Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | peer-cfg: Use struct to pass data to constructor | Tobias Brunner | 2016-04-09 | 1 | -7/+10 |
| | |||||
* | child-cfg: Use struct to pass data to constructor | Tobias Brunner | 2016-04-09 | 1 | -10/+10 |
| | |||||
* | Use standard unsigned integer types | Andreas Steffen | 2016-03-24 | 1 | -3/+3 |
| | |||||
* | controller: Optionally adhere to init limits also when initiating IKE_SAs | Tobias Brunner | 2015-08-21 | 1 | -1/+1 |
| | |||||
* | ike: Add an additional but separate AEAD proposal to CHILD config | Martin Willi | 2014-05-16 | 1 | -0/+1 |
| | | | | | | | This currently has no effect: We don't include AEAD algorithms in the default ESP proposal, as we don't know if it is supported by the backend. But as we hopefully get an algorithm query mechanism on kernel interfaces some day, we add the appropriate functionality nonetheless. | ||||
* | ike: Add an additional but separate AEAD proposal to IKE config, if supported | Martin Willi | 2014-05-16 | 1 | -0/+1 |
| | |||||
* | charon-xpc: Set AUTH_RULE_IDENTITY_LOOSE on responder config | Martin Willi | 2013-11-01 | 1 | -0/+4 |
| | | | | | This allows the server to use a different IKE identity as long as the configured hostname is contained in the certificate. | ||||
* | charon-xpc: Properly xpc_retain() connections we xpc_release() | Martin Willi | 2013-10-28 | 1 | -0/+1 |
| | |||||
* | ike: support multiple addresses, ranges and subnets in IKE address config | Martin Willi | 2013-09-04 | 1 | -2/+2 |
| | | | | | | | Replace the allowany semantic by a more powerful subnet and IP range matching. Multiple addresses, DNS names, subnets and ranges can be specified in a comma separated list. Initiators ignore the ranges/subnets, responders match configurations against all addresses, ranges and subnets. | ||||
* | peer-cfg: add a pull/push mode option to use with mode config | Martin Willi | 2013-09-04 | 1 | -1/+1 |
| | |||||
* | charon-xpc: include and prefer AES-GCM algorithms in ESP proposal | Martin Willi | 2013-08-29 | 1 | -0/+3 |
| | |||||
* | xpc: move XPC RPC reply creation to command dispatching | Martin Willi | 2013-07-18 | 1 | -24/+16 |
| | |||||
* | xpc: terminate daemon when last XPC connection to App gone | Martin Willi | 2013-07-18 | 1 | -0/+28 |
| | |||||
* | xpc: fix some refcounting issues related to XPC connections | Martin Willi | 2013-07-18 | 1 | -16/+6 |
| | |||||
* | xpc: use the same XPC message "type" mechanism on Mach service as on channels | Martin Willi | 2013-07-18 | 1 | -11/+32 |
| | |||||
* | xpc: use IKE_SA specific XPC return channels for further communication | Martin Willi | 2013-07-18 | 1 | -9/+25 |
| | |||||
* | xpc: don't send certificate requests, there are too many when using keychain | Martin Willi | 2013-07-18 | 1 | -1/+1 |
| | |||||
* | xpc: add support for initiate simple IKEv2 EAP connections | Martin Willi | 2013-07-18 | 1 | -0/+126 |
| | |||||
* | xpc: move dispatching to dedicated class, using dedicated thread | Martin Willi | 2013-07-18 | 1 | -0/+168 |