Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | merged the modularization branch (credentials) back to trunk | Martin Willi | 2008-03-13 | 35 | -788/+875 |
| | |||||
* | improved P2P_NAT debugging | Andreas Steffen | 2008-02-27 | 1 | -2/+2 |
| | |||||
* | implemented Expanded EAP types to support vendor specific methods | Martin Willi | 2007-12-13 | 1 | -3/+5 |
| | |||||
* | removed c++ style comments4.1.9 | Martin Willi | 2007-12-04 | 1 | -51/+42 |
| | | | | | fixed compiler warnings | ||||
* | fixed mobike/auth_lifetime in conjunction with p2p-natt | Martin Willi | 2007-12-04 | 2 | -6/+6 |
| | |||||
* | removed redundant server reflexive endpoint debug message | Andreas Steffen | 2007-12-04 | 1 | -1/+0 |
| | |||||
* | improved P2P_ENDPOINT debugging | Andreas Steffen | 2007-12-03 | 2 | -1/+5 |
| | |||||
* | moved AUTH_LIFETIME handling in its own task (cleaner separation, proper ↵ | Martin Willi | 2007-12-03 | 5 | -23/+265 |
| | | | | payload order) | ||||
* | implemented RFC4478 (repeated authentication) | Martin Willi | 2007-11-20 | 1 | -0/+27 |
| | | | | | changed %V printf handler to take a time delta, %#V now takes two arguments | ||||
* | experimental P2P-NAT-T for IKEv2 merged back from branch | Tobias Brunner | 2007-10-03 | 5 | -2/+987 |
| | |||||
* | ID payload with explicit payload type | Tobias Brunner | 2007-10-02 | 1 | -2/+2 |
| | |||||
* | moved force_encap to ike_config, enables responder to enforce udp encapsulation | Martin Willi | 2007-10-01 | 1 | -8/+9 |
| | | | | fixed bugs in force_encap code | ||||
* | implemented IKEv2 force_encap connection parameter | Martin Willi | 2007-10-01 | 1 | -3/+37 |
| | | | | | enforces UDP encapsulation by faking NAT detection payloads to hurdle restrictive firewalls | ||||
* | implemented more aggressive MOBIKE path probing | Martin Willi | 2007-09-28 | 2 | -0/+17 |
| | | | | | do not queue more than one MOBIKE task | ||||
* | improved MOBIKE roaming between interfaces | Martin Willi | 2007-09-24 | 1 | -11/+4 |
| | |||||
* | connection name to IKE_SA initiating | Andreas Steffen | 2007-09-15 | 2 | -2/+3 |
| | |||||
* | put IKE_SA and CHILD_SA names in single quotes | Andreas Steffen | 2007-09-15 | 2 | -5/+5 |
| | |||||
* | log name of established IKE_SA | Andreas Steffen | 2007-09-15 | 1 | -4/+8 |
| | |||||
* | log name of established CHILD_SA | Andreas Steffen | 2007-09-15 | 1 | -2/+4 |
| | |||||
* | only switch to port 4500 if we are on 500: fixed reauthentication in NAT | Martin Willi | 2007-09-12 | 1 | -2/+9 |
| | | | | scenarios | ||||
* | moving virtual IP when interface changes due mobike | Martin Willi | 2007-09-12 | 1 | -0/+11 |
| | |||||
* | fixed NAT detection with mobike | Martin Willi | 2007-09-12 | 2 | -7/+7 |
| | |||||
* | implemented routeability checks for mobike (experimental) | Martin Willi | 2007-09-03 | 2 | -14/+110 |
| | |||||
* | added mobike=yes|no connection option | Martin Willi | 2007-08-29 | 1 | -11/+18 |
| | | | | | | | yes: include mobike support notifies as initiator no: only enable mobike as responder when initiator supports it default: yes | ||||
* | not touching IKE_SA_INIT from ike_mobike_t anymore | Martin Willi | 2007-07-19 | 1 | -1/+1 |
| | |||||
* | fixed payload order (Nonce, KE) for IKE_SA_INIT | Martin Willi | 2007-07-16 | 1 | -3/+11 |
| | |||||
* | fixed responder initiated CHILD_SA rekeying when using virtual IPs | Martin Willi | 2007-07-04 | 1 | -11/+45 |
| | |||||
* | improved MOBIKE: | Martin Willi | 2007-07-03 | 2 | -36/+80 |
| | | | | | | | | prefer address family already used do not change address implicit when mobike supported handle multiple simultaneous roaming requests more properly proper enabling/disabling of UDP encapsulation | ||||
