ach-master.git
5 years agofixed path for prosody (#81)
Aaron Zauner [Sun, 16 Nov 2014 15:34:57 +0000 (16:34 +0100)]
fixed path for prosody (#81)

5 years agopath was wrong
Aaron Kaplan [Mon, 10 Nov 2014 19:50:41 +0000 (20:50 +0100)]
path was wrong

5 years agoremoved the supporting older clients as requested by Adi .
Aaron Kaplan [Mon, 10 Nov 2014 19:44:18 +0000 (20:44 +0100)]
removed the supporting older clients as requested by Adi .
Why? Because the POODLE killed it ;-)
Older clients which do not support SNI can't speak TLSv1.0 and above.
We don't support SSLv3 anymore anyway.

5 years agoMerge github.com:BetterCrypto/Applied-Crypto-Hardening
Aaron Kaplan [Mon, 10 Nov 2014 19:11:16 +0000 (20:11 +0100)]
Merge github.com:BetterCrypto/Applied-Crypto-Hardening

5 years agominor
Aaron Kaplan [Mon, 10 Nov 2014 19:06:45 +0000 (20:06 +0100)]
minor

5 years agoremove tlsv1 exclusion
Aaron Zauner [Thu, 6 Nov 2014 19:09:23 +0000 (20:09 +0100)]
remove tlsv1 exclusion

5 years agoMerge pull request #82 from stasic/patch-3
AaronK [Thu, 6 Nov 2014 06:19:01 +0000 (07:19 +0100)]
Merge pull request #82 from stasic/patch-3

added ubuntu 14.10

5 years agoadded ubuntu 14.10
Arsen Stasic [Wed, 5 Nov 2014 19:49:25 +0000 (20:49 +0100)]
added ubuntu 14.10

5 years agoMerge pull request #80 from MeikoDis/master
Aaron Zauner [Wed, 5 Nov 2014 13:38:12 +0000 (14:38 +0100)]
Merge pull request #80 from MeikoDis/master

Adding prosody

5 years agoText adjusted.
MeikoDis [Wed, 5 Nov 2014 13:31:03 +0000 (13:31 +0000)]
Text adjusted.

5 years agoRecommended Cipherstring
MeikoDis [Wed, 5 Nov 2014 09:44:28 +0000 (09:44 +0000)]
Recommended Cipherstring

5 years agoRC4, SHA1 and MD5
MeikoDis [Wed, 5 Nov 2014 00:08:38 +0000 (00:08 +0000)]
RC4, SHA1 and MD5

5 years agoCorrection2
MeikoDis [Wed, 5 Nov 2014 00:03:42 +0000 (00:03 +0000)]
Correction2

5 years agoCorrection
MeikoDis [Tue, 4 Nov 2014 23:59:38 +0000 (23:59 +0000)]
Correction

5 years agoCiphers, curve and depth added
MeikoDis [Tue, 4 Nov 2014 23:54:14 +0000 (23:54 +0000)]
Ciphers, curve and depth added

5 years agoMerge branch 'master' of github.com:MeikoDis/Applied-Crypto-Hardening
MeikoDis [Tue, 4 Nov 2014 22:53:43 +0000 (22:53 +0000)]
Merge branch 'master' of github.com:MeikoDis/Applied-Crypto-Hardening

5 years agoMerge https://github.com/BetterCrypto/Applied-Crypto-Hardening
Aaron Zauner [Sun, 2 Nov 2014 00:00:35 +0000 (01:00 +0100)]
Merge https://github.com/BetterCrypto/Applied-Crypto-Hardening

5 years agoMerge pull request #77 from DigNative/master
Aaron Zauner [Sun, 2 Nov 2014 00:00:29 +0000 (01:00 +0100)]
Merge pull request #77 from DigNative/master

Document did not compile under Windows, typo fixes

5 years agoMerge https://github.com/DigNative/Applied-Crypto-Hardening
Aaron Zauner [Sat, 1 Nov 2014 23:59:51 +0000 (00:59 +0100)]
Merge https://github.com/DigNative/Applied-Crypto-Hardening

5 years agoMerge pull request #78 from chdorb/patch-1
Aaron Zauner [Sat, 1 Nov 2014 23:58:28 +0000 (00:58 +0100)]
Merge pull request #78 from chdorb/patch-1

