Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | added CHILD_SA states, which allows us to detect further simultaneous ↵ | Martin Willi | 2006-07-13 | 17 | -131/+238 | |
| | | | | | | | transactions reimplemented the buggy message id handling | |||||
* | updated some inline docs | Martin Willi | 2006-07-12 | 3 | -2/+36 | |
| | ||||||
* | fixed crypter/signer in/out to conform with standard | Martin Willi | 2006-07-12 | 1 | -9/+9 | |
| | ||||||
* | fixed payload order | Martin Willi | 2006-07-12 | 1 | -5/+4 | |
| | ||||||
* | added policy cache to kernel interface | Martin Willi | 2006-07-12 | 4 | -156/+50 | |
| | | | | | | allows refcounting of multiple installed policies finally brings us stable simultaneous rekeying | |||||
* | leak detective blanks memory on free & alloc, allows further membug detection | Martin Willi | 2006-07-12 | 1 | -1/+1 | |
| | ||||||
* | identification_t.matches() supports multiple wildcard counts | Andreas Steffen | 2006-07-11 | 1 | -8/+10 | |
| | ||||||
* | further work done for simultaneous rekeying/delete | Martin Willi | 2006-07-10 | 6 | -49/+236 | |
| | | | | | still some cases which cause trouble | |||||
* | updated copyright information | Martin Willi | 2006-07-07 | 11 | -11/+22 | |
| | ||||||
* | reimplemented CHILD_SA rekeying & delete | Martin Willi | 2006-07-07 | 13 | -248/+1516 | |
| | | | | | no simultanous transaction with CHILD_SAs yet! | |||||
* | improved CHILD_SA output for "ipsec statusall" | Martin Willi | 2006-07-05 | 1 | -61/+106 | |
| | ||||||
* | redesigned IKE_SA using a transaction mechanism: | Martin Willi | 2006-07-05 | 37 | -7598/+4353 | |
| | | | | | | | | | | | | removed old state machine reimplemented IKE_SA setup and delete implemented dead peer detection implemented keep-alives a lot of fixes no rekeying yet | |||||
* | applied latest NATT patch with some fixes and cleanups | Martin Willi | 2006-07-04 | 1 | -1/+1 | |
| | ||||||
* | log entries start with lowcercase character | Andreas Steffen | 2006-07-04 | 1 | -23/+27 | |
| | ||||||
* | fixed natd_hash memory leak | Andreas Steffen | 2006-07-03 | 1 | -2/+7 | |
| | ||||||
* | support of cert payloads | Andreas Steffen | 2006-07-03 | 9 | -470/+661 | |
| | ||||||
* | lowercase log entries | Andreas Steffen | 2006-07-03 | 1 | -1/+1 | |
| | ||||||
* | applied new changes from NATT team | Martin Willi | 2006-06-23 | 7 | -33/+232 | |
| | | | | | DPD only done when no IPsec and IKE traffic processed minor changes here and there | |||||
* | first merge of NATT code | Martin Willi | 2006-06-22 | 11 | -114/+1175 | |
| | ||||||
* | fixed bug: usage of already freed mem | Martin Willi | 2006-06-20 | 1 | -1/+2 | |
| | ||||||
* | fixed SPI when acting as initiator of rekeying | Martin Willi | 2006-06-19 | 1 | -2/+2 | |
| | ||||||
* | fixed SPI when rekeying and deleting CHILD_SAs | Martin Willi | 2006-06-19 | 5 | -14/+19 | |
| | ||||||
* | change key derivation order to fullfill RFC | Martin Willi | 2006-06-19 | 1 | -11/+26 | |
| | ||||||
* | (no commit message) | Martin Willi | 2006-06-16 | 1 | -5/+5 | |
| | ||||||
* | fixed aes code, we support now aes128, aes192, aes256 in IKE | Martin Willi | 2006-06-15 | 1 | -6/+6 | |
| | ||||||
* | added support for "ike" and "esp" keywords | Martin Willi | 2006-06-15 | 3 | -16/+16 | |
| | | | | | | | fixed bugs in proposal code algorithm selection for charon works now with ipsec.conf a lot of other fixes | |||||
* | implemented clean spi allocation behavior when using multiple proposals | Martin Willi | 2006-06-15 | 1 | -35/+104 | |
| | ||||||
* | debug and logging improvements | Martin Willi | 2006-06-13 | 1 | -3/+3 | |
