aboutsummaryrefslogtreecommitdiffstats
path: root/main/strongswan
Commit message (Collapse)AuthorAgeFilesLines
* main/strongswan: ikev1 grekeyTimo Teräs2015-07-142-1/+512
| | | | | | | interoperability fix to work with Alpine patched ipsec-tools (will probably be removed after a migration period) (cherry picked from commit 2a4023dfee4f68916ac96d02fc41874d7286d625)
* main/strongswan: rebuild against openssl 1.0.2cBartłomiej Piotrowski2015-07-031-1/+1
|
* main/strongswan: security upgrade to 5.3.2 (CVE-2015-4171)Timo Teräs2015-07-015-5/+972
| | | | and apply the quagga-nhrp required patches
* main/strongswan: security upgrade to 5.3.1 (CVE-2015-3991)Timo Teräs2015-06-041-10/+12
|
* main/strongswan: run as non-rootTimo Teräs2015-05-014-7/+57
| | | | | | | | | | | | Make charon use 'ipsec' user and group, and enable the libcap support as few capabilities need to be retained for configuring IPsec SAs in to kernel. This also introduces charon.initd which starts charon daemon only and uses swanctl for configuration. It is a little bit more light weight than running the 'starter' which seems to be deprecated. Also the config format is completely different, but more flexible and extensive.
* main/*: replace all sbin/runscript with sbin/openrc-runNatanael Copa2015-04-282-5/+5
|
* main/strongswan: upgrade to 5.3.0Timo Teräs2015-04-071-4/+4
|
* main/strongswan: security upgrade to 5.2.2 (CVE-2014-9221)Timo Teräs2015-01-301-5/+5
|
* main/strongswan: enable EAP TLSNatanael Copa2015-01-011-1/+2
|
* main/strongswan: linux-headers build fixNatanael Copa2015-01-011-1/+1
|
* main/strongswan: enable vici and swanctlTimo Teräs2014-08-201-1/+3
|
* main/strongswan: upgrade to 5.2.0Timo Teräs2014-08-061-6/+4
|
* main/strongswan: security upgrade to 5.1.3Timo Teräs2014-04-152-33/+5
| | | | fixes CVE-2014-2338 along with multiple bug fixes
* main/strongswan: define _GNU_SOURCENatanael Copa2014-02-241-3/+5
| | | | | | | | We need define _GNU_SOURCE for strndup and others. It has been fixed upstream. see http://wiki.strongswan.org/issues/516 But rather than apply the patches we simply add _GNU_SOURCE to CFLAGS for now.
* main/strongswan: fix from upstream for a segfaultNatanael Copa2014-02-172-1/+29
| | | | http://wiki.strongswan.org/issues/452
* main/strongswan: moved from testingNatanael Copa2014-02-052-0/+126