Update webserver.tex

5 years agoMerge pull request #70 from blakefrantz/master
Aaron Zauner [Sat, 1 Nov 2014 23:57:51 +0000 (00:57 +0100)]
Merge pull request #70 from blakefrantz/master

fixed small typos in IIS section

5 years agoMerge pull request #71 from oparoz/patch-1
Aaron Zauner [Sat, 1 Nov 2014 23:56:23 +0000 (00:56 +0100)]
Merge pull request #71 from oparoz/patch-1

Wrong verb for HSTS header

5 years agoMerge pull request #79 from stasic/patch-2
AaronK [Tue, 28 Oct 2014 22:57:00 +0000 (23:57 +0100)]
Merge pull request #79 from stasic/patch-2

added freebsd 10
Thx Arsen!

5 years agoadded freebsd 10
Arsen Stasic [Tue, 28 Oct 2014 21:23:21 +0000 (22:23 +0100)]
added freebsd 10

added ssh signature for freebsd 10

5 years agoUpdate webserver.tex
chdorb [Thu, 23 Oct 2014 12:33:23 +0000 (14:33 +0200)]
Update webserver.tex

Just a little lack of conjugation.

5 years agoChange email address
David Durvaux [Wed, 22 Oct 2014 07:37:15 +0000 (09:37 +0200)]
Change email address

5 years agoadd all the things
Aaron Zauner [Tue, 21 Oct 2014 08:10:35 +0000 (10:10 +0200)]
add all the things

5 years agoadd summary paper on curves progress within CFRG
Aaron Zauner [Tue, 21 Oct 2014 07:57:01 +0000 (09:57 +0200)]
add summary paper on curves progress within CFRG

5 years agoadd slides on IETF
Aaron Zauner [Tue, 21 Oct 2014 07:55:01 +0000 (09:55 +0200)]
add slides on IETF

5 years agostill minor modifications
Aaron Kaplan [Mon, 20 Oct 2014 22:26:48 +0000 (00:26 +0200)]
still minor modifications

5 years agoreplace medical-test.jpg picture :)
Aaron Kaplan [Mon, 20 Oct 2014 22:12:36 +0000 (00:12 +0200)]
replace medical-test.jpg picture :)
minor changes to the text

5 years agookay, I think we are ready for the presentation tomorrow
Aaron Kaplan [Mon, 20 Oct 2014 21:59:56 +0000 (23:59 +0200)]
okay, I think we are ready for the presentation tomorrow

5 years agoMerge branch 'master' of https://git.bettercrypto.org/ach-master
Aaron Kaplan [Mon, 20 Oct 2014 21:52:30 +0000 (23:52 +0200)]
Merge branch 'master' of https://git.bettercrypto.org/ach-master

5 years agorestructure, last slides
Aaron Kaplan [Mon, 20 Oct 2014 21:52:15 +0000 (23:52 +0200)]
restructure, last slides

5 years agofinish attacks part
Aaron Zauner [Mon, 20 Oct 2014 21:48:26 +0000 (23:48 +0200)]
finish attacks part

5 years agoMerge branch 'master' of https://git.bettercrypto.org/ach-master
Aaron Kaplan [Mon, 20 Oct 2014 21:12:23 +0000 (23:12 +0200)]
Merge branch 'master' of https://git.bettercrypto.org/ach-master

5 years agomore images
Aaron Kaplan [Mon, 20 Oct 2014 21:12:06 +0000 (23:12 +0200)]
more images

5 years agomore slides
Aaron Kaplan [Mon, 20 Oct 2014 21:11:35 +0000 (23:11 +0200)]
more slides

5 years agoget rid of company logo
Aaron Zauner [Mon, 20 Oct 2014 21:02:50 +0000 (23:02 +0200)]
get rid of company logo

5 years agoadd slides for attacks (seperate)
Aaron Zauner [Mon, 20 Oct 2014 20:54:17 +0000 (22:54 +0200)]
add slides for attacks (seperate)

5 years agodoes not work... remove \input
Aaron Kaplan [Mon, 20 Oct 2014 20:39:50 +0000 (22:39 +0200)]
does not work... remove \input

5 years agoMerge branch 'master' of https://git.bettercrypto.org/ach-master
Aaron Kaplan [Mon, 20 Oct 2014 20:38:13 +0000 (22:38 +0200)]
Merge branch 'master' of https://git.bettercrypto.org/ach-master

5 years agoadd more slides
Aaron Kaplan [Mon, 20 Oct 2014 20:37:56 +0000 (22:37 +0200)]
add more slides

