Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
| * | sql: Set default values for some fields in addresses table | Tobias Brunner | 2014-02-12 | 2 | -6/+6 | |
| | | ||||||
| * | testing: Use installed PTS SQL schema and data instead of local copy | Tobias Brunner | 2014-02-12 | 6 | -1456/+8 | |
| | | ||||||
| * | testing: Use installed SQL schema instead of local copy | Tobias Brunner | 2014-02-12 | 25 | -334/+64 | |
| | | ||||||
| * | libimcv: Install SQL files in /usr/share/strongswan/templates/database | Tobias Brunner | 2014-02-12 | 2 | -2/+3 | |
| | | ||||||
| * | sql: Install SQL schemas in /usr/share/strongswan/templates/database | Tobias Brunner | 2014-02-12 | 1 | -0/+3 | |
| | | ||||||
| * | sql: Remove unused cred.sql snippet | Tobias Brunner | 2014-02-12 | 1 | -24/+0 | |
|/ | ||||||
* | asn1: Support dates before 1970-01-01 (i.e. when time_t gets negative) | Tobias Brunner | 2014-02-12 | 3 | -4/+29 | |
| | | | | | | On x86 we allow "overflows" around 1969/1970 but not for other dates. Fixes #509. | |||||
* | asn1: Add additional validation for parsed ASN.1 date/time values | Tobias Brunner | 2014-02-12 | 2 | -1/+20 | |
| | ||||||
* | ikev1: Fix config switching due to failed authentication during Aggressive mode | Tobias Brunner | 2014-02-12 | 1 | -3/+1 | |
| | | | | | | | The encoded ID payload gets destroyed by the authenticator, which caused a segmentation fault after the switch. Fixes #501. | |||||
* | kernel-pfroute: Don't cache route entries if installation fails | Tobias Brunner | 2014-02-12 | 1 | -2/+5 | |
| | ||||||
* | kernel-netlink: Don't cache route entries if installation fails | Tobias Brunner | 2014-02-12 | 1 | -2/+5 | |
| | | | | Fixes #500. | |||||
* | identification: Fix printing of empty RDNs on FreeBSD | Tobias Brunner | 2014-02-12 | 1 | -1/+6 | |
| | | | | On FreeBSD (null) is printed for NULL even if the precision is 0. | |||||
* | tests: Fix test for printing NULL on FreeBSD | Tobias Brunner | 2014-02-12 | 1 | -2/+13 | |
| | ||||||
* | Fixed description of ikev1/rw-ntru-psk scenario | Andreas Steffen | 2014-02-12 | 1 | -1/+1 | |
| | ||||||
* | Updated test kvm tests to Linux 3.13 kernel | Andreas Steffen | 2014-02-12 | 2 | -3/+2050 | |
| | ||||||
* | Added ikev1/net2net-ntru-cert and ikev1/rw-ntru-psk scenarios | Andreas Steffen | 2014-02-12 | 23 | -0/+302 | |
| | ||||||
* | testing: Add ssh script to distribution | Tobias Brunner | 2014-02-12 | 1 | -1/+1 | |
| | ||||||
* | unit-tests: added asn1_parser tests | Andreas Steffen | 2014-02-10 | 3 | -0/+293 | |
| | ||||||
* | unit-tests: added some more ASN.1 length tests | Andreas Steffen | 2014-02-10 | 1 | -0/+13 | |
| | ||||||
* | leak_detective: Assign return value of realloc to buf | Thomas Egerer | 2014-02-10 | 1 | -1/+1 | |
| | | | | | | | If realloc return a pointer value different from the value to be reallocated, a double free can occur in this context. Signed-off-by: Thomas Egerer <thomas.egerer@secunet.com> | |||||
* | rdrand: Provide get_features() regardless of RDRAND availability | Martin Willi | 2014-02-10 | 1 | -6/+6 | |
| | | | | | As having no get_features() raises a deprecated warning, we return no features instead. | |||||
* | rdrand: Move RDRAND detection log to level 2 | Martin Willi | 2014-02-10 | 1 | -2/+2 | |
| | | | | | When having RDRAND support, these log messages might be confusing when using pki or other tools. | |||||
* | updown: Return an empty DNS server enumerator if no IKE_SA available | Martin Willi | 2014-02-06 | 1 | -1/+1 | |
| | | | | | The one existing caller does not handle a NULL return and always expects an enumerator; and returning FALSE does not make sense anyway. | |||||
* | Merge branch 'cmd-proposals' | Martin Willi | 2014-02-06 | 5 | -6/+119 | |
|\ | | | | | | | | | | | | | Introduce --ike/esp/ah-proposal options to offer custom proposals, and requests an IPv6 virtual IP if an IPv6 --remote-ts is given. Fixes #508. | |||||
| * | charon-cmd: Request an IPv6 virtual IP if an IPv6 remote subnet given | Martin Willi | 2014-02-06 | 1 | -4/+23 | |
