aboutsummaryrefslogtreecommitdiffstats
Commit message (Collapse)AuthorAgeFilesLines
* version bump to 5.0.3dr25.0.3dr2Andreas Steffen2013-02-192-1/+5
|
* treat IF-M and IF-TNCCS remediation instructions/parameters in an equal wayAndreas Steffen2013-02-194-107/+204
|
* Merge branch 'dnssec'Tobias Brunner2013-02-19103-7/+3723
|\
| * NEWS about ipseckey and unbound plugins addedTobias Brunner2013-02-191-0/+9
| |
| * Added ikev2/rw-dnssec scenarioAndreas Steffen2013-02-1921-0/+301
| |
| * Added ikev2/net2net-dnssec scenarioAndreas Steffen2013-02-1917-0/+220
| |
| * Configure winnetou as a DNSSEC enabled nameserver for the strongswan.org, ↵Andreas Steffen2013-02-1923-2/+378
| | | | | | | | org, and root zones
| * Build unbound and ipseckey plugins on KVM imageAndreas Steffen2013-02-192-2/+4
| |
| * Streamlined log messages in ipseckey pluginAndreas Steffen2013-02-192-58/+30
| |
| * Encode RSA public keys in RFC 3110 DNSKEY formatAndreas Steffen2013-02-198-3/+155
| |
| * Moved configuration from resolver manager to unbound pluginAndreas Steffen2013-02-197-52/+47
| | | | | | | | Also streamlined log messages in unbound plugin.
| * ipseckey: Report IPSECKEYs with invalid DNSSEC security stateReto Guadagnini2013-02-191-2/+12
| |
| * ipseckey: Added "enable" option for the IPSECKEY plugin to strongswan.confReto Guadagnini2013-02-192-3/+19
| |
| * Added ipseckey plugin, which provides support for public keys in IPSECKEY RRsReto Guadagnini2013-02-199-0/+863
| |
| * Implemented the resolver test script "dnssec"Reto Guadagnini2013-02-193-1/+130
| |
| * unbound: Implementation of query method of unbound_resolver_tReto Guadagnini2013-02-192-7/+64
| |
| * unbound: Implemented resolver_response_t as unbound_response_tReto Guadagnini2013-02-193-1/+316
| |
| * Implemented rr_set_t interfaceReto Guadagnini2013-02-193-1/+113
| |
| * unbound: Implemented rr_t as unbound_rr_tReto Guadagnini2013-02-193-1/+215
| |
| * Added unbound plugin implementing the resolver interface using libunboundReto Guadagnini2013-02-197-0/+245
| |
| * Added manager for DNS resolversReto Guadagnini2013-02-195-1/+181
| |
| * Added interface for DNS resolversReto Guadagnini2013-02-196-0/+548
|/
* added missing return statementAndreas Steffen2013-02-191-0/+1
|
* Fix encoding of issuerAndSubject while handling SCEP pending stateMartin Willi2013-02-191-1/+1
|
* reject PB-Experimental messages with NOSKIP flag setAndreas Steffen2013-02-191-0/+7
|
* added parameter descriptionsAndreas Steffen2013-02-191-1/+8
|
* removed superfluous debug outputAndreas Steffen2013-02-152-4/+0
|
* Add a timeout to clean up PDP RADIUS connectionsMartin Willi2013-02-141-0/+51
|
* Keep the PDP connections lock while accessing its objectsMartin Willi2013-02-143-7/+34
| | | | | | When we introduce connection timeouts, the state may disappear at any time. This change prevents that, but is not very clear. We probably have to refactor connection handling.
* Add locking to TNC-PDP connectionsMartin Willi2013-02-141-7/+23
|
* Add IF-M message subtype getter to IMC/IMV messagesMartin Willi2013-02-144-1/+28
|
* Use a generic constructor to create PA-TNC error attributesMartin Willi2013-02-141-62/+32
|
* Add a global return_success() method implementationMartin Willi2013-02-143-8/+15
|
* Add a convenience method to check pen_type_t for vendor and typeMartin Willi2013-02-141-0/+14
|
* Add a comparison function for pen_type_tMartin Willi2013-02-141-0/+12
|
* Whitespace and comment cleanups in pen.[ch]Martin Willi2013-02-142-20/+28
|
* resolve dependency on libtlsAndreas Steffen2013-02-141-0/+1
|
* Merge branch 'ike-dscp'Martin Willi2013-02-1427-68/+242
|\
| * Add ikedscp documentation to ipsec.conf.5Martin Willi2013-02-061-0/+5
| |
| * Add a ikedscp ipsec.conf option to set DSCP value on outgoing IKE packetsMartin Willi2013-02-067-4/+23
| |
| * Set configured DSCP value while generating IKE packetsMartin Willi2013-02-061-1/+26
| |
| * Add a DSCP configuration value to IKE configsMartin Willi2013-02-0614-25/+41
| |
| * Set DSCP values when sending IP packets in socket-defaultMartin Willi2013-02-061-1/+65
| |
| * Don't send a packet in default socket if family is not IPv4 nor IPv6Martin Willi2013-02-061-12/+18
| |
| * Add a DSCP value with getter/setter on packet_tMartin Willi2013-02-063-0/+47
| |
| * Avoid extensive casting of sockaddr types in socket-default by using a unionMartin Willi2013-02-061-24/+16
| | | | | | | | Additionally fixes a strict-aliasing rule compiler warning with older gcc.
| * Set sockaddr family on ifreq instead of casted familiy specific sockaddrMartin Willi2013-02-061-2/+2
| | | | | | | | Fixes a strict-aliasing rule compiler warning with older gcc.
* | Check if recommendations is set before applying language preferenceMartin Willi2013-02-141-3/+6
| |
* | PT-TLS dispatcher TNCCS constructor takes peer identities to pass to factoryMartin Willi2013-02-142-4/+23
| |
* | Merge branch 'pt-tls'Martin Willi2013-02-1420-94/+1413
|\ \