Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | Merge branch 'ext-auth'5.2.1dr1 | Martin Willi | 2014-10-06 | 18 | -249/+1644 |
|\ | | | | | | | | | | | Integrates the ext-auth plugin by Vyronas Tsingaras. The new child process abstraction simplifies implementation in both the new ext-auth and the existing updown plugin, and makes them available on the Windows platform. | ||||
| * | NEWS: Mention new ext-auth plugin | Martin Willi | 2014-10-06 | 1 | -0/+3 |
| | | |||||
| * | ext-auth: Add an ext-auth plugin invoking an external authorization script | Martin Willi | 2014-10-06 | 9 | -0/+512 |
| | | | | | | | | Original patch courtesy of Vyronas Tsingaras. | ||||
| * | updown: Use process abstraction to invoke updown script | Martin Willi | 2014-10-06 | 1 | -246/+215 |
| | | |||||
| * | process: Add a wrapper to invoke a command under the system default shell | Martin Willi | 2014-10-06 | 3 | -0/+110 |
| | | |||||
| * | process: Port child process spawning to the Windows platform | Martin Willi | 2014-10-06 | 2 | -1/+315 |
| | | |||||
| * | process: Provide an abstraction to spawn child processes with redirected I/O | Martin Willi | 2014-10-06 | 7 | -3/+490 |
|/ | |||||
* | testing: Updated certificates and keys in sql scenarios | Andreas Steffen | 2014-10-06 | 35 | -121/+121 |
| | |||||
* | Added IF-M Segmentation support to NEWS | Andreas Steffen | 2014-10-05 | 1 | -0/+5 |
| | |||||
* | Incremental parsing fixes | Andreas Steffen | 2014-10-05 | 2 | -14/+9 |
| | |||||
* | Updated revoked certificate in ikev2/ocsp-revoked scenario | Andreas Steffen | 2014-10-05 | 2 | -42/+42 |
| | |||||
* | The critical-extension scenarios need the old private keys | Andreas Steffen | 2014-10-05 | 4 | -0/+108 |
| | |||||
* | Added add_segment() method to TCG/PTS attributes | Andreas Steffen | 2014-10-05 | 18 | -26/+157 |
| | |||||
* | Added add_segment() method to TCG/SEG attributes | Andreas Steffen | 2014-10-05 | 3 | -25/+49 |
| | |||||
* | OS IMV proposes IF-M segmentation contract | Andreas Steffen | 2014-10-05 | 6 | -108/+153 |
| | | | | | | | The OS IMV sends a TCG IF-M Segmentation contract request. All IETF standard attributes support segmentation. Additionally the IETF Installed Packages standard attributes supports incremental processing while segments are received. | ||||
* | SWID IMC proposes IF-M segmentation contracts | Andreas Steffen | 2014-10-05 | 3 | -24/+42 |
| | |||||
* | unit-tests: Updated libimcv test suite | Andreas Steffen | 2014-10-05 | 1 | -22/+125 |
| | |||||
* | Added add_segment() method to IETF attributes | Andreas Steffen | 2014-10-05 | 12 | -0/+95 |
| | |||||
* | Added add_segment() method to ITA attributes | Andreas Steffen | 2014-10-05 | 6 | -0/+47 |
| | |||||
* | Implemented incremental processing of SWID tag [ID] inventory attribute | Andreas Steffen | 2014-10-05 | 8 | -199/+253 |
| | |||||
* | Implemented add_segment method for PA-TNC attributes | Andreas Steffen | 2014-10-05 | 11 | -90/+208 |
| | |||||
* | Added total length parameter in PA-TNC attribute constructor | Andreas Steffen | 2014-10-05 | 91 | -319/+957 |
| | |||||
* | Assignment of flags starts with bit 0 | Andreas Steffen | 2014-10-05 | 2 | -5/+5 |
| | |||||
* | Register the reception of the AIK attribute | Andreas Steffen | 2014-10-05 | 3 | -2/+9 |
| | |||||
* | Unit tests for libimcv | Andreas Steffen | 2014-10-05 | 5 | -0/+649 |
| | |||||
* | Compacted chunk creation in ita_attr_command constructor | Andreas Steffen | 2014-10-05 | 1 | -2/+1 |
