Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | further work done for simultaneous rekeying/delete | Martin Willi | 2006-07-10 | 15 | -229/+312 | |
| | | | | | still some cases which cause trouble | |||||
* | fixed compiler warnings in parser when using -O2 | Martin Willi | 2006-07-07 | 1 | -3/+3 | |
| | ||||||
* | updated copyright information | Martin Willi | 2006-07-07 | 160 | -170/+325 | |
| | ||||||
* | reimplemented CHILD_SA rekeying & delete | Martin Willi | 2006-07-07 | 21 | -294/+1582 | |
| | | | | | no simultanous transaction with CHILD_SAs yet! | |||||
* | added support for leftprotoport and rightprotoport | Martin Willi | 2006-07-05 | 3 | -11/+24 | |
| | ||||||
* | improved CHILD_SA output for "ipsec statusall" | Martin Willi | 2006-07-05 | 1 | -61/+106 | |
| | ||||||
* | redesigned IKE_SA using a transaction mechanism: | Martin Willi | 2006-07-05 | 71 | -8081/+4767 | |
| | | | | | | | | | | | | removed old state machine reimplemented IKE_SA setup and delete implemented dead peer detection implemented keep-alives a lot of fixes no rekeying yet | |||||
* | made thread ids unsigned again, to avoid negative thread ids on some systems | Martin Willi | 2006-07-04 | 4 | -4/+4 | |
| | ||||||
* | fixed memleak when initiating a connection already up | Martin Willi | 2006-07-04 | 1 | -0/+1 | |
| | ||||||
* | applied latest NATT patch with some fixes and cleanups | Martin Willi | 2006-07-04 | 2 | -9/+16 | |
| | ||||||
* | log entries start with lowcercase character | Andreas Steffen | 2006-07-04 | 2 | -25/+33 | |
| | ||||||
* | fixed natd_hash memory leak | Andreas Steffen | 2006-07-03 | 1 | -2/+7 | |
| | ||||||
* | support of cert payloads | Andreas Steffen | 2006-07-03 | 22 | -619/+959 | |
| | ||||||
* | lowercase log entries | Andreas Steffen | 2006-07-03 | 1 | -1/+1 | |
| | ||||||
* | added X.509 trust chain verification | Andreas Steffen | 2006-06-27 | 3 | -6/+265 | |
| | ||||||
* | applied new changes from NATT team | Martin Willi | 2006-06-23 | 17 | -69/+356 | |
| | | | | | DPD only done when no IPsec and IKE traffic processed minor changes here and there | |||||
* | some message code cleanups | Martin Willi | 2006-06-23 | 3 | -38/+46 | |
| | ||||||
* | cleaner error handling on UDP encapsultion sockopt failure | Martin Willi | 2006-06-22 | 1 | -8/+7 | |
| | ||||||
* | added mysterious UDP encapsulation socket option to get encapsulation working | Martin Willi | 2006-06-22 | 1 | -0/+20 | |
| | ||||||
* | first merge of NATT code | Martin Willi | 2006-06-22 | 43 | -758/+2867 | |
| | ||||||
* | fixed testing build4.0.1 | Martin Willi | 2006-06-21 | 1 | -1/+1 | |
| | ||||||
* | reworked function ignore mechanism to not-report whitelist | Martin Willi | 2006-06-20 | 1 | -2/+2 | |
| | | | | rather than overriding functions | |||||
* | fixed bug: usage of already freed mem | Martin Willi | 2006-06-20 | 1 | -1/+2 | |
| | ||||||
* | readded local_credential_store | Martin Willi | 2006-06-20 | 10 | -88/+256 | |
| | | | | | | added sendcert policy to connection some other cleanups | |||||
* | implemented rereadcrls rereadcacerts | Andreas Steffen | 2006-06-20 | 4 | -10/+702 | |
| | ||||||
* | removed local_credential_store | Andreas Steffen | 2006-06-20 | 4 | -696/+8 | |
| | ||||||
* | fixed SPI when acting as initiator of rekeying | Martin Willi | 2006-06-19 | 1 | -2/+2 | |
| | ||||||
* | fixed SPI when rekeying and deleting CHILD_SAs | Martin Willi | 2006-06-19 | 5 | -14/+19 | |
| | ||||||
* | change key derivation order to fullfill RFC | Martin Willi | 2006-06-19 | 1 | -11/+26 | |
| | ||||||
* | (no commit message) | Martin Willi | 2006-06-16 | 2 | -6/+6 | |
| | ||||||
* | added crl support | Andreas Steffen | 2006-06-16 | 3 | -15/+188 | |
| | ||||||
* | added listcrls | Andreas Steffen | 2006-06-16 | 1 | -1/+7 | |
| | ||||||
* | fixed compilation error | Martin Willi | 2006-06-15 | 1 | -2/+1 | |
| | ||||||
* | fixed aes code, we support now aes128, aes192, aes256 in IKE | Martin Willi | 2006-06-15 | 4 | -9/+108 | |
| | ||||||
* | added support for "ike" and "esp" keywords | Martin Willi | 2006-06-15 | 15 | -97/+367 | |
| | | | | | | | fixed bugs in proposal code algorithm selection for charon works now with ipsec.conf a lot of other fixes | |||||
* | implemented clean spi allocation behavior when using multiple proposals | Martin Willi | 2006-06-15 | 1 | -35/+104 | |
| | ||||||
* | added default CRL directory path | Andreas Steffen | 2006-06-14 | 1 | -0/+7 | |
| | ||||||
* | added option parsing | Andreas Steffen | 2006-06-14 | 1 | -11/+59 | |
| | ||||||
* | debug and logging improvements | Martin Willi | 2006-06-13 | 8 | -16/+43 | |
| | ||||||
* | support for stroke listcerts|listcacerts|listall and left|rightca= | Andreas Steffen | 2006-06-12 | 1 | -55/+91 | |
| | ||||||
* | using same reqid if a child sa rekeys an existing one | Martin Willi | 2006-06-12 | 7 | -20/+37 | |
| | ||||||
* | add_certificate() now returns pointer to added cert | Andreas Steffen | 2006-06-12 | 2 | -8/+8 | |
| | ||||||
* | cosmetics | Andreas Steffen | 2006-06-12 | 4 | -101/+101 | |
| | ||||||
* | workaround for peers rekeying at the same time | Martin Willi | 2006-06-12 | 9 | -16/+87 | |
| | | | | | loading lifetime policies from ipsec.conf | |||||
* | old child_sa gets deleted after rekeying | Martin Willi | 2006-06-09 | 19 | -99/+583 | |
| | | | | | | rekeying almost complete, but: IKE_SA get in an invalid state when both initiate rekeying at the same time, | |||||
* | improved kernel interface logging | Martin Willi | 2006-06-09 | 5 | -63/+50 | |
| | ||||||
* | fixed clone/destroy behavior when not using CAs | Martin Willi | 2006-06-09 | 1 | -5/+17 | |
| | ||||||
* | specifying keysize in bits, as it is required in IKEv2 | Martin Willi | 2006-06-09 | 8 | -142/+171 | |
| | | | | | | added generic kernel SA algorithm handling, which brings us: aes-128, aes-256, blowfish, des, 3des and null encryption for CHILD_SAs | |||||
* | added support for leftsendcert= and left|rightca= parameters | Andreas Steffen | 2006-06-09 | 3 | -10/+66 | |
| | ||||||
* | discard cert if CA basic constraints flag is not set and warn if cert is not ↵ | Andreas Steffen | 2006-06-09 | 1 | -5/+16 | |
| | | | | valide |