Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
| * | Simplify test starting and stopping logic | Reto Buerki | 2013-01-17 | 4 | -36/+0 | |
| | | | | | | | | | | | | | | | | | | Reduce the coupling of the different scripts. make-testing : Build the testing environment start-testing : Start switches and guests do-tests : Run tests stop-testing : Stop switches and guests | |||||
| * | Use key(and password-)less SSH authentication | Tobias Brunner | 2013-01-17 | 6 | -67/+18 | |
| | | ||||||
| * | Adjust strongSwan version handling in HTML output | Reto Buerki | 2013-01-17 | 4 | -25/+29 | |
| | | ||||||
| * | Patch AVP parsing in EAP-TTLS module in FreeRADIUS | Tobias Brunner | 2013-01-17 | 2 | -0/+19 | |
| | | ||||||
| * | Add recipes for libtnc and TNC@FHH | Tobias Brunner | 2013-01-17 | 6 | -3/+6750 | |
| | | ||||||
| * | Copy and display host specific tcpdump.log files | Tobias Brunner | 2013-01-17 | 1 | -0/+22 | |
| | | ||||||
| * | Drop SHAREDTREE in favor of mounting the compile dir | Tobias Brunner | 2013-01-17 | 2 | -15/+4 | |
| | | ||||||
| * | Patch EAP-SIM module in FreeRADIUS | Tobias Brunner | 2013-01-17 | 3 | -4/+45 | |
| | | ||||||
| * | Don't generate do-tests | Tobias Brunner | 2013-01-17 | 2 | -16/+7 | |
| | | ||||||
| * | Adapt test configurations | Reto Buerki | 2013-01-17 | 394 | -2576/+791 | |
| | | | | | | | | Adapt test configurations to the new Debian-based system. | |||||
| * | Adapt host configuration | Reto Buerki | 2012-12-18 | 94 | -24813/+680 | |
| | | | | | | | | | | Adapt the configuration of the test hosts to the new Debian-based system. | |||||
| * | Add recipe for iptables | Reto Buerki | 2012-12-18 | 1 | -0/+27 | |
| | | ||||||
| * | Add freeradius recipe | Reto Buerki | 2012-12-18 | 1 | -0/+32 | |
| | | ||||||
| * | Factor out building of strongswan into own Makefile | Reto Buerki | 2012-12-18 | 3 | -382/+117 | |
| | | | | | | | | | | Small Makefiles (recipes) are used to install software from source into the root UML image. | |||||
| * | testing: Switch to Debian based guest images | Reto Buerki | 2012-12-18 | 16 | -655/+189 | |
| | | | | | | | | | | | | | | | | | | | | Instead of extracting a downloaded Gentoo filesystem tree into a file containing a reiserfs filesystem, create an ext3 filesystem inside a sparse file, mount it and debootstrap an up-to-date Debian system. Use this image as base for all UML guest images. Also, drop support for the various consoles and use xterm unconditionally. | |||||
* | | Reseed rdrand after every 128bit sample only | Martin Willi | 2013-01-15 | 1 | -2/+2 | |
| | | ||||||
* | | version bump to 5.0.2rc1 | Andreas Steffen | 2013-01-15 | 1 | -1/+1 | |
| | | ||||||
* | | android: Properly escape apostrophes in Ukrainian translation5.0.2dr4 | Tobias Brunner | 2013-01-14 | 1 | -8/+8 | |
| | | ||||||
* | | android: Implement kernel_net_t.get_interface via JNI | Tobias Brunner | 2013-01-14 | 4 | -6/+92 | |
| | | | | | | | | | | | | This is now required to properly accept/install a virtual IP address. Fixes #275. | |||||
* | | android: Moved chunk_from_byte_array and byte_array_from_chunk helper functions | Tobias Brunner | 2013-01-14 | 2 | -24/+32 | |
| | | ||||||
* | | android: Set OPENSSL_NO_CMS in Android.mk as it is not set in opensslconf.h ↵ | Tobias Brunner | 2013-01-14 | 2 | -0/+2 | |
| | | | | | | | | on Android | |||||
* | | Properly send IKEv1 packets if no ike_cfg is known yet | Tobias Brunner | 2013-01-14 | 1 | -2/+5 | |
| | | | | | | | | This applies for error notifies. | |||||
* | | Don't handle right=%any6 as "loose" identity, but as %any | Martin Willi | 2013-01-14 | 1 | -2/+1 | |
| | | ||||||
* | | Respect given address family when resolving "%any" | Martin Willi | 2013-01-14 | 1 | -1/+5 | |
| | | ||||||
* | | Android.mk of libstrongswan updated | Tobias Brunner | 2013-01-14 | 1 | -2/+2 | |
| | | ||||||
* | | Merge branch 'ikev1-fragmentation' | Tobias Brunner | 2013-01-12 | 37 | -59/+882 | |
|\ \ | | | | | | | | | | | | | | | | | | | This adds support for the proprietary IKEv1 fragmentation extension. Conflicts: NEWS | |||||
