Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | time values in strongswan.conf can be optionally specified in days (d), ↵ | Andreas Steffen | 2008-09-04 | 1 | -1/+1 | |
| | | | | hours (h), minutes (m), or seconds (s) | |||||
* | charon.keep_alive = 0 disables the sending of NAT keep alives | Andreas Steffen | 2008-09-03 | 1 | -1/+1 | |
| | ||||||
* | configure NAT keep alive interval using the charon.keep_alive key | Andreas Steffen | 2008-09-03 | 1 | -2/+9 | |
| | ||||||
* | handle INFORMATIONAL exchanges with NATD payloads in mobike task | Martin Willi | 2008-09-02 | 1 | -0/+2 | |
| | ||||||
* | cosmetics | Andreas Steffen | 2008-08-26 | 1 | -1/+1 | |
| | ||||||
* | completed support of AUTHZ_CA_CERT and AUTHZ_CA_CERT_NAME attributes | Andreas Steffen | 2008-08-26 | 1 | -7/+24 | |
| | ||||||
* | ported parts of two-sim branch | Martin Willi | 2008-08-22 | 9 | -80/+326 | |
| | | | | | | eap_identity parameter to exchange in eap_identity some auth_info/peer_cfg refactorings fixed some bugs, introduced new ones | |||||
* | a (incomplete) implementation of draft-sheffer-ikev2-gtc-00.txt using PAM | Martin Willi | 2008-08-21 | 2 | -6/+6 | |
| | ||||||
* | corrected typo | Andreas Steffen | 2008-08-11 | 1 | -1/+1 | |
| | ||||||
* | initiator sends contents of rightca= if present as a certificate request ↵ | Andreas Steffen | 2008-08-05 | 1 | -9/+15 | |
| | | | | without searching for further CA certificates | |||||
* | using a entry cache for duplicate checks, avoids deadlocks | Martin Willi | 2008-07-30 | 1 | -4/+37 | |
| | ||||||
* | demoted IKE state change output to debug level 2 | Andreas Steffen | 2008-07-28 | 1 | -1/+1 | |
| | ||||||
* | ignore AUTH_LIFETIME value if reauthentication has already been scheduled ↵ | Andreas Steffen | 2008-07-28 | 1 | -8/+13 | |
| | | | | earlier | |||||
* | completed IKE_SA logging at the AUDIT level | Andreas Steffen | 2008-07-23 | 3 | -8/+43 | |
| | ||||||
* | IKE_SA rekeying inherits other_host from old IKE_SA | Andreas Steffen | 2008-07-23 | 1 | -0/+3 | |
| | ||||||
* | cosmetics | Andreas Steffen | 2008-07-23 | 1 | -1/+1 | |
| | ||||||
* | some more changes to IKE_SA and CHILD_SA logging | Andreas Steffen | 2008-07-22 | 6 | -22/+46 | |
| | ||||||
* | cosmetics | Andreas Steffen | 2008-07-22 | 1 | -1/+1 | |
| | ||||||
* | ipsec status lists IPCOMP CPIs | Andreas Steffen | 2008-07-22 | 3 | -6/+31 | |
| | ||||||
* | own CPI was not deleted due to copy-and-paste error | Andreas Steffen | 2008-07-22 | 1 | -1/+1 | |
| | ||||||
* | consistent logging of SPIs and CPIs | Andreas Steffen | 2008-07-22 | 1 | -2/+2 | |
| | ||||||
* | consistent logging of IKE and CHILD SAs | Andreas Steffen | 2008-07-21 | 4 | -23/+39 | |
| | ||||||
* | introduced an additional bus->signal parameter for signal specific data | Martin Willi | 2008-07-18 | 8 | -94/+100 | |
| | | | | added SIG_IKE/SIG_CHD macros for signal emitting | |||||
* | fixed potential segfault in resolve_hosts | Martin Willi | 2008-07-17 | 1 | -1/+4 | |
| | ||||||
* | fixed acquire-delay bug by: | Martin Willi | 2008-07-16 | 4 | -15/+21 | |
