Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | Version bump to 5.2.0dr35.2.0dr3 | Andreas Steffen | 2014-05-12 | 1 | -1/+1 |
| | |||||
* | Added implementation of RFC 7171 to NEWS | Andreas Steffen | 2014-05-12 | 1 | -0/+3 |
| | |||||
* | Implemented PT-EAP protocol (RFC 7171) | Andreas Steffen | 2014-05-12 | 56 | -236/+337 |
| | |||||
* | Extended build-database.sh | Andreas Steffen | 2014-05-12 | 1 | -2/+25 |
| | |||||
* | attest now maintains multiple versions of a file hash | Andreas Steffen | 2014-05-10 | 6 | -95/+86 |
| | |||||
* | Changed default value to libimcv.imc-attestation.pcr_info = no | Andreas Steffen | 2014-05-10 | 2 | -2/+2 |
| | |||||
* | child-sa: Reclaim old state if SA updating is not supported | Martin Willi | 2014-05-09 | 1 | -0/+2 |
| | | | | | If the state stays at UPDATING, the fallback using IKEv1 rekeying fails as the task manager refuses to rekey a CHILD_SA in non-INSTALLED state. | ||||
* | NEWS: Add swanctl news | Martin Willi | 2014-05-08 | 1 | -0/+5 |
| | |||||
* | Merge branch 'swanctl' | Martin Willi | 2014-05-07 | 28 | -7/+4861 |
|\ | | | | | | | | | Adds a swanctl command line tool to manage the IKE daemon charon using the VICI interface provided by the vici plugin. | ||||
| * | swanctl: By default print local swanctl version with --version | Martin Willi | 2014-05-07 | 1 | -2/+12 |
| | | | | | | | | But add a --daemon option to query the IKE daemon for its version. | ||||
| * | swanctl: Install empty credential folders with appropriate permissions | Martin Willi | 2014-05-07 | 1 | -0/+8 |
| | | |||||
| * | swanctl: Document most swanctl.conf options in manpage | Martin Willi | 2014-05-07 | 2 | -130/+693 |
| | | |||||
| * | swanctl: Keep swanctl.conf man/template section order as defined | Martin Willi | 2014-05-07 | 1 | -2/+2 |
| | | |||||
| * | conf: Add a format-options --nosort option to keep order of sections as defined | Martin Willi | 2014-05-07 | 1 | -4/+10 |
| | | |||||
| * | swanctl: Add a swanctl command overview manpage | Martin Willi | 2014-05-07 | 4 | -0/+86 |
| | | |||||
| * | swanctl: Generate swanctl.conf(5) man page | Tobias Brunner | 2014-05-07 | 5 | -0/+36 |
| | | |||||
| * | swanctl: Generate man page snippet with config options | Tobias Brunner | 2014-05-07 | 1 | -3/+7 |
| | | |||||
| * | conf: Properly propagate whether a section is commented or not | Tobias Brunner | 2014-05-07 | 1 | -3/+4 |
| | | |||||
| * | swanctl: Convert swanctl.conf to an options file and generate config | Tobias Brunner | 2014-05-07 | 4 | -126/+198 |
| | | |||||
| * | swanctl: Install swanctl.conf if it does not exist yet | Tobias Brunner | 2014-05-07 | 1 | -2/+6 |
| | | |||||
| * | swanctl: Change syntax of secrets to accept identities with special chars | Martin Willi | 2014-05-07 | 2 | -46/+55 |
| | | | | | | | | | | | | | | | | | | | | | | Having identity strings in the settings key is problematic, as the parser can't handle arbitrary characters in it. Further, the space separation makes it impossible to define identities with spaces. The new format uses key prefixes, similar to those used in local/remote auth sections of connections. The secrets section takes subsections with type prefixes, and each subsection uses "id" prefixes to define an arbitrary number of identities. | ||||
| * | swanctl: List local and remote addresses in list-conns | Martin Willi | 2014-05-07 | 1 | -1/+18 |
| | | |||||
| * | swanctl: Add a list-pools command to summarize pool status | Martin Willi | 2014-05-07 | 3 | -1/+98 |
| | | |||||
