Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | Added options and a lookup function that will allow filtering of network ↵ | Tobias Brunner | 2012-09-21 | 1 | -1/+9 | |
| | | | | interfaces | |||||
* | Update ipsec.conf.5, leftsubnet can handle multiple subnets in IKEv1 with Unity | Martin Willi | 2012-09-18 | 1 | -2/+3 | |
| | ||||||
* | Set AUTH_RULE_IDENTITY_LOOSE for rightid=%<identity> | Tobias Brunner | 2012-09-18 | 1 | -0/+12 | |
| | ||||||
* | Option added to enforce a configured destination address for DHCP packets | Tobias Brunner | 2012-09-13 | 1 | -0/+8 | |
| | ||||||
* | Updates to strongswan.conf(5) man page (added several missing options) | Tobias Brunner | 2012-09-12 | 1 | -39/+82 | |
| | ||||||
* | Some updates to ipsec.conf(5) man page | Tobias Brunner | 2012-09-12 | 1 | -49/+70 | |
| | ||||||
* | Add uniqueids=never to ignore INITIAL_CONTACT notifies | Tobias Brunner | 2012-09-10 | 1 | -9/+16 | |
| | | | | | | With uniqueids=no the daemon still deletes any existing IKE_SA with the same peer if an INITIAL_CONTACT notify is received. With this new option it also ignores these notifies. | |||||
* | Add random plugin options to strongswan.conf.5 | Martin Willi | 2012-09-10 | 2 | -0/+8 | |
| | ||||||
* | added libimcv.assessment_result to strongswan.conf man page | Andreas Steffen | 2012-09-09 | 1 | -0/+3 | |
| | ||||||
* | Merge branch 'multi-vip' | Martin Willi | 2012-08-31 | 1 | -6/+16 | |
|\ | | | | | | | | | | | | | Brings support for multiple virtual IPs and multiple pools in left/rigthsourceip definitions. Also introduces the new left/rightdns options to configure requested DNS server address family and respond with multiple connection specific servers. | |||||
| * | Updated ipsec.conf.5 with multiple left/rightsourceip support | Martin Willi | 2012-08-30 | 1 | -6/+6 | |
| | | ||||||
| * | Add a description of the leftdns option to ipsec.conf.5 | Martin Willi | 2012-08-21 | 1 | -0/+10 | |
| | | ||||||
* | | Documentation for eap-dynamic added | Tobias Brunner | 2012-08-31 | 2 | -0/+11 | |
|/ | ||||||
* | Merge branch 'android-ndk' | Tobias Brunner | 2012-08-13 | 2 | -2/+18 | |
|\ | | | | | | | | | | | | | | | | | | | | | | | This branch comes with some preliminary changes for the user-land IPsec implementation and the Android App. One important change is that the UDP ports used by the socket-default plugin were made configurable (either via ./configure or strongswan.conf). Also, the plugin does randomly allocate a port if it is configured to 0, which is useful for client implementations. A consequence of these changes is that the local UDP port used when creating ike_cfg_t objects has to be fetched from the socket. | |||||
| * | Added option to prevent socket-default from setting the source address on ↵ | Tobias Brunner | 2012-08-08 | 1 | -0/+3 | |
| | | | | | | | | outbound packets | |||||
| * | socket-default plugin allocates random ports if configured to 0. | Tobias Brunner | 2012-08-08 | 1 | -0/+9 | |
| | | | | | | | | Also added strongswan.conf options to change the ports. | |||||
| * | Added ESP log group for libipsec log messages. | Tobias Brunner | 2012-08-08 | 2 | -1/+5 | |
| | | ||||||
| * | Moved Android specific logger to separate plugin. | Tobias Brunner | 2012-08-08 | 1 | -1/+1 | |
| | | | | | | | | | | | | This is mainly because the other parts of the existing android plugin can not be built in the NDK (access to keystore and system properties are not part of the stable NDK libraries). | |||||
* | | Documentation fixes regarding xauth-pam/eap-gtc plugins | Tobias Brunner | 2012-08-11 | 1 | -3/+5 | |
| | | ||||||
* | | make max_message_size parameter consistent with similar options | Andreas Steffen | 2012-08-09 | 1 | -2/+2 | |
|/ | ||||||
* | Add an ipsec.conf leftgroups2 parameter for the second authentication round | Martin Willi | 2012-07-26 | 1 | -0/+6 | |
| | ||||||
* | added PA-TNC max_msg_len option to man page | Andreas Steffen | 2012-07-13 | 1 | -0/+6 | |
| | ||||||
* | make maximum PB-TNC batch size configurable | Andreas Steffen | 2012-07-11 | 1 | -0/+3 | |
| | ||||||
* | added charon.plugins.eap-tnc.protocol option | Andreas Steffen | 2012-07-11 | 1 | -0/+3 | |
| | ||||||
* | EAP-TNC does not support fragmentation | Andreas Steffen | 2012-07-11 | 1 | -6/+0 | |
| | ||||||
* | configure size of ITA Dummy PA-TNC attribute | Andreas Steffen | 2012-07-11 | 1 | -0/+3 | |
