Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | implemented clean spi allocation behavior when using multiple proposals | Martin Willi | 2006-06-15 | 1 | -35/+104 | |
| | ||||||
* | added default CRL directory path | Andreas Steffen | 2006-06-14 | 1 | -0/+7 | |
| | ||||||
* | added option parsing | Andreas Steffen | 2006-06-14 | 1 | -11/+59 | |
| | ||||||
* | debug and logging improvements | Martin Willi | 2006-06-13 | 8 | -16/+43 | |
| | ||||||
* | support for stroke listcerts|listcacerts|listall and left|rightca= | Andreas Steffen | 2006-06-12 | 1 | -55/+91 | |
| | ||||||
* | using same reqid if a child sa rekeys an existing one | Martin Willi | 2006-06-12 | 7 | -20/+37 | |
| | ||||||
* | add_certificate() now returns pointer to added cert | Andreas Steffen | 2006-06-12 | 2 | -8/+8 | |
| | ||||||
* | cosmetics | Andreas Steffen | 2006-06-12 | 4 | -101/+101 | |
| | ||||||
* | workaround for peers rekeying at the same time | Martin Willi | 2006-06-12 | 9 | -16/+87 | |
| | | | | | loading lifetime policies from ipsec.conf | |||||
* | old child_sa gets deleted after rekeying | Martin Willi | 2006-06-09 | 19 | -99/+583 | |
| | | | | | | rekeying almost complete, but: IKE_SA get in an invalid state when both initiate rekeying at the same time, | |||||
* | improved kernel interface logging | Martin Willi | 2006-06-09 | 5 | -63/+50 | |
| | ||||||
* | fixed clone/destroy behavior when not using CAs | Martin Willi | 2006-06-09 | 1 | -5/+17 | |
| | ||||||
* | specifying keysize in bits, as it is required in IKEv2 | Martin Willi | 2006-06-09 | 8 | -142/+171 | |
| | | | | | | added generic kernel SA algorithm handling, which brings us: aes-128, aes-256, blowfish, des, 3des and null encryption for CHILD_SAs | |||||
* | added support for leftsendcert= and left|rightca= parameters | Andreas Steffen | 2006-06-09 | 3 | -10/+66 | |
| | ||||||
* | discard cert if CA basic constraints flag is not set and warn if cert is not ↵ | Andreas Steffen | 2006-06-09 | 1 | -5/+16 | |
| | | | | valide | |||||
* | fixed compile warnings when using -Wall | Martin Willi | 2006-06-08 | 25 | -206/+829 | |
| | | | | | | | | further CHILD_SA rekeying work done: creation of a new CHILD_SA on a expire from a kernel works delete of old CHILD_SA still missing some issues when both initiate rekeing | |||||
* | further work for rekeying: | Martin Willi | 2006-06-07 | 36 | -1398/+1392 | |
| | | | | | | | | | get liftimes from policy added new state initiation of rekeying done proposal redone: removed support for AH+ESP proposals | |||||
* | fixed a memleak | Martin Willi | 2006-06-07 | 1 | -1/+5 | |
| | ||||||
* | created IPv6 environment | Andreas Steffen | 2006-06-06 | 1 | -4/+4 | |
| | ||||||
* | job management: | Martin Willi | 2006-05-31 | 31 | -738/+929 | |
| | | | | | | | | | | | | | moved job code from thread_pool to job, jobs have an "execute" method now added two new jobs: delete_child_sa & rekey_child_sa kernel interface: listens now for ACQUIRE & EXPIRE supports hard and soft lifetimes fires jobs for delete and rekey child sa ike sa manager: can checkout IKE SAs by requid of owned CHILD SAs we have now the infrastructure to do the rekeying... :-) | |||||
* | - fixed some memleaks/freebugs | Martin Willi | 2006-05-31 | 3 | -9/+6 | |
| | | | | | - leak detective works almost usable now (?!) | |||||
