aboutsummaryrefslogtreecommitdiffstats
Commit message (Collapse)AuthorAgeFilesLines
* Merge branch 'ext-auth'5.2.1dr1Martin Willi2014-10-0618-249/+1644
|\ | | | | | | | | | | Integrates the ext-auth plugin by Vyronas Tsingaras. The new child process abstraction simplifies implementation in both the new ext-auth and the existing updown plugin, and makes them available on the Windows platform.
| * NEWS: Mention new ext-auth pluginMartin Willi2014-10-061-0/+3
| |
| * ext-auth: Add an ext-auth plugin invoking an external authorization scriptMartin Willi2014-10-069-0/+512
| | | | | | | | Original patch courtesy of Vyronas Tsingaras.
| * updown: Use process abstraction to invoke updown scriptMartin Willi2014-10-061-246/+215
| |
| * process: Add a wrapper to invoke a command under the system default shellMartin Willi2014-10-063-0/+110
| |
| * process: Port child process spawning to the Windows platformMartin Willi2014-10-062-1/+315
| |
| * process: Provide an abstraction to spawn child processes with redirected I/OMartin Willi2014-10-067-3/+490
|/
* testing: Updated certificates and keys in sql scenariosAndreas Steffen2014-10-0635-121/+121
|
* Added IF-M Segmentation support to NEWSAndreas Steffen2014-10-051-0/+5
|
* Incremental parsing fixesAndreas Steffen2014-10-052-14/+9
|
* Updated revoked certificate in ikev2/ocsp-revoked scenarioAndreas Steffen2014-10-052-42/+42
|
* The critical-extension scenarios need the old private keysAndreas Steffen2014-10-054-0/+108
|
* Added add_segment() method to TCG/PTS attributesAndreas Steffen2014-10-0518-26/+157
|
* Added add_segment() method to TCG/SEG attributesAndreas Steffen2014-10-053-25/+49
|
* OS IMV proposes IF-M segmentation contractAndreas Steffen2014-10-056-108/+153
| | | | | | | The OS IMV sends a TCG IF-M Segmentation contract request. All IETF standard attributes support segmentation. Additionally the IETF Installed Packages standard attributes supports incremental processing while segments are received.
* SWID IMC proposes IF-M segmentation contractsAndreas Steffen2014-10-053-24/+42
|
* unit-tests: Updated libimcv test suiteAndreas Steffen2014-10-051-22/+125
|
* Added add_segment() method to IETF attributesAndreas Steffen2014-10-0512-0/+95
|
* Added add_segment() method to ITA attributesAndreas Steffen2014-10-056-0/+47
|
* Implemented incremental processing of SWID tag [ID] inventory attributeAndreas Steffen2014-10-058-199/+253
|
* Implemented add_segment method for PA-TNC attributesAndreas Steffen2014-10-0511-90/+208
|
* Added total length parameter in PA-TNC attribute constructorAndreas Steffen2014-10-0591-319/+957
|
* Assignment of flags starts with bit 0Andreas Steffen2014-10-052-5/+5
|
* Register the reception of the AIK attributeAndreas Steffen2014-10-053-2/+9
|
* Unit tests for libimcvAndreas Steffen2014-10-055-0/+649
|
* Compacted chunk creation in ita_attr_command constructorAndreas Steffen2014-10-051-2/+1
|
* Merged libpts into libimcvAndreas Steffen2014-10-05159-440/+233
|
* Added out message queue for imv_msg receive methodAndreas Steffen2014-10-058-86/+81
|
* Implemented IF-M segmentationAndreas Steffen2014-10-0524-320/+1660
|
* Added request variable to get_info_string methodAndreas Steffen2014-10-035-11/+12
|
* Implemented IF-M segmentation contractsAndreas Steffen2014-10-0332-63/+1354
|
* Allow to treat specified Attribute-Type-Not-Supported errors as non-fatalAndreas Steffen2014-10-0310-16/+110
|
* testing: Updated swanctl certificates and keysTobias Brunner2014-10-0314-292/+292
|
* testing: Wait a bit in swanctl scenarios before interacting with the daemonTobias Brunner2014-10-037-9/+16
|
* testing: Actually build swanctlTobias Brunner2014-10-031-1/+2
|
* testing: Make sure the whitelist plugin is ready before configuring itTobias Brunner2014-10-031-1/+3
|
* testing: Update PKCS#12 containersTobias Brunner2014-10-034-0/+0
|
* testing: Update PKCS#8 keysTobias Brunner2014-10-033-81/+81
|
* testing: Update public keys in DNSSEC scenariosTobias Brunner2014-10-033-0/+0
| | | | | The tests are successful even if the public keys are not stored locally, but an additional DNS query is required to fetch them.
* testing: Update public keys and certificates in DNS zoneTobias Brunner2014-10-031-64/+60
|
* testing: Update carols certificate in several test casesTobias Brunner2014-10-036-129/+129
|
* testing: Add some notes about how to reissue attribute certificatesMartin Willi2014-10-033-0/+61
|
* testing: Reissue attribute certificates for the new holder certificatesMartin Willi2014-10-038-72/+72
| | | | | | Due to the expired and reissued holder certificates of carol and dave, new attribute certificates are required to match the holder certificates serial in the ikev2/acert-{cached,fallback,inline} tests.
* starter: Allow specifying the ipsec.conf location in strongswan.confShea Levy2014-10-022-1/+5
|
* stroke: Allow specifying the ipsec.secrets location in strongswan.confShea Levy2014-10-023-5/+20
|
* library: Allow specifying the path to strongswan.conf in the STRONGSWAN_CONF ↵Shea Levy2014-10-021-1/+1
| | | | env var
* Don't fail to install if sysconfdir isn't writableShea Levy2014-09-262-4/+4
|
* ikev1: Be more verbose if a peer config would match, but is unusable for ModeMartin Willi2014-09-251-0/+12
|
* ikev2: Reorder task activation for established IKE SAsTobias Brunner2014-09-251-11/+11
| | | | We now prefer MOBIKE tasks over delete tasks then the rest.
* Revert "ikev2: Insert MOBIKE tasks at the front of the queue"Tobias Brunner2014-09-251-6/+1
| | | | | | | | This reverts commit 3293d146289d7c05e6c6089ae1f7cdbcea378e63. The position of tasks in the queue does not actually determine the order in which they are activated. Instead this is determined by the statements in task_manager_v2_t.initiate().