qemu/crypto
Daniel P. Berrange 1d7b5b4afd crypto: add support for loading encrypted x509 keys
Make use of the QCryptoSecret object to support loading of
encrypted x509 keys. The optional 'passwordid' parameter
to the tls-creds-x509 object type, provides the ID of a
secret object instance that holds the decryption password
for the PEM file.

 # printf "123456" > mypasswd.txt
 # $QEMU \
    -object secret,id=sec0,filename=mypasswd.txt \
    -object tls-creds-x509,passwordid=sec0,id=creds0,\
            dir=/home/berrange/.pki/qemu,endpoint=server \
    -vnc :1,tls-creds=creds0

This requires QEMU to be linked to GNUTLS >= 3.1.11. If
GNUTLS is too old an error will be reported if an attempt
is made to pass a decryption password.

Reviewed-by: Eric Blake <eblake@redhat.com>
Signed-off-by: Daniel P. Berrange <berrange@redhat.com>
2015-12-18 16:25:08 +00:00
..
aes.c crypto: move built-in AES implementation into crypto/ 2015-07-07 12:04:13 +02:00
cipher-builtin.c crypto: add sanity checking of plaintext/ciphertext length 2015-10-22 19:03:08 +01:00
cipher-gcrypt.c crypto: add sanity checking of plaintext/ciphertext length 2015-10-22 19:03:08 +01:00
cipher-nettle.c crypto: add sanity checking of plaintext/ciphertext length 2015-10-22 19:03:08 +01:00
cipher.c crypto: allow use of nettle/gcrypt to be selected explicitly 2015-10-22 19:03:07 +01:00
desrfb.c crypto: move built-in D3DES implementation into crypto/ 2015-07-07 12:04:31 +02:00
hash.c crypto: introduce new module for computing hash digests 2015-07-07 12:04:07 +02:00
init.c crypto: allow use of nettle/gcrypt to be selected explicitly 2015-10-22 19:03:07 +01:00
Makefile.objs crypto: add QCryptoSecret object class for password/key handling 2015-12-18 16:25:08 +00:00
secret.c crypto: add QCryptoSecret object class for password/key handling 2015-12-18 16:25:08 +00:00
tlscreds.c crypto: avoid two coverity false positive error reports 2015-12-04 09:39:55 +03:00
tlscredsanon.c crypto: introduce new module for TLS anonymous credentials 2015-09-15 15:00:20 +01:00
tlscredspriv.h crypto: introduce new base module for TLS credentials 2015-09-15 14:47:37 +01:00
tlscredsx509.c crypto: add support for loading encrypted x509 keys 2015-12-18 16:25:08 +00:00
tlssession.c crypto: fix mistaken setting of Error in success code path 2015-11-18 14:56:58 +00:00