Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | added ikev1/net2net-fragmentation scenario5.0.3dr1 | Andreas Steffen | 2013-02-12 | 9 | -0/+122 |
| | |||||
* | treat EAP identities as user IDs | Andreas Steffen | 2013-02-12 | 1 | -3/+3 |
| | |||||
* | use EAP identity in tnc/tnccs-20-pdp scenario | Andreas Steffen | 2013-02-12 | 8 | -10/+12 |
| | |||||
* | make TNC client authentication type available to IMVs | Andreas Steffen | 2013-02-12 | 10 | -27/+215 |
| | |||||
* | determine underlying IF-T transport protocol | Andreas Steffen | 2013-02-12 | 13 | -65/+231 |
| | |||||
* | make AR identities available to IMVs via IF-IMV 1.4 draft | Andreas Steffen | 2013-02-11 | 14 | -0/+645 |
| | |||||
* | Make IKE/EAP IDs available to TNC server/client | Andreas Steffen | 2013-02-11 | 10 | -28/+92 |
| | |||||
* | Don't use a time_t variable with fscanf when parsing uptime | Tobias Brunner | 2013-02-08 | 1 | -1/+1 |
| | | | | | | | | | Because "%u" is used as format string in the fscanf call that parses the uptime and because the length of time_t varies on different platforms and architectures the value was not written properly if time_t was longer than an unsigned int and depending on how the target variable was aligned on the stack. Since there is no conversion specifier to properly parse a time_t value we use the appropriate integer type instead. | ||||
* | Allow more than one CERTREQ payload for IKEv2 | Tobias Brunner | 2013-02-08 | 1 | -2/+2 |
| | | | | | | There is no reason not to do so (RFC 5996 explicitly mentions multiple CERTREQ payloads) and some implementations seem to use the same behavior as had to be used with IKEv1 (i.e. each CA in its own CERTREQ payload). | ||||
* | Add a --httptimeout option to scepclient | Martin Willi | 2013-02-08 | 3 | -7/+22 |
| | |||||
* | Use CURL_TIMEOUT and not CURL_CONNECTTIMEOUT for FETCHER_TIMEOUT in curl | Martin Willi | 2013-02-08 | 1 | -5/+12 |
| | | | | | This allows us to use this timeout beyond DNS resolution. For the initial connect, we use a hardcoded timeout of 10s for now. | ||||
* | Report enabled plugins at the end of configure | Tobias Brunner | 2013-02-04 | 1 | -0/+13 |
| | |||||
* | Streamlined comments in configure.in | Tobias Brunner | 2013-02-04 | 1 | -80/+83 |
| | | | | dnl should only be used in rare cases (like escaping newlines) | ||||
* | Updated configure.in to newer autoconf | Tobias Brunner | 2013-02-04 | 1 | -145/+161 |
| | | | | | | AC_TRY_COMPILE and AC_TRY_RUN are deprecated. The new construct with AC_*_IFELSE and AC_LANG_PROGRAM requires double quoting the source code of these test programs. | ||||
* | Add a configure option to disable all default plugins | Tobias Brunner | 2013-02-04 | 2 | -2/+16 |
| | | | | | | The --disable-defaults option disables all plugins that would be enabled by default. This allows to selectively enable specific plugins without issues when new default options get added in future releases. | ||||
* | time is a time_t pointer | Andreas Steffen | 2013-02-04 | 1 | -1/+1 |
| | |||||
* | version bump to 5.0.3dr1 | Andreas Steffen | 2013-02-04 | 1 | -1/+1 |
| | |||||
* | improved control when an attribute request is sent | Andreas Steffen | 2013-02-03 | 3 | -2/+54 |
| | |||||
* | print PEN value 0xfffffe as Unassigned | Andreas Steffen | 2013-02-03 | 2 | -15/+17 |
| | |||||
* | send an error attribute if vendor ID or type of received attribute is reserved | Andreas Steffen | 2013-02-03 | 1 | -0/+12 |
| | |||||
* | openssl: Properly honor OPENSSL_NO_* defines | Tobias Brunner | 2013-01-31 | 7 | -5/+31 |
| | |||||
* | Fix Doxygen comment for rdrand plugin | Tobias Brunner | 2013-01-31 | 1 | -1/+1 |
| | |||||
* | Typo in strongswan.conf(5) man page fixed | Tobias Brunner | 2013-01-31 | 1 | -1/+1 |