* | DBG1 level for 'peer supports MOBIKE' debug message | Andreas Steffen | 2007-07-02 | 1 | -1/+1 |
| | |||||
* | further mobike improvements, regarding to NAT-T | Martin Willi | 2007-06-27 | 2 | -18/+49 |
| | |||||
* | simple roaming of the client works (not MOBIKE conform yet!) | Martin Willi | 2007-06-26 | 1 | -8/+9 |
| | |||||
* | further fixed for mobike roaming | Martin Willi | 2007-06-25 | 1 | -3/+48 |
| | |||||
* | further MOBIKE stuff: | Martin Willi | 2007-06-21 | 9 | -21/+412 |
| | | | | | | | | | kernel properly reports network reconfiguration and informs all IKE_SAs MOBIKE in IKE_AUTH: MOBIKE_SUPPORTED notify and address exchange reestablishment of IKE_SAs on network reconfiguration kinda works not stable yet! | ||||
* | added extensions management to IKE_SA | Martin Willi | 2007-06-18 | 1 | -0/+3 |
| | | | | fixed NATD payload (port) when using route lookup | ||||
* | source address lookup in kernel interface | Martin Willi | 2007-06-18 | 1 | -17/+33 |
| | | | | | | use it for NAT detection if no source address known from config support for %any...%any connections | ||||
* | implemented address change notification (for MOBIKE) | Martin Willi | 2007-06-14 | 1 | -6/+5 |
| | | | | | implemented up to date address list cache to list interfaces | ||||
* | added missing files to the last commit | Martin Willi | 2007-06-14 | 2 | -0/+232 |
| | |||||
* | proper reauthentication: | Martin Willi | 2007-06-14 | 2 | -2/+5 |
| | | | | | IKE_SA is closed completely before the new is initiated, resolves some issues when a dynamic IP is requested from a pool | ||||
* | introduced callback_job: | Martin Willi | 2007-06-11 | 2 | -3/+3 |
| | | | | | | | | | | | | simple asynchronous method invocation use daemons thread pool for all threads proper cancellation and cleanups cancellation mechanism to dynamically unload multithreaded code unified event_queue and scheduler => scheduler unified job_queue and thread_pool => processor removed job_type_t, not really needed fixes here, there and everywhere | ||||
* | removed misleading warning when rekeying | Martin Willi | 2007-05-23 | 1 | -1/+0 |
| | |||||
* | support for virtual IP definition on client side: | Martin Willi | 2007-05-22 | 2 | -4/+13 |
| | | | | | | | if leftsourceip is defined, it is requested. server may define rightsourceip=%config to accept any, or it may overwrite it using rightsourceip. if server does not return an IP, client enforces its configured leftsourceip. | ||||
* | fixed memleak | Martin Willi | 2007-05-22 | 1 | -0/+1 |
| | |||||
* | support of CA-based ipsec policies | Andreas Steffen | 2007-05-18 | 1 | -9/+11 |
| | |||||
* | cosmetics | Andreas Steffen | 2007-05-15 | 1 | -5/+5 |
| | |||||
* | adapted authentication failure text to those in the authenticators | Andreas Steffen | 2007-05-15 | 1 | -3/+3 |
| | |||||
* | cosmetics | Andreas Steffen | 2007-05-15 | 1 | -9/+7 |
| | |||||
* | properly implemented interface_managers initiate, terminte_[ike|child] | Martin Willi | 2007-05-09 | 1 | -0/+22 |
| | | | | | proper thread release when stroke is CTRL+C'ed fixed some permission issues | ||||
* | restructuring of configuration backends | Martin Willi | 2007-04-27 | 1 | -1/+1 |
| | | | | | | | | | added propotypes of new control interfaces (xml & dbus) introduced loadable: configuration backends control interfaces using pluggable modules as in EAP | ||||
* | properly checking received IDr as initiator | Martin Willi | 2007-04-25 | 1 | -1/+8 |
| | |||||
* | added PDF support for CHILD_SAs | Martin Willi | 2007-04-19 | 4 | -106/+227 |
| | | | | support for INVALID_KE_PAYLOAD negotiation for rekeying |