aboutsummaryrefslogtreecommitdiffstats
Commit message (Collapse)AuthorAgeFilesLines
...
| * android: Add utility method to convert a byte array to a hex stringTobias Brunner2014-07-221-0/+40
| |
| * android: Remove unused hash argument from getTrustedCertificates()Tobias Brunner2014-07-222-25/+6
| |
| * android: Use correct tag to define category for CREATE_SHORTCUT intent-filterTobias Brunner2014-07-221-1/+1
|/
* starter: Fix memory leaks and warn if conn/ca sections are ignored due to ↵Tobias Brunner2014-07-181-2/+8
| | | | parse errors
* receiver: Send a single INVALID_MAJOR_VERSION notify for IKE version > 2Martin Willi2014-07-171-3/+1
| | | | | | | | | We sent both a notify using IKEv1 and IKEv2. This is a little more aggressive than required, RFC 5996 says we "SHOULD send an unauthenticated Notify message of type INVALID_MAJOR_VERSION containing the highest (closest) version number it supports". Fixes #657.
* Version bump to 5.2.1dr1Andreas Steffen2014-07-161-1/+1
|
* Determine type of unsupported PA-TNC attribute in error messageAndreas Steffen2014-07-163-47/+84
|
* Replaced Tag File Path by Instance ID fieldAndreas Steffen2014-07-167-49/+49
| | | | | This update reflects the latest changes in the TCG TNC SWID Messages and Attributes for IF-M specification
* man: Document where left|rightsigkey searches for public key filesTobias Brunner2014-07-141-2/+3
|
* swanctl: Fix the swanctl.conf cacerts option name in the manpage and templateMartin Willi2014-07-141-1/+1
|
* Updated URL to swidGenerator in recipe5.2.0Andreas Steffen2014-07-091-1/+1
|
* dumm: Undefine _GNU_SOURCE before including <ruby.h>, as it usually redefines itMartin Willi2014-07-091-0/+2
|
* Version bump to 5.2.0Andreas Steffen2014-07-081-1/+1
|
* NEWS: Updated URL to swidGeneratorTobias Brunner2014-07-071-3/+4
|
* settings: Allow spaces in time settings before the optional unitMartin Willi2014-07-072-2/+7
|
* settings: Be more strict in converting settings to specific data typesMartin Willi2014-07-072-25/+30
| | | | | | | As the behavior was inconsistent for empty strings or strings with characters appended to a number, testing the code failed on some platforms. The new rules are more strict, returning the default if additional characters or an empty string was found for a setting.
* utils: Undefine mem{cpy,move,set} if set before defining themMartin Willi2014-07-071-0/+9
| | | | | Some platforms, such as OS X, use macros for these functions. Undefine them to avoid compiler warnings.
* enumerator: Enumerate glob(3) matches using gl_pathcMartin Willi2014-07-071-9/+6
| | | | | | | While glob should return a NULL terminated gl_pathv when having no matches, at least on OS X this is not true when using GLOB_DOOFFS. Rely on the number of matches returned in gl_pathc, which seems to be more reliable in error cases.
* xauth-pam: Add workaround for null-terminated passwordsTobias Brunner2014-07-071-1/+6
| | | | Fixes #631.
* kernel-netlink: Rename algorithm identifier from cast128 to cast5Martin Willi2014-07-041-1/+1
| | | | | | | | | | | Even if the XFRM identifier was named cast128 in the kernel before 2.6.31, it actually never worked, because there is no such crypto algorithm. The identifier has been changed to cast5 in https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=245acb87 to make it work, so we should use that. Fixes #633.
* winhttp: Do not use countof() on pointer argumentTobias Brunner2014-07-021-1/+1
|
* optionsfrom: Properly handle errors when determining file sizeTobias Brunner2014-07-021-2/+7
|
* windows: Fix off-by-one error in strerror_s_extended()Tobias Brunner2014-07-021-1/+1
|
* windows: accept() socket handle could theoretically be 0Tobias Brunner2014-07-021-1/+1
|
* windows: Close correct socket when opening second socket fails in socketpair()Tobias Brunner2014-07-021-1/+1
|
* windows: Make sure the string returned from ReadConsole() is null terminatedTobias Brunner2014-07-021-0/+2
|
* windows: Remove useless assignment in put_thread()Tobias Brunner2014-07-021-1/+1
|
* backtrace: Remove name checks after SymFromAddr() callsTobias Brunner2014-07-021-9/+5
| | | | The Name member is an array whose address is always defined.
* pts: Avoid integer overflow when reading file names in the old IMA formatTobias Brunner2014-07-011-1/+1
|
* imv-attestation: Avoid memory leak when skipping unsupported work itemsTobias Brunner2014-07-011-0/+1
|
* pts: Use memchr(3) instead of strchr(3) to extract hash algorithm nameTobias Brunner2014-07-011-1/+1
| | | | The string read with read(2) might not be null terminated.
* swid: fgets(3) returns a pointer to the read string or NULLTobias Brunner2014-07-011-3/+3
|
* parser-helper: Ensure file_next() does not remove the sentinel itemTobias Brunner2014-07-011-1/+1
|
* gcrypt: Use predefined pthread locking functions instead of custom hooksMartin Willi2014-07-011-50/+4
| | | | | | | | | | | | | Starting with libgcrypt 1.6, it seems that custom locking functions are not supported anymore. Instead, the user has to select from one of the pre-defined set of locking functions. Given that we have a proper threading abstraction API with optional profiling on all platforms, this is somewhat annoying. However, there does not seem to be a way to use custom functions, and we have no other choice than using the provided macro magic to support all libgcrypt versions. Fixes #630.
* man: Document replay_window ipsec.conf optionTobias Brunner2014-06-301-0/+9
|
* stroke: Don't log unspecified options of conn and ca sectionsTobias Brunner2014-06-301-37/+50
|
* utils: Helper macros to define overloaded macros based on number of argumentsTobias Brunner2014-06-301-0/+26
|
* pki: Document --online option for pki --verify and all exit codesTobias Brunner2014-06-301-5/+11
|
* conf: Document load-tester.crl optionTobias Brunner2014-06-301-0/+4
|
* conf: Document charon.*-scripts optionsTobias Brunner2014-06-301-0/+8
|
* conf: Document swanctl optionsTobias Brunner2014-06-303-0/+4
|
* conf: Document aikgen optionsTobias Brunner2014-06-303-0/+4
|
* autoconf: Replace --disable-tools option with --disable-scepclientTobias Brunner2014-06-309-23/+23
| | | | | Since using a separate option for pki this was the only tool that was still enabled by that option.
* checksum: Fix checksum generation for pki if tools are disabledTobias Brunner2014-06-301-0/+3
|
* doc: Remove obsolete architecture description and empty known bugs listTobias Brunner2014-06-302-61/+0
|
* apidoc: Include *.md and files from the complete source directory (not only src)Tobias Brunner2014-06-301-2/+2
|
* Converted existing README to MarkdownTobias Brunner2014-06-301-741/+525
|
* Move README to README.md so it gets evaluated as MarkdownTobias Brunner2014-06-302-1514/+1515
|
* swid: Fix parameter documentation in Doxygen commentsTobias Brunner2014-06-302-2/+2
|
* windows: Fix parameter name in Doxygen commentTobias Brunner2014-06-301-1/+1
|