| | |||||
* | version bump to 5.0.25.0.2 | Andreas Steffen | 2013-01-30 | 1 | -1/+1 |
| | |||||
* | Documented new options in strongswan.conf(5) man page | Tobias Brunner | 2013-01-25 | 1 | -3/+60 |
| | |||||
* | Don't use pointer to a union member in host_create_from_string_and_family() | Tobias Brunner | 2013-01-25 | 1 | -5/+4 |
| | |||||
* | Properly check MSB in openssl plugin's PKCS#7 implementation | Tobias Brunner | 2013-01-24 | 1 | -1/+1 |
| | |||||
* | Use proper buffer sizes for parse_smartcard() | Tobias Brunner | 2013-01-24 | 1 | -7/+10 |
| | |||||
* | Cast first argument for %.*s to int | Tobias Brunner | 2013-01-24 | 5 | -18/+18 |
| | |||||
* | Removed unused command name when printing usage info for lookip | Tobias Brunner | 2013-01-24 | 1 | -1/+1 |
| | |||||
* | Removed unused argument | Tobias Brunner | 2013-01-24 | 1 | -1/+1 |
| | |||||
* | Properly read data from stream in pki --pkcs7 | Tobias Brunner | 2013-01-24 | 1 | -6/+9 |
| | |||||
* | Properly destroy mem_cred object on pki --pkcs7 --help | Tobias Brunner | 2013-01-24 | 1 | -0/+1 |
| | |||||
* | Try to determine OS type if name and version are configured | Tobias Brunner | 2013-01-24 | 1 | -0/+2 |
| | |||||
* | Add missing va_end() call | Tobias Brunner | 2013-01-24 | 1 | -1/+2 |
| | |||||
* | g_thread_init() is deprecated since Glib 2.23 | Tobias Brunner | 2013-01-24 | 2 | -0/+6 |
| | |||||
* | Fix check-in of IKE_SA when IKE_SA_INIT fails and hash table is enabled | Tobias Brunner | 2013-01-24 | 1 | -2/+13 |
| | | | | | | | Setting the responder SPI to 0 can only be done while generating the response, otherwise we'd fail to check in the IKE_SA again in case the hash table is enabled. That's because we use the responder SPI as hash value since 5.0.0. | ||||
* | Return SS_RC_INITIALIZATION_FAILED if pid file exists | Adrian-Ken Rueegsegger | 2013-01-23 | 1 | -1/+0 |
| | | | | | | Let charon return SS_RC_INITIALIZATION_FAILED if an existing pid file is found. Starter only terminates itself if the result code of the daemon is a valid SS_RC_* value. | ||||
* | Avoid a deadlock when installing a trap policy failed | Tobias Brunner | 2013-01-23 | 1 | -1/+5 |
| | |||||
* | Encode IETF Numeric Version Service Pack Version with two byte words | Martin Willi | 2013-01-22 | 1 | -3/+2 |
| | |||||
* | starter: Add --attach-gdb option to usage text | Adrian-Ken Rueegsegger | 2013-01-22 | 1 | -1/+2 |
| | |||||
* | Fix IKE SA inherit API doc | Adrian-Ken Rueegsegger | 2013-01-22 | 1 | -2/+1 |
| | |||||
* | Filter TS list for Split-Includes before printing them to debug log | Martin Willi | 2013-01-21 | 1 | -10/+34 |
| | |||||
* | Add the ability to use a named pool for conftest configs | Tobias Brunner | 2013-01-21 | 2 | -4/+10 |
| | |||||
* | Removed INSTALL from EXTRA_DIST5.0.2rc1 | Andreas Steffen | 2013-01-17 | 1 | -1/+1 |
| | |||||
* | Merge branch 'debian-testing' | Tobias Brunner | 2013-01-17 | 1400 | -41153/+18258 |
|\ | | | | | | | | | | | | | | | | | | | These changes update the integration test system. It previously was based on a pretty much unmaintainable Gentoo root image and the dated UML virtualization technology. Among many other changes the test environment is now based on KVM and uses reproducible Debian-based guest images. Conflicts: NEWS | ||||
| * | NEWS about updated integration tests added | Tobias Brunner | 2013-01-17 | 1 | -0/+3 |
| | | |||||
| * | Updated documentation for the integration tests | Tobias Brunner | 2013-01-17 | 2 | -265/+50 |
| | | |||||
| * | Removed UML from description of ikev2/default-keys test | Tobias Brunner | 2013-01-17 | 1 | -3/+3 |
| | | |||||
| * | Updated comments in test.conf of all tests | Tobias Brunner | 2013-01-17 | 264 | -816/+816 |
| | |