Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | support for transport in create_child_sa | Martin Willi | 2007-01-08 | 2 | -6/+11 | |
| | | | | include TRANSPORT/TUNNEL information in statusall | |||||
* | fixed typo | Andreas Steffen | 2007-01-04 | 1 | -1/+1 | |
| | ||||||
* | fixed reuathentication when connections other host is %any | Martin Willi | 2007-01-03 | 2 | -10/+18 | |
| | ||||||
* | added support for transport mode and (experimental!) BEET mode | Martin Willi | 2006-12-21 | 5 | -77/+347 | |
| | | | | | support for the type=transport/tunnel parameter in charon | |||||
* | implemented reauthentication using the new reauth=yes|no parameter | Martin Willi | 2006-12-19 | 6 | -44/+118 | |
| | ||||||
* | log IKE SPIs on a separate line | Andreas Steffen | 2006-11-01 | 1 | -3/+3 | |
| | ||||||
* | redesigned formatting of ipsec status|statusall | Andreas Steffen | 2006-11-01 | 3 | -19/+28 | |
| | ||||||
* | some fixes for doxygen | Martin Willi | 2006-10-31 | 3 | -8/+8 | |
| | ||||||
* | better split up of library files "types.h" & "definitions.h" | Martin Willi | 2006-10-31 | 13 | -89/+40 | |
| | | | | | | | | | centralized all printf specifier character definitions reuse of arginfo handlers more cleanups fixed more AMD64 issues added DEBUG_LEVEL compile flag to exclude DBGn() statements | |||||
* | preparations to include certreqs in policy decisions | Andreas Steffen | 2006-10-31 | 3 | -10/+28 | |
| | ||||||
* | moved (myself) in log output | Andreas Steffen | 2006-10-31 | 1 | -1/+1 | |
| | ||||||
* | moved typedefs to beginning of files to solve some include problems | Martin Willi | 2006-10-30 | 26 | -617/+828 | |
| | | | | | | | splitted authenticator to have a separate implementation for each auth_method_t using va_copy to clone va_lists, should fix proplems on AMD64 some other cleanups | |||||
* | fixed SIGSEGV when setup of an additional CHILD_SA fails | Martin Willi | 2006-10-30 | 1 | -2/+8 | |
| | ||||||
* | changed debug level of certreq log output | Andreas Steffen | 2006-10-29 | 1 | -13/+9 | |
| | ||||||
* | support of certreq payload in IKE_AUTH messages | Andreas Steffen | 2006-10-28 | 1 | -12/+53 | |
| | ||||||
* | send a certreq as initiator if other_ca is set | Andreas Steffen | 2006-10-28 | 1 | -2/+19 | |
| | ||||||
* | some improvements in signaling code | Martin Willi | 2006-10-27 | 3 | -8/+52 | |
| | ||||||
* | include only source NATD payloads really needed | Martin Willi | 2006-10-27 | 1 | -7/+17 | |
| | ||||||
* | improved signal handling and emitting | Martin Willi | 2006-10-26 | 10 | -292/+384 | |
| | ||||||
* | removed deprecated iterator methods (has_next & current) | Martin Willi | 2006-10-24 | 11 | -138/+122 | |
| | | | | added iterator hook to manipulate iterator the clean way | |||||
* | linked list cleanups | Martin Willi | 2006-10-24 | 6 | -193/+73 | |
| | | | | | added list methods invoke(), destroy_offset(), destroy_function() simplified list destruction when destroying its items | |||||
* | code cleanups in printf handlers | Martin Willi | 2006-10-20 | 1 | -30/+27 | |
| | ||||||
* | introduced new logging subsystem using bus: | Martin Willi | 2006-10-18 | 17 | -1092/+677 | |
| | | | | | | | passive listeners can register on the bus active listeners wait for signals actively multiplexing allows multiple listeners to receive debug signals a lot more... | |||||
* | fixed DPD to survive IKE_SA rekeying | Martin Willi | 2006-09-28 | 1 | -1/+1 | |
| | ||||||
* | introduced printf() specifiers for: | Martin Willi | 2006-09-27 | 6 | -70/+66 | |
