Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
| * | nm: Version bumb to 1.3.2 | Tobias Brunner | 2016-09-05 | 1 | -1/+1 | |
| | | ||||||
| * | nm: Remove incorrect top-level GtkWindow | Tobias Brunner | 2016-09-05 | 1 | -312/+306 | |
| | | | | | | | | Fixes #1013. | |||||
| * | nm: Replace libgnomekeyring with libsecret | Lubomir Rintel | 2016-09-05 | 4 | -40/+20 | |
| | | | | | | | | The former is deprecated and the newer API is nicer anyway. | |||||
| * | nm: Drop useless calls to AC_SUBST | Lubomir Rintel | 2016-09-05 | 1 | -11/+0 | |
| | | | | | | | | PKG_CHECK_MODULES does the substitutions. | |||||
| * | nm: Drop some unneeded dependencies | Lubomir Rintel | 2016-09-05 | 3 | -10/+0 | |
| | | ||||||
| * | nm: Install the .name file into /usr/lib/NetworkManager/VPN | Lubomir Rintel | 2016-09-05 | 3 | -3/+25 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | It's the preferred location for system-provided plugins. A compatible file in /etc is still kept. Also, the compatibility /etc file needs to use a full path due to a bug in GNOME Shell. The full path to a arch-dependent file in a supposedly arch-independent file is a sin and a multilib violation in some distributions. However. some pre-release versions of NetworkManager-1.2 as shipped by distributions require a full path. Let's keep a configure-time option for that. | |||||
| * | nm: Automatically determine NM plugin directory | Tobias Brunner | 2016-09-05 | 2 | -2/+3 | |
| | | ||||||
| * | nm: Automatically determine path to the auth dialog | Lubomir Rintel | 2016-09-05 | 4 | -3/+6 | |
| | | ||||||
| * | nm: Don't do <deny send_interface="..." /> in dbus service file | Lubomir Rintel | 2016-09-05 | 1 | -1/+0 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | It does more than intended; apart from denying messages to that particular interface it also denies all messages non-qualified with an interface globally. This blocks messages completely unrelated to strongSwan's VPN plugin, such as NetworkManager communication with the VPN plugins. From the dbus-daemon manual: Be careful with send_interface/receive_interface, because the interface field in messages is optional. In particular, do NOT specify <deny send_interface="org.foo.Bar"/>! This will cause no-interface messages to be blocked for all services, which is almost certainly not what you intended. Always use rules of the form: <deny send_interface="org.foo.Bar" send_destination="org.foo.Service"/> We can just safely remove those rules, since we're sufficiently protected by the send_destination matches and method calls are disallowed by default anyway. Closes strongswan/strongswan#42. | |||||
| * | nm: Move the D-Bus policy to charon-nm | Lubomir Rintel | 2016-09-05 | 3 | -5/+5 | |
|/ | | | | It's needed for useful use of charon-nm, unlike the GUI. | |||||
* | nm: Add AppStream metadata | Lubomir Rintel | 2016-09-05 | 5 | -1/+51 | |
| | | | | | | | This will ensure the strongSwan NetworkManager plugin will be easily installable from the app stores such as GNOME Software. Closes strongswan/strongswan#41. | |||||
* | pt-tls-client: Added support of ECDSA keys | Andreas Steffen | 2016-08-31 | 1 | -7/+23 | |
| | ||||||
* | libimcv: No need to load AIK pubkey if AIK certificate is available | Andreas Steffen | 2016-08-31 | 1 | -13/+16 | |
| | ||||||
* | swanctl: Document how DH groups in CHILD_SA proposals are applied | Tobias Brunner | 2016-08-31 | 1 | -6/+13 | |
| | | | | References #1039. | |||||
* | man: Update description of the esp keyword | Tobias Brunner | 2016-08-31 | 1 | -8/+19 | |
| | | | | | | | Clarifies how DH groups are applied, updates the proposal selection description and ESN can now also be configured for IKEv1. References #1039. | |||||
* | padlock: Use builtin bswap32() to fix compilation on FreeBSD | Tobias Brunner | 2016-08-31 | 1 | -6/+5 | |
| | | | | Fixes #591. | |||||
* | testing: Try to properly abort a test run after CTRL-C | Tobias Brunner | 2016-08-30 | 1 | -0/+15 | |
| | | | | | | | | | The run is aborted after the current scenario. Depending on which command was interrupted it might be necessary to press CTRL-C multiple times (e.g. if a later command depends on the interrupted one). This should fix HTML files and get us some proper console output after the run. | |||||
* | testing: Report number of tests per subdirectory in main index | Tobias Brunner | 2016-08-30 | 1 | -7/+22 | |
| | ||||||
* | testing: Mount and serve testresults from the host | Tobias Brunner | 2016-08-29 | 3 | -10/+8 | |
| | | | | | | | | This avoids having to copy testresults, makes results of cancelled runs browsable (runs may actually be followed live) and preserves old results when rebuilding guest images (e.g. when using the build-strongswan script). The number of consecutive test runs without any intermittent rebuild of the guest images is also not limited by the image size anymore. | |||||