| | | ||||||
| * | charon-cmd: Document new proposal options in manpage | Martin Willi | 2014-02-06 | 1 | -0/+18 | |
| | | ||||||
| * | charon-cmd: Add --esp/--ah-proposal options to specify CHILD_SA proposals | Martin Willi | 2014-02-06 | 3 | -1/+43 | |
| | | ||||||
| * | charon-cmd: Add an --ike-proposal option to specify non-default IKE proposals | Martin Willi | 2014-02-06 | 3 | -1/+34 | |
| | | ||||||
| * | charon-cmd: Block SIGUSR1 on worker threads | Martin Willi | 2014-02-06 | 1 | -0/+1 | |
|/ | | | | | | To properly shut down charon-cmd with leak reports, only the main thread should catch SIGUSR1 to shut down the application. Work threads should ignore SIGUSR1 to avoid any hard application termination. | |||||
* | Document ipsec attest --session command | Andreas Steffen | 2014-02-05 | 1 | -2/+5 | |
| | ||||||
* | Allow output of session time in UTC | Andreas Steffen | 2014-02-05 | 1 | -2/+2 | |
| | ||||||
* | Added missing semicolon in SQL statements | Andreas Steffen | 2014-02-05 | 2 | -12/+12 | |
| | ||||||
* | Added Android 4.3.1 to products database table | Andreas Steffen | 2014-02-04 | 2 | -4/+28 | |
| | ||||||
* | Added new Android versions to PTS database | Andreas Steffen | 2014-02-04 | 2 | -0/+120 | |
| | ||||||
* | testing: Fetch the FreeRADIUS tarball from the "old" directory | Martin Willi | 2014-01-31 | 1 | -1/+1 | |
| | | | | Fixes #483. | |||||
* | unit-tests: Add some test cases for HTTP GET/POST fetches | Martin Willi | 2014-01-31 | 3 | -1/+275 | |
| | ||||||
* | unit-tests: Fix test_runner_run() apidoc | Martin Willi | 2014-01-29 | 1 | -1/+1 | |
| | ||||||
* | pki: Declare correct section in pki --issue man page | Tobias Brunner | 2014-01-24 | 1 | -1/+1 | |
| | ||||||
* | NEWS: Add unit testing improvements | Martin Willi | 2014-01-24 | 1 | -0/+5 | |
| | ||||||
* | ike: Restart inactivity counter after doing a CHILD_SA rekey | Martin Willi | 2014-01-23 | 2 | -3/+6 | |
| | | | | | | | | | | | | When doing a rekey for a CHILD_SA, the use counters get reset. An inactivity job is queued for a time unrelated to the rekey time, so it might happen that the inactivity job gets executed just after rekeying. If this happens, inactivity is detected even if we had traffic on the rekeyed CHILD_SA just before rekeying. This change implies that inactivity checks can't handle inactivity timeouts for rekeyed CHILD_SAs, and therefore requires that inactivity timeout is shorter than the rekey time to have any effect. | |||||
* | child-sa: Add a getter for CHILD_SA install time | Martin Willi | 2014-01-23 | 2 | -0/+20 | |
| | ||||||
* | Merge branch 'pam-session' | Martin Willi | 2014-01-23 | 7 | -10/+276 | |
|\ | | | | | | | Add support for PAM session management in xauth-pam. | |||||
| * | NEWS: Introduce PAM session management | Martin Willi | 2014-01-23 | 1 | -0/+3 | |
| | | ||||||
| * | man: Document xauth-pam session option | Martin Willi | 2014-01-23 | 1 | -0/+3 | |
| | | ||||||
| * | xauth-pam: Open/close a PAM session for each connected client | Andrea Bonomi | 2014-01-23 | 4 | -9/+265 | |
| | | | | | | | | Signed-off-by: Andrea Bonomi <a.bonomi@endian.com> | |||||
| * | xauth-pam: Sanitize XAuth attributes before passing them to PAM | Martin Willi | 2014-01-23 | 1 | -1/+5 | |
|/ | ||||||
* | Merge branch 'vendor-ids' | Martin Willi | 2014-01-23 | 1 | -16/+63 | |
|\ | | | | | | | | | Refactors IKEv2 vendor ID handling, and introduces some IDs seen when talking to Cisco devices. | |||||
| * | ikev2: Add Cisco FRAGMENTATION vendor ID | Martin Willi | 2014-01-23 | 1 | -0/+2 | |
| | | | | | | | | Courtesy of C.J. Adams-Collier, ZeroLag Communications, Inc. | |||||
| * | ikev2: Add Cisco Copyright vendor ID | Martin Willi | 2014-01-23 | 1 | -0/+2 | |
| | | | | | | | | Courtesy of C.J. Adams-Collier, ZeroLag Communications, Inc. | |||||
| * | ikev2: Add Cisco Delete Reason vendor ID | Martin Willi | 2014-01-23 | 1 | -0/+2 | |
| | | | | | | | | Courtesy of C.J. Adams-Collier, ZeroLag Communications, Inc. |