aboutsummaryrefslogtreecommitdiffstats
Commit message (Expand)AuthorAgeFilesLines
* testing: attr-sql is a charon plugin5.4.0dr8Andreas Steffen2016-03-0511-42/+10
* testing: Added swanctl/rw-psk-ikev1 scenarioAndreas Steffen2016-03-0511-0/+271
* testing: Include IKE port information in evaltestsAndreas Steffen2016-03-0568-238/+221
* Version bump to 5.4.0dr8Andreas Steffen2016-03-041-1/+1
* ike-sa-manager: Log some additional details like SPIs when checking out SAsTobias Brunner2016-03-041-7/+16
* smp: Correctly return IKE SPIs stored in network orderTobias Brunner2016-03-041-4/+4
* vici: Correctly return IKE SPIs stored in network orderTobias Brunner2016-03-041-2/+4
* stroke: Correctly print IKE SPIs stored in network orderTobias Brunner2016-03-041-2/+4
* byteorder: Simplify htoun64/untoh64 functionsTobias Brunner2016-03-041-27/+0
* byteorder: Always define be64toh/htobe64 macrosTobias Brunner2016-03-041-20/+30
* Merge branch 'ike-sig-contraints'Tobias Brunner2016-03-0412-90/+316
|\
| * NEWS: Add note about IKEv2 signature scheme constraintsTobias Brunner2016-03-041-0/+4
| * swanctl: Document signature scheme constraintsTobias Brunner2016-03-041-1/+30
| * vici: Add support for pubkey constraints with EAP-TLSTobias Brunner2016-03-041-0/+8
| * auth-cfg: Make IKE signature schemes configurableTobias Brunner2016-03-048-46/+203
| * ikev2: Always store signature scheme in auth-cfgTobias Brunner2016-03-041-12/+1
| * ikev2: Diversify signature scheme ruleThomas Egerer2016-03-044-33/+72
|/
* NEWS: Document RFC 5685 supportTobias Brunner2016-03-041-0/+6
* Merge branch 'ike-redirect'Tobias Brunner2016-03-0450-122/+2168
|\
| * ike-init: Verify REDIRECT notify before processing IKE_SA_INIT messageTobias Brunner2016-03-041-7/+51
| * ikev2: Allow tasks to verify request messages before processing themTobias Brunner2016-03-041-4/+47
| * ikev2: Allow tasks to verify response messages before processing themTobias Brunner2016-03-041-1/+27
| * task: Add optional pre_process() methodTobias Brunner2016-03-041-1/+13
| * testing: Add ikev2/redirect-active scenarioTobias Brunner2016-03-0420-0/+322
| * ike-init: Ignore notifies related to redirects during rekeyingTobias Brunner2016-03-041-3/+13
| * ike-sa: Add limit for the number of redirects within a defined time periodTobias Brunner2016-03-042-0/+54
| * ike-sa: Reauthenticate to the same addresses we currently useTobias Brunner2016-03-041-2/+5
| * vici: Don't redirect all SAs if no selectors are givenTobias Brunner2016-03-041-1/+1
| * vici: Match subnets and ranges against peer IP in redirect commandTobias Brunner2016-03-043-13/+43
| * vici: Match identity with wildcards against remote ID in redirect commandTobias Brunner2016-03-043-6/+10
| * swanctl: Add --redirect commandTobias Brunner2016-03-044-1/+138
| * vici: Add redirect commandTobias Brunner2016-03-045-0/+150
| * redirect-job: Add job to redirect an active IKE_SATobias Brunner2016-03-044-0/+159
| * ike-sa: Add redirect() method to actively redirect an IKE_SATobias Brunner2016-03-042-0/+50
| * ike-redirect: Add task to redirect active IKE_SAsTobias Brunner2016-03-047-0/+220
| * ike-auth: Handle REDIRECT notifies during IKE_AUTHTobias Brunner2016-03-041-22/+44
| * ike-sa: Handle redirect requests for established SAs as reestablishmentTobias Brunner2016-03-041-82/+174
| * ike-auth: Send REDIRECT notify during IKE_AUTH if requested by providersTobias Brunner2016-03-041-27/+51
| * ike-config: Do not assign attributes for redirected IKE_SAsTobias Brunner2016-03-041-0/+5
| * child-create: Don't create CHILD_SA if the IKE_SA got redirected in IKE_AUTHTobias Brunner2016-03-041-0/+4
| * ike-sa: Add a condition to mark redirected IKE_SAsTobias Brunner2016-03-041-0/+5
| * ike-init: Handle REDIRECTED_FROM similar to REDIRECT_SUPPORTED as serverTobias Brunner2016-03-041-0/+17
| * ike-init: Send REDIRECTED_FROM instead of REDIRECT_SUPPORTED if appropriateTobias Brunner2016-03-041-1/+19
| * ike-sa: Keep track of the address of the gateway that redirected usTobias Brunner2016-03-042-1/+27
| * ikev2: Add option to disable following redirects as clientTobias Brunner2016-03-043-1/+23
| * ikev2: Handle REDIRECT notifies during IKE_SA_INITTobias Brunner2016-03-043-0/+64
| * ike-init: Send REDIRECT notify during IKE_SA_INIT if requested by providersTobias Brunner2016-03-041-0/+17
| * redirect-manager: Add helper function to create and parse REDIRECT notify dataTobias Brunner2016-03-042-11/+162
| * redirect-manager: Verify type of returned gateway IDTobias Brunner2016-03-041-1/+12
| * ike-init: Send REDIRECT_SUPPORTED as initiatorTobias Brunner2016-03-041-0/+5