Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | First swanctl scenario5.2.0dr5 | Andreas Steffen | 2014-06-01 | 17 | -14/+515 |
| | |||||
* | Added SWID IMV REST API implementation to NEWS | Andreas Steffen | 2014-05-31 | 1 | -1/+4 |
| | |||||
* | Allow large lines output by swid_generator to be processed | Andreas Steffen | 2014-05-31 | 1 | -5/+13 |
| | |||||
* | Make REST POST request timeout configurable | Andreas Steffen | 2014-05-31 | 3 | -11/+25 |
| | |||||
* | Test SWID REST API ins tnc/tnccs-20-pdp scenarios | Andreas Steffen | 2014-05-31 | 83 | -73/+1113 |
| | |||||
* | Detect RADIUS packet retransmissions | Andreas Steffen | 2014-05-31 | 1 | -2/+89 |
| | |||||
* | Updated IMC/IMV entries in strongswan.conf man page | Andreas Steffen | 2014-05-31 | 11 | -35/+41 |
| | |||||
* | Migration from Debian 7.4 to 7.5 | Andreas Steffen | 2014-05-31 | 11 | -18/+18 |
| | |||||
* | Fixed swid_generator interface | Andreas Steffen | 2014-05-31 | 1 | -6/+5 |
| | |||||
* | Detect oversize SWID tags | Andreas Steffen | 2014-05-31 | 1 | -3/+14 |
| | |||||
* | max_attr_size is an uint32_t value | Andreas Steffen | 2014-05-31 | 1 | -1/+1 |
| | |||||
* | Update of Ubuntu 14.04 kernel | Andreas Steffen | 2014-05-31 | 1 | -1/+1 |
| | |||||
* | Wait for the arrival of the TCPG_PTS_DH_NONCE_PARAMS_RESP | Andreas Steffen | 2014-05-31 | 3 | -2/+9 |
| | |||||
* | Increased maximum PT-TLS message size to 2MB | Andreas Steffen | 2014-05-31 | 2 | -3/+3 |
| | |||||
* | log SWID tags and tag IDs on debug level 3 | Andreas Steffen | 2014-05-31 | 1 | -2/+2 |
| | |||||
* | Automatic determination of maximum PB-TNC batch and PA-TNC message size | Andreas Steffen | 2014-05-31 | 5 | -12/+46 |
| | |||||
* | Completed the command line options of the pt-tls-client | Andreas Steffen | 2014-05-31 | 1 | -29/+79 |
| | |||||
* | Split TCG SWID Request attribute into chunks if needed | Andreas Steffen | 2014-05-31 | 4 | -7/+28 |
| | |||||
* | Check for libjson | Andreas Steffen | 2014-05-31 | 1 | -0/+5 |
| | |||||
* | Added Debian 7.5 product and all Debian armv6l products | Andreas Steffen | 2014-05-31 | 1 | -6/+102 |
| | |||||
* | Fixed typo in tables.sql | Andreas Steffen | 2014-05-31 | 1 | -1/+1 |
| | |||||
* | Additional index to improve performance | Andreas Steffen | 2014-05-31 | 1 | -0/+4 |
| | |||||
* | Support targeted retrieval of SWID tags | Andreas Steffen | 2014-05-31 | 1 | -93/+164 |
| | |||||
* | curl: Don't set CURLOPT_FAILONERROR | Tobias Brunner | 2014-05-31 | 1 | -14/+5 |
| | | | | | With the strongTNC REST API some errors will actually be accompanied by a response we want to receive completely. | ||||
* | Implemented SWID REST API | Andreas Steffen | 2014-05-31 | 6 | -103/+508 |
| | |||||
* | Set entity_name to strongSwan Project | Andreas Steffen | 2014-05-31 | 1 | -5/+7 |
| | |||||
* | Updated strongSwan SWID Tag from ISO 2009 to 2014 format | Andreas Steffen | 2014-05-31 | 1 | -29/+19 |
| | |||||
* | Version bump to 5.2.0dr5 | Andreas Steffen | 2014-05-31 | 1 | -1/+1 |
| | |||||
* | Make sure getpass() is available | Tobias Brunner | 2014-05-29 | 3 | -3/+9 |
| | | | | It's not on Android for example. | ||||
* | starter: Fix build on Android | Tobias Brunner | 2014-05-28 | 1 | -0/+1 |
| | | | | | While the (default) ipsec script does not work on Android starter still passes the script's name to charon if leftfirewall is configured. | ||||
* | Some more files to measure | Andreas Steffen | 2014-05-21 | 1 | -0/+7 |
| | |||||
* | Added all SWID tables and example regids | Andreas Steffen | 2014-05-21 | 2 | -122/+105 |
| | |||||
* | scripts: Ignore settings-test script | Tobias Brunner | 2014-05-20 | 1 | -7/+8 |
| | |||||
* | peer-cfg: Add missing UNIQUE_NEVER to unique_policy_names | Martin Willi | 2014-05-19 | 1 | -1/+2 |
| | |||||