5 years agoinclude attack.tex in agenda.md
Aaron Zauner [Mon, 20 Oct 2014 20:33:32 +0000 (22:33 +0200)]
include attack.tex in agenda.md

5 years agoadd images
Aaron Kaplan [Mon, 20 Oct 2014 20:30:07 +0000 (22:30 +0200)]
add images

5 years agoMerge branch 'master' of https://git.bettercrypto.org/ach-master
Aaron Kaplan [Mon, 20 Oct 2014 20:29:36 +0000 (22:29 +0200)]
Merge branch 'master' of https://git.bettercrypto.org/ach-master

Conflicts:
presentations/HACK.LU-2014/presentation/agenda.md

5 years agomerge in David's changes and adapt
Aaron Kaplan [Mon, 20 Oct 2014 20:28:04 +0000 (22:28 +0200)]
merge in David's changes and adapt

5 years agoadd attacks.tex (still issues with compiling that though)
Aaron Zauner [Mon, 20 Oct 2014 20:27:11 +0000 (22:27 +0200)]
add attacks.tex (still issues with compiling that though)

5 years agoadd attacks.tex (still issues with compiling that though)
Aaron Zauner [Mon, 20 Oct 2014 20:26:53 +0000 (22:26 +0200)]
add attacks.tex (still issues with compiling that though)

5 years agoRemoving XXX
David Durvaux [Mon, 20 Oct 2014 20:25:07 +0000 (22:25 +0200)]
Removing XXX

5 years agoMerge branch 'master' of https://git.bettercrypto.org/ach-master
Aaron Kaplan [Mon, 20 Oct 2014 20:24:20 +0000 (22:24 +0200)]
Merge branch 'master' of https://git.bettercrypto.org/ach-master

5 years agomore slides
Aaron Kaplan [Mon, 20 Oct 2014 20:24:11 +0000 (22:24 +0200)]
more slides

5 years agoAdding history
David Durvaux [Mon, 20 Oct 2014 19:54:48 +0000 (21:54 +0200)]
Adding history

5 years agoadd comment in README: many small commits are better
Aaron Kaplan [Mon, 20 Oct 2014 16:07:58 +0000 (18:07 +0200)]
add comment in README: many small commits are better

5 years agoModifications after comment from @krono.
René Schwarz [Mon, 20 Oct 2014 06:11:59 +0000 (08:11 +0200)]
Modifications after comment from @krono.

5 years agointermediate version, add missing files
Aaron Kaplan [Sun, 19 Oct 2014 23:50:08 +0000 (01:50 +0200)]
intermediate version, add missing files

5 years agointermediate version for hack.lu
Aaron Kaplan [Sun, 19 Oct 2014 23:48:56 +0000 (01:48 +0200)]
intermediate version for hack.lu

5 years agoCorrecting typo in HACK.LU 2014 presentation: It's not `Diffie-Helleman`, it's `Diffi...
René Schwarz [Sun, 19 Oct 2014 21:12:40 +0000 (23:12 +0200)]
Correcting typo in HACK.LU 2014 presentation: It's not `Diffie-Helleman`, it's `Diffie-Hellman`.

5 years agoMerge remote-tracking branch 'remotes/upstream/master'
René Schwarz [Sun, 19 Oct 2014 21:06:55 +0000 (23:06 +0200)]
Merge remote-tracking branch 'remotes/upstream/master'

5 years agoMerge branch 'master' of https://git.bettercrypto.org/ach-master
Aaron Kaplan [Sun, 19 Oct 2014 20:58:07 +0000 (22:58 +0200)]
Merge branch 'master' of https://git.bettercrypto.org/ach-master

5 years agoDocument did not compile under Windows because `\lstinputlisting` was not able to...
René Schwarz [Sun, 19 Oct 2014 20:57:35 +0000 (22:57 +0200)]
Document did not compile under Windows because `\lstinputlisting` was not able to find files without extension (e.g. `configuration/Webservers/Apache/default-ssl`). Workaround is to add a dot at the end of the file name. This patch modifies the `\configfile` command to detect the platform via the `ifplatform` package and adds a dot at the end of all file names on Windows systems.

