Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | requesting the same virtual IP on reauthentication | Martin Willi | 2007-04-10 | 2 | -51/+68 | |
| | ||||||
* | proper notification handling | Martin Willi | 2007-04-10 | 1 | -1/+103 | |
| | ||||||
* | restructured file layout | Martin Willi | 2007-04-10 | 101 | -46383/+3449 | |
| | | | | | | | | | new configuration structure: peer_cfg: configuration related to a peer (authenitcation, ...= ike_cfg: config to use for IKE setup (proposals) child_Cfg: config for CHILD_SA (proposals, traffic selectors) a peer_cfg has one ike_cfg and multiple child_cfg's stroke now uses fixed count of threads | |||||
* | removed list_crls() and list_ocsp() methods | Andreas Steffen | 2007-04-06 | 2 | -59/+42 | |
| | ||||||
* | support cachecrls=yes | Andreas Steffen | 2007-04-05 | 2 | -7/+21 | |
| | ||||||
* | support of crlcheckinterval=0 to disable IKEv2 CRL fetching | Andreas Steffen | 2007-04-04 | 1 | -0/+12 | |
| | ||||||
* | improved log output for checkout_by_message() | Martin Willi | 2007-04-04 | 2 | -27/+28 | |
| | ||||||
* | implemented dynamic http-based CRL fetching | Andreas Steffen | 2007-04-03 | 1 | -8/+3 | |
| | ||||||
* | removed unneded includes | Martin Willi | 2007-03-30 | 2 | -2/+0 | |
| | ||||||
* | using IFA_LOCAL for interface enumeration to support ppp links | Martin Willi | 2007-03-30 | 1 | -5/+20 | |
| | ||||||
* | added IKE_SA_INIT retransmission detection | Martin Willi | 2007-03-29 | 5 | -130/+204 | |
| | | | | fixed thread exhaustion when IKE_SA is blocked for a longer time | |||||
* | implemented DoS protection with cookies and IP filter | Martin Willi | 2007-03-29 | 2 | -106/+252 | |
| | ||||||
* | fixed task manager message id bug for cookies | Martin Willi | 2007-03-29 | 1 | -1/+1 | |
| | ||||||
* | added retry limit for IKE_SA_INIT (give up after 5 cookie failures) | Martin Willi | 2007-03-29 | 1 | -0/+15 | |
| | ||||||
* | implemented ipsec purgeocsp | Andreas Steffen | 2007-03-28 | 1 | -1/+8 | |
| | ||||||
* | removed send_queue, handled internally in sender_t know | Martin Willi | 2007-03-28 | 20 | -641/+407 | |
| | | | | | do header parsing in receiver, ready for cookie integration | |||||
* | implemented a simple IP blocking filter in receiver thread | Martin Willi | 2007-03-28 | 2 | -11/+119 | |
| | ||||||
* | merged changes from eap-aka trunk | Martin Willi | 2007-03-28 | 3 | -29/+63 | |
| | ||||||
* | is_trusted() adds cert_status to cert_to_be_trusted | Andreas Steffen | 2007-03-28 | 1 | -3/+37 | |
| | ||||||
* | fixed state and logging of IKE_SA when using EAP authentication | Martin Willi | 2007-03-27 | 1 | -5/+16 | |
| | ||||||
* | fixed deferred CHILD_SA rekeying while IKE_SA rekeying in progress | Martin Willi | 2007-03-27 | 4 | -5/+16 | |
| | ||||||
* | giving up EAP-SIM authentication after 3 failed challenges | Martin Willi | 2007-03-27 | 1 | -0/+15 | |
| | ||||||
* | implemented ipsec listocsp function | Andreas Steffen | 2007-03-27 | 2 | -5/+36 | |
| | ||||||
* | added CERT_ROOF | Andreas Steffen | 2007-03-23 | 1 | -1/+1 | |
| | ||||||
* | added CERT_ROOF | Andreas Steffen | 2007-03-23 | 2 | -2/+3 | |
| | ||||||
* | added certificate encoding OCSP content | Andreas Steffen | 2007-03-23 | 2 | -3/+5 | |
| | ||||||
* | added CHILD_SA compare check for rekeying collisions | Martin Willi | 2007-03-22 | 6 | -9/+47 | |
| | ||||||
* | adjusted rekey-retry delay and jitter | Martin Willi | 2007-03-21 | 1 | -2/+2 | |
| | ||||||
* | fixed some rekey collision issues | Martin Willi | 2007-03-21 | 5 | -43/+88 | |
| | | | | added retry with jitter when rekeying fails | |||||
* | fixed SPI byte order | Martin Willi | 2007-03-21 | 1 | -1/+1 | |
| | ||||||
* | fixed child rekey collision | Martin Willi | 2007-03-21 | 8 | -67/+150 | |
| | | | | | implemented ike rekey collision | |||||
* | handling of CHILD_SA rekeying collisions | Martin Willi | 2007-03-21 | 6 | -47/+175 | |
| | ||||||
* | fixed inproper delete of CHILD_SA | Martin Willi | 2007-03-21 | 1 | -4/+7 | |
| | ||||||
* | prevent from initiating to %any | Martin Willi | 2007-03-21 | 1 | -0/+7 | |
| | ||||||
* | fixed some exchange collisions (except IKE/CHILD rekeying) | Martin Willi | 2007-03-20 | 7 | -126/+188 | |
| | ||||||
* | fixed statusall rekey time jitter bug (again) | Martin Willi | 2007-03-20 | 1 | -4/+9 | |
| | ||||||
* | fixed CHILD_SA rekeying time in statusall | Martin Willi | 2007-03-20 | 1 | -2/+2 | |
| | ||||||
* | fixed nat detection bug | Martin Willi | 2007-03-20 | 1 | -2/+2 | |
| | ||||||
* | respecting "keyingtries" parameter on IKE_SA setup | Martin Willi | 2007-03-20 | 1 | -154/+172 | |
| | ||||||
* | cleanups | Martin Willi | 2007-03-20 | 1 | -10/+2 | |
| | | | | fixed reset() | |||||
* | not installing a route when policy gets updated | Martin Willi | 2007-03-20 | 1 | -2/+8 | |
| | ||||||
* | renamed keyingtries attribute | Martin Willi | 2007-03-20 | 2 | -13/+10 | |
| | ||||||
* | adjusted loglevels | Martin Willi | 2007-03-20 | 1 | -13/+6 | |
| | ||||||
* | always update reqid on policy install, fixes dpdaction=hold issue | Martin Willi | 2007-03-19 | 1 | -9/+1 | |
| | ||||||
* | EAP-SIM cleanups | Martin Willi | 2007-03-19 | 1 | -2/+2 | |
| | ||||||
* | fixed CHILD_SA rekeying/delete bug on 64bit machines | Martin Willi | 2007-03-19 | 3 | -147/+13 | |
| | | | | removed obsolete methods in delete_payload | |||||
* | added --with-sim-reader option to configure script | Martin Willi | 2007-03-14 | 2 | -27/+30 | |
| | | | | | some cleanups in eap_sim | |||||
* | removed dublicated code in eap_authenticator | Martin Willi | 2007-03-14 | 1 | -12/+3 | |
| | ||||||
* | version number selection fix | Martin Willi | 2007-03-14 | 2 | -11/+18 | |
| | | | | some cleanups | |||||
* | cleaned up and fixed DPD handling code | Martin Willi | 2007-03-14 | 2 | -94/+114 | |
| |