* | unit-tests: Sync threads with main thread in test_cleanup_cancel() | Tobias Brunner | 2014-05-19 | 1 | -0/+5 |
| | | | | | Without synchronization threads could get canceled before they could disable their cancelability. | ||||
* | pfkey: Always include stdint.h | Tobias Brunner | 2014-05-19 | 1 | -1/+1 |
| | | | | | | On some systems (e.g. on Debian/kFreeBSD) that header is required when including ipsec.h, on Linux we require it too when including pfkeyv2.h, so to simplify things we just always include it. | ||||
* | Merge branch 'fetcher-response-code' | Tobias Brunner | 2014-05-19 | 9 | -25/+158 |
|\ | | | | | | | Extends the fetcher API to retrieve the response status code for a request. | ||||
| * | soup: Add support to retrieve the response code | Tobias Brunner | 2014-05-19 | 1 | -2/+14 |
| | | |||||
| * | unit-tests: Allow some HTTP write operations to fail | Tobias Brunner | 2014-05-19 | 1 | -7/+12 |
| | | | | | | | | | | | | Because CURLOPT_FAILONERROR is enabled in the curl plugin an error code will often (not always) cause the client to close the TCP connection before the server has written the complete response. | ||||
| * | curl: Add support to return the response code | Tobias Brunner | 2014-05-19 | 1 | -1/+27 |
| | | |||||
| * | unit-tests: Add a test case for HTTP response codes | Tobias Brunner | 2014-05-19 | 1 | -8/+57 |
| | | |||||
| * | fetcher: Add option to retrieve response code from a fetcher | Tobias Brunner | 2014-05-19 | 2 | -0/+10 |
| | | |||||
| * | unit-tests: Defer failures by worker threads | Tobias Brunner | 2014-05-19 | 2 | -5/+36 |
| | | | | | | | | | | | | | | | | | | | | | | In some cases the main thread is not ready to immediately call siglongjmp(), e.g. if it currently holds a mutex that is later required during shutdown. Therefore, we delay handling errors in worker threads until the main thread performs the next check itself (or the test function ends). The same issue remains with SIGALRM. | ||||
| * | unit-tests: Make sure plugins in the builddir are loaded | Tobias Brunner | 2014-05-19 | 2 | -2/+2 |
|/ | | | | | | When running the tests in GDB the working directory apparently is different. With the relative path used previously the plugins would not be found and those installed on the system would get used. | ||||
* | unit-tests: Don't assert failures for unreadable settings files as root | Tobias Brunner | 2014-05-16 | 1 | -5/+8 |
| | | | | The file can still be read by root even if nobody has read privileges. | ||||
* | Merge branch 'aead-proposal' | Martin Willi | 2014-05-16 | 18 | -80/+190 |
|\ | | | | | | | | | | | | | | | | | Encode default AEAD encryption algorithms to a proposal separate from non-AEAD algorithms. RFC 4306 and 5282 where less explicit, but RFC 5996 requires separate proposals for AEAD and non-AEAD algorithms. As responder we still accept both encoding variants. Fixes #573. | ||||
| * | proposal: Don't return a default IKE proposal without encryption/AEAD algs | Martin Willi | 2014-05-16 | 1 | -3/+23 |
| | | |||||
| * | ike: Add an additional but separate AEAD proposal to CHILD config | Martin Willi | 2014-05-16 | 10 | -2/+22 |
| | | | | | | | | | | | | | | This currently has no effect: We don't include AEAD algorithms in the default ESP proposal, as we don't know if it is supported by the backend. But as we hopefully get an algorithm query mechanism on kernel interfaces some day, we add the appropriate functionality nonetheless. | ||||
| * | ike: Add an additional but separate AEAD proposal to IKE config, if supported | Martin Willi | 2014-05-16 | 12 | -10/+37 |
| | | |||||
| * | child-cfg: Allow passing NULL as proposal to add_proposal() | Martin Willi | 2014-05-16 | 2 | -4/+7 |
| | | | | | | | | Making the API consistent to the one of ike_cfg. |