Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | daemon: Use separate method to set default loggers | Tobias Brunner | 2017-01-25 | 1 | -6/+3 |
| | | | | | This way it is not necessary to pass the same values to reload the loggers. | ||||
* | peer-cfg: Use struct to pass data to constructor | Tobias Brunner | 2016-04-09 | 1 | -7/+10 |
| | |||||
* | child-cfg: Use struct to pass data to constructor | Tobias Brunner | 2016-04-09 | 1 | -10/+10 |
| | |||||
* | Use standard unsigned integer types | Andreas Steffen | 2016-03-24 | 5 | -14/+14 |
| | |||||
* | libhydra: Remove empty unused library | Tobias Brunner | 2016-03-03 | 1 | -6/+0 |
| | |||||
* | sigwaitinfo() may fail with EINTR if interrupted by an unblocked signal not ↵ | Tobias Brunner | 2015-11-23 | 1 | -3/+4 |
| | | | | | | in the set Fixes #1213. | ||||
* | Replace usages of sigwait(3) with sigwaitinfo(2) | Tobias Brunner | 2015-10-29 | 1 | -3/+5 |
| | | | | | | | This is basically the same call, but it has the advantage of being supported by FreeBSD's valgrind, which sigwait() is not. References #1106. | ||||
* | controller: Optionally adhere to init limits also when initiating IKE_SAs | Tobias Brunner | 2015-08-21 | 1 | -1/+1 |
| | |||||
* | charon-xpc: Use DNS non-append/replace mode in osx-attr plugin | Martin Willi | 2015-06-18 | 1 | -0/+2 |
| | |||||
* | osx: Initial import of the Objective-C App graphical user interface | Martin Willi | 2014-12-17 | 1 | -1/+1 |
| | |||||
* | charon-xpc: Add a work-around to trigger IP address add events after boot | Martin Willi | 2014-12-16 | 1 | -0/+24 |
| | |||||
* | ike: Add an additional but separate AEAD proposal to CHILD config | Martin Willi | 2014-05-16 | 1 | -0/+1 |
| | | | | | | | This currently has no effect: We don't include AEAD algorithms in the default ESP proposal, as we don't know if it is supported by the backend. But as we hopefully get an algorithm query mechanism on kernel interfaces some day, we add the appropriate functionality nonetheless. | ||||
* | ike: Add an additional but separate AEAD proposal to IKE config, if supported | Martin Willi | 2014-05-16 | 1 | -0/+1 |
| | |||||
* | libcharon: Remove unused charon->name | Tobias Brunner | 2014-02-12 | 1 | -1/+1 |
| | |||||
* | libhydra: Remove unused hydra->daemon | Tobias Brunner | 2014-02-12 | 1 | -1/+1 |
| | |||||
* | lib: Add global config namespace | Tobias Brunner | 2014-02-12 | 1 | -1/+1 |
| | |||||
* | charon-xpc: Set AUTH_RULE_IDENTITY_LOOSE on responder config | Martin Willi | 2013-11-01 | 1 | -0/+4 |
| | | | | | This allows the server to use a different IKE identity as long as the configured hostname is contained in the certificate. | ||||
* | charon-xpc: Load missing eap-md5 plugin after enabling it | Martin Willi | 2013-10-28 | 1 | -1/+1 |
| | |||||
* | charon-xpc: Properly xpc_retain() connections we xpc_release() | Martin Willi | 2013-10-28 | 2 | -0/+2 |
| | |||||
* | charon-xpc: Properly cast SA identifier to uintptr representation | Martin Willi | 2013-10-28 | 1 | -1/+1 |
| | |||||
* | ike: support multiple addresses, ranges and subnets in IKE address config | Martin Willi | 2013-09-04 | 1 | -2/+2 |
