Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | fixed EAP-GTC secret lookup | Martin Willi | 2008-08-21 | 1 | -2/+9 | |
| | | | | | improved error logging PAM authentication needs CAP_AUDIT_WRITE capability | |||||
* | fixed libstrongswan integrity test | Andreas Steffen | 2008-08-19 | 1 | -14/+14 | |
| | ||||||
* | introduced an additional bus->signal parameter for signal specific data | Martin Willi | 2008-07-18 | 1 | -1/+1 | |
| | | | | added SIG_IKE/SIG_CHD macros for signal emitting | |||||
* | added %P printf handler for poposal_t | Martin Willi | 2008-06-12 | 1 | -0/+3 | |
| | | | | added some proposal selection debugging code | |||||
* | correctly initialize the mediation and connection manager | Tobias Brunner | 2008-05-22 | 1 | -0/+4 | |
| | ||||||
* | added a fixup for addresses from shared libraries in segmentation fault handler | Tobias Brunner | 2008-05-19 | 1 | -1/+24 | |
| | ||||||
* | loading default modules depending on configure options | Martin Willi | 2008-05-16 | 1 | -2/+1 | |
| | ||||||
* | plugin load configuration in strongswan.conf | Martin Willi | 2008-05-15 | 1 | -14/+15 | |
| | | | | | | some components accept a "component.load" option with a space separated list of plugins to load libcharon- plugins are now handled the same way as libstrongswan- plugins | |||||
* | replaced --with-gid/uid by --with-group/user | Martin Willi | 2008-05-08 | 1 | -11/+52 | |
| | | | | | using named users, groups fixed capability dropping in pluto | |||||
* | using capset version 1 if a newer is available | Martin Willi | 2008-05-07 | 1 | -0/+6 | |
| | ||||||
* | respecting ipsec.conf cachecrls= option | Martin Willi | 2008-04-17 | 1 | -13/+0 | |
| | ||||||
* | splitted IKE_SA manager destroy to allow plugin interaction | Martin Willi | 2008-04-17 | 1 | -0/+4 | |
| | ||||||
* | added API for random number generators, served through credential factory | Martin Willi | 2008-04-15 | 1 | -13/+10 | |
| | | | | ported randomizer_t to a rng_t on top of /dev/(u)random (plugin random) | |||||
* | implementation of an CFG attribute framework, currently supporting virtual IPs | Martin Willi | 2008-04-09 | 1 | -2/+3 | |
| | | | | | | updated ipsec.conf sourceip parameter to support CIDR notatation to serve from a pool %poolname to query a separate (database?) pool | |||||
* | added ./configure option --with-strongswan-conf= | Martin Willi | 2008-04-07 | 1 | -1/+1 | |
| | | | | defaults to /etc/strongswan.conf | |||||
* | replaced mutex in leak detective with thread scheduling | Tobias Brunner | 2008-04-03 | 1 | -1/+1 | |
| | ||||||
* | configure option in strongswan.conf for thread count | Martin Willi | 2008-04-03 | 1 | -1/+3 | |
| | ||||||
* | mediation extension adapted to the naming convention of the current version ↵ | Tobias Brunner | 2008-03-26 | 1 | -4/+4 | |
| | | | | of the draft. note: the external interface (config, autotools) has not yet been changed | |||||
* | merged the modularization branch (credentials) back to trunk | Martin Willi | 2008-03-13 | 1 | -47/+50 | |
| | ||||||
* | socket_t implementation withouth raw sockets | Martin Willi | 2007-11-26 | 1 | -1/+1 | |
| | | | | | | --disable-raw-socket configure option prevents charon/pluto to run in parallel | |||||
* | experimental P2P-NAT-T for IKEv2 merged back from branch | Tobias Brunner | 2007-10-03 | 1 | -2/+12 | |
| | ||||||
* | fixed stuid()/setgid() and error handling | Martin Willi | 2007-10-01 | 1 | -2/+12 | |
| | ||||||
* | changed inheritable capability set to the permitted one to execute firewall ↵ | Martin Willi | 2007-09-28 | 1 | -2/+1 | |
| | | | | script with CAP_NET_ADMIN | |||||
* | refactored strongswan manager | Martin Willi | 2007-09-26 | 1 | -0/+3 | |
| | | | | | | | | removed buggy request parsing code, use ClearSilvers CGI kit instead fixed CHILD_SA listing in manager (needs better design) using secure XML communication through unix sockets removed images with questionable (non-GPL) license | |||||
