Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | added eap authentication draft for ikev2 | Martin Willi | 2006-10-18 | 1 | -0/+729 | |
| | ||||||
* | introduced new logging subsystem using bus: | Martin Willi | 2006-10-18 | 92 | -3969/+3168 | |
| | | | | | | | passive listeners can register on the bus active listeners wait for signals actively multiplexing allows multiple listeners to receive debug signals a lot more... | |||||
* | removed module tests, outdated. We need something more system-test like | Martin Willi | 2006-10-18 | 62 | -8203/+0 | |
| | ||||||
* | fixed auxillary message data parsing for IPV6 socket | Martin Willi | 2006-10-09 | 1 | -14/+12 | |
| | | | | using SOL_* constants for socket level | |||||
* | fixed IPV6_PKTINFO setsockopt() to work with most kernel headers | Martin Willi | 2006-10-09 | 1 | -28/+22 | |
| | | | | | replaced strerror(errno) with %m printf specifier | |||||
* | fixed DPD to survive IKE_SA rekeying | Martin Willi | 2006-09-28 | 1 | -1/+1 | |
| | ||||||
* | introduced printf() specifiers for: | Martin Willi | 2006-09-27 | 26 | -203/+1300 | |
| | | | | | | | | | | | host_t (%H) identification_t (%D) chunk pointers (%B) memory pointer/length (%b) added a signaling bus: receives event and debug messages, sends them to its listeners stream_logger, sys_logger, file_logger added, listen to bus some other tweaks here and there | |||||
* | added often used RFCs and drafts | Martin Willi | 2006-09-27 | 9 | -0/+29363 | |
| | ||||||
* | fixed retransmission policy for responder | Martin Willi | 2006-09-25 | 3 | -9/+9 | |
| | ||||||
* | fixed dpd for responder | Martin Willi | 2006-09-25 | 3 | -0/+19 | |
| | ||||||
* | added hostaccess support | Andreas Steffen | 2006-09-25 | 1 | -0/+2 | |
| | ||||||
* | moved auth_method to policy | Andreas Steffen | 2006-09-25 | 1 | -5/+7 | |
| | ||||||
* | added hostaccess support | Andreas Steffen | 2006-09-25 | 1 | -3/+5 | |
| | ||||||
* | added hostaccess support | Andreas Steffen | 2006-09-25 | 1 | -1/+2 | |
| | ||||||
* | more consistent authentication logging | Andreas Steffen | 2006-09-25 | 1 | -44/+33 | |
| | ||||||
* | added hostaccess support | Andreas Steffen | 2006-09-25 | 1 | -4/+11 | |
| | ||||||
* | moved auth_method to policy | Andreas Steffen | 2006-09-25 | 1 | -1/+1 | |
| | ||||||
* | moved auth_method to policy | Andreas Steffen | 2006-09-25 | 2 | -74/+1 | |
| | ||||||
* | added hostaccess support; moved auth_method to policy | Andreas Steffen | 2006-09-25 | 3 | -31/+138 | |
| | ||||||
* | added hostaccess support | Andreas Steffen | 2006-09-25 | 1 | -5/+6 | |
| | ||||||
* | extended statusall output | Martin Willi | 2006-09-21 | 1 | -9/+21 | |
| | | | | | added job/event-queue statistics added allocation statistics when using LEAK_DETECTIVE | |||||
* | support of encrypted private key files | Andreas Steffen | 2006-09-20 | 1 | -1/+19 | |
| | ||||||
* | added copyright notice to sha2_hasher | Martin Willi | 2006-09-19 | 1 | -1/+1 | |
| | | | | included SHA2 in build process | |||||
* | added support for 3DES encryption algorithm in IKE | Martin Willi | 2006-09-19 | 2 | -0/+2 | |
| | ||||||
* | fixed the ids parsing bug | Andreas Steffen | 2006-09-19 | 1 | -1/+4 | |
| | ||||||
* | updated TODOs | Martin Willi | 2006-09-18 | 1 | -9/+10 | |
| | ||||||
* | fixed memleak | Martin Willi | 2006-09-18 | 1 | -10/+27 | |