| | | | | | | | | | | | host_t (%H) identification_t (%D) chunk pointers (%B) memory pointer/length (%b) added a signaling bus: receives event and debug messages, sends them to its listeners stream_logger, sys_logger, file_logger added, listen to bus some other tweaks here and there | |||||
* | fixed retransmission policy for responder | Martin Willi | 2006-09-25 | 3 | -9/+9 | |
| | ||||||
* | fixed dpd for responder | Martin Willi | 2006-09-25 | 3 | -0/+19 | |
| | ||||||
* | added hostaccess support | Andreas Steffen | 2006-09-25 | 1 | -0/+2 | |
| | ||||||
* | moved auth_method to policy | Andreas Steffen | 2006-09-25 | 1 | -5/+7 | |
| | ||||||
* | added hostaccess support | Andreas Steffen | 2006-09-25 | 1 | -3/+5 | |
| | ||||||
* | added hostaccess support | Andreas Steffen | 2006-09-25 | 1 | -1/+2 | |
| | ||||||
* | more consistent authentication logging | Andreas Steffen | 2006-09-25 | 1 | -44/+33 | |
| | ||||||
* | added hostaccess support | Andreas Steffen | 2006-09-25 | 1 | -4/+11 | |
| | ||||||
* | added HOST_ACCESS for firewall script as default | Martin Willi | 2006-09-18 | 1 | -0/+1 | |
| | ||||||
* | more debugging output for PSK authentication | Martin Willi | 2006-09-18 | 1 | -3/+11 | |
| | ||||||
* | added PSK support | Andreas Steffen | 2006-09-18 | 3 | -140/+156 | |
| | ||||||
* | handle certificate parsing error more generous | Martin Willi | 2006-09-14 | 1 | -9/+16 | |
| | ||||||
* | fixed memleak when receiving invalid certificate | Martin Willi | 2006-09-14 | 1 | -0/+1 | |
| | ||||||
* | implemented updown script to handle firewalling | Martin Willi | 2006-09-12 | 5 | -19/+191 | |
| | ||||||
* | add priority management for kernel policy | Martin Willi | 2006-09-08 | 6 | -165/+231 | |
| | | | | | | | let ROUTED policies installed, until manuall removed introduced new naming scheme to allow proper shutdown of IKE/CHILD_SAs ike_sa_manager cleanups | |||||
* | implemented handling of dpdaction and dpddelay ipsec.conf parameters | Martin Willi | 2006-09-08 | 4 | -15/+96 | |
| | ||||||
* | reuse reqid when a ROUTED child_sa gets INSTALLED | Martin Willi | 2006-09-05 | 9 | -54/+183 | |
| | | | | | | | | | fixed a bug in retransmission code added support for the "keyingtries" ipsec.conf parameter added support for the "dpddelay" ipsec.conf parameter done some work for "dpdaction" behavior some other cleanups and fixes | |||||
* | fixed a at-least-one-year-old bug which caused crashed in the scheduler | Martin Willi | 2006-08-31 | 1 | -1/+1 | |
| | ||||||
* | implemented NAT detection for IPv6 | Martin Willi | 2006-08-31 | 1 | -36/+19 | |
| | ||||||
* | initial support for IPv6 (more testing needed) | Martin Willi | 2006-08-30 | 2 | -3/+5 | |
| | | | | | | | | | socket works (without v6 filter) traffic selector handle IPv4/v4 cleanly improvements in traffic selector code kernel interface accepts v6 traffic selectors and hosts host_t class has full IPv6 support | |||||
* | moved interface enumeration code to socket, where it belongs | Martin Willi | 2006-08-28 | 2 | -4/+7 | |
| | | | | | query interfaces every time we need it to respect changes in network config added address listing on startup and "ipsec statusall" | |||||
* | added name property in CHILD_SA, allows proper status output | Martin Willi | 2006-08-25 | 5 | -14/+75 | |
| | ||||||
* | (no commit message) | Martin Willi | 2006-08-25 | 1 | -5/+0 | |
| | ||||||
* | fixed bug which prevented port float when nat is detected | Martin Willi | 2006-08-25 | 1 | -0/+8 | |
| | ||||||
* | fixed rekeying behavior when proposing an inacceptable DH group ↵4.0.3 | Martin Willi | 2006-08-23 | 2 | -35/+26 | |
| | | | | (INVALID_KE_PAYLOAD) |