Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | | | Provide RNG_STRONG quality in rdrand by forcing PRNG reseed after every sample | Martin Willi | 2013-01-11 | 2 | -1/+69 | |
| | | | ||||||
* | | | Provide RNG_WEAK quality random generator in rdrand | Martin Willi | 2013-01-11 | 4 | -2/+342 | |
| | | | ||||||
* | | | Add a rdrand plugin stub detecting availability of RDRAND instructions | Martin Willi | 2013-01-11 | 5 | -0/+187 | |
| | | | ||||||
* | | | Add NEWS about improved Windows IKEv1 compatibility | Martin Willi | 2013-01-11 | 1 | -0/+4 | |
| | | | ||||||
* | | | Streamline debug output when receiving intermediate CA certificates in IKEv1 | Martin Willi | 2013-01-11 | 1 | -1/+1 | |
| | | | ||||||
* | | | Refactored IKEv2 cert/certreq payload processing to multiple functions | Martin Willi | 2013-01-11 | 1 | -112/+141 | |
| | | | ||||||
* | | | Refactored IKEv1 cert payload processing to multiple functions | Martin Willi | 2013-01-11 | 1 | -73/+102 | |
| | | | ||||||
* | | | IKEv1 support for PKCS#7 wrapped certificates | Volker Rümelin | 2013-01-11 | 3 | -0/+96 | |
| | | | ||||||
* | | | Fixed some typos in comments | Volker Rümelin | 2013-01-11 | 4 | -6/+6 | |
| | | | ||||||
* | | | Fixed some typos in Ukrainian translation | Pavel Kopchyk | 2013-01-09 | 1 | -15/+16 | |
| | | | ||||||
* | | | conftest: Add support for time_format and ike_name options in log sections | Thomas Klute | 2013-01-08 | 1 | -1/+18 | |
| | | | | | | | | | | | | | | | | | | Both options are well supported for normal operation but were completely ignored by conftest, which used hard coded defaults. File options are still missing but could be added in a similar way. | |||||
* | | | conftest: Fix log level settings for stdout | Thomas Klute | 2013-01-08 | 1 | -0/+3 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This patch fixes bug #272 ("conftest ignores log settings for stdout"). http://wiki.strongswan.org/issues/272 According to the documentation of add_logger in src/libcharon/bus/bus.h, the relevant log levels of a logger are registered with the logging subsystem when adding the logger. If the log levels change later, the logger must be re-added to propagate the new settings. In conftest.c, the stdout logger is initialized and added before reading the logging settings, but wasn't re-added after reading the settings. | |||||
* | | | conftest: Make outgoing sequence number set by reset_seq configurable | Thomas Klute | 2013-01-08 | 2 | -8/+70 | |
| | | | | | | | | | | | | | | | | | | | | | | | | This is useful for certain test cases. Passing the sequence number to the callback requires a new struct that contains both the number and the xfrm_usersa_id. The new configuration parameter is called oseq in accordance with the kernel name, see the comment in the reset_cb callback function for details. | |||||
* | | | Include opensslconf.h before checking its defines | Martin Willi | 2013-01-03 | 1 | -0/+2 | |
| | | | ||||||
* | | | Don't build OpenSSL PKCS#7 code if OPENSSL_NO_CMS defined | Martin Willi | 2013-01-03 | 1 | -0/+4 | |
| | | | ||||||
* | | | make pacman.sh run under cron | Andreas Steffen | 2012-12-26 | 1 | -9/+13 | |
| | | | ||||||
* | | | deleted newly constructed attributes in send_assessment | Andreas Steffen | 2012-12-24 | 3 | -21/+7 | |
| | | | ||||||
* | | | Added Russian and Ukrainian strings for Android client | Dmitry Korzhevin | 2012-12-24 | 4 | -0/+252 | |
|/ / | ||||||
* | | Add parantheses to avoid compiler warning | Martin Willi | 2012-12-24 | 1 | -1/+1 | |
| | | ||||||
* | | Send empty CDATA batch if TNC client has no data to send | Andreas Steffen | 2012-12-23 | 1 | -16/+28 | |
| | | ||||||
