Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
| | * | Use a more complete implementation of a HA specific diffie_hellman_t | Martin Willi | 2012-03-20 | 1 | -11/+50 | |
| | | | ||||||
| | * | Show IKE version in ipsec statusall | Martin Willi | 2012-03-20 | 1 | -1/+2 | |
| | | | ||||||
| | * | Apply proposal to a HA synced IKE_SA | Martin Willi | 2012-03-20 | 1 | -0/+1 | |
| | | | ||||||
| | * | Updated HA plugin to new IKEv2 specific keymat functions | Martin Willi | 2012-03-20 | 2 | -12/+24 | |
| | | | ||||||
| | * | Added a "aggressive" ipsec.conf connection option | Martin Willi | 2012-03-20 | 1 