Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | android: Add new VpnType to enable BYOD features | Tobias Brunner | 2013-07-08 | 1 | -3/+9 |
| | |||||
* | android: Use stronger ESP proposal including AES-GCM | Tobias Brunner | 2013-05-03 | 1 | -0/+6 |
| | |||||
* | android: Request and install an IPv6 DNS server | Tobias Brunner | 2013-03-20 | 1 | -4/+16 |
| | |||||
* | android: Also request a virtual IPv6 address and propose IPv6 TS | Tobias Brunner | 2013-03-20 | 1 | -7/+17 |
| | | | | | This allows IPv6 over IPv4 but falls back nicely if we don't get a virtual IPv6 (or IPv4) address. | ||||
* | android: Add support for combined certificate and EAP authentication | Tobias Brunner | 2013-03-07 | 1 | -27/+50 |
| | | | | | | This uses RFC 4739 multiple authentication rounds to first authenticate the client with a certificate followed by an EAP authentication round with username and password. | ||||
* | Fixed Doxygen comments after scanning complete src directory | Tobias Brunner | 2013-03-02 | 1 | -1/+1 |
| | |||||
* | android: Mitigate race condition on reauthentication | Tobias Brunner | 2013-03-01 | 1 | -0/+4 |
| | | | | | | | | If the TUN device gets recreated while another thread in handle_plain() has not yet called select(2) but already stored the file descriptor of the old TUN device in its FD set, select() will fail with EBADF. Fixes #301. | ||||
* | Add a DSCP configuration value to IKE configs | Martin Willi | 2013-02-06 | 1 | -1/+1 |
| | |||||
* | android: Moved chunk_from_byte_array and byte_array_from_chunk helper functions | Tobias Brunner | 2013-01-14 | 1 | -24/+0 |
| | |||||
* | Added an option that allows to force IKEv1 fragmentation | Tobias Brunner | 2013-01-12 | 1 | -1/+2 |
| | |||||
* | Use a connection specific option to en-/disable IKEv1 fragmentation | Tobias Brunner | 2012-12-24 | 1 | -1/+1 |
| | |||||
* | android: Private key bug has been fixed with Android 4.2 | Tobias Brunner | 2012-11-19 | 1 | -1/+1 |
| | |||||
* | Moved debug.[ch] to utils folder | Tobias Brunner | 2012-10-24 | 2 | -2/+2 |
| | |||||
* | Remove version argument on peer_cfg constructor, use ike_cfg version instead | Martin Willi | 2012-10-24 | 1 | -1/+1 |
| | |||||
* | Add IKE version information to ike_cfg_t | Martin Willi | 2012-10-24 | 1 | -1/+1 |
| | |||||
* | android: Ignore if peer is unreachable when reestablishing an SA | Tobias Brunner | 2012-10-18 | 1 | -2/+7 |
| | |||||
* | android: Use keyingtries=%forever and dpd|closeaction=restart | Tobias Brunner | 2012-10-18 | 1 | -3/+3 |
| | | | | | | | We also ignore the CHILD_SA_DOWN event. This should allow us to keep the connection up as long as the user does not manually disconnect. | ||||
* | android: Handle unreachable peers via alert | Tobias Brunner | 2012-10-16 | 1 | -17/+5 |
| | |||||
* | android: Use 0.0.0.0/0 as local traffic selector | Tobias Brunner | 2012-10-16 | 1 | -1/+2 |
| | | | | | This is helpful if the responder also wants to tunnel e.g. multicast packages. | ||||
* | android: Determine source address dynamically | Tobias Brunner | 2012-10-16 | 2 | -13/+5 |
| | |||||
* | android: Don't use the default ESP proposal as it includes unsupported ↵ | Tobias Brunner | 2012-10-16 | 1 | -1/+4 |
| | | | | algorithms | ||||
* | android: Leak the private key reference on Jelly Bean to avoid a bug in the ↵ | Tobias Brunner | 2012-09-24 | 1 | -1/+10 |
| | | | | | | | | | framework A bug in the framework on Android Jelly Bean causes a SIGSEGV when the private key object returned from KeyChain.getPrivateKey is garbage collected. Leaking the global reference to that object prevents the garbage collection and thereby the crash. | ||||
* | android: Load the private key and certificates separately in android_creds_t | Tobias Brunner | 2012-09-24 | 1 | -27/+28 |
| | |||||
* | android: Added a JNI backed private key implementation | Tobias Brunner | 2012-09-24 | 2 | -0/+323 |
| | | | | | This is required because private keys are provided by an OpenSSL engine in Jelly Bean, which makes them inaccessible directly via getEncoding. | ||||
* | android: Use AUTH_RULE_IDENTITY_LOOSE | Tobias Brunner | 2012-09-18 | 1 | -0/+1 |
| | |||||
* | android: Properly handle reauthentication initiated by the client | Tobias Brunner | 2012-09-06 | 1 | -7/+42 |
| | |||||
* | Merge branch 'android-client-cert' | Tobias Brunner | 2012-09-04 | 4 | -13/+159 |
|\ | | | | | | | Introduces IKEv2 client certificate authentication for the Android App. | ||||
| * | android: Native parts handle ikev2-cert VPN type | Tobias Brunner | 2012-08-31 | 2 | -10/+69 |
| | | |||||
| * | android: android_creds_t can provide a user's private key and certificate | Tobias Brunner | 2012-08-31 | 2 | -3/+89 |
| | | |||||
* | | Pass a list instead of a single virtual IP to attribute enumerators | Martin Willi | 2012-08-30 | 1 | -1/+1 |
| | | |||||
* | | Support multiple address pools configured on a peer_cfg | Martin Willi | 2012-08-30 | 1 | -1/+1 |
| | | |||||
* | | Support multiple virtual IPs on peer_cfg and ike_sa classes | Martin Willi | 2012-08-30 | 1 | -8/+22 |
|/ | |||||
* | Job added which handles plain text packets read from TUN device | Tobias Brunner | 2012-08-13 | 1 | -1/+63 |
| | |||||
* | Added a handler that writes inbound plain text packets to the TUN device | Tobias Brunner | 2012-08-13 | 1 | -0/+35 |
| | |||||
* | Add simple callbacks to receive/send ESP packets via libipsec/receiver. | Tobias Brunner | 2012-08-13 | 1 | -0/+31 |
| | |||||
* | Add routes based on the installed IPsec policies to the TUN device builder | Tobias Brunner | 2012-08-13 | 1 | -0/+46 |
| | |||||
* | Add virtual IP to the TUN device builder | Tobias Brunner | 2012-08-13 | 1 | -1/+9 |
| | | | | | After the CHILD_SA is established we can easily get this address from the IKE_SA. | ||||
* | Create a TUN device via VpnService.Builder once the CHILD_SA is established | Tobias Brunner | 2012-08-13 | 1 | -0/+82 |
| | |||||
* | An Android specific attribute handler installs DNS servers via Builder | Tobias Brunner | 2012-08-13 | 2 | -0/+172 |
| | |||||
* | android_service_t handles initiation of an SA and tracks its progress | Tobias Brunner | 2012-08-13 | 2 | -0/+330 |
| | | | | Status updates are delivered via charonservice (JNI). | ||||
* | Android specific credential set also provides user credentials | Tobias Brunner | 2012-08-13 | 2 | -4/+37 |
| | |||||
* | Added an Android specific credential set that provides CA certificates via JNI | Tobias Brunner | 2012-08-13 | 2 | -0/+210 |