| | | | | | | | Replace the allowany semantic by a more powerful subnet and IP range matching. Multiple addresses, DNS names, subnets and ranges can be specified in a comma separated list. Initiators ignore the ranges/subnets, responders match configurations against all addresses, ranges and subnets. | ||||
* | peer-cfg: add a pull/push mode option to use with mode config | Martin Willi | 2013-09-04 | 1 | -1/+1 |
| | |||||
* | charon-xpc: include and prefer AES-GCM algorithms in ESP proposal | Martin Willi | 2013-08-29 | 1 | -0/+3 |
| | |||||
* | charon-xpc: load missing ctr/ccm/gcm plugins | Martin Willi | 2013-07-31 | 1 | -2/+3 |
| | |||||
* | charon-xpc: use kernel-libipsec instead of kernel-pfkey | Martin Willi | 2013-07-31 | 1 | -1/+1 |
| | |||||
* | charon-xpc: fix TS getting after changing CHILD_SA API | Martin Willi | 2013-07-31 | 1 | -2/+6 |
| | |||||
* | charon-xpc: Use correct namespace when setting default settings | Tobias Brunner | 2013-07-22 | 1 | -3/+3 |
| | |||||
* | Fix various API doc issues and typos | Tobias Brunner | 2013-07-18 | 1 | -0/+2 |
| | | | | Partially based on an old patch by Adrian-Ken Rueegsegger. | ||||
* | xpc: forward some risen alerts over XPC to App | Martin Willi | 2013-07-18 | 1 | -0/+57 |
| | |||||
* | xpc: enable close_ike_on_child_failure | Martin Willi | 2013-07-18 | 1 | -0/+2 |
| | |||||
* | xpc: send a "connecting" event when establishing a connection starts | Martin Willi | 2013-07-18 | 1 | -0/+27 |
| | |||||
* | xpc: use osx-attr plugin to install configuration attributes | Martin Willi | 2013-07-18 | 1 | -1/+1 |
| | |||||
* | xpc: send child_updown events over XPC channel | Martin Willi | 2013-07-18 | 1 | -0/+43 |
| | |||||
* | xpc: support termination of IKE_SAs using XPC RPC on connection channel | Martin Willi | 2013-07-18 | 1 | -8/+102 |
| | |||||
* | xpc: move XPC RPC reply creation to command dispatching | Martin Willi | 2013-07-18 | 1 | -24/+16 |
| | |||||
* | xpc: terminate daemon when last XPC connection to App gone | Martin Willi | 2013-07-18 | 1 | -0/+28 |
| | |||||
* | xpc: fix some refcounting issues related to XPC connections | Martin Willi | 2013-07-18 | 2 | -26/+15 |
| | |||||
* | xpc: no need to clear channel table, they are bound to IKE_SA lifetime | Martin Willi | 2013-07-18 | 1 | -8/+0 |
| | |||||
* | xpc: add support for logging over XPC channels | Martin Willi | 2013-07-18 | 3 | -1/+168 |
| | |||||
* | xpc: use the same XPC message "type" mechanism on Mach service as on channels | Martin Willi | 2013-07-18 | 1 | -11/+32 |
| | |||||
* | xpc: ask App for passwords using connection specific channel | Martin Willi | 2013-07-18 | 1 | -0/+90 |
| | |||||
* | xpc: use IKE_SA specific XPC return channels for further communication | Martin Willi | 2013-07-18 | 3 | -9/+312 |
| | |||||
* | xpc: don't send certificate requests, there are too many when using keychain | Martin Willi | 2013-07-18 | 1 | -1/+1 |
| | |||||
* | xpc: build with support for the keychain plugin | Martin Willi | 2013-07-18 | 1 | -1/+1 |
| | |||||
* | xpc: add support for initiate simple IKEv2 EAP connections | Martin Willi | 2013-07-18 | 1 | -0/+126 |
| | |||||
* | xpc: move dispatching to dedicated class, using dedicated thread | Martin Willi | 2013-07-18 | 3 | -86/+298 |
| | |||||
* | xpc: add Xcode project for a charon controlled through XPC | Martin Willi | 2013-07-18 | 3 | -0/+234 |