Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | ike_sa_manager enumerable, not iterable | Martin Willi | 2008-04-14 | 5 | -30/+41 | |
| | ||||||
* | added close_action as a seperate config option to dpd_action | Martin Willi | 2008-04-14 | 2 | -6/+7 | |
| | ||||||
* | fixed rightsourceip=%config scenarios | Martin Willi | 2008-04-14 | 2 | -40/+62 | |
| | ||||||
* | using dpd actions to enforce connection state | Martin Willi | 2008-04-11 | 2 | -4/+17 | |
| | | | | dpd actions a per child-, not peer ike-sa | |||||
* | implemented a simple attribute provider for stroke | Martin Willi | 2008-04-09 | 4 | -0/+398 | |
| | ||||||
* | implementation of an CFG attribute framework, currently supporting virtual IPs | Martin Willi | 2008-04-09 | 1 | -8/+30 | |
| | | | | | | updated ipsec.conf sourceip parameter to support CIDR notatation to serve from a pool %poolname to query a separate (database?) pool | |||||
* | use cert->equals() to filter out equal certificates in seperate instances | Martin Willi | 2008-04-07 | 1 | -1/+1 | |
| | ||||||
* | cosmetics | Andreas Steffen | 2008-04-07 | 1 | -2/+2 | |
| | ||||||
* | log shared secret with debug level 4 | Andreas Steffen | 2008-04-06 | 1 | -1/+1 | |
| | ||||||
* | default is hostaccess=no | Andreas Steffen | 2008-04-06 | 2 | -2/+2 | |
| | ||||||
* | updated test data to use correct encoding data | Martin Willi | 2008-04-03 | 1 | -3/+4 | |
| | ||||||
* | fixed med_db test | Martin Willi | 2008-04-02 | 1 | -1/+1 | |
| | ||||||
* | updated mediation database to public key authentication | Martin Willi | 2008-04-02 | 10 | -62/+409 | |
| | | | | | | added mysql table definition, test data testcase | |||||
* | fixed compile warnings | Martin Willi | 2008-04-02 | 1 | -1/+0 | |
| | ||||||
* | workaround for parsing IPv6 PSKs requires extract_last_token() | Andreas Steffen | 2008-04-01 | 1 | -1/+1 | |
| | ||||||
* | loading of subjectPublicKeyInfo wrapped keys using KEY_ANY (openssl format) | Martin Willi | 2008-04-01 | 2 | -2/+44 | |
| | | | | testcase | |||||
* | minimal stroke_list_ocsp() implementation | Andreas Steffen | 2008-04-01 | 1 | -2/+23 | |
| | ||||||
* | stroke_list groups certificates by issuer | Andreas Steffen | 2008-04-01 | 1 | -7/+18 | |
| | ||||||
* | put DN in double quotes | Andreas Steffen | 2008-03-31 | 1 | -1/+1 | |
| | ||||||
* | ipsec list suppresses duplicates | Andreas Steffen | 2008-03-31 | 1 | -19/+79 | |
| | ||||||
* | output uptime in status in local time | Andreas Steffen | 2008-03-29 | 1 | -1/+1 | |
| | ||||||
* | renamed xml plugin to smp to avoid confusion | Martin Willi | 2008-03-28 | 6 | -30/+30 | |
| | | | | | | added some dependency checks to configure configure checks ClearSilver and fastcgi cleanups in the build system here and there | |||||
* | changed external interface to the mediation extension. | Tobias Brunner | 2008-03-27 | 1 | -3/+3 | |
| | ||||||
* | reusing generic shared_key_t implementation in med_db | Martin Willi | 2008-03-27 | 1 | -55/+1 | |
| | ||||||
* | implemented cert cache flushing, ipsec purgeocsp | Martin Willi | 2008-03-27 | 1 | -4/+6 | |
| | ||||||
* | fixed plugin/stroke Makefile | Andreas Steffen | 2008-03-26 | 1 | -1/+2 | |
| | ||||||
* | mediation extension adapted to the naming convention of the current version ↵ | Tobias Brunner | 2008-03-26 | 2 | -16/+16 | |
| | | | | of the draft. note: the external interface (config, autotools) has not yet been changed | |||||
