15:41:42 +0000 (16:41 +0100)]
Remove <sys/socket.h> from files which don't use it

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoRevamp certificate/privkey command line handling
David Woodhouse [Mon, 1 Jun 2009 14:37:41 +0000 (15:37 +0100)]
Revamp certificate/privkey command line handling

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoClean up detection of TPM vs. PEM certificates
David Woodhouse [Mon, 1 Jun 2009 13:58:53 +0000 (14:58 +0100)]
Clean up detection of TPM vs. PEM certificates

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoSplit out load_tpm_certificate()
David Woodhouse [Mon, 1 Jun 2009 13:08:37 +0000 (14:08 +0100)]
Split out load_tpm_certificate()

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoHandle detection of PKCS#12 certificates a bit better
David Woodhouse [Mon, 1 Jun 2009 13:07:18 +0000 (14:07 +0100)]
Handle detection of PKCS#12 certificates a bit better

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agochangelog update
David Woodhouse [Mon, 1 Jun 2009 00:14:50 +0000 (01:14 +0100)]
changelog update

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoUse correct get_issuer() function
David Woodhouse [Mon, 1 Jun 2009 00:14:02 +0000 (01:14 +0100)]
Use correct get_issuer() function

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoAsk for PKCS#12 passphrase if we need it
David Woodhouse [Sun, 31 May 2009 21:18:43 +0000 (22:18 +0100)]
Ask for PKCS#12 passphrase if we need it

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoOnly use issuer certificate if X509_STORE_CTX_get1_issuer() succeeded.
David Woodhouse [Sun, 31 May 2009 20:39:09 +0000 (21:39 +0100)]
Only use issuer certificate if X509_STORE_CTX_get1_issuer() succeeded.

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoWork around OpenSSL bug with certificate chains.
David Woodhouse [Sun, 31 May 2009 19:00:16 +0000 (20:00 +0100)]
Work around OpenSSL bug with certificate chains.

This will probably be RT#1942 -- OpenSSL will look up issuer
certificates by name, but there might be more than one certificate in
the trust chain with the same name, and it doesn't make sure it gets the
right one. The server suffers this bug too, which is why the client has
to submit the full trust chain with its own certificate.

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoInclude only useful certificates from PKCS#12 file
David Woodhouse [Sun, 31 May 2009 18:38:27 +0000 (19:38 +0100)]
Include only useful certificates from PKCS#12 file

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoAdd PKCS#12 support
David Woodhouse [Sun, 31 May 2009 14:33:56 +0000 (15:33 +0100)]
Add PKCS#12 support

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoAdd option to generate PEM passphrase from fsid
David Woodhouse [Thu, 28 May 2009 19:24:53 +0000 (20:24 +0100)]
Add option to generate PEM passphrase from fsid

This is entirely stupid; some corporations have a policy which requires
that we make some token effort to 'prevent' people from moving
certificates from machine to machine -- even if it's trivially
bypassable.

So they accept idiotic nonsense like the 'non-exportable' flag in the
Windows certificate store (despite the existence of tools like Jailbreak
http://www.isecpartners.com/jailbreak.html) and they accept this stupid
trick to use a passphrase which is taken from the file system's fsid --
on the basis that if you copy the certificate file to another machine,
the fsid will be different and you might actually have to sober up and
spend more than 5 seconds thinking about it before you can use the
copied certificate.

Obviously you lose the protection of a _real_ passphrase, but that was
redundant anyway in the case where they use two-stage authentication and
ask for a RADIUS password after your certificate is accepted.

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoAllow PEM passphrase to be set on command line
David Woodhouse [Thu, 28 May 2009 16:09:41 +0000 (17:09 +0100)]
Allow PEM passphrase to be set on command line

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoTag version 1.40 v1.40
David Woodhouse [Wed, 27 May 2009 12:54:51 +0000 (13:54 +0100)]
Tag version 1.40

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoupdate changelog for 1.40
David Woodhouse [Wed, 27 May 2009 12:54:30 +0000 (13:54 +0100)]
update changelog for 1.40

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoRetry passphrase entry when it's wrong
David Woodhouse [Wed, 27 May 2009 10:38:55 +0000 (11:38 +0100)]
Retry passphrase entry when it's wrong

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoReport SSL errors through vpninfo->progress()
David Woodhouse [Wed, 27 May 2009 10:19:50 +0000 (11:19 +0100)]
Report SSL errors through vpninfo->progress()

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoFix double-free of vpninfo->dtls_cipher
David Woodhouse [Wed, 27 May 2009 08:41:28 +0000 (09:41 +0100)]
Fix double-free of vpninfo->dtls_cipher

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoPass only the signature of the server's cert from NetworkManager.
David Woodhouse [Tue, 26 May 2009 18:00:21 +0000 (19:00 +0100)]
Pass only the signature of the server's cert from NetworkManager.

Since we run openconnect as an unprivileged user, it may not be able to
read the original trust chain and validate the certificate for itself.
But since the auth-dialog has already connected to the server and done
the authentication, it can just give us the known signature for the
certificate the server is using today...

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoReconnect after SSL write fails
David Woodhouse [Tue, 26 May 2009 17:59:58 +0000 (18:59 +0100)]
Reconnect after SSL write fails

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoTag version 1.30 v1.30
David Woodhouse [Wed, 13 May 2009 12:46:22 +0000 (13:46 +0100)]
Tag version 1.30

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agochangelog for 1.30 release
David Woodhouse [Wed, 13 May 2009 12:46:12 +0000 (13:46 +0100)]
changelog for 1.30 release

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoAdd changelog entry for form saving
David Woodhouse [Sun, 10 May 2009 23:05:16 +0000 (00:05 +0100)]
Add changelog entry for form saving

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoHandle dependencies on stuff like gconf/gtk better.
David Woodhouse [Sun, 10 May 2009 09:28:33 +0000 (10:28 +0100)]
Handle dependencies on stuff like gconf/gtk better.

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoAvoid duplicate form entries, especially in wrong order
David Woodhouse [Sat, 9 May 2009 16:45:37 +0000 (17:45 +0100)]
Avoid duplicate form entries, especially in wrong order

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoRemember form entries
David Woodhouse [Sat, 9 May 2009 16:16:12 +0000 (17:16 +0100)]
Remember form entries

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoEnsure prompt overrides are honoured for default selection
David Woodhouse [Sat, 9 May 2009 15:43:24 +0000 (16:43 +0100)]
Ensure prompt overrides are honoured for default selection

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoUse form answers from gconf
David Woodhouse [Sat, 9 May 2009 15:23:48 +0000 (16:23 +0100)]
Use form answers from gconf

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoAllow default settings for UI form elements to be set
David Woodhouse [Sat, 9 May 2009 15:14:40 +0000 (16:14 +0100)]
Allow default settings for UI form elements to be set

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoFix default result for combobox
David Woodhouse [Sat, 9 May 2009 15:13:49 +0000 (16:13 +0100)]
Fix default result for combobox

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoImport web page into git where it'll be easier to manage.
David Woodhouse [Sat, 9 May 2009 14:31:09 +0000 (15:31 +0100)]
Import web page into git where it'll be easier to manage.

Signed-off-by: David Woodhouse <dwmw2@infradead.org>
15 years agoFix up TODO list. We seem to have done everything that was in there before.
David Woodhouse [Sat, 9 May 2009 14:06:08 +0000 (15:06 +0100)]
Fix up TODO list. We seem to have done everything that was in there before.

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
15 years agoTag version 1.20 v1.20
David Woodhouse [Fri, 8 May 2009 18:56:06 +0000 (19:56 +0100)]
Tag version 1.20

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>