Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | checking pretrusted but bad certificates only once | Martin Willi | 2008-04-01 | 1 | -13/+18 | |
| | ||||||
* | stroke_list groups certificates by issuer | Andreas Steffen | 2008-04-01 | 1 | -7/+18 | |
| | ||||||
* | minor changes in debug output | Andreas Steffen | 2008-03-31 | 1 | -1/+3 | |
| | ||||||
* | put DN in double quotes | Andreas Steffen | 2008-03-31 | 1 | -1/+1 | |
| | ||||||
* | output error message if maximum ca path length is reached | Andreas Steffen | 2008-03-31 | 1 | -0/+4 | |
| | ||||||
* | ipsec list suppresses duplicates | Andreas Steffen | 2008-03-31 | 1 | -19/+79 | |
| | ||||||
* | timing of connectivity checks adjusted | Tobias Brunner | 2008-03-31 | 1 | -28/+39 | |
| | ||||||
* | defining ME globally, as we need it in plugins | Martin Willi | 2008-03-31 | 1 | -1/+0 | |
| | ||||||
* | utc argument in %#T was missing | Andreas Steffen | 2008-03-31 | 1 | -4/+6 | |
| | ||||||
* | signal fixed | Tobias Brunner | 2008-03-31 | 1 | -2/+2 | |
| | ||||||
* | changed order of server and peer reflexive endpoints (and also the priorities) | Tobias Brunner | 2008-03-31 | 2 | -8/+8 | |
| | ||||||
* | received certificates have least priority | Martin Willi | 2008-03-31 | 1 | -9/+5 | |
| | | | | | fixed manager unlocking | |||||
* | fixed refcounting in certificate trustchain validation | Martin Willi | 2008-03-31 | 1 | -3/+5 | |
| | ||||||
* | changed error message | Andreas Steffen | 2008-03-29 | 1 | -1/+1 | |
| | ||||||
* | output uptime in status in local time | Andreas Steffen | 2008-03-29 | 1 | -1/+1 | |
| | ||||||
* | renamed xml plugin to smp to avoid confusion | Martin Willi | 2008-03-28 | 7 | -40/+48 | |
| | | | | | | added some dependency checks to configure configure checks ClearSilver and fastcgi cleanups in the build system here and there | |||||
* | fixed crash if crl fetching fails | Martin Willi | 2008-03-28 | 1 | -6/+12 | |
| | ||||||
* | reentrant save cert_cache | Martin Willi | 2008-03-28 | 1 | -12/+65 | |
| | ||||||
* | caching of CRLs | Martin Willi | 2008-03-28 | 2 | -127/+124 | |
| | ||||||
* | replaced get_public() by create_public_enumerator() to try multiple public ↵ | Martin Willi | 2008-03-27 | 3 | -129/+231 | |
| | | | | keys for signature verification | |||||
* | use trusted self-signed root CA certificates as trust anchor only | Martin Willi | 2008-03-27 | 1 | -6/+16 | |
| | ||||||
* | changed external interface to the mediation extension. | Tobias Brunner | 2008-03-27 | 1 | -3/+3 | |
| | ||||||
* | corrected ME_ENDPOINT length check | Tobias Brunner | 2008-03-27 | 1 | -1/+2 | |
| | ||||||
* | reusing generic shared_key_t implementation in med_db | Martin Willi | 2008-03-27 | 1 | -55/+1 | |
| | ||||||
* | checking the size of ME_* notify payloads | Tobias Brunner | 2008-03-27 | 2 | -9/+22 | |
| | ||||||
* | replaced the COOKIE notify payload in connectivity checks with a ↵ | Tobias Brunner | 2008-03-27 | 3 | -17/+21 | |
| | | | | ME_CONNECTAUTH notify payload | |||||
* | implemented cert cache flushing, ipsec purgeocsp | Martin Willi | 2008-03-27 | 5 | -4/+54 | |
| | ||||||
* | fixed plugin/stroke Makefile | Andreas Steffen | 2008-03-26 | 1 | -1/+2 | |
| | ||||||
* | mediation extension adapted to the naming convention of the current version ↵ | Tobias Brunner | 2008-03-26 | 30 | -482/+482 | |
