- Feb 27, 2019
-
-
Roger A. Light authored
-
- Feb 26, 2019
-
-
Nicolás Pernas Maradei authored
Some OpenSSL engines (selectable via tls_engine option) may require a password to make use of private keys created with them in the first place. The TPM engine for example, will require a password to access the underlying TPM's Storage Root Key (SRK), which is the root key of a hierarchy of keys associated with a TPM; it is generated within a TPM and is a non-migratable key. Each owned TPM contains a SRK, generated by the TPM at the request of the Owner. [1] By default, the engine will prompt the user to introduce the SRK password before any private keys created with the engine can be used. This could be inconvenient when running on an unattended system. Here's where the new tls_engine_kpass_sha option comes in handy. The user can specify a SHA1 hash of its engine private key password via command line or config file and it will be passed on to the engine directly. This commit adds support for both clients (libmosquitto) and broker. [1] https://goo.gl/qQoXBY Signed-off-by:
Nicolás Pernas Maradei <nicopernas@gmail.com>
-
Nicolás Pernas Maradei authored
Add same OpenSSL engine support to mosquitto (server side) previously added to client side only. Signed-off-by:Nicolás Pernas Maradei <nicopernas@gmail.com>
-
Nicolás Pernas Maradei authored
- Clients can now offload crypto tasks to an external crypto device through the OpenSSL ENGINE API. - The keyfiles can now be treated as PEM or ENGINE keys. - Two new functions were added to libmosquitto to set up the previously mentioned features. - Both mosquitto_sub and mosquitto_pub include support to turn on the mentioned features through command line options. Signed-off-by:Nicolás Pernas Maradei <nicopernas@gmail.com>
-
- Nov 13, 2018
-
-
Roger A. Light authored
-
Roger A. Light authored
-
- Nov 12, 2018
-
-
Roger A. Light authored
-
- Nov 09, 2018
-
-
Roger A. Light authored
-
Roger A. Light authored
-
- Nov 08, 2018
-
-
Roger A. Light authored
-
Roger A. Light authored
-
Roger A. Light authored
When using a TLS enabled websockets listener with "require_certificate" enabled, the mosquitto broker does not correctly verify client certificates. This is now fixed. All other security measures operate as expected, and in particular non-websockets listeners are not affected by this. Closes #996. Thanks to creising.
-
Roger A. Light authored
Affects the use of mosquitto_loop_read() and mosquitto_write(). Closes #990.
-
Roger A. Light authored
-
Roger A. Light authored
-
Roger A. Light authored
Closes #1015. Thanks to TabascoEye.
-
Roger A. Light authored
Closes #287. Thanks to Lovisa Johansson. Bug: https://github.com/eclipse/mosquitto/issues/287
-
- Nov 07, 2018
-
-
Roger A. Light authored
-
Roger A. Light authored
-
Iblis Lin authored
Signed-off-by:Iblis Lin <iblis@hs.ntnu.edu.tw>
-
Roger A. Light authored
Thanks to Ibrahim Koujar. Bug: https://github.com/eclipse/mosquitto/issues/1016
-
Abilio Marques authored
Signed-off-by:Abilio Marques <abiliojr@gmail.com>
-
Bernd Kuhls authored
Define of _GNU_SOURCE is needed to be able to use EAI_INPROGRESS in loop.c. This patch fixes a build error loop.c:334:17: error: ‘EAI_INPROGRESS’ undeclared (first use in this function) if(rc == EAI_INPROGRESS){ occuring with a glibc-2.27-based buildroot toolchain for sparc64 Target: sparc64-buildroot-linux-gnu [...] gcc version 6.4.0 (Buildroot 2018.05) Source: http://autobuild.buildroot.org/toolchains/tarballs/br-sparc64-full-2018.05.tar.bz2 Signed-off-by:Bernd Kuhls <bernd.kuhls@t-online.de>
-
Bartosz Taczała authored
Change-Id: Id01e2880aa5cadc0e93a46b95fe675e1938051fa Signed-off-by:Bartosz Taczała <bartosz.taczala@mobica.com>
-
Roger A. Light authored
Closes #7.
-
Roger A. Light authored
-
Roger A. Light authored
This should never happen, but just in case.
-
- Nov 03, 2018
-
-
Roger A. Light authored
- Don't remove apk database, closes #1011. - Install mosquitto_passwd, closes #1009.
-
- Oct 30, 2018
-
-
Roger A. Light authored
-
- Oct 27, 2018
-
-
Roger A. Light authored
https://github.com/docker-library/official-images/pull/4987#issuecomment-433570818 Revert to stderr logging. Use wget instead of curl. Don't redownload libuuid or libwebsockets.
-
- Oct 26, 2018
-
-
Roger A. Light authored
- Oct 25, 2018
-
-
Roger A. Light authored
Builds from source. Carries out security checks on downloads.
-
- Oct 24, 2018
-
-
majekw authored
Since dde005ef mosquito_pub is throwing error that 'threading support has not been compiled' when compiled using cmake. It looks like WITH_THREADING flag is not set at top level Makefile and used only in lib/ directory, so library is correctly compiled with threading. But for client this flag is undefined, so it gives error on '-l' option. This commit moves part related to WITH_THREADING flag out of lib/CMakeLists.txt to top levele CMakeLists.txt, so it could be accessible to all subdirectories. Signed-off-by:
Marek Wodzinski <majek@w7i.pl>
-
- Oct 23, 2018
-
-
Jonathan Hanson authored
Add a new dockerfile and associated files, to build from a source tarball, instead of installing a built and published Alpine APK package. Signed-off-by:Jonathan Hanson <jonathan@jonathan-hanson.org>
-
Roger A. Light authored
Fix memory leak that occurred if mosquitto_reconnect() was used when TLS errors were present. Closes #592. Thanks to smartdabao and aaronovz1.
-
Roger A. Light authored
-
- Oct 07, 2018
-
-
Roger A. Light authored
-
- Oct 03, 2018
-
-
Roger A. Light authored
-
Roger A. Light authored
-