1. Feb 27, 2019
  2. Feb 26, 2019
    • Nicolás Pernas Maradei's avatar
      Add engine private key password support · 20894fcb
      Nicolás Pernas Maradei authored
      Some OpenSSL engines (selectable via tls_engine option) may require a
      password to make use of private keys created with them in the first place.
      
      The TPM engine for example, will require a password to access the underlying
      TPM's Storage Root Key (SRK), which is the root key of a hierarchy of keys
      associated with a TPM; it is generated within a TPM and is a non-migratable
      key. Each owned TPM contains a SRK, generated by the TPM at the request
      of the Owner. [1]
      
      By default, the engine will prompt the user to introduce the SRK password
      before any private keys created with the engine can be used. This could
      be inconvenient when running on an unattended system.
      
      Here's where the new tls_engine_kpass_sha option comes in handy. The user
      can specify a SHA1 hash of its engine private key password via command
      line or config file and it will be passed on to the engine directly.
      
      This commit adds support for both clients (libmosquitto) and broker.
      
      [1] https://goo.gl/qQoXBY
      
      
      
      Signed-off-by: default avatarNicolás Pernas Maradei <nicopernas@gmail.com>
      20894fcb
    • Nicolás Pernas Maradei's avatar
      Add TLS engine and keyform support to mosquitto · d5f039ec
      Nicolás Pernas Maradei authored
      
      
      Add same OpenSSL engine support to mosquitto (server side) previously added to
      client side only.
      
      Signed-off-by: default avatarNicolás Pernas Maradei <nicopernas@gmail.com>
      d5f039ec
    • Nicolás Pernas Maradei's avatar
      Add TLS engine and keyform support to libmosquitto · f88cc064
      Nicolás Pernas Maradei authored
      
      
      - Clients can now offload crypto tasks to an external crypto device through
        the OpenSSL ENGINE API.
      - The keyfiles can now be treated as PEM or ENGINE keys.
      - Two new functions were added to libmosquitto to set up the previously
        mentioned features.
      - Both mosquitto_sub and mosquitto_pub include support to turn on the mentioned
        features through command line options.
      
      Signed-off-by: default avatarNicolás Pernas Maradei <nicopernas@gmail.com>
      f88cc064
  3. Nov 13, 2018
  4. Nov 12, 2018
  5. Nov 09, 2018
  6. Nov 08, 2018
  7. Nov 07, 2018
  8. Nov 03, 2018
    • Roger A. Light's avatar
      Docker fixes. · da2879c3
      Roger A. Light authored
      - Don't remove apk database, closes #1011.
      - Install mosquitto_passwd, closes #1009.
      da2879c3
  9. Oct 30, 2018
  10. Oct 27, 2018
  11. Oct 26, 2018
  12. Oct 25, 2018
  13. Oct 24, 2018
    • majekw's avatar
      Fix mosquitto_pub -l if compiled using cmake. · 7f1419e4
      majekw authored
      Since dde005ef
      
       mosquito_pub is throwing error
      that 'threading support has not been compiled' when compiled using cmake.
      It looks like WITH_THREADING flag is not set at top level Makefile and used
      only in lib/ directory, so library is correctly compiled with threading.
      But for client this flag is undefined, so it gives error on '-l' option.
      
      This commit moves part related to WITH_THREADING flag out of lib/CMakeLists.txt
      to top levele CMakeLists.txt, so it could be accessible to all subdirectories.
      
      Signed-off-by: default avatarMarek Wodzinski <majek@w7i.pl>
      7f1419e4
  14. Oct 23, 2018
  15. Oct 07, 2018
  16. Oct 03, 2018