| | | | | of the draft. note: the external interface (config, autotools) has not yet been changed | |||||
* | added uptime statistics to statusall | Martin Willi | 2008-03-26 | 1 | -0/+10 | |
| | ||||||
* | caching of ocsp responses (experimental), no crl caching yet | Martin Willi | 2008-03-26 | 2 | -173/+149 | |
| | ||||||
* | fixed compile error if --enable-p2p is set | Martin Willi | 2008-03-26 | 2 | -2/+2 | |
| | ||||||
* | fixed rightca= constraint checking | Martin Willi | 2008-03-26 | 1 | -21/+58 | |
| | | | | implemented rightca= for intermediate CAs we do not have the certificate at config load | |||||
* | fixed auth_info_t.equals() | Martin Willi | 2008-03-26 | 1 | -1/+1 | |
| | ||||||
* | splitted stroke plugin to several files: | Martin Willi | 2008-03-26 | 18 | -3285/+4155 | |
| | | | | | | | | | | | socket: reads messages from socket, dispatching config: process add/del conn, serves configs through backend_t control: controlling of the daemon (up/down/route/...( cred: credential loading, serves creds through credential_set_t ca: ca sections from ipsec.conf, serves cdp's through credential_set_t list: log status information to stroke console (status/statusall/list*) shared_key: shared key implementation for keys read from ipsec.secrets plugin: registers stroke plugin and starts socket w/ thread | |||||
* | added equals() method to peer_cfg, ike_cfg, proposals, auth_info | Martin Willi | 2008-03-26 | 18 | -261/+569 | |
| | | | | | | allows easier merging of ipsec.conf connections replaced some iterators through enumerators made proposals algorithm_t private using enumerator | |||||
* | certificate factory can load certs from file | Andreas Steffen | 2008-03-25 | 1 | -52/+54 | |
| | ||||||
* | defined *_create_from_file() constructors in ↵ | Andreas Steffen | 2008-03-25 | 1 | -103/+60 | |
| | | | | libstrongswan/credentials/certificates | |||||
* | shortened debug output | Andreas Steffen | 2008-03-21 | 1 | -2/+2 | |
| | ||||||
* | detect trusted self-signed before trust chain verification | Andreas Steffen | 2008-03-21 | 1 | -4/+14 | |
| | ||||||
* | optimized debug output of credential_manager.c | Andreas Steffen | 2008-03-21 | 1 | -21/+21 | |
| | ||||||
* | modified debug text | Andreas Steffen | 2008-03-20 | 1 | -1/+1 | |
| | ||||||
* | cert_cache_t caches subject-issuer relations and subject certificates | Martin Willi | 2008-03-20 | 4 | -3/+293 | |
| | | | | ocsp/crl do not benefit yet due missing lookup function | |||||
* | fallback to random end entity certificate if trustchain building fails | Martin Willi | 2008-03-20 | 1 | -3/+18 | |
| | ||||||
* | (no commit message) | Martin Willi | 2008-03-20 | 2 | -14/+86 | |
| | ||||||
* | added support for certificate requests for not yet known CAs | Martin Willi | 2008-03-20 | 4 | -5/+31 | |
| | ||||||
* | fixed verification of preinstalled certificates | Martin Willi | 2008-03-20 | 1 | -1/+1 | |
| | ||||||
* | more trustchain verification improvements | Martin Willi | 2008-03-20 | 1 | -99/+103 | |
| | | | | should fix crl-revoked and two-certs scenarios | |||||
* | refactored trustchain verification, this should fix #33 | Martin Willi | 2008-03-19 | 7 | -329/+531 | |
| | | | | moved auth_info/ocsp_response credset wrapper to separate files | |||||
* | increased debug level in trust chain verification for auditing purposes | Andreas Steffen | 2008-03-19 | 1 | -31/+50 | |
| |