| | ||||||
* | max_message_count = 0 disables limit | Andreas Steffen | 2012-07-11 | 1 | -4/+4 | |
| | ||||||
* | Some updates in ipsec.conf(5) for 5.0.0 | Tobias Brunner | 2012-06-26 | 1 | -36/+50 | |
| | ||||||
* | added charon.cisco_unity to strongswan.conf.5 man page | Andreas Steffen | 2012-06-25 | 1 | -0/+3 | |
| | ||||||
* | added secret as valid authby argument | Andreas Steffen | 2012-06-18 | 1 | -1/+1 | |
| | ||||||
* | Add documentation for signature hash algorithm enforcing to man ipsec.conf | Martin Willi | 2012-06-12 | 1 | -4/+11 | |
| | ||||||
* | starter: Drop support for %defaultroute. | Tobias Brunner | 2012-06-11 | 1 | -16/+2 | |
| | ||||||
* | Retry IKE_SA initiation if DNS resolution failed. | Tobias Brunner | 2012-05-30 | 1 | -0/+4 | |
| | | | | | This is disabled by default and can be enabled with the charon.retry_initiate_interval option in strongswan.conf. | |||||
* | Updated ipsec.conf(5) to reflect changes to IPComp support. | Tobias Brunner | 2012-05-24 | 1 | -4/+2 | |
| | ||||||
* | Merge branch 'ikev1' | Martin Willi | 2012-05-02 | 1 | -367/+79 | |
|\ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Conflicts: configure.in man/ipsec.conf.5.in src/libcharon/encoding/generator.c src/libcharon/encoding/payloads/notify_payload.c src/libcharon/encoding/payloads/notify_payload.h src/libcharon/encoding/payloads/payload.c src/libcharon/network/receiver.c src/libcharon/sa/authenticator.c src/libcharon/sa/authenticator.h src/libcharon/sa/ikev2/tasks/ike_init.c src/libcharon/sa/task_manager.c src/libstrongswan/credentials/auth_cfg.c | |||||
| * | Merge branch 'ikev1-clean' into ikev1-master | Martin Willi | 2012-03-20 | 1 | -360/+78 | |
| |\ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Conflicts: configure.in man/ipsec.conf.5.in src/libcharon/daemon.c src/libcharon/plugins/eap_ttls/eap_ttls_peer.c src/libcharon/plugins/eap_radius/eap_radius_accounting.c src/libcharon/plugins/eap_radius/eap_radius_forward.c src/libcharon/plugins/farp/farp_listener.c src/libcharon/sa/ike_sa.c src/libcharon/sa/keymat.c src/libcharon/sa/task_manager.c src/libcharon/sa/trap_manager.c src/libstrongswan/plugins/x509/x509_cert.c src/libstrongswan/utils.h Applied lost changes of moved files keymat.c and task_manager.c. Updated listener_t.message hook signature in new plugins. | |||||
| | * | Updated ipsec.conf man page for the use of IKEv1 with pluto | Martin Willi | 2012-03-20 | 1 | -332/+73 | |
| | | | ||||||
| | * | Dropped support of deprecated authby=eap and eap= options | Martin Willi | 2012-03-20 | 1 | -33/+4 | |
| | | | ||||||
* | | | Documented strongswan.conf options for radattr plugin. | Tobias Brunner | 2012-05-01 | 1 | -1/+8 | |
| | | | ||||||
* | | | Option added to set identifier for syslog(3) logging. | Tobias Brunner | 2012-04-20 | 1 | -0/+8 | |
| | | | | | | | | | | | | This identifier is added to each log message by syslog. | |||||
* | | | updated supported EAP methods | Andreas Steffen | 2012-03-30 | 1 | -5/+14 | |
| | | | ||||||
* | | | Make resolvconf interface prefix configurable. | Tobias Brunner | 2012-03-27 | 1 | -0/+6 | |
|/ / | ||||||
* | | added the strongswan.conf options of the tnc-pdp plugin | Andreas Steffen | 2012-03-16 | 1 | -0/+12 | |
| | | ||||||
* | | completed imc/imv-attestation settings | Andreas Steffen | 2012-02-07 | 1 | -1/+20 | |
| | | ||||||
* | | Added an option to load CA certificates without CA basic constraint. | Tobias Brunner | 2012-02-01 | 1 | -0/+4 | |
| | | | | | | | | | | | | Enabling this option treats all certificates in ipsec.d/cacerts and ipsec.conf ca sections as CA certificates even if they do not contain a CA basic constraint. | |||||
* | | Added RADIUS accounting option to strongswan.conf manual | Martin Willi | 2012-02-01 | 1 | -0/+3 | |
| | | ||||||
* | | Make number of concurrently handled stroke messages configurable. | Tobias Brunner | 2011-12-29 | 1 | -0/+3 | |
| | | ||||||
* | | Added ASN debug group to log low-level encoding/decoding (ASN.1, X.509). | Tobias Brunner | 2011-12-16 | 2 | -1/+4 | |
| | | | | | | | | | | This will allow us to remove quite some clutter from the LIB debug group for higher debug levels. | |||||
* | | Charon also supports type=passthrough|drop. | Tobias Brunner | 2011-12-14 | 1 | -6/+0 | |
| | | ||||||
* | | Documented xauth_identity in ipsec.conf(5) man page. | Tobias Brunner | 2011-12-14 | 1 | -3/+7 | |
| | |