Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | charon-xpc: Load missing eap-md5 plugin after enabling it | Martin Willi | 2013-10-28 | 1 | -1/+1 | |
| | ||||||
* | charon-xpc: Disable warnings about deprecated functions | Martin Willi | 2013-10-28 | 1 | -1/+1 | |
| | | | | This avoids all the deprecated warnings when using OpenSSL functins. | |||||
* | charon-xpc: Avoid -all_load linker flag | Martin Willi | 2013-10-28 | 1 | -1/+0 | |
| | | | | This seems to be not required anymore with the LLVM 5 toolchain. | |||||
* | charon-xpc: Properly xpc_retain() connections we xpc_release() | Martin Willi | 2013-10-28 | 2 | -0/+2 | |
| | ||||||
* | charon-xpc: Properly cast SA identifier to uintptr representation | Martin Willi | 2013-10-28 | 1 | -1/+1 | |
| | ||||||
* | charon-xpc: Don’t build against libvstr anymore | Martin Willi | 2013-10-28 | 2 | -14/+4 | |
| | | | | We now have our own printf backend and use it instead of Vstr. | |||||
* | charon-xpc: Build with EAP-MD5 support | Martin Willi | 2013-10-28 | 1 | -2/+2 | |
| | ||||||
* | utils: Fix check for fmemopen() fallback implementation | Martin Willi | 2013-10-24 | 2 | -2/+3 | |
| | ||||||
* | unit-tests: Set sa_len in sockaddr template data, if required | Martin Willi | 2013-10-24 | 1 | -0/+6 | |
| | ||||||
* | printf-hook-builtin: Don't rely on isinf() return value signedness | Martin Willi | 2013-10-24 | 1 | -8/+9 | |
| | | | | | Many systems don't return a negative value for negative infinities; so do a separate check. | |||||
* | watcher: Rebuild fdset when select() fails | Martin Willi | 2013-10-24 | 1 | -1/+12 | |
| | | | | | | This should make sure we refresh the fdset if a user closes an FD it just removed. Some selects() seem to complain about the bad FD before signaling the notification pipe. | |||||
* | rwlock: Disable thread cancelability while waiting in (fallback) rwlock | Martin Willi | 2013-10-24 | 1 | -0/+7 | |
| | | | | | | An rwlock wait is not a thread cancellation point. As a canceled thread would not have released the mutex, the rwlock would have been left in unusable state. | |||||
* | rwlock: Don't use buggy pthread_rwlock on OS X | Martin Willi | 2013-10-24 | 1 | -0/+7 | |
| | | | | Recursive read locks don't seem to work properly, at least on 10.9. | |||||
* | utils: Provide a fmemopen(3) fallback using BSD funopen() | Martin Willi | 2013-10-24 | 3 | -0/+62 | |
| | ||||||
* | Fixed sql/net2net-route-pem scenario evaluation5.1.1rc1 | Andreas Steffen | 2013-10-23 | 1 | -2/+2 | |
| | ||||||
* | Added some example Debian SWID tags | Andreas Steffen | 2013-10-23 | 8 | -1/+211 | |
| | ||||||
* | Added Brainpool ECP support to NEWS | Andreas Steffen | 2013-10-23 | 1 | -0/+4 | |
| | ||||||
* | Added two Brainpool IKEv2 scenarios | Andreas Steffen | 2013-10-23 | 22 | -0/+298 | |
| | ||||||
* | pki: Replace BUILD_FROM_FD with passing a chunk via BUILD_BLOB | Tobias Brunner | 2013-10-23 | 11 | -74/+54 | |
| | | | | This allows more than one builder to try parsing the data read from STDIN. | |||||
* | chunk: Add helper function to create a chunk from data read from a file ↵ | Tobias Brunner | 2013-10-23 | 2 | -0/+40 | |
| | | | | descriptor | |||||
* | semaphore: Support cancellation in wait functions of semaphore fallback | Martin Willi | 2013-10-23 | 1 | -4/+6 | |
| | | | | | Semaphore wait functions should be a thread cancellation point, but did not properly release the mutex in the fallback implementation. | |||||
* | rwlock: Re-acquire rwlock even if condvar wait times out | Martin Willi | 2013-10-23 | 1 | -1/+1 | |
| | | | | | A caller expects that the associated rwlock is held, whether the condvar gets signaled or the wait times out. | |||||
* | Updated and split data.sql | Andreas Steffen | 2013-10-23 | 18 | -4565/+392 | |
| | ||||||