| | ||||||
* | using same reqid if a child sa rekeys an existing one | Martin Willi | 2006-06-12 | 6 | -18/+35 | |
| | ||||||
* | cosmetics | Andreas Steffen | 2006-06-12 | 2 | -53/+53 | |
| | ||||||
* | workaround for peers rekeying at the same time | Martin Willi | 2006-06-12 | 5 | -6/+41 | |
| | | | | | loading lifetime policies from ipsec.conf | |||||
* | old child_sa gets deleted after rekeying | Martin Willi | 2006-06-09 | 9 | -43/+462 | |
| | | | | | | rekeying almost complete, but: IKE_SA get in an invalid state when both initiate rekeying at the same time, | |||||
* | improved kernel interface logging | Martin Willi | 2006-06-09 | 1 | -7/+4 | |
| | ||||||
* | specifying keysize in bits, as it is required in IKEv2 | Martin Willi | 2006-06-09 | 2 | -60/+25 | |
| | | | | | | added generic kernel SA algorithm handling, which brings us: aes-128, aes-256, blowfish, des, 3des and null encryption for CHILD_SAs | |||||
* | fixed compile warnings when using -Wall | Martin Willi | 2006-06-08 | 10 | -186/+804 | |
| | | | | | | | | further CHILD_SA rekeying work done: creation of a new CHILD_SA on a expire from a kernel works delete of old CHILD_SA still missing some issues when both initiate rekeing | |||||
* | further work for rekeying: | Martin Willi | 2006-06-07 | 13 | -618/+883 | |
| | | | | | | | | | get liftimes from policy added new state initiation of rekeying done proposal redone: removed support for AH+ESP proposals | |||||
* | fixed a memleak | Martin Willi | 2006-06-07 | 1 | -1/+5 | |
| | ||||||
* | job management: | Martin Willi | 2006-05-31 | 6 | -74/+121 | |
| | | | | | | | | | | | | | moved job code from thread_pool to job, jobs have an "execute" method now added two new jobs: delete_child_sa & rekey_child_sa kernel interface: listens now for ACQUIRE & EXPIRE supports hard and soft lifetimes fires jobs for delete and rekey child sa ike sa manager: can checkout IKE SAs by requid of owned CHILD SAs we have now the infrastructure to do the rekeying... :-) | |||||
* | - fixed some memleaks/freebugs | Martin Willi | 2006-05-31 | 1 | -0/+1 | |
| | | | | | - leak detective works almost usable now (?!) | |||||
* | - fixed host-host tunnel traffic selection, host-host works now | Martin Willi | 2006-05-31 | 3 | -2/+6 | |
| | ||||||
* | cosmetics in log_status output | Andreas Steffen | 2006-05-30 | 1 | -1/+1 | |
| | ||||||
* | use of streq | Andreas Steffen | 2006-05-30 | 1 | -1/+1 | |
| | ||||||
* | lookup of private key based on keyid of public key | Andreas Steffen | 2006-05-30 | 1 | -24/+47 | |
| | ||||||
* | - policies contain a connections name now | Martin Willi | 2006-05-29 | 4 | -44/+54 | |
| | | | | | | | | - used for initiate and delete - connections won't get initiated twice anymore - deleting of connections is now possible, which allows us to use ipsec update and ipsec reload | |||||
* | changed to standard connection log output | Andreas Steffen | 2006-05-29 | 1 | -4/+7 | |
| | ||||||
* | - some logging improvements and cosmetics | Martin Willi | 2006-05-24 | 3 | -5/+15 | |
| | ||||||
* | - handle IKE_SA setup without a piggy-packed CHILD_SA | Martin Willi | 2006-05-24 | 2 | -40/+67 | |
| | | | | | more IKEv2 conform | |||||
* | - initiate IKE_SA deletion befor manager destruction | Martin Willi | 2006-05-24 | 1 | -7/+14 | |
| | ||||||
* | - show connection templates in status & statusall | Martin Willi | 2006-05-23 | 3 | -4/+6 | |
| | | | | | - don't complain on termination of IKEv1 connections | |||||
* | - reimplemented proper IKE SA deletion using a seperate state, | Martin Willi | 2006-05-23 | 15 | -355/+580 | |
| | | | | | should conform now to IKEv2 |