<feed xmlns='http://www.w3.org/2005/Atom'>
<title>tteras/strongswan/src/libcharon/plugins/eap_tnc, branch master</title>
<subtitle>tteras' strongSwan tree
</subtitle>
<id>https://git-old.alpinelinux.org/user/tteras/strongswan/atom?h=master</id>
<link rel='self' href='https://git-old.alpinelinux.org/user/tteras/strongswan/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git-old.alpinelinux.org/user/tteras/strongswan/'/>
<updated>2016-03-03T16:36:11Z</updated>
<entry>
<title>libhydra: Remove empty unused library</title>
<updated>2016-03-03T16:36:11Z</updated>
<author>
<name>Tobias Brunner</name>
<email>tobias@strongswan.org</email>
</author>
<published>2016-02-12T15:35:54Z</published>
<link rel='alternate' type='text/html' href='https://git-old.alpinelinux.org/user/tteras/strongswan/commit/?id=28649f6d91971e0fe50078aec2937010e8c61cd8'/>
<id>urn:sha1:28649f6d91971e0fe50078aec2937010e8c61cd8</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Fix of the mutual TNC measurement use case</title>
<updated>2016-02-16T17:00:27Z</updated>
<author>
<name>Andreas Steffen</name>
<email>andreas.steffen@strongswan.org</email>
</author>
<published>2016-02-16T17:00:27Z</published>
<link rel='alternate' type='text/html' href='https://git-old.alpinelinux.org/user/tteras/strongswan/commit/?id=4d83c5b4a6bcbf6a6426d7ba79fac4494ab36329'/>
<id>urn:sha1:4d83c5b4a6bcbf6a6426d7ba79fac4494ab36329</id>
<content type='text'>
If the IKEv2 initiator acting as a TNC server receives invalid TNC measurements
from the IKEv2 responder acting as a TNC clienti, the exchange of PB-TNC batches
is continued until the IKEv2 responder acting as a TNC server has also finished
its TNC measurements.

In the past if these measurements in the other direction were correct
the IKEv2 responder acting as EAP server declared the IKEv2 EAP authentication
successful and the IPsec connection was established even though the TNC
measurement verification on the EAP peer side failed.

The fix adds an "allow" group membership on each endpoint if the corresponding
TNC measurements of the peer are successful. By requiring a "allow" group
membership in the IKEv2 connection definition the IPsec connection succeeds
only if the TNC measurements on both sides are valid.
</content>
</entry>
<entry>
<title>Fixed AR identities in mutual TNC measurements case</title>
<updated>2015-08-15T20:46:21Z</updated>
<author>
<name>Andreas Steffen</name>
<email>andreas.steffen@strongswan.org</email>
</author>
<published>2015-08-15T20:46:21Z</published>
<link rel='alternate' type='text/html' href='https://git-old.alpinelinux.org/user/tteras/strongswan/commit/?id=a330f72ecfd4b798efa0d4db63a7f4917e29e8be'/>
<id>urn:sha1:a330f72ecfd4b798efa0d4db63a7f4917e29e8be</id>
<content type='text'>
</content>
</entry>
<entry>
<title>eap-tnc: Free eap-tnc object if IKE_SA not found to get IPs</title>
<updated>2015-03-25T12:24:37Z</updated>
<author>
<name>Tobias Brunner</name>
<email>tobias@strongswan.org</email>
</author>
<published>2015-03-25T12:24:37Z</published>
<link rel='alternate' type='text/html' href='https://git-old.alpinelinux.org/user/tteras/strongswan/commit/?id=328db935bb16a17654a66bc4e8a1f3365153b23e'/>
<id>urn:sha1:328db935bb16a17654a66bc4e8a1f3365153b23e</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Make access requestor IP address available to TNC server</title>
<updated>2015-03-08T16:17:11Z</updated>
<author>
<name>Andreas Steffen</name>
<email>andreas.steffen@strongswan.org</email>
</author>
<published>2015-02-19T10:44:11Z</published>
<link rel='alternate' type='text/html' href='https://git-old.alpinelinux.org/user/tteras/strongswan/commit/?id=00cd79b6780acf1d2682038cb630e6871782f819'/>
<id>urn:sha1:00cd79b6780acf1d2682038cb630e6871782f819</id>
<content type='text'>
</content>
</entry>
<entry>
<title>plugins: Don't link with -rdynamic on Windows</title>
<updated>2014-06-04T13:53:02Z</updated>
<author>
<name>Martin Willi</name>
<email>martin@revosec.ch</email>
</author>
<published>2013-10-25T14:03:47Z</published>
<link rel='alternate' type='text/html' href='https://git-old.alpinelinux.org/user/tteras/strongswan/commit/?id=4163421f918d830585bfdccde0973d8801aad258'/>
<id>urn:sha1:4163421f918d830585bfdccde0973d8801aad258</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Implemented PT-EAP protocol (RFC 7171)</title>
<updated>2014-05-12T04:59:21Z</updated>
<author>
<name>Andreas Steffen</name>
<email>andreas.steffen@strongswan.org</email>
</author>
<published>2014-05-11T18:49:21Z</published>
<link rel='alternate' type='text/html' href='https://git-old.alpinelinux.org/user/tteras/strongswan/commit/?id=8d59090349cb95e624c134533283a68ae95b8476'/>
<id>urn:sha1:8d59090349cb95e624c134533283a68ae95b8476</id>
<content type='text'>
</content>
</entry>
<entry>
<title>libcharon: Use lib-&gt;ns instead of charon-&gt;name</title>
<updated>2014-02-12T13:34:32Z</updated>
<author>
<name>Tobias Brunner</name>
<email>tobias@strongswan.org</email>
</author>
<published>2014-01-22T14:18:58Z</published>
<link rel='alternate' type='text/html' href='https://git-old.alpinelinux.org/user/tteras/strongswan/commit/?id=d223fe807a0a7fe6f358420256d11d407f7c9f07'/>
<id>urn:sha1:d223fe807a0a7fe6f358420256d11d407f7c9f07</id>
<content type='text'>
</content>
</entry>
<entry>
<title>check it specified IF-TNCCS protocol is enabled</title>
<updated>2013-10-21T19:03:53Z</updated>
<author>
<name>Andreas Steffen</name>
<email>andreas.steffen@strongswan.org</email>
</author>
<published>2013-10-21T19:03:53Z</published>
<link rel='alternate' type='text/html' href='https://git-old.alpinelinux.org/user/tteras/strongswan/commit/?id=27bf5c06dcaeee6d42b15d48ef4a0127a3d23f49'/>
<id>urn:sha1:27bf5c06dcaeee6d42b15d48ef4a0127a3d23f49</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Keep a copy of the tnccs instance for PT-TLS handover</title>
<updated>2013-10-09T17:03:07Z</updated>
<author>
<name>Andreas Steffen</name>
<email>andreas.steffen@strongswan.org</email>
</author>
<published>2013-10-09T17:03:07Z</published>
<link rel='alternate' type='text/html' href='https://git-old.alpinelinux.org/user/tteras/strongswan/commit/?id=3588299fb8a14c4b260c30fc4dd6419cb74a8159'/>
<id>urn:sha1:3588299fb8a14c4b260c30fc4dd6419cb74a8159</id>
<content type='text'>
</content>
</entry>
</feed>