* | Adapted recipe and patches to freeradius-2.2.1 | Andreas Steffen | 2013-10-22 | 3 | -23/+4 | |
| | ||||||
* | Support Ubuntu 13.10 measurements | Andreas Steffen | 2013-10-21 | 2 | -1/+46 | |
| | ||||||
* | check it specified IF-TNCCS protocol is enabled | Andreas Steffen | 2013-10-21 | 1 | -0/+6 | |
| | ||||||
* | kernel-netlink: Check existence of linux/fib_rules.h, don't include it in ↵ | Tobias Brunner | 2013-10-18 | 4 | -77/+12 | |
| | | | | | | distribution This reverts commit b0761f1f0a5abd225edc291c8285f99a538e6a66. | |||||
* | Merge branch 'icmp' | Tobias Brunner | 2013-10-17 | 8 | -44/+245 | |
|\ | | | | | | | | | | | | | Improves handling of ICMP[v6] traffic selectors that specify message type and code. Fixes #421. | |||||
| * | ipsec.conf.5: Note about ICMP[v6] message type/code added | Tobias Brunner | 2013-10-17 | 1 | -0/+8 | |
| | | ||||||
| * | updown: Properly configure ICMP[v6] message type and code in firewall rules | Tobias Brunner | 2013-10-17 | 1 | -4/+29 | |
| | | ||||||
| * | updown: Pass ICMP[v6] message type and code to updown script | Tobias Brunner | 2013-10-17 | 2 | -4/+27 | |
| | | | | | | | | The type is passed in $PLUTO_MY_PORT and the code in $PLUTO_PEER_PORT. | |||||
| * | kernel-pfkey: Install ICMP[v6] type/code as expected by the Linux kernel | Tobias Brunner | 2013-10-17 | 1 | -19/+52 | |
| | | ||||||
| * | kernel-netlink: Convert ports in acquires to ICMP[v6] type and code | Tobias Brunner | 2013-10-17 | 1 | -3/+8 | |
| | | ||||||
| * | kernel-netlink: Properly install policies with ICMP[v6] types and codes | Tobias Brunner | 2013-10-17 | 1 | -1/+12 | |
| | | ||||||
| * | traffic-selector: Print ICMP[v6] message type and code in a more readable way | Tobias Brunner | 2013-10-17 | 1 | -4/+35 | |
| | | ||||||
| * | traffic-selector: Store ICMP[v6] message type and code properly | Tobias Brunner | 2013-10-17 | 2 | -8/+70 | |
| | | | | | | | | We now store them as defined in RFC 4301, section 4.4.1.1. | |||||
| * | traffic-selector: Move class to its own Doxygen group | Tobias Brunner | 2013-10-17 | 2 | -1/+4 | |
|/ | ||||||
* | Merge branch 'ecc-brainpool' | Tobias Brunner | 2013-10-17 | 6 | -9/+311 | |
|\ | | | | | | | Adds support for ECC Brainpool curves for DH exchanges. | |||||
| * | proposal: Add ECC Brainpool DH groups to the default proposal | Tobias Brunner | 2013-10-17 | 1 | -0/+4 | |
| | | ||||||
| * | openssl: Add workaround if ECC Brainpool curves are not defined | Tobias Brunner | 2013-10-17 | 1 | -11/+247 | |
| | | ||||||
| * | openssl: Add support for ECC Brainpool curves for DH, if defined by OpenSSL | Tobias Brunner | 2013-10-17 | 2 | -6/+51 | |
| | | | | | | | | OpenSSL does not include them in releases before 1.0.2. | |||||
| * | ecc: Added ECC Brainpool ECDH groups as registered with IANA | Andreas Steffen | 2013-10-17 | 3 | -3/+20 | |
|/ | ||||||
* | unit-tests: Make test for bio_writer_t more portable | Tobias Brunner | 2013-10-17 | 1 | -2/+8 | |
| | ||||||
* | libipsec: Don't print ciphertext with ICV in log message | Tobias Brunner | 2013-10-17 | 1 | -1/+2 | |
| | ||||||
* | libipsec: Properly calculate padding length especially for AES-GCM | Tobias Brunner | 2013-10-17 | 1 | -1/+3 | |
| | ||||||
* | utils: Add utility function to calculate padding length | Tobias Brunner | 2013-10-17 | 2 | -13/+24 | |
| | ||||||
* | stroke: Reuse reqids of established CHILD_SAs when routing connections | Tobias Brunner | 2013-10-17 | 1 | -1/+45 | |
| | ||||||
* | trap-manager: Make sure a config is not trapped twice | Tobias Brunner | 2013-10-17 | 1 | -4/+16 | |
| | ||||||
* | Doxygen fixes | Tobias Brunner | 2013-10-15 | 7 | -11/+8 | |
| | ||||||
* | Set recommendation in the case of PCR measurement failures | Andreas Steffen | 2013-10-13 | 3 | -6/+27 | |
| |