Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
| * | android: Unregister listener in case of error alerts | Tobias Brunner | 2016-12-08 | 1 | -3/+9 | |
| | | | | | | | | | | | | | | | | This avoids triggering additional errors via e.g. ike_updown() that might cause the error message displayed in the GUI to change if the status fragment is recreated. References #2134. | |||||
| * | android: Report an error for invalid integer values | Tobias Brunner | 2016-12-08 | 1 | -4/+27 | |
| | | | | | | | | | | Previously we'd just ignore the invalid values without notifying the user. | |||||
| * | android: Propose curve25519 in the ESP proposals | Tobias Brunner | 2016-12-08 | 1 | -3/+3 | |
| | | ||||||
| * | android: Enable curve25519 plugin in the app | Tobias Brunner | 2016-12-08 | 1 | -1/+1 | |
| | | ||||||
| * | android: Optionally build the curve25519 plugin | Tobias Brunner | 2016-12-08 | 1 | -0/+2 | |
| | | ||||||
| * | android: Propose ChaCha20/Poly1305 in the ESP AEAD proposals | Tobias Brunner | 2016-12-08 | 1 | -2/+3 | |
| | | ||||||
| * | android: Enable chapoly plugin in the app | Tobias Brunner | 2016-12-08 | 1 | -1/+1 | |
| | | ||||||
| * | android: Optionally build the chapoly plugin | Tobias Brunner | 2016-12-08 | 1 | -0/+2 | |
| | | ||||||
| * | android: Update Gradle plugin and wrapper | Tobias Brunner | 2016-12-08 | 2 | -3/+3 | |
|/ | ||||||
* | ikev1: Minor code optimization in task manager | Thomas Egerer | 2016-12-07 | 1 | -11/+5 | |
| | | | | Signed-off-by: Thomas Egerer <thomas.egerer@secunet.com> | |||||
* | travis: The xcode7.3 image is now the default | Tobias Brunner | 2016-12-02 | 1 | -1/+0 | |
| | ||||||
* | travis: Output config.log on failure | Tobias Brunner | 2016-12-02 | 1 | -0/+3 | |
| | ||||||
* | configure: Check for actual functions in libraries with AC_CHECK_LIB | Tobias Brunner | 2016-12-02 | 1 | -27/+32 | |
| | | | | | | | | | | | | | | | | | Checking for `main` produces code like this in the test program: int main () { return main (); ; return 0; } This recursive call results in a warning message with some compilers (e.g. Clang in newer Xcode versions: "all paths through this function will call itself [-Winfinite-recursion]"), which lets the tests fail when compiling with -Werror. | |||||
* | plugin-loader: Strip '!' from critical plugin names when setting paths | Tobias Brunner | 2016-11-18 | 1 | -1/+1 | |
| | ||||||
* | child-sa: Use single return statement in update_usebytes() | Thomas Egerer | 2016-11-18 | 1 | -4/+8 | |
| | | | | Signed-off-by: Thomas Egerer <thomas.egerer@secunet.com> | |||||
* | proposal: Remove RFC 5114 MODP DH groups from default proposal | Martin Willi | 2016-11-15 | 1 | -2/+4 | |
| | | | | | | | | | | | | | | Recent research demonstrates that at least for 1024-bit DH groups, it is possible to create specially crafted primes having a backdoor. From the prime itself this is not detectable, creating a perfect NOBUS attack. http://eprint.iacr.org/2016/961 For the primes defined in RFC 5114 no information is provided on how these have been selected. In the default proposal we included one of the 2048-bit primes only, where it is questionable if constructing a backdoored prime is feasible. Nevertheless, this patch removes the group from the set of default proposals as well. | |||||
* | Version bump to 5.5.2dr25.5.2dr2 | Andreas Steffen | 2016-11-14 | 3 | -3/+6 | |
| | ||||||
* | testing: make curve25519 the default DH group | Andreas Steffen | 2016-11-14 | 820 | -1072/+1050 | |
| | ||||||
* | proposal: Add curve25519 and curve448 to default proposal | Tobias Brunner | 2016-11-14 | 1 | -0/+2 | |
| | ||||||
* | configure: Enable curve25519 plugin by default | Tobias Brunner | 2016-11-14 | 1 | -1/+1 | |
| | ||||||
* | curve22519: Add a portable backend implemented in plain C | Martin Willi | 2016-11-14 | 4 | -0/+647 | |
| | ||||||
* | curve25519: Add a plugin providing Curve25519 DH using backend drivers | Martin Willi | 2016-11-14 | 9 | -0/+473 | |
| | ||||||
* | dh-speed: Compare the shared secrets for equality after test | Martin Willi | 2016-11-14 | 1 | -3/+7 | |