* | | Fixed some typos, courtesy of codespell | Tobias Brunner | 2012-12-20 | 11 | -12/+12 | |
| | | ||||||
* | | Raise an alert if IKE SA is kept | Adrian-Ken Rueegsegger | 2012-12-20 | 2 | -0/+3 | |
| | | | | | | | | | | This alert is raised when the establishment of a child SA fails but the IKE SA is kept. | |||||
* | | stroke: Drop unneeded [MY|OTHER]_NETBITS | Reto Buerki | 2012-12-19 | 1 | -2/+2 | |
| | | ||||||
* | | stroke: Enable install_policy in add_connection() | Reto Buerki | 2012-12-19 | 1 | -0/+1 | |
| | | ||||||
* | | Add support for draft-ietf-ipsec-nat-t-ike-03 and earlier | Volker Rümelin | 2012-12-19 | 14 | -90/+311 | |
| | | | | | | | | | | This adds support for early versions of the draft that eventually resulted in RFC 3947. | |||||
* | | NEWS about error-notify | Martin Willi | 2012-12-19 | 1 | -0/+3 | |
| | | ||||||
* | | Add missing error_notify_msg.h to distribution tarball | Martin Willi | 2012-12-19 | 1 | -1/+2 | |
| | | ||||||
* | | Add an error-notify sample application to listen to error notifications | Martin Willi | 2012-12-19 | 3 | -0/+66 | |
| | | ||||||
* | | Add an error-notify plugin to send catched alerts to listening applications | Martin Willi | 2012-12-19 | 10 | -0/+747 | |
| | | ||||||
* | | Raise an alert if half-open timeout limit reached | Martin Willi | 2012-12-19 | 2 | -0/+3 | |
| | | ||||||
* | | Raise an alert if an authorize() hook fails | Martin Willi | 2012-12-19 | 2 | -0/+6 | |
| | | ||||||
* | | Raise an alert if allocating virtual IPs fails | Martin Willi | 2012-12-19 | 2 | -0/+4 | |
| | | ||||||
* | | Raise an alert if kernel policy installation fails | Martin Willi | 2012-12-19 | 2 | -0/+4 | |
| | | ||||||
* | | Raise an alert if kernel SA installation fails | Martin Willi | 2012-12-19 | 2 | -0/+4 | |
| | | ||||||
* | | Raise an alert on traffic selector mismatch | Martin Willi | 2012-12-19 | 2 | -0/+5 | |
| | | ||||||
* | | Raise alerts when enforcing IKE_SA unique policy | Martin Willi | 2012-12-19 | 4 | -0/+7 | |
| | | ||||||
* | | Raise an alert if CHILD_SA proposals mismatch | Martin Willi | 2012-12-19 | 2 | -0/+4 | |
| | | ||||||
* | | Raise an alert if IKE proposals mismatch | Martin Willi | 2012-12-19 | 2 | -0/+7 | |
| | | ||||||
* | | Raise an alert of generating local authentication data fails | Martin Willi | 2012-12-19 | 2 | -6/+12 | |
| | | ||||||
* | | Add NEWS about BER capable OpenSSL PKCS#7 backend | Martin Willi | 2012-12-19 | 1 | -0/+5 | |
| | | ||||||
* | | Free leaking scep attributes | Martin Willi | 2012-12-19 | 1 | -0/+4 | |
| | | ||||||
* | | Corrected error message if enveloped-data decryption fails | Martin Willi | 2012-12-19 | 1 | -1/+1 | |
| | | ||||||
* | | Fix up serialNumber in openssl PKCS#7 if it has a leading MSB set | Martin Willi | 2012-12-19 | 1 | -2/+7 | |
| | | ||||||
* | | Don't handle PKCS#7 containers with infinite length encodings in pkcs7 plugin | Martin Willi | 2012-12-19 | 1 | -0/+6 | |
| | | ||||||
* | | Implement PKCS#7 decryption using openssl | Martin Willi | 2012-12-19 | 1 | -16/+255 | |
| | | ||||||
* | | Make available wrapped certificates while verifying PKCS#7 signatures in openssl | Martin Willi | 2012-12-19 | 1 | -0/+22 | |
| | | ||||||
* | | Implement openssl PKCS#7 certficiate enumeration | Martin Willi | 2012-12-19 | 1 | -0/+72 | |
| | | ||||||
* | | Fix doxygen grouping regarding containers and PKCS#7 | Martin Willi | 2012-12-19 | 8 | -11/+14 | |
| | | ||||||
* | | Enable pkcs7 plugin when building scepclient on Android | Martin Willi | 2012-12-19 | 2 | -1/+3 | |
| | | ||||||
* | | Move PKCS#9 attribute lists to pkcs7 plugin, as we currently use it there only | Martin Willi | 2012-12-19 | 6 | -45/+48 | |
| | |