Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
| * | Added possibility to register custom kernel algorithms to kernel interface | Tobias Brunner | 2012-09-13 | 2 | -1/+172 | |
| | | ||||||
| * | Added possibility to register custom proposal keywords | Tobias Brunner | 2012-09-13 | 9 | -20/+186 | |
| | | | | | | | | Keyword lookup and registration are handled via the new lib->proposal object. | |||||
| * | Removed len argument from proposal_get_token() | Tobias Brunner | 2012-09-13 | 6 | -32/+30 | |
| | | | | | | | | Also use enumerators instead of lexparser.h to parse proposal strings. | |||||
| * | Make arguments for enumerator_create_token|directory const | Tobias Brunner | 2012-09-13 | 2 | -7/+10 | |
| | | ||||||
| * | Moved proposal_keywords to proposal_keywords_static | Francois ten Krooden | 2012-09-13 | 7 | -34/+131 | |
|/ | | | | Added new proposal keywords with function to reference the static keywords. | |||||
* | Option added to enforce a configured destination address for DHCP packets | Tobias Brunner | 2012-09-13 | 2 | -1/+17 | |
| | ||||||
* | version bump to 5.0.1rc1 | Andreas Steffen | 2012-09-12 | 1 | -1/+1 | |
| | ||||||
* | Allow calls to set_address() for any host-sized TS, not only dynamic ones | Tobias Brunner | 2012-09-12 | 1 | -1/+1 | |
| | | | | | This fixes CHILD_SA updates (e.g. due to MOBIKE), which were broken since 4cb0783. | |||||
* | Ensure traffic selectors are dynamic before calling set_address() when ↵ | Tobias Brunner | 2012-09-12 | 1 | -2/+2 | |
| | | | | deriving them | |||||
* | Consistently log XFRM mark masks with 0 prefix in kernel-netlink plugin | Tobias Brunner | 2012-09-12 | 1 | -13/+13 | |
| | ||||||
* | starter: Added --nolog option to suppress logging in starter itself | Tobias Brunner | 2012-09-12 | 1 | -2/+6 | |
| | | | | Fixes #224. | |||||
* | Updates to strongswan.conf(5) man page (added several missing options) | Tobias Brunner | 2012-09-12 | 1 | -39/+82 | |
| | ||||||
* | Some updates to ipsec.conf(5) man page | Tobias Brunner | 2012-09-12 | 1 | -49/+70 | |
| | ||||||
* | starter: Allow %any also for protocol in left|rightprotoport | Tobias Brunner | 2012-09-12 | 1 | -9/+15 | |
| | ||||||
* | Don't allow NULL encryption with PEAP | Martin Willi | 2012-09-12 | 1 | -1/+3 | |
| | ||||||
* | Use memmove on overlapping regions, and operate with correct sizeof() | Martin Willi | 2012-09-12 | 1 | -2/+2 | |
| | ||||||
* | Whitespace cleanups in tls_eap | Martin Willi | 2012-09-12 | 1 | -6/+6 | |
| | ||||||
* | Use uintptr_t in mem pool to avoid compiler warning if sizeof(void*) != ↵ | Martin Willi | 2012-09-12 | 1 | -3/+2 | |
| | | | | sizeof(int) | |||||
* | ikev1 hybrid authentication does not need client certificates | Andreas Steffen | 2012-09-12 | 4 | -6/+0 | |
| | ||||||
* | corrected topology in ikev2/rw-radius-accounting scenario | Andreas Steffen | 2012-09-12 | 1 | -3/+2 | |
| | ||||||
* | added ikev2/rw-eap-dynamic scenario | Andreas Steffen | 2012-09-12 | 16 | -3/+172 | |
| | ||||||
* | Always send a configuration payload in IKEv1 TRANSACTIONs, even if it is empty | Martin Willi | 2012-09-11 | 1 | -29/+14 | |
| | ||||||
* | Don't use host address for dynamic TS in IKEv1 if a virtual IP was expected | Martin Willi | 2012-09-11 | 1 | -40/+57 | |
| | ||||||
* | Don't use host address for dynamic TS in IKEv2 if a virtual IP was expected | Martin Willi | 2012-09-11 | 1 | -1/+33 | |
| | ||||||
* | Don't return a subset for a dynamic TS unless set_address has been called | Martin Willi | 2012-09-11 | 1 | -1/+5 | |
| | ||||||
* | Send FAILED_CP_REQUIRED if a configuration payload was expected, but not ↵ | Martin Willi | 2012-09-11 | 1 | -0/+9 | |
| | | | | received | |||||
* | Check for an existing lease in all stroke pools before creating a new one | Martin Willi | 2012-09-11 | 3 | -83/+180 | |
