aboutsummaryrefslogtreecommitdiffstats
path: root/src/charon/sa/ike_sa.c
Commit message (Collapse)AuthorAgeFilesLines
* reset IKE_SA on bus during child_sa destructionMartin Willi2008-11-141-0/+2
|
* removed some obsolete includesMartin Willi2008-11-121-11/+0
|
* moved ike_initiator flag to IKE_SAs condition bitfieldMartin Willi2008-11-121-20/+4
|
* fixed compiler warnings issued by:Martin Willi2008-11-111-2/+2
| | | | | | gcc 4.3 curl.h gcc type-checking glibc with enabled FORTIFY_SOURCE checking
* fixing mediation extensionTobias Brunner2008-11-111-4/+8
|
* merging kernel_klips plugin back into trunkTobias Brunner2008-11-111-2/+9
|
* preliminary support of Mobile IPv6Andreas Steffen2008-11-111-17/+62
|
* got rid of deprecated create_iterator_locked()Martin Willi2008-11-051-0/+1
|
* %any is IP family neutralAndreas Steffen2008-11-051-2/+2
|
* added hooks for IKE and CHILD keymatMartin Willi2008-10-301-0/+26
|
* moved key derivation and management into keymat objectMartin Willi2008-10-281-320/+20
| | | | | | allows secured implementation of key management (e.g. in kernel or HW) only IKE keys for now
* store IKE proposal implicitly during derive_keysMartin Willi2008-10-281-16/+9
|
* use more generic stats getter, introducing new statsMartin Willi2008-10-271-65/+37
|
* more CHILD_SA refactoringsMartin Willi2008-10-241-14/+12
|
* moved updown script invocation to an optional pluginMartin Willi2008-10-161-3/+6
|
* passing chunks, not prf+, to kernel interfaceMartin Willi2008-10-141-10/+10
| | | | gives us better control of keymat in CHILD_SA
* reintegrated bus-refactoring branchMartin Willi2008-10-141-34/+28
|
* fixed MOBIKE roaming if clients address changesMartin Willi2008-10-091-5/+2
|
* mobike: try to keep existing source address before switching to anotherMartin Willi2008-10-081-13/+13
|
* userland support to process notifies for new NAT mappings detected in UDP ↵Martin Willi2008-10-071-6/+4
| | | | encapsulation
* use MOBIKE enabled DPD if we are NATedMartin Willi2008-10-061-2/+41
| | | | update SAs if we detect changes in NAT mappings
* time values in strongswan.conf can be optionally specified in days (d), ↵Andreas Steffen2008-09-041-1/+1
| | | | hours (h), minutes (m), or seconds (s)
* charon.keep_alive = 0 disables the sending of NAT keep alivesAndreas Steffen2008-09-031-1/+1
|
* configure NAT keep alive interval using the charon.keep_alive keyAndreas Steffen2008-09-031-2/+9
|
* ported parts of two-sim branchMartin Willi2008-08-221-0/+26
| | | | | | eap_identity parameter to exchange in eap_identity some auth_info/peer_cfg refactorings fixed some bugs, introduced new ones
* corrected typoAndreas Steffen2008-08-111-1/+1
|
* demoted IKE state change output to debug level 2Andreas Steffen2008-07-281-1/+1
|
* ignore AUTH_LIFETIME value if reauthentication has already been scheduled ↵Andreas Steffen2008-07-281-8/+13
| | | | earlier
* some more changes to IKE_SA and CHILD_SA loggingAndreas Steffen2008-07-221-3/+3
|
* consistent logging of IKE and CHILD SAsAndreas Steffen2008-07-211-3/+3
|
* introduced an additional bus->signal parameter for signal specific dataMartin Willi2008-07-181-21/+21
| | | | added SIG_IKE/SIG_CHD macros for signal emitting
* fixed potential segfault in resolve_hostsMartin Willi2008-07-171-1/+4
|
* fixed acquire-delay bug by:Martin Willi2008-07-161-1/+1
| | | | | installing policies before states updating policies if protocol has changed
* do a route lookup to allow routing of left=%any connections Martin Willi2008-07-091-5/+15
|
* flushing task_manager on shutdown while IKE_SA is usableMartin Willi2008-06-251-1/+2
|
* resolving hosts before routeMartin Willi2008-06-231-0/+2
|
* display selected IKE proposal in ipsec statusallAndreas Steffen2008-06-221-0/+26
|
* DNS resolving of ike_cfg hosts dynamically on demandMartin Willi2008-06-061-14/+26
|
* do not roam IKE_SA in created or deleting stateMartin Willi2008-06-041-0/+8
|
* using fixed size keys in key derivation for AES-XCBC PRFMartin Willi2008-05-211-7/+24
|
* IPComp for IKEv2Tobias Brunner2008-05-081-1/+1
|
* added close_action as a seperate config option to dpd_actionMartin Willi2008-04-141-6/+23
|
* fixed jumping IKE_SA unique idsMartin Willi2008-04-141-28/+53
|
* using dpd actions to enforce connection stateMartin Willi2008-04-111-147/+135
| | | | dpd actions a per child-, not peer ike-sa
* enabling acquire for mediated connectionsTobias Brunner2008-04-101-53/+33
|
* enabling reauthentication on mediation connectionsTobias Brunner2008-04-101-1/+6
|
* fixing a problem if the mediation server initiates the rekeyingTobias Brunner2008-04-101-0/+10
|
* mediation connections should now properly rekeyTobias Brunner2008-04-091-3/+30
|
* implementation of an CFG attribute framework, currently supporting virtual IPsMartin Willi2008-04-091-1/+10
| | | | | | updated ipsec.conf sourceip parameter to support CIDR notatation to serve from a pool %poolname to query a separate (database?) pool
* fixed two other memory leaksTobias Brunner2008-04-031-2/+3
|