* | fixed shutdown order to prevent crash when kernel interface schedules events | Martin Willi | 2007-09-12 | 1 | -1/+1 | |
| | ||||||
* | correct debug4.1.6 | Andreas Steffen | 2007-09-02 | 1 | -3/+3 | |
| | ||||||
* | renamed integrity check to integrity test | Andreas Steffen | 2007-08-29 | 1 | -3/+3 | |
| | ||||||
* | fips_verify_hmac_signature() now returns a boolean status | Andreas Steffen | 2007-08-29 | 1 | -1/+1 | |
| | ||||||
* | changed interface of fips_verify_hmac_signature | Andreas Steffen | 2007-08-29 | 1 | -1/+1 | |
| | ||||||
* | started implementation of libstrongswan code integrity check | Andreas Steffen | 2007-08-29 | 1 | -4/+28 | |
| | ||||||
* | support of ipsec rereadsecrets for stroke | Andreas Steffen | 2007-08-10 | 1 | -1/+1 | |
| | ||||||
* | further fixed for mobike roaming | Martin Willi | 2007-06-25 | 1 | -0/+3 | |
| | ||||||
* | implemented address change notification (for MOBIKE) | Martin Willi | 2007-06-14 | 1 | -12/+0 | |
| | | | | | implemented up to date address list cache to list interfaces | |||||
* | introduced callback_job: | Martin Willi | 2007-06-11 | 1 | -88/+72 | |
| | | | | | | | | | | | | simple asynchronous method invocation use daemons thread pool for all threads proper cancellation and cleanups cancellation mechanism to dynamically unload multithreaded code unified event_queue and scheduler => scheduler unified job_queue and thread_pool => processor removed job_type_t, not really needed fixes here, there and everywhere | |||||
* | simplified capability dropping | Martin Willi | 2007-05-09 | 1 | -26/+17 | |
| | ||||||
* | properly implemented interface_managers initiate, terminte_[ike|child] | Martin Willi | 2007-05-09 | 1 | -1/+1 | |
| | | | | | proper thread release when stroke is CTRL+C'ed fixed some permission issues | |||||
* | changing UID/GID after startup of pluto/charon | Martin Willi | 2007-05-07 | 1 | -7/+30 | |
| | | | | added --with-uid/--with-gid configure option | |||||
* | reducing capabilities of the threads to a minimum | Martin Willi | 2007-05-03 | 1 | -7/+46 | |
| | | | | | | proper flush of pending packets on daemon shutdown adding local address as gateway address in dynamic route | |||||
* | restructuring of configuration backends | Martin Willi | 2007-04-27 | 1 | -14/+6 | |
| | | | | | | | | | added propotypes of new control interfaces (xml & dbus) introduced loadable: configuration backends control interfaces using pluggable modules as in EAP | |||||
* | implementation of strictcrlpolicy=ifuri | Andreas Steffen | 2007-04-20 | 1 | -9/+8 | |
| | ||||||
* | moved initiate() code to the generic controller_t class | Martin Willi | 2007-04-16 | 1 | -0/+3 | |
| | ||||||
* | started support of X.509 attribute certificates | Andreas Steffen | 2007-04-12 | 1 | -0/+2 | |
| | ||||||
* | cleaned up apidoc | Martin Willi | 2007-04-11 | 1 | -3/+0 | |
| | | | | | | added some comments removed configuration.[ch], as it does not make sense like it is | |||||
* | restructured file layout | Martin Willi | 2007-04-10 | 1 | -9/+10 | |
| | | | | | | | | | new configuration structure: peer_cfg: configuration related to a peer (authenitcation, ...= ike_cfg: config to use for IKE setup (proposals) child_Cfg: config for CHILD_SA (proposals, traffic selectors) a peer_cfg has one ike_cfg and multiple child_cfg's stroke now uses fixed count of threads | |||||
* | support cachecrls=yes | Andreas Steffen | 2007-04-05 | 1 | -2/+8 | |
| | ||||||
* | support of crlcheckinterval=0 to disable IKEv2 CRL fetching | Andreas Steffen | 2007-04-04 | 1 | -0/+12 | |
| | ||||||
* | removed send_queue, handled internally in sender_t know | Martin Willi | 2007-03-28 | 1 | -3/+0 | |
| | | | | | do header parsing in receiver, ready for cookie integration | |||||
* | added fetcher_finalize() to clean up libcurl | Andreas Steffen | 2007-03-08 | 1 | -0/+1 | |
| | ||||||
* | support if ocsp signing certificates | Andreas Steffen | 2007-03-08 | 1 | -0/+1 | |
| | ||||||
* | http post fetching using libcurl implemented | Andreas Steffen | 2007-03-07 | 1 | -0/+4 | |
| |