aboutsummaryrefslogtreecommitdiffstats
Commit message (Collapse)AuthorAgeFilesLines
...
* testing: Serve images in testresults via mod_rewrite and not a symlinkTobias Brunner2016-08-293-1/+4
|
* conf: Extend description of charon.plugins.kernel-netlink.xfrm_acq_expiresTobias Brunner2016-08-291-5/+9
|
* proposal: Use proper list to get function pointer when adding custom parserThomas Egerer2016-08-291-1/+1
| | | | Signed-off-by: Thomas Egerer <thomas.egerer@secunet.com>
* android: Add missing xof.c fileTobias Brunner2016-08-291-0/+1
| | | | Fixes #2093.
* xof: Add header to dev headersTobias Brunner2016-08-291-1/+2
|
* Version bump to 5.5.1dr25.5.1dr2Andreas Steffen2016-08-262-3/+3
|
* configure: Improve check for built-in __atomic_* functionsTobias Brunner2016-08-261-2/+13
| | | | | | | | | | | | | | With AC_SEARCH_LIBS() we don't succeed if the searched function is a built-in as the check uses the wrong signature so the built-in will not be applied (the warning issued by GCC is "conflicting types for built-in function '...'"). So even if not required, libatomic will be linked if it is found, which could be problematic if compiling on a separate host and the target host does not have libatomic installed. Also, some tests showed that it's more likely that __atomic_and_fetch() requires linking libatomic than __atomic_load_n() does. References #1533.
* travis: Add a workaround for a bug regarding libtool installed via HomebrewTobias Brunner2016-08-251-0/+2
|
* ikev1: Don't require AH mapping for integrity algorithm when generating proposalThomas Egerer2016-08-251-6/+9
| | | | Signed-off-by: Thomas Egerer <thomas.egerer@secunet.com>
* libtpmtss: TCTI finalization call changedAndreas Steffen2016-08-251-1/+2
|
* conf: aikpub2.opt added to Makefile.amAndreas Steffen2016-08-251-0/+1
|
* pki: Allow to load CRLs from files in --verifyTobias Brunner2016-08-252-3/+21
|
* ikev1: Ignore the last two bytes of the Cisco Unity vendor IDTobias Brunner2016-08-241-0/+3
| | | | | | | | | These seem to indicate the major and minor version of the protocol, like e.g. for the DPD vendor ID. Some implementations seem to send versions other than 1.0 so we just ignore these for now when checking for known vendor IDs. Fixes #2088.
* utils: Fix definition of BYTE_ORDER with MinGWTobias Brunner2016-08-242-2/+6
|
* ikev1: Accept more than one certificate payload in aggressive modeTobias Brunner2016-08-171-2/+2
| | | | Fixes #2085.
* testing: Virtual IPs went missingAndreas Steffen2016-08-165-15/+17
|
* unit-tests: Removed unused variableAndreas Steffen2016-08-111-2/+0
|
* Version bump to 5.5.1dr15.5.1dr1Andreas Steffen2016-08-103-4/+2464
|
* Merge branch 'newhope'Andreas Steffen2016-08-10137-925/+6559
|\
| * testing: Added swanctl/rw-newhope-bliss scenarioAndreas Steffen2016-08-1020-0/+212
| |
| * testing: Add chapoly, ntru and newhope plugins to crypto and integrity testsAndreas Steffen2016-08-103-3/+3
| |
| * testing: Added ikev2/rw-newhope-bliss scenarioAndreas Steffen2016-08-1024-1/+195
| |
| * unit-tests: Created newhope unit-testsAndreas Steffen2016-08-1010-7/+1339
| |
| * Created newhope plugin implementing the New Hope key exchange algorithmAndreas Steffen2016-08-1015-2/+1353
| |
| * xof: Added ChaCha20 stream as XOFAndreas Steffen2016-08-069-3/+311
| |
| * utils: Defined uletoh16() and htole16()Andreas Steffen2016-08-061-0/+42
| |
| * integrity-test: Added ntru_param_sets to read-only segmentAndreas Steffen2016-07-297-36/+96
| |
| * integrity-test: Added bliss_param_sets to read-only segmentAndreas Steffen2016-07-2914-63/+68
| |
| * integrity-test: check code and ro segments of libnttfftAndreas Steffen2016-07-298-32/+51
| |
| * Created libnttfftAndreas Steffen2016-07-2920-121/+261
| | | | | | | | | | This makes Number Theoretic Transforms (NTT) based on the efficient Fast-Fourier-Transform (FFT) available to multiple plugins.
| * Share twiddle factors table between 512 and 1024 point FFTAndreas Steffen2016-07-293-134/+14
| |
| * Implemented FFT with n = 1024 and q = 11289 using Montgomery arithmeticAndreas Steffen2016-07-293-8/+495
| |
| * bliss: Implemented FFT with fast Montgomery arithmeticAndreas Steffen2016-07-298-102/+294
| |
| * xof: Implemented SHAKE128 and SHAKE256 Extended Output FunctionsAndreas Steffen2016-07-2911-415/+1293
| |
| * xof: Defined Extended Output FunctionsAndreas Steffen2016-07-2914-5/+539
|/
* vici: Increased various string buffers to BUF_LEN (512 bytes)Andreas Steffen2016-07-292-5/+5
|
* integrity-test: Added charon-systemdAndreas Steffen2016-07-291-0/+4
|
* Added SHA-3 signature OIDsAndreas Steffen2016-07-261-1/+10
|
* libcharon: Add exchange_tests to .gitignoreTobias Brunner2016-07-251-0/+1
|
* unit-tests: Decreased loop count of FFT speed test to 10'000Andreas Steffen2016-07-221-1/+1
|
* unit-tests: Added bliss_fft_speed testAndreas Steffen2016-07-221-1/+42
|
* Merge branch 'tss2-sapi'Andreas Steffen2016-07-204-7/+11
|\
| * libtpmtss: Use pkconfig to configure TSS 2.0 includes and librariesAndreas Steffen2016-07-204-7/+11
|/
* ike1: Flush active queue when queueing a delete of the IKE_SATobias Brunner2016-07-191-0/+3
| | | | | | | | | | | By aborting the active task we don't have to wait for potential retransmits if the other peer does not respond to the current task. Since IKEv1 has no sequential message IDs and INFORMATIONALs are no real exchanges this should not be a problem. Fixes #1537 References #429, #1410 Closes strongswan/strongswan#48
* Version bump to 5.5.05.5.0Andreas Steffen2016-07-132-2/+2
|
* NEWS: Some updates for the 5.5.0 releaseTobias Brunner2016-07-111-4/+28
|
* Fixed some typos, courtesy of codespellTobias Brunner2016-07-045-5/+5
|
* testing: Remove obsolete openssl-fips recipeTobias Brunner2016-07-041-23/+0
| | | | | | This was only required when we initially started and OpenSSL was built from sources, which was changed with b97dd59ba841 ("install FIPS-aware OpenSSL Debian packages").
* Revert "testing: Only load selected plugins in swanctl"Tobias Brunner2016-07-011-4/+0
| | | | | | | This reverts commit dee01d019ba9743b2784b417155601d10c173a66. Thanks to 505c31870162 ("leak-detective: Try to properly free allocations after deinitialization") this is not required anymore.
* Version bump to 5.5.0rc15.5.0rc1Andreas Steffen2016-06-302-1/+7
|