| | ||||||
* | dh-speed: Include the get_my_public_value() call in public exponent timing | Martin Willi | 2016-11-14 | 1 | -4/+4 | |
| | | | | | This fixes results where a DH backend does not generate the public value in the constructor internally. | |||||
* | dh-speed: Add an identifier to test curve25519 performance | Martin Willi | 2016-11-14 | 1 | -0/+1 | |
| | ||||||
* | test-vectors: Add a Curve25519 DH test vector | Martin Willi | 2016-11-14 | 3 | -0/+36 | |
| | ||||||
* | proposal: Add a curve25519 proposal keyword | Martin Willi | 2016-11-14 | 1 | -0/+1 | |
| | ||||||
* | diffie-hellman: Add DH group identifiers for Curve25519 and Curve448 | Martin Willi | 2016-11-14 | 2 | -3/+14 | |
| | ||||||
* | bus: Re-add ampersand that got lost in refactoring | Tobias Brunner | 2016-11-14 | 1 | -1/+1 | |
| | | | | | Fixes: 4af02c6c61cf ("bus: Fix maximum log level for different groups after removal of a logger") | |||||
* | peer-cfg: Fix memory leak when replacing child configs | Tobias Brunner | 2016-11-11 | 1 | -0/+1 | |
| | | | | | Fixes: 622c2b2c3386 ("peer-cfg: Add method to atomically replace child configs") | |||||
* | bus: Fix maximum log level for different groups after removal of a logger | Tobias Brunner | 2016-11-11 | 1 | -5/+5 | |
| | | | | | | | The log level was incorrectly set to the same value for all groups. Fixes: dac15e03c828 ("bus: Fix maximum log levels when mixing log/vlog implementing loggers") | |||||
* | farp: Fix BPF jump false offset | Volker RĂ¼melin | 2016-10-31 | 1 | -1/+1 | |
| | | | | Jump to BPF_STMT(BPF_RET+BPF_K, 0) if protocol_size != 4 | |||||
* | Version bump to 5.5.2dr15.5.2dr1 | Andreas Steffen | 2016-10-30 | 3 | -3/+10 | |
| | ||||||
* | Fixed in-place update of cached base and delta CRLs | Andreas Steffen | 2016-10-30 | 1 | -4/+4 | |
| | ||||||
* | Newer CRLs replace older versions of the CRL in the cache | Andreas Steffen | 2016-10-26 | 1 | -0/+39 | |
| | ||||||
* | connmark: Add CAP_NET_RAW to capabilities keep list | Tim Kent | 2016-10-25 | 1 | -0/+6 | |
| | | | | | | | | | Fix for "Permission denied (you must be root)" error when calling iptc_init(), which opens a RAW socket to communicate with the kernel, when built with "--with-capabilities=libcap". Closes strongswan/strongswan#53. Fixes #2157. | |||||
* | Version bump to 5.5.15.5.1 | Andreas Steffen | 2016-10-20 | 4 | -3/+13 | |
| | ||||||
* | nm: Enable IKE fragmentation | Tobias Brunner | 2016-10-20 | 1 | -1/+1 | |
| | ||||||
* | Version bump to 5.5.1rc25.5.1rc2 | Andreas Steffen | 2016-10-18 | 2 | -3/+3 | |
| | ||||||
* | testing: Renewed expired certificates | Andreas Steffen | 2016-10-18 | 13 | -140/+221 | |
| | ||||||
* | added XOF dependencies of bliss and ntru plugins | Andreas Steffen | 2016-10-18 | 2 | -4/+26 | |
| | ||||||
* | testing: enable MACsec in guest kernel | Andreas Steffen | 2016-10-18 | 1 | -1/+1 | |
| | ||||||
* | configure: Reorder mgf1 in list of crypto plugins | Tobias Brunner | 2016-10-18 | 1 | -1/+1 | |
| | ||||||
* | newhope: Fix Doxygen group name | Tobias Brunner | 2016-10-14 | 1 | -1/+1 | |
| | ||||||
* | libnttfft: Fix Doxygen group | Tobias Brunner | 2016-10-14 | 1 | -1/+3 | |
| | ||||||
* | Fixed some typos, courtesy of codespell | Tobias Brunner | 2016-10-14 | 2 | -3/+3 | |
| | ||||||
* | newhope: Properly release allocated arrays if RNG can't be created | Tobias Brunner | 2016-10-14 | 1 | -8/+8 | |
| | ||||||
* | nm: Add D-Bus policy to the distribution | Tobias Brunner | 2016-10-14 | 1 | -0/+2 | |
| | ||||||
* | nm: Version bump to 1.4.1 | Tobias Brunner | 2016-10-14 | 2 | -1/+6 | |
| | ||||||
* | kernel-netlink: Fix get_route() interface determination | Christophe Gouault | 2016-10-12 | 1 | -2/+2 | |
| | | | | | | | | | | | | A wrong variable is used (route instead of best), so much that the returned interface belongs to the last seen route instead of the best choice route. get_route() may therefore return mismatching interface and gateway. Fixes: 66e9165bc686 ("kernel-netlink: Return outbound interface in get_nexthop()") Signed-off-by: Christophe Gouault <christophe.gouault@6wind.com> |