* | added uptime statistics to statusall | Martin Willi | 2008-03-26 | 1 | -0/+10 | |
| | ||||||
* | fixed compile error if --enable-p2p is set | Martin Willi | 2008-03-26 | 2 | -2/+2 | |
| | ||||||
* | splitted stroke plugin to several files: | Martin Willi | 2008-03-26 | 18 | -3285/+4155 | |
| | | | | | | | | | | | socket: reads messages from socket, dispatching config: process add/del conn, serves configs through backend_t control: controlling of the daemon (up/down/route/...( cred: credential loading, serves creds through credential_set_t ca: ca sections from ipsec.conf, serves cdp's through credential_set_t list: log status information to stroke console (status/statusall/list*) shared_key: shared key implementation for keys read from ipsec.secrets plugin: registers stroke plugin and starts socket w/ thread | |||||
* | certificate factory can load certs from file | Andreas Steffen | 2008-03-25 | 1 | -52/+54 | |
| | ||||||
* | defined *_create_from_file() constructors in ↵ | Andreas Steffen | 2008-03-25 | 1 | -103/+60 | |
| | | | | libstrongswan/credentials/certificates | |||||
* | modified debug text | Andreas Steffen | 2008-03-20 | 1 | -1/+1 | |
| | ||||||
* | (no commit message) | Martin Willi | 2008-03-20 | 2 | -14/+86 | |
| | ||||||
* | The introduced SHA1_NOFINAL hasher was not sufficient for EAP-AKA, | Martin Willi | 2008-03-19 | 2 | -38/+25 | |
| | | | | | | as it requires to XOR the key into the hashers state. A new SHA1 based keyed hash function, implemented as PRF, enables EAP-AKA and the FIPS-PRF function to properly use the existing SHA1 implementation. | |||||
* | fixed shared key lookup in stroke | Martin Willi | 2008-03-19 | 1 | -1/+1 | |
| | ||||||
* | fixed peer_cfg lookup when omitting IDr | Martin Willi | 2008-03-19 | 1 | -3/+13 | |
| | ||||||
* | fixed CRL check return value on revoked certificates | Martin Willi | 2008-03-19 | 3 | -24/+0 | |
| | | | | | fixed possible refcounting bugs generic return_null() implementation | |||||
* | fixed ike_cfg lookup in stroke | Martin Willi | 2008-03-18 | 1 | -1/+1 | |
| | ||||||
* | added false positive signature check | Martin Willi | 2008-03-18 | 1 | -0/+6 | |
| | ||||||
* | added missing test case file ([3607]) | Martin Willi | 2008-03-18 | 1 | -0/+61 | |
| | ||||||
* | creating public key from RSA private key | Martin Willi | 2008-03-18 | 2 | -2/+4 | |
| | | | | RSA key generation and signature test | |||||
* | made is_newer() a certificate_t method | Andreas Steffen | 2008-03-18 | 1 | -1/+1 | |
| | ||||||
* | better normalized tables for SQL plugin (IDs) | Martin Willi | 2008-03-18 | 6 | -286/+453 | |
| | ||||||
* | enforcing x509_flags on certificate construction | Martin Willi | 2008-03-17 | 1 | -23/+12 | |
| | ||||||
* | logging to SQL database | Martin Willi | 2008-03-15 | 6 | -1/+255 | |
| | ||||||
* | removed X509_PEER flag; flags are meant to read cert, not to store ↵ | Martin Willi | 2008-03-14 | 1 | -21/+12 | |
| | | | | | | | additional state in cert removed x509_t.set_flags for the reason above implemented a simple, generic shared_key_t | |||||
* | credential lookup in mysql/sqlite database | Martin Willi | 2008-03-14 | 7 | -2/+493 | |
| | ||||||
* | SQL schema for MySQL and SQLite, test data | Martin Willi | 2008-03-14 | 4 | -89/+165 | |
| | ||||||
* | fixed apidoc grouping | Martin Willi | 2008-03-13 | 2 | -2/+2 | |
| |