aboutsummaryrefslogtreecommitdiffstats
Commit message (Collapse)AuthorAgeFilesLines
...
* Respect key types in stroke key/certificate backendMartin Willi2010-09-021-15/+24
|
* Added an enumerator for registered credential buildersMartin Willi2010-09-022-0/+32
|
* Migrated credential_factory to INIT/METHOD macrosMartin Willi2010-09-021-30/+22
|
* adapted evaltest.dat to new RULE_OCSP_VALIDATIONAndreas Steffen2010-09-013-3/+3
|
* cosmetics in debug outputAndreas Steffen2010-09-011-2/+3
|
* defined aaa_identityAndreas Steffen2010-09-013-2/+6
|
* increase number of message due to large certificate payloadsAndreas Steffen2010-09-011-1/+1
|
* clarified debug outputAndreas Steffen2010-08-311-1/+1
|
* fixed typoAndreas Steffen2010-08-311-1/+1
|
* Do not process any more TLS handshake messages on fatal alertsMartin Willi2010-08-311-0/+4
|
* Load a left/rightcert2 for EAP-TLS even if no left/rightauth2 is definedMartin Willi2010-08-311-1/+10
|
* Strictly check if the server certificate matches the TLS server identityMartin Willi2010-08-311-0/+44
|
* Use the AAA Identity for EAP authentication, if givenMartin Willi2010-08-312-1/+14
|
* Added support for the ipsec.conf aaa_identity keywordMartin Willi2010-08-319-0/+18
|
* Added an AAA identity authentication config optionMartin Willi2010-08-312-0/+10
|
* Added strongswan.conf options for EAP-TLS/TTLS fragment sizeMartin Willi2010-08-314-14/+30
|
* Support processing of partial TLS record headersMartin Willi2010-08-311-15/+39
|
* Migrated EAP-TTLS to the generic TLS helperMartin Willi2010-08-311-281/+21
|
* Migrated EAP-TLS to the generic TLS helperMartin Willi2010-08-311-272/+19
|
* Implemented a generic TLS EAP helper to implement EAP-TLS, TTLS and other ↵Martin Willi2010-08-313-0/+415
| | | | variants
* Support output fragmentation of TLS recordsMartin Willi2010-08-315-52/+123
|
* Moved EAP type/code definitions to a seprate header file in libstrongswanMartin Willi2010-08-319-179/+228
|
* Implemented buffering of partial records in TLS stackMartin Willi2010-08-311-15/+65
|
* Log TLS handshake subtypes as handshakesMartin Willi2010-08-311-5/+5
|
* Added a TLS debug level option, use debugging hookMartin Willi2010-08-311-13/+38
|
* Do not strdup() zero length strings in identification_create_from_string()Martin Willi2010-08-311-4/+20
|
* Corrected some URLs.Tobias Brunner2010-08-313-3/+3
|
* Enable the generation of unencrypted messages (e.g. ME connectivity checks).Tobias Brunner2010-08-301-9/+10
|
* fixed typosAndreas Steffen2010-08-301-7/+7
|
* fixed copy-and-paste errorsAndreas Steffen2010-08-302-2/+2
|
* created an eap-tnc method hullAndreas Steffen2010-08-309-0/+373
|
* for the time being assume a single request/response exchange for a given EAP ↵Andreas Steffen2010-08-301-2/+3
| | | | method
* Port floating patch partially reversed.Tobias Brunner2010-08-302-12/+8
| | | | | | If MOBIKE is enabled, we do have to switch to port 4500 with the IKE_AUTH request, that is, before we know whether the other peer actually supports MOBIKE or not.
* Slightly refactored port floating.Tobias Brunner2010-08-305-35/+39
| | | | In case of MOBIKE, only float to port 4500 if the other peer actually supports MOBIKE.
* defined EAP-TNCAndreas Steffen2010-08-302-2/+8
|
* Unwrap crlNumber INTEGER in openssl CRL parsingMartin Willi2010-08-301-4/+13
|
* Added crl support to pki --printMartin Willi2010-08-301-7/+52
|
* Typo in doxygen comment fixed.Tobias Brunner2010-08-301-1/+1
|
* Fixed ME after introduction of AEAD wrapper.Tobias Brunner2010-08-301-1/+1
|
* Fixed pluto smartcard support after introducing encryption schemesMartin Willi2010-08-301-2/+2
|
* replaced ikev2/esp-alg-aes-ctr by ikev2/alg-aes-ctrAndreas Steffen2010-08-2910-9/+12
|
* added ctr ccm and gcm plugins to ikev2/rw-cert scenarioAndreas Steffen2010-08-293-3/+3
|
* added ctr ccm and gcm plugins to openssl-ikev2/rw-cert scenarioAndreas Steffen2010-08-293-3/+3
|
* added ctr ccm and gcm plugins to gcrypt-ikev2/rw-cert scenarioAndreas Steffen2010-08-293-3/+3
|
* replaced ikev2/esp-alg-aes-gcm by ikev2/alg-aes-gcmAndreas Steffen2010-08-2910-11/+14
|
* replaced ikev2/esp-alg-aes-ccm by ikev2/alg-aes-ccmAndreas Steffen2010-08-2910-11/+13
|
* Win7 might send up to 7k of certificate requestsAndreas Steffen2010-08-273-3/+3
|
* Fixed documentation of XAUTH in ipsec.secrets.Tobias Brunner2010-08-261-3/+3
|
* Prefer AES/Camellia suites over 3DES/NULL encryptionMartin Willi2010-08-251-16/+16
|
* Send TLS alerts for errors in TLS handshake buildingMartin Willi2010-08-253-0/+12
|