| | ||||||
* | Pass full pool list to release_address | Martin Willi | 2012-09-11 | 9 | -47/+95 | |
| | ||||||
* | Pass the full list of pools to acquire_address, enumerate in providers | Martin Willi | 2012-09-11 | 10 | -73/+109 | |
| | | | | | | | | If the provider has access to the full pool list, it can enumerate them twice, for example to search for existing leases first, and only search for new leases in a second step. Fixes lease enumeration in attr-sql using multiple pools. | |||||
* | Add a linked list constructor initializing from an enumerator | Martin Willi | 2012-09-11 | 2 | -0/+27 | |
| | ||||||
* | Add a responder narrow() hook to change TS in the kernel, but not on the wire | Martin Willi | 2012-09-11 | 3 | -3/+48 | |
| | ||||||
* | Support RADIUS accounting when using IKEv1 with xauth-eap and eap-radius | Martin Willi | 2012-09-11 | 1 | -2/+10 | |
| | ||||||
* | Fix leak while enumerating RADIUS Framed-IPs from IKE_SA | Martin Willi | 2012-09-11 | 1 | -0/+1 | |
| | ||||||
* | Add uniqueids=never to ignore INITIAL_CONTACT notifies | Tobias Brunner | 2012-09-10 | 6 | -14/+28 | |
| | | | | | | With uniqueids=no the daemon still deletes any existing IKE_SA with the same peer if an INITIAL_CONTACT notify is received. With this new option it also ignores these notifies. | |||||
* | Add random plugin options to strongswan.conf.5 | Martin Willi | 2012-09-10 | 2 | -0/+8 | |
| | ||||||
* | Add strongswan.conf runtime options for /dev/[u]random files | Martin Willi | 2012-09-10 | 1 | -2/+7 | |
| | | | | Fixes #221. | |||||
* | this is the correct evaltest | Andreas Steffen | 2012-09-10 | 1 | -4/+3 | |
| | ||||||
* | recovered ikev2/ip-two-pools-mixed evaltest | Andreas Steffen | 2012-09-10 | 1 | -4/+5 | |
| | ||||||
* | adapted ip-pool evaltests | Andreas Steffen | 2012-09-10 | 5 | -15/+15 | |
| | ||||||
* | Use the proper types for comma separated attributes read from strongswan.conf | Tobias Brunner | 2012-09-10 | 1 | -27/+25 | |
| | | | | | | Attributes of different address families previously were mapped to the same attribute type (the one derived from the address family of the first address). | |||||
* | Print the name of mem pools instead of the confusing <base>/<size> | Tobias Brunner | 2012-09-10 | 1 | -2/+4 | |
| | ||||||
* | Properly remove broadcast address from mem pools | Tobias Brunner | 2012-09-10 | 1 | -1/+1 | |
| | ||||||
* | use base IMC ID if src IMC ID is not supported | Andreas Steffen | 2012-09-10 | 3 | -5/+11 | |
| | ||||||
* | added libimcv.assessment_result to strongswan.conf man page | Andreas Steffen | 2012-09-09 | 1 | -0/+3 | |
| | ||||||
* | make sending of IETF Assessment Result attributes configurable | Andreas Steffen | 2012-09-09 | 3 | -11/+15 | |
| | ||||||
* | introduced sending of standard IETF Assessment Result PA-TNC attribute by IMVs | Andreas Steffen | 2012-09-09 | 21 | -83/+638 | |
| | ||||||
* | Only initiate an exchange from send_dpd() if a task was actually queued | Tobias Brunner | 2012-09-07 | 1 | -2/+8 | |
| | | | | | Otherwise, the initiator would prematurely initiate Quick Mode if it has DPD enabled and XAuth is used. | |||||
* | android: New release after adding certificate authentication and reauth fix | Tobias Brunner | 2012-09-06 | 1 | -2/+2 | |
| | ||||||
* | Trigger ike_updown event caused by retransmits only after reestablish() has ↵ | Tobias Brunner | 2012-09-06 | 3 | -10/+5 | |
| | | | | | | | | been called This allows listeners to migrate to the new IKE_SA with the ike_reestablish event without having to worry about an ike_updown event for the old IKE_SA. | |||||
* | android: Properly handle reauthentication initiated by the client | Tobias Brunner | 2012-09-06 | 1 | -7/+42 | |
| |