| * | | NEWS for fragmentation extension added | Tobias Brunner | 2013-01-12 | 1 | -0/+4 | |
| | | | | | | | | | | | | | | | Conflicts: NEWS | |||||
| * | | Added an option to configure the maximum size of a fragment | Tobias Brunner | 2013-01-12 | 2 | -3/+14 | |
| | | | ||||||
| * | | Properly detect fragmentation capabilities | Tobias Brunner | 2013-01-12 | 1 | -3/+27 | |
| | | | | | | | | | | | | Cisco sends 0xc0000000 so we check that part of the VID separately. | |||||
| * | | Added an option that allows to force IKEv1 fragmentation | Tobias Brunner | 2013-01-12 | 20 | -33/+76 | |
| | | | ||||||
| * | | Use a connection specific option to en-/disable IKEv1 fragmentation | Tobias Brunner | 2012-12-24 | 25 | -33/+69 | |
| | | | ||||||
| * | | Include source port in init hash for fragmented messages | Tobias Brunner | 2012-12-24 | 1 | -1/+8 | |
| | | | ||||||
| * | | Add an option to en-/disable IKE fragmentation | Tobias Brunner | 2012-12-24 | 3 | -5/+25 | |
| | | | | | | | | | | | | | | | Fragments are always accepted but will not be sent if disabled. The vendor ID is only sent if the option is enabled. | |||||
| * | | Split larger messages into fragments if IKE fragmentation is supported by peer | Tobias Brunner | 2012-12-24 | 1 | -14/+114 | |
| | | | ||||||
| * | | Log message size for in- and outbound IKE messages | Tobias Brunner | 2012-12-24 | 2 | -4/+7 | |
| | | | ||||||
| * | | Add support to create IKE fragments | Tobias Brunner | 2012-12-24 | 2 | -0/+30 | |
| | | | | | | | | | | | | | | | All fragments currently use the same fragment ID (1) as that's what other implementations are doing. | |||||
| * | | Log added NAT-T vendor IDs | Tobias Brunner | 2012-12-24 | 1 | -0/+1 | |
| | | | ||||||
| * | | Detect a peer's support for IKE fragmentation | Tobias Brunner | 2012-12-24 | 2 | -0/+9 | |
| | | | | | | | | | | | | Fragments are accepted even if this vendor ID is not seen. | |||||
| * | | Map fragmented initial initial Main or Aggressive Mode messages to the same ↵ | Tobias Brunner | 2012-12-24 | 1 | -1/+17 | |
| | | | | | | | | | | | | IKE_SA | |||||
| * | | Allow ID_PROT/AGGRESSIVE messages for established IKE_SAs if they contain ↵ | Tobias Brunner | 2012-12-24 | 1 | -1/+2 | |
| | | | | | | | | | | | | | | | | | | | | | fragments Other implementations send fragments always in an initial message type even for transaction or quick mode exchanges. | |||||
| * | | Don't handle fragmented messages larger than charon.max_packet | Tobias Brunner | 2012-12-24 | 1 | -4/+39 | |
| | | | ||||||
| * | | Don't update an IKE_SA-entry's cached message ID when handling fragments | Tobias Brunner | 2012-12-24 | 1 | -1/+4 | |
| | | | ||||||
| * | | Store inbound IKE fragments and reassemble the message when all fragments ↵ | Tobias Brunner | 2012-12-24 | 1 | -3/+166 | |
| | | | | | | | | | | | | are received | |||||
| * | | Add message rules to properly handle IKE fragments | Tobias Brunner | 2012-12-24 | 1 | -0/+8 | |
| | | | | | | | | | | | | | | | These are sent in unencrypted messages and are the only payload contained in such messages. | |||||
| * | | Reset the encrypted flag when handling IKE messages that contain a fragment | Tobias Brunner | 2012-12-24 | 1 | -0/+6 | |
| | | | | | | | | | | | | | | | Racoon sets the encrypted bit for messages containing a fragment, but these messages are not really encrypted (the fragmented message is though). | |||||
| * | | Payload added to handle IKE fragments | Tobias Brunner | 2012-12-24 | 6 | -11/+314 | |
| | | | ||||||
* | | | Don't use bio_writer_t.skip() to write length field when appending more data | Martin Willi | 2013-01-11 | 2 | -6/+9 | |
| | | | | | | | | | | | | | | | If the writer reallocates its buffer, the length pointer might not be valid anymore, or even worse, point to an arbitrary allocation. | |||||
* | | | Add rdrand NEWS | Martin Willi | 2013-01-11 | 1 | -0/+3 | |
| | | | ||||||
* | | | Use raw opcodes for rdrand to build with older binutils | Martin Willi | 2013-01-11 | 1 | -6/+6 | |
| | | | ||||||
* | | | Provide RNG_TRUE quality in rdrand by mixing reseeded outputs using AES | Martin Willi | 2013-01-11 | 2 | -8/+108 | |
| | | |