Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | | | Added method to add additional shared secrets to stroke_cred_t. | Tobias Brunner | 2012-04-17 | 2 | -2/+20 | |
| | | | ||||||
* | | | Additional prompt keyword added to stroke. | Tobias Brunner | 2012-04-17 | 1 | -1/+3 | |
| | | | ||||||
* | | | Typo fixed. | Tobias Brunner | 2012-04-17 | 1 | -1/+1 | |
| | | | ||||||
* | | | Keep COOKIEs enabled once threshold is hit, until we see no COOKIEs for a ↵ | Martin Willi | 2012-04-17 | 1 | -5/+43 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | few secs Toggling COOKIEs on/off is problematic: After doing a COOKIE exchange as initiator, we can't know if the completing IKE_SA_INIT message is to our first request or the one with the COOKIE. If the responder just enabled/disabled COOKIEs and packets get retransmitted, both might be true. Avoiding COOKIE behavior toggling improves the situation, but does not solve the problem during the initial COOKIE activation. | |||||
* | | | Added a note about DH/keymat lifecycle for custom implementations | Martin Willi | 2012-04-17 | 1 | -1/+6 | |
| | | | ||||||
* | | | Reuse existing DH value when retrying IKE_SA_INIT with a COOKIE | Martin Willi | 2012-04-17 | 1 | -2/+5 | |
| | | | ||||||
* | | | Use IP address as ID as responder if not configured or no IDr received. | Tobias Brunner | 2012-04-16 | 1 | -3/+11 | |
| | | | ||||||
* | | | Fall back on IP address as IDi if none is configured at all. | Tobias Brunner | 2012-04-16 | 1 | -7/+7 | |
| | | | ||||||
* | | | Use auth_cfg_t.replace_value where appropriate. | Tobias Brunner | 2012-04-16 | 2 | -26/+5 | |
| | | | ||||||
* | | | Added a simple method to replace the value of a rule in auth_cfg_t. | Tobias Brunner | 2012-04-16 | 2 | -32/+74 | |
| | | | ||||||
* | | | Fixed IDi in case neither left nor leftid is configured. | Tobias Brunner | 2012-04-16 | 1 | -0/+21 | |
| | | | ||||||
* | | | fixed parsing of port ranges in Scanner IMV | Andreas Steffen | 2012-04-15 | 1 | -4/+4 | |
| | | | ||||||
* | | | Typo fixed in NEWS. | Tobias Brunner | 2012-04-14 | 1 | -1/+1 | |
| | | | ||||||
* | | | Don't invoke child_updown hook twice as responder | Martin Willi | 2012-04-11 | 1 | -3/+8 | |
| | | | ||||||
* | | | Accept zero-length certificate request payloads | Martin Willi | 2012-04-11 | 1 | -2/+1 | |
| | | | ||||||
* | | | Properly initialize src in ike_sa_t.is_any_path_valid(). | Tobias Brunner | 2012-04-06 | 1 | -1/+1 | |
| | | | ||||||
* | | | checksum need a libradius_init() symbol | Andreas Steffen | 2012-04-05 | 2 | -0/+13 | |
| | | | ||||||
* | | | version bump to 4.6.3rc1 | Andreas Steffen | 2012-04-05 | 1 | -1/+1 | |
| | | | ||||||
* | | | remove leading zero in ASN.1 encoded serial numbers | Andreas Steffen | 2012-04-05 | 6 | -12/+14 | |
| | | | ||||||
* | | | ASN.1 two's complement encoding prevents overflow in CRL serial number | Andreas Steffen | 2012-04-04 | 1 | -10/+18 | |
| | | | ||||||
* | | | Make AES-CMAC actually usable for IKEv2. | Tobias Brunner | 2012-04-04 | 2 | -0/+6 | |
| | | | ||||||
* | | | represent 0 as a single byte | Andreas Steffen | 2012-04-03 | 1 | -5/+1 | |
| | | | ||||||
* | | | moved chunk_skip_zero to chunk.h | Andreas Steffen | 2012-04-03 | 3 | -19/+21 | |
| | | | ||||||
* | | | added IKEv2 Generic Secure Password Authentication Method | Andreas Steffen | 2012-04-03 | 2 | -3/+10 | |
| | | | ||||||
* | | | added IKEv2 Generic Secure Password Authentication Method | Andreas Steffen | 2012-04-03 | 2 | -6/+17 | |
| | | | ||||||
* | | | added GSPM IKEv2 payload | Andreas Steffen | 2012-04-03 | 2 | -8/+20 | |