* | - fixed host-host tunnel traffic selection, host-host works now | Martin Willi | 2006-05-31 | 4 | -8/+30 | |
| | ||||||
* | minimized prefixed on stroke logger output | Andreas Steffen | 2006-05-31 | 1 | -1/+1 | |
| | ||||||
* | charon outputs strongSwan version | Andreas Steffen | 2006-05-31 | 1 | -0/+3 | |
| | ||||||
* | (no commit message) | Martin Willi | 2006-05-30 | 1 | -10/+13 | |
| | ||||||
* | - fixed event queue for events >36min | Martin Willi | 2006-05-30 | 1 | -30/+17 | |
| | ||||||
* | (no commit message) | Martin Willi | 2006-05-30 | 1 | -0/+1 | |
| | ||||||
* | - included charons module tests to build & dist | Martin Willi | 2006-05-30 | 9 | -11/+44 | |
| | ||||||
* | full support of ikev1 and ikev2 connection flags | Andreas Steffen | 2006-05-30 | 1 | -6/+7 | |
| | ||||||
* | cosmetics in log_status output | Andreas Steffen | 2006-05-30 | 1 | -1/+1 | |
| | ||||||
* | use of streq | Andreas Steffen | 2006-05-30 | 1 | -1/+1 | |
| | ||||||
* | lookup of private key based on keyid of public key | Andreas Steffen | 2006-05-30 | 1 | -24/+47 | |
| | ||||||
* | new functions to add certificates and retrieve private and public keys | Andreas Steffen | 2006-05-30 | 3 | -120/+182 | |
| | ||||||
* | changed log level | Andreas Steffen | 2006-05-30 | 1 | -2/+2 | |
| | ||||||
* | list ca certificates | Andreas Steffen | 2006-05-30 | 1 | -2/+3 | |
| | ||||||
* | define default CA_CERTIFICATE_DIR | Andreas Steffen | 2006-05-30 | 1 | -2/+9 | |
| | ||||||
* | load all ca certificates | Andreas Steffen | 2006-05-30 | 1 | -1/+1 | |
| | ||||||
* | - fixed daemon destruction order to prevent | Martin Willi | 2006-05-30 | 1 | -25/+33 | |
| | | | | | crashes on termination | |||||
* | - fixed memleak when deleting a connection | Martin Willi | 2006-05-29 | 1 | -1/+5 | |
| | ||||||
* | - updated todo list | Martin Willi | 2006-05-29 | 1 | -1/+4 | |
| | ||||||
* | - policies contain a connections name now | Martin Willi | 2006-05-29 | 13 | -307/+438 | |
| | | | | | | | | - used for initiate and delete - connections won't get initiated twice anymore - deleting of connections is now possible, which allows us to use ipsec update and ipsec reload | |||||
* | stroke now uses constant size string buffer | Andreas Steffen | 2006-05-29 | 1 | -28/+44 | |
| | ||||||
* | changed to standard connection log output | Andreas Steffen | 2006-05-29 | 1 | -4/+7 | |
| | ||||||
* | - some logging improvements and cosmetics | Martin Willi | 2006-05-24 | 4 | -8/+19 | |
| | ||||||
* | - handle IKE_SA setup without a piggy-packed CHILD_SA | Martin Willi | 2006-05-24 | 7 | -48/+78 | |
| | | | | | more IKEv2 conform | |||||
* | - initiate IKE_SA deletion befor manager destruction | Martin Willi | 2006-05-24 | 1 | -7/+14 | |
| | ||||||
* | (no commit message) | Martin Willi | 2006-05-24 | 1 | -1/+1 | |
| | ||||||
* | - show connection templates in status & statusall | Martin Willi | 2006-05-23 | 6 | -19/+108 | |
| | | | | | - don't complain on termination of IKEv1 connections | |||||
* | - changed config load strategy: | Martin Willi | 2006-05-23 | 3 | -10/+41 | |
| | | | | | | | starter loads both connections in charon & pluto, charon ignores anything with keyexchange!=ikev2. pluto needs the same behavior. | |||||
* | load_end_certificate() now loads certificates | Andreas Steffen | 2006-05-23 | 1 | -27/+46 | |
| |