5 years agofirst commit for the hack.lu 2014 talk
Aaron Kaplan [Sun, 19 Oct 2014 20:57:13 +0000 (22:57 +0200)]
first commit for the hack.lu 2014 talk

5 years agogitignore
Aaron Kaplan [Sun, 19 Oct 2014 20:56:35 +0000 (22:56 +0200)]
gitignore

5 years agoMerge https://github.com/BetterCrypto/Applied-Crypto-Hardening
Aaron Zauner [Sun, 19 Oct 2014 16:16:41 +0000 (18:16 +0200)]
Merge https://github.com/BetterCrypto/Applied-Crypto-Hardening

5 years agoMerge pull request #75 from FireFart/dovecot
Aaron Zauner [Sun, 19 Oct 2014 16:16:12 +0000 (18:16 +0200)]
Merge pull request #75 from FireFart/dovecot

disable SSLv3 for Dovecot

5 years agoUpdate prosody.cfg.lua
Bandie [Sat, 18 Oct 2014 13:53:27 +0000 (13:53 +0000)]
Update prosody.cfg.lua

5 years agoI forgot to add me. :E
MeikoDis [Sat, 18 Oct 2014 08:17:43 +0000 (08:17 +0000)]
I forgot to add me. :E

5 years agoJabber server Prosody added
MeikoDis [Sat, 18 Oct 2014 07:48:55 +0000 (07:48 +0000)]
Jabber server Prosody added

5 years agorevert cipher list
Christian Mehlmauer [Sat, 18 Oct 2014 06:43:51 +0000 (08:43 +0200)]
revert cipher list

5 years agoadded tested system
Christian Mehlmauer [Fri, 17 Oct 2014 20:49:42 +0000 (22:49 +0200)]
added tested system

5 years agomore sslv3
Christian Mehlmauer [Fri, 17 Oct 2014 20:45:05 +0000 (22:45 +0200)]
more sslv3

5 years agoDisable SSLv3 for Dovecot
Christian Mehlmauer [Fri, 17 Oct 2014 20:42:55 +0000 (22:42 +0200)]
Disable SSLv3 for Dovecot

5 years ago+SSLv3 in the SSLCipherSuite, -SSLv3 in the SSLProtocol.
Aaron Kaplan [Fri, 17 Oct 2014 12:30:04 +0000 (14:30 +0200)]
+SSLv3 in the SSLCipherSuite, -SSLv3 in the SSLProtocol.
See the posting "The Poodle killed it" on the www.bettercrypto.org homepage

5 years agoReverted the "Revert "!SSLv3 damn it"" commit.
Aaron Kaplan [Fri, 17 Oct 2014 12:27:38 +0000 (14:27 +0200)]
Reverted the "Revert "!SSLv3 damn it"" commit.
Damn... I threw out too much. This was a decision on 7.7.

This reverts commit ab51c68aa63dea11cc1e019e68c3bb8917da891f.

5 years agoRevert "!SSLv3 damn it"
Aaron Kaplan [Fri, 17 Oct 2014 12:21:08 +0000 (14:21 +0200)]
Revert "!SSLv3 damn it"

This reverts commit baff2df8387234c4fe7d255cac07cf7f8307a634.

5 years agoRevert "no SSLv3 damn it"
Aaron Kaplan [Fri, 17 Oct 2014 12:21:07 +0000 (14:21 +0200)]
Revert "no SSLv3 damn it"

This reverts commit b62a01c3883767ad1f4af4b3b807423830ef915d.

5 years agoRevert "no SSLv3 damn it"
Aaron Kaplan [Fri, 17 Oct 2014 12:21:05 +0000 (14:21 +0200)]
Revert "no SSLv3 damn it"

This reverts commit 6ae00d390dd40343ecfd3607ae7475fc6896f6a7.

5 years agoRevert "no SSLv3 damn it"
Aaron Kaplan [Fri, 17 Oct 2014 12:21:05 +0000 (14:21 +0200)]
Revert "no SSLv3 damn it"

This reverts commit a4fed6e2245d31aca055f599617902a8a2deb2f4.

5 years agoRevert "no SSLv3 damn it"
Aaron Kaplan [Fri, 17 Oct 2014 12:21:04 +0000 (14:21 +0200)]
Revert "no SSLv3 damn it"

This reverts commit e8b61af0270bcd31ef55f35cebd1d0b3a35342ea.

5 years agoRevert "no SSLv3 damn it"
Aaron Kaplan [Fri, 17 Oct 2014 12:21:03 +0000 (14:21 +0200)]
Revert "no SSLv3 damn it"

This reverts commit 3cffbdde793d21fa93446f43a35d615bc21c8894.