| | | | | | installing policies before states updating policies if protocol has changed | |||||
* | reverted [4125],[4166], reimplemented the proper way | Martin Willi | 2008-07-11 | 1 | -2/+8 | |
| | ||||||
* | setting ike_sa on bus in checkout_new | Martin Willi | 2008-07-11 | 1 | -0/+1 | |
| | ||||||
* | do a route lookup to allow routing of left=%any connections | Martin Willi | 2008-07-09 | 1 | -5/+15 | |
| | ||||||
* | peer_cfg lookup takes peer addresses into account | Martin Willi | 2008-07-01 | 1 | -1/+2 | |
| | ||||||
* | strongswan.conf's charon.close_ike_on_child_failure closes IKE_SA if ↵ | Martin Willi | 2008-07-01 | 1 | -2/+36 | |
| | | | | CHILD_SA setup in IKE_AUTH fails | |||||
* | sending INTERNAL_ADDRESS_FAILURE if virtual IP requested but none found | Martin Willi | 2008-07-01 | 2 | -14/+46 | |
| | ||||||
* | log received vendor id as a hex value | Andreas Steffen | 2008-06-27 | 1 | -0/+9 | |
| | ||||||
* | flushing task_manager on shutdown while IKE_SA is usable | Martin Willi | 2008-06-25 | 1 | -1/+2 | |
| | ||||||
* | resolving hosts before route | Martin Willi | 2008-06-23 | 1 | -0/+2 | |
| | ||||||
* | display selected IKE proposal in ipsec statusall | Andreas Steffen | 2008-06-22 | 3 | -4/+61 | |
| | ||||||
* | make config_auth_method_t backward compatible to existing sql templates | Andreas Steffen | 2008-06-10 | 1 | -9/+5 | |
| | ||||||
* | ECDSA with OpenSSL | Tobias Brunner | 2008-06-10 | 6 | -55/+162 | |
| | ||||||
* | DNS resolving of ike_cfg hosts dynamically on demand | Martin Willi | 2008-06-06 | 3 | -61/+79 | |
| | ||||||
* | do not roam IKE_SA in created or deleting state | Martin Willi | 2008-06-04 | 1 | -0/+8 | |
| | ||||||
* | filtering out non matching path probing pairs explicitly | Martin Willi | 2008-05-23 | 1 | -0/+5 | |
| | ||||||
* | replying to COOKIE2 mobike notify properly4.2.2 | Martin Willi | 2008-05-21 | 1 | -1/+49 | |
| | | | | including COOKIE2 ourself after path probing | |||||
* | using fixed size keys in key derivation for AES-XCBC PRF | Martin Willi | 2008-05-21 | 1 | -7/+24 | |
| | ||||||
* | IPComp for IKEv2 | Tobias Brunner | 2008-05-08 | 4 | -12/+215 | |
| | ||||||
* | Hash and URL cosmetics | Andreas Steffen | 2008-04-18 | 2 | -11/+11 | |
| | ||||||
* | support for hash and URL encoded certificate payloads in charon | Tobias Brunner | 2008-04-18 | 3 | -51/+235 | |
| | ||||||
* | splitted IKE_SA manager destroy to allow plugin interaction | Martin Willi | 2008-04-17 | 2 | -5/+24 | |
| | ||||||
* | slightly optimized IKE_SA checkin | Martin Willi | 2008-04-16 | 1 | -3/+7 | |
| | ||||||
* | optimized half-open IKE_SA lookup (no checkout) | Martin Willi | 2008-04-16 | 1 | -3/+13 | |
| | ||||||
* | added API for random number generators, served through credential factory | Martin Willi | 2008-04-15 | 6 | -52/+47 | |
| | | | | ported randomizer_t to a rng_t on top of /dev/(u)random (plugin random) | |||||
* | implemented IKE_SA uniqueness using ipsec.conf uniqueids paramater | Martin Willi | 2008-04-14 | 3 | -0/+115 | |
| | | | | additionally supports a "keep" value to keep the old IKE_SA |