| | |||||
* | Merged libpts into libimcv | Andreas Steffen | 2014-10-05 | 159 | -440/+233 |
| | |||||
* | Added out message queue for imv_msg receive method | Andreas Steffen | 2014-10-05 | 8 | -86/+81 |
| | |||||
* | Implemented IF-M segmentation | Andreas Steffen | 2014-10-05 | 24 | -320/+1660 |
| | |||||
* | Added request variable to get_info_string method | Andreas Steffen | 2014-10-03 | 5 | -11/+12 |
| | |||||
* | Implemented IF-M segmentation contracts | Andreas Steffen | 2014-10-03 | 32 | -63/+1354 |
| | |||||
* | Allow to treat specified Attribute-Type-Not-Supported errors as non-fatal | Andreas Steffen | 2014-10-03 | 10 | -16/+110 |
| | |||||
* | testing: Updated swanctl certificates and keys | Tobias Brunner | 2014-10-03 | 14 | -292/+292 |
| | |||||
* | testing: Wait a bit in swanctl scenarios before interacting with the daemon | Tobias Brunner | 2014-10-03 | 7 | -9/+16 |
| | |||||
* | testing: Actually build swanctl | Tobias Brunner | 2014-10-03 | 1 | -1/+2 |
| | |||||
* | testing: Make sure the whitelist plugin is ready before configuring it | Tobias Brunner | 2014-10-03 | 1 | -1/+3 |
| | |||||
* | testing: Update PKCS#12 containers | Tobias Brunner | 2014-10-03 | 4 | -0/+0 |
| | |||||
* | testing: Update PKCS#8 keys | Tobias Brunner | 2014-10-03 | 3 | -81/+81 |
| | |||||
* | testing: Update public keys in DNSSEC scenarios | Tobias Brunner | 2014-10-03 | 3 | -0/+0 |
| | | | | | The tests are successful even if the public keys are not stored locally, but an additional DNS query is required to fetch them. | ||||
* | testing: Update public keys and certificates in DNS zone | Tobias Brunner | 2014-10-03 | 1 | -64/+60 |
| | |||||
* | testing: Update carols certificate in several test cases | Tobias Brunner | 2014-10-03 | 6 | -129/+129 |
| | |||||
* | testing: Add some notes about how to reissue attribute certificates | Martin Willi | 2014-10-03 | 3 | -0/+61 |
| | |||||
* | testing: Reissue attribute certificates for the new holder certificates | Martin Willi | 2014-10-03 | 8 | -72/+72 |
| | | | | | | Due to the expired and reissued holder certificates of carol and dave, new attribute certificates are required to match the holder certificates serial in the ikev2/acert-{cached,fallback,inline} tests. | ||||
* | starter: Allow specifying the ipsec.conf location in strongswan.conf | Shea Levy | 2014-10-02 | 2 | -1/+5 |
| | |||||
* | stroke: Allow specifying the ipsec.secrets location in strongswan.conf | Shea Levy | 2014-10-02 | 3 | -5/+20 |
| | |||||
* | library: Allow specifying the path to strongswan.conf in the STRONGSWAN_CONF ↵ | Shea Levy | 2014-10-02 | 1 | -1/+1 |
| | | | | env var | ||||
* | Don't fail to install if sysconfdir isn't writable | Shea Levy | 2014-09-26 | 2 | -4/+4 |
| | |||||
* | ikev1: Be more verbose if a peer config would match, but is unusable for Mode | Martin Willi | 2014-09-25 | 1 | -0/+12 |
| | |||||
* | ikev2: Reorder task activation for established IKE SAs | Tobias Brunner | 2014-09-25 | 1 | -11/+11 |
| | | | | We now prefer MOBIKE tasks over delete tasks then the rest. | ||||
* | Revert "ikev2: Insert MOBIKE tasks at the front of the queue" | Tobias Brunner | 2014-09-25 | 1 | -6/+1 |
| | | | | | | | | This reverts commit 3293d146289d7c05e6c6089ae1f7cdbcea378e63. The position of tasks in the queue does not actually determine the order in which they are activated. Instead this is determined by the statements in task_manager_v2_t.initiate(). |