5 years agoRevert "no SSLv3 damn it"
Aaron Kaplan [Fri, 17 Oct 2014 12:21:01 +0000 (14:21 +0200)]
Revert "no SSLv3 damn it"

This reverts commit 8b1a5f055fb9d436e7bb7b1325d632cc803b1123.

5 years agoRevert "no SSLv3 damn it"
Aaron Kaplan [Fri, 17 Oct 2014 12:20:59 +0000 (14:20 +0200)]
Revert "no SSLv3 damn it"

This reverts commit 4f7d76eb7d395b66cf12eab0c57b135c9f9277a0.

5 years agoRevert "!SSLv3 damn it"
Aaron Kaplan [Fri, 17 Oct 2014 12:19:06 +0000 (14:19 +0200)]
Revert "!SSLv3 damn it"

This reverts commit ab51c68aa63dea11cc1e019e68c3bb8917da891f.

5 years agoRevert "no SSLv3 damn it"
Aaron Kaplan [Fri, 17 Oct 2014 12:18:43 +0000 (14:18 +0200)]
Revert "no SSLv3 damn it"

This reverts commit 301c910000a27714a13ba7843c16379271a5ef7a.

5 years agono SSLv3 damn it
Aaron Kaplan [Fri, 17 Oct 2014 10:15:30 +0000 (12:15 +0200)]
no SSLv3 damn it

5 years agono SSLv3 damn it
Aaron Kaplan [Fri, 17 Oct 2014 10:14:43 +0000 (12:14 +0200)]
no SSLv3 damn it

5 years agono SSLv3 damn it
Aaron Kaplan [Fri, 17 Oct 2014 10:14:09 +0000 (12:14 +0200)]
no SSLv3 damn it

5 years agono SSLv3 damn it
Aaron Kaplan [Fri, 17 Oct 2014 10:14:01 +0000 (12:14 +0200)]
no SSLv3 damn it

5 years agono SSLv3 damn it
Aaron Kaplan [Fri, 17 Oct 2014 10:13:27 +0000 (12:13 +0200)]
no SSLv3 damn it

5 years agono SSLv3 damn it
Aaron Kaplan [Fri, 17 Oct 2014 10:10:49 +0000 (12:10 +0200)]
no SSLv3 damn it

5 years agono SSLv3 damn it
Aaron Kaplan [Fri, 17 Oct 2014 10:10:13 +0000 (12:10 +0200)]
no SSLv3 damn it

5 years agono SSLv3 damn it
Aaron Kaplan [Fri, 17 Oct 2014 10:09:25 +0000 (12:09 +0200)]
no SSLv3 damn it

5 years ago!SSLv3 damn it
Aaron Kaplan [Fri, 17 Oct 2014 10:08:29 +0000 (12:08 +0200)]
!SSLv3 damn it

5 years ago!SSLv3 damn it
Aaron Kaplan [Fri, 17 Oct 2014 09:56:15 +0000 (11:56 +0200)]
!SSLv3 damn it

5 years agoMerge branch 'master' of https://git.bettercrypto.org/ach-master
Aaron Kaplan [Fri, 17 Oct 2014 09:47:46 +0000 (11:47 +0200)]
Merge branch 'master' of https://git.bettercrypto.org/ach-master

5 years agocore presentation hack.lu
David Durvaux [Wed, 15 Oct 2014 16:35:19 +0000 (18:35 +0200)]
core presentation hack.lu

5 years agoMerge branch 'master' of https://git.bettercrypto.org/ach-master
Aaron Kaplan [Thu, 9 Oct 2014 09:09:19 +0000 (11:09 +0200)]
Merge branch 'master' of https://git.bettercrypto.org/ach-master

5 years agominor changes
Aaron Kaplan [Thu, 9 Oct 2014 09:09:06 +0000 (11:09 +0200)]
minor changes

5 years agoMerge pull request #73 from oe1rfc/master
Aaron Zauner [Mon, 6 Oct 2014 00:17:08 +0000 (02:17 +0200)]
Merge pull request #73 from oe1rfc/master

nginx/https-redirect: redirect to request domain, ditch regex

5 years agonginx/https-redirect: use return instead of rewrite regex, $host instead of $server_name
Clemens Hopfer [Sun, 5 Oct 2014 18:55:46 +0000 (20:55 +0200)]
nginx/https-redirect: use return instead of rewrite regex, $host instead of $server_name