* | testing: Create a symlink to the testresults under a known path when ↵ | Tobias Brunner | 2016-08-29 | 2 | -0/+8 | |
| | | | | starting the environment | |||||
* | testing: Serve images in testresults via mod_rewrite and not a symlink | Tobias Brunner | 2016-08-29 | 3 | -1/+4 | |
| | ||||||
* | conf: Extend description of charon.plugins.kernel-netlink.xfrm_acq_expires | Tobias Brunner | 2016-08-29 | 1 | -5/+9 | |
| | ||||||
* | proposal: Use proper list to get function pointer when adding custom parser | Thomas Egerer | 2016-08-29 | 1 | -1/+1 | |
| | | | | Signed-off-by: Thomas Egerer <thomas.egerer@secunet.com> | |||||
* | android: Add missing xof.c file | Tobias Brunner | 2016-08-29 | 1 | -0/+1 | |
| | | | | Fixes #2093. | |||||
* | xof: Add header to dev headers | Tobias Brunner | 2016-08-29 | 1 | -1/+2 | |
| | ||||||
* | Version bump to 5.5.1dr25.5.1dr2 | Andreas Steffen | 2016-08-26 | 2 | -3/+3 | |
| | ||||||
* | configure: Improve check for built-in __atomic_* functions | Tobias Brunner | 2016-08-26 | 1 | -2/+13 | |
| | | | | | | | | | | | | | | With AC_SEARCH_LIBS() we don't succeed if the searched function is a built-in as the check uses the wrong signature so the built-in will not be applied (the warning issued by GCC is "conflicting types for built-in function '...'"). So even if not required, libatomic will be linked if it is found, which could be problematic if compiling on a separate host and the target host does not have libatomic installed. Also, some tests showed that it's more likely that __atomic_and_fetch() requires linking libatomic than __atomic_load_n() does. References #1533. | |||||
* | travis: Add a workaround for a bug regarding libtool installed via Homebrew | Tobias Brunner | 2016-08-25 | 1 | -0/+2 | |
| | ||||||
* | ikev1: Don't require AH mapping for integrity algorithm when generating proposal | Thomas Egerer | 2016-08-25 | 1 | -6/+9 | |
| | | | | Signed-off-by: Thomas Egerer <thomas.egerer@secunet.com> | |||||
* | libtpmtss: TCTI finalization call changed | Andreas Steffen | 2016-08-25 | 1 | -1/+2 | |
| | ||||||
* | conf: aikpub2.opt added to Makefile.am | Andreas Steffen | 2016-08-25 | 1 | -0/+1 | |
| | ||||||
* | pki: Allow to load CRLs from files in --verify | Tobias Brunner | 2016-08-25 | 2 | -3/+21 | |
| | ||||||
* | ikev1: Ignore the last two bytes of the Cisco Unity vendor ID | Tobias Brunner | 2016-08-24 | 1 | -0/+3 | |
| | | | | | | | | | These seem to indicate the major and minor version of the protocol, like e.g. for the DPD vendor ID. Some implementations seem to send versions other than 1.0 so we just ignore these for now when checking for known vendor IDs. Fixes #2088. | |||||
* | utils: Fix definition of BYTE_ORDER with MinGW | Tobias Brunner | 2016-08-24 | 2 | -2/+6 | |
| | ||||||
* | ikev1: Accept more than one certificate payload in aggressive mode | Tobias Brunner | 2016-08-17 | 1 | -2/+2 | |
| | | | | Fixes #2085. | |||||
* | testing: Virtual IPs went missing | Andreas Steffen | 2016-08-16 | 5 | -15/+17 | |
| | ||||||
* | unit-tests: Removed unused variable | Andreas Steffen | 2016-08-11 | 1 | -2/+0 | |
| | ||||||
* | Version bump to 5.5.1dr15.5.1dr1 | Andreas Steffen | 2016-08-10 | 3 | -4/+2464 | |
| | ||||||
* | Merge branch 'newhope' | Andreas Steffen | 2016-08-10 | 137 | -925/+6559 | |
|\ | ||||||
| * | testing: Added swanctl/rw-newhope-bliss scenario | Andreas Steffen | 2016-08-10 | 20 | -0/+212 | |
| | | ||||||
| * | testing: Add chapoly, ntru and newhope plugins to crypto and integrity tests | Andreas Steffen | 2016-08-10 | 3 | -3/+3 | |
| | | ||||||
| * | testing: Added ikev2/rw-newhope-bliss scenario | Andreas Steffen | 2016-08-10 | 24 | -1/+195 | |
| | | ||||||
| * | unit-tests: Created newhope unit-tests | Andreas Steffen | 2016-08-10 | 10 | -7/+1339 | |
| | | ||||||
| * | Created newhope plugin implementing the New Hope key exchange algorithm | Andreas Steffen | 2016-08-10 | 15 | -2/+1353 | |
| | | ||||||
| * | xof: Added ChaCha20 stream as XOF | Andreas Steffen | 2016-08-06 | 9 | -3/+311 | |
| | | ||||||
| * | utils: Defined uletoh16() and htole16() | Andreas Steffen | 2016-08-06 | 1 | -0/+42 | |
| | | ||||||
| * | integrity-test: Added ntru_param_sets to read-only segment | Andreas Steffen | 2016-07-29 | 7 | -36/+96 | |
| | | ||||||
| * | integrity-test: Added bliss_param_sets to read-only segment | Andreas Steffen | 2016-07-29 | 14 | -63/+68 | |
| | | ||||||
| * | integrity-test: check code and ro segments of libnttfft | Andreas Steffen | 2016-07-29 | 8 | -32/+51 | |
| | | ||||||
| * | Created libnttfft | Andreas Steffen | 2016-07-29 | 20 | -121/+261 | |
| | | | | | | | | | | This makes Number Theoretic Transforms (NTT) based on the efficient Fast-Fourier-Transform (FFT) available to multiple plugins. |