| | | | ||||||
* | | | fixed typo | Andreas Steffen | 2012-04-03 | 1 | -2/+2 | |
| | | | ||||||
* | | | Doxygen fixes. | Tobias Brunner | 2012-04-03 | 2 | -2/+2 | |
| | | | ||||||
* | | | Added NEWS about cmac plugin. | Tobias Brunner | 2012-04-03 | 1 | -0/+3 | |
| | | | ||||||
* | | | Added test vectors for AES-CMAC. | Tobias Brunner | 2012-04-03 | 3 | -0/+153 | |
| | | | ||||||
* | | | Implemented AES-CMAC based PRF and signer. | Tobias Brunner | 2012-04-03 | 11 | -0/+926 | |
| | | | | | | | | | | | | | | | | | | The cmac plugin implements AES-CMAC as defined in RFC 4493 and the signer and PRF based on it as defined in RFC 4494 and RFC 4615, respectively. | |||||
* | | | Fixed GNU license header in hmac and xcbc plugins. | Tobias Brunner | 2012-04-03 | 2 | -4/+4 | |
| | | | ||||||
* | | | More detailed NEWS about RADIUS extensions | Martin Willi | 2012-04-02 | 1 | -2/+9 | |
| | | | ||||||
* | | | updated supported EAP methods | Andreas Steffen | 2012-03-30 | 1 | -5/+14 | |
| | | | ||||||
* | | | Add support for dnQualifier in DNs. | Tobias Brunner | 2012-03-29 | 3 | -1/+6 | |
| | | | ||||||
* | | | remove leading zeros in ASN.1 encoded serial numbers | Andreas Steffen | 2012-03-27 | 1 | -2/+22 | |
| | | | ||||||
* | | | Added NEWS about resolvconf support. | Tobias Brunner | 2012-03-27 | 1 | -0/+2 | |
| | | | ||||||
* | | | Make resolvconf interface prefix configurable. | Tobias Brunner | 2012-03-27 | 2 | -2/+16 | |
| | | | ||||||
* | | | Added support for the resolvconf framework in resolve plugin. | Tobias Brunner | 2012-03-27 | 1 | -52/+149 | |
| | | | | | | | | | | | | | | | If /sbin/resolvconf is found nameservers are not written directly to /etc/resolv.conf but instead resolvconf is invoked. | |||||
* | | | Don't cast second argument of mem_printf_hook (%b) to size_t. | Tobias Brunner | 2012-03-27 | 9 | -19/+25 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Also treat the given number as unsigned int. Due to the printf hook registration the second argument of mem_printf_hook (if called via printf etc.) is always of type int*. Casting this to a size_t pointer and then dereferencing that as int does not work on big endian machines if int is smaller than size_t (e.g. on ppc64). In order to make this change work if the argument is of a type larger than int, size_t for instance, the second argument for %b has to be casted to (u_)int. | |||||
* | | | smp: Use proper signed type to get return value of read(2). | Tobias Brunner | 2012-03-27 | 1 | -1/+1 | |
| | | | ||||||
* | | | pluto: Use time_monotonic() instead of a custom implementation. | Tobias Brunner | 2012-03-27 | 1 | -12/+1 | |
| | | | ||||||
* | | | Don't include individual glib headers in nm plugin. | Tobias Brunner | 2012-03-26 | 1 | -1/+1 | |
| | | | | | | | | | | | | | | | Expections are glib/gi18n.h, glib/gi18n-lib.h, glib/gprintf.h and glib/gstdio.h. | |||||
* | | | fixed parsing of IF-MAP SOAP responses | Andreas Steffen | 2012-03-21 | 1 | -35/+30 | |
|/ / | ||||||
* | | corrected description | Andreas Steffen | 2012-03-17 | 1 | -1/+1 | |
| | | ||||||
* | | added ikev2/esp-alg-sha1-160 scenario | Andreas Steffen | 2012-03-17 | 9 | -0/+103 | |
| | | ||||||
* | | added ikev2/esp-alg-md5-128 scenario | Andreas Steffen | 2012-03-17 | 9 | -0/+103 | |
| | | ||||||
* | | version bump to 4.6.3dr2 | Andreas Steffen | 2012-03-16 | 1 | -1/+1 | |
| | | ||||||
* | | added the strongswan.conf options of the tnc-pdp plugin | Andreas Steffen | 2012-03-16 | 2 | -1/+13 | |
| | | ||||||
* | | keep a copy of refreshed carolCert-ocsp.pem | Andreas Steffen | 2012-03-15 | 1 | -0/+95 | |
| | |