| | | | | | fixed proper handling of id parsing errors proper return value when no PSK found | |||||
* | added HOST_ACCESS for firewall script as default | Martin Willi | 2006-09-18 | 1 | -0/+1 | |
| | ||||||
* | more debugging output for PSK authentication | Martin Willi | 2006-09-18 | 1 | -3/+11 | |
| | ||||||
* | added PSK support | Andreas Steffen | 2006-09-18 | 8 | -166/+433 | |
| | ||||||
* | proper error handling for socket creation | Martin Willi | 2006-09-18 | 1 | -12/+23 | |
| | ||||||
* | handle certificate parsing error more generous | Martin Willi | 2006-09-14 | 1 | -9/+16 | |
| | ||||||
* | fixed memleak when receiving invalid certificate | Martin Willi | 2006-09-14 | 1 | -0/+1 | |
| | ||||||
* | implemented updown script to handle firewalling | Martin Willi | 2006-09-12 | 9 | -32/+207 | |
| | ||||||
* | add priority management for kernel policy | Martin Willi | 2006-09-08 | 12 | -221/+256 | |
| | | | | | | | let ROUTED policies installed, until manuall removed introduced new naming scheme to allow proper shutdown of IKE/CHILD_SAs ike_sa_manager cleanups | |||||
* | implemented handling of dpdaction and dpddelay ipsec.conf parameters | Martin Willi | 2006-09-08 | 8 | -23/+153 | |
| | ||||||
* | reuse reqid when a ROUTED child_sa gets INSTALLED | Martin Willi | 2006-09-05 | 31 | -456/+521 | |
| | | | | | | | | | fixed a bug in retransmission code added support for the "keyingtries" ipsec.conf parameter added support for the "dpddelay" ipsec.conf parameter done some work for "dpdaction" behavior some other cleanups and fixes | |||||
* | fixed a at-least-one-year-old bug which caused crashed in the scheduler | Martin Willi | 2006-08-31 | 3 | -8/+10 | |
| | ||||||
* | added raw socket filter for IPv6 | Martin Willi | 2006-08-31 | 2 | -23/+16 | |
| | ||||||
* | implemented NAT detection for IPv6 | Martin Willi | 2006-08-31 | 1 | -36/+19 | |
| | ||||||
* | initial support for IPv6 (more testing needed) | Martin Willi | 2006-08-30 | 13 | -289/+787 | |
| | | | | | | | | | socket works (without v6 filter) traffic selector handle IPv4/v4 cleanly improvements in traffic selector code kernel interface accepts v6 traffic selectors and hosts host_t class has full IPv6 support | |||||
* | moved interface enumeration code to socket, where it belongs | Martin Willi | 2006-08-28 | 12 | -348/+207 | |
| | | | | | query interfaces every time we need it to respect changes in network config added address listing on startup and "ipsec statusall" | |||||
* | fixed crash bug when doing "ipsec down" with an unknown connection | Martin Willi | 2006-08-25 | 1 | -2/+5 | |
| | ||||||
* | added name property in CHILD_SA, allows proper status output | Martin Willi | 2006-08-25 | 5 | -14/+75 | |
| | ||||||
* | (no commit message) | Martin Willi | 2006-08-25 | 1 | -5/+0 | |
| | ||||||
* | fixed bug which prevented port float when nat is detected | Martin Willi | 2006-08-25 | 1 | -0/+8 | |
| | ||||||
* | updated Changelog and other docs | Martin Willi | 2006-08-23 | 2 | -11/+10 | |
| | ||||||
* | fixed rekeying behavior when proposing an inacceptable DH group ↵4.0.3 | Martin Willi | 2006-08-23 | 2 | -35/+26 | |
| | | | | (INVALID_KE_PAYLOAD) | |||||
* | implement proper handling of most simultaneous IKE_SA rekeying cases | Martin Willi | 2006-08-23 | 8 | -57/+288 | |
| | ||||||
* | implemented proper refcounting using atomic operations | Martin Willi | 2006-07-28 | 6 | -6/+15 | |
| |