| * | swanctl: Add a load-pools command to (re-)load pool configurations from file | Martin Willi | 2014-05-07 | 3 | -1/+285 |
| | | |||||
| * | swanctl: Encode connection "pools" as list items | Martin Willi | 2014-05-07 | 1 | -0/+1 |
| | | |||||
| * | swanctl: Fix enumeration of registered commands if MAX_COMMANDS is hit | Martin Willi | 2014-05-07 | 1 | -3/+3 |
| | | |||||
| * | swanctl: Implement a --log command to trace debugging log | Martin Willi | 2014-05-07 | 3 | -1/+98 |
| | | |||||
| * | swanctl: Add a swanctl.conf template file | Martin Willi | 2014-05-07 | 2 | -0/+124 |
| | | |||||
| * | swanctl: Implement a --list-certs command to print or export daemon certificates | Martin Willi | 2014-05-07 | 3 | -1/+670 |
| | | |||||
| * | swanctl: Be more verbose while loading connections and credentials | Martin Willi | 2014-05-07 | 2 | -2/+26 |
| | | |||||
| * | swanctl: Add a list-conns command to query loaded connections | Martin Willi | 2014-05-07 | 2 | -0/+220 |
| | | |||||
| * | swanctl: Register --version as last command | Martin Willi | 2014-05-07 | 1 | -1/+1 |
| | | |||||
| * | swanctl: Support groups, certs and cacerts keywords | Martin Willi | 2014-05-07 | 1 | -0/+70 |
| | | |||||
| * | swanctl: Load shared secrets from the swanctl.conf secrets section | Martin Willi | 2014-05-07 | 1 | -1/+96 |
| | | |||||
| * | swanctl: Load different private keys with load-creds | Martin Willi | 2014-05-07 | 2 | -1/+197 |
| | | |||||
| * | swanctl: Add a command to (re-)load credentials | Martin Willi | 2014-05-07 | 3 | -0/+197 |
| | | |||||
| * | swanctl: Use a ./configure-able swanctl base directory | Martin Willi | 2014-05-07 | 4 | -6/+35 |
| | | |||||
| * | swanctl: After loading connections, unload those that are not in config anymore | Martin Willi | 2014-05-07 | 1 | -7/+114 |
| | | |||||
| * | swanctl: Implement a load-conn command to load connections from a file | Martin Willi | 2014-05-07 | 2 | -0/+229 |
| | | |||||
| * | swanctl: Implement a list-pols command to query trap/shunt policies | Martin Willi | 2014-05-07 | 2 | -0/+205 |
| | | |||||
| * | swanctl: Implement install/uninstall commands to manage shunt/trap policies | Martin Willi | 2014-05-07 | 2 | -0/+121 |
| | | |||||
| * | swanctl: Add a version command to query daemon and OS info | Martin Willi | 2014-05-07 | 2 | -0/+82 |
| | | |||||
| * | swanctl: Add a terminate command | Martin Willi | 2014-05-07 | 2 | -0/+154 |
| | | |||||
| * | swanctl: Add a subcommand to initiate connections by name | Martin Willi | 2014-05-07 | 2 | -0/+129 |
| | | |||||
| * | swanctl: Add a list-sas command to query active IKE_SAs | Martin Willi | 2014-05-07 | 2 | -0/+360 |
| | | |||||
| * | swanctl: Add a stub for a vici based configuration and control utility | Martin Willi | 2014-05-07 | 8 | -0/+496 |
| | | |||||
| * | libcharon: Execute scripts defined in strongswan.conf during startup/shutdown | Martin Willi | 2014-05-07 | 1 | -0/+52 |
|/ | |||||
* | Merge branch 'vici' | Martin Willi | 2014-05-07 | 42 | -6/+10401 |
|\ | | | | | | | | | | | Introduces the vici plugin providing a Versatile IKE Configuration Interface to configure, monitor and control the IKE daemon charon over a stable IPC socket interface. | ||||
| * | NEWS: Add vici plugin news | Martin Willi | 2014-05-07 | 1 | -0/+6 |
| | | |||||
| * | vici: Check if header has been received before processing an empty message | Martin Willi | 2014-05-07 | 1 | -1/+2 |
| | | | | | | | | | | | | If do_read() returns with EWOULDBLOCK, we must ensure that we actually have processed the full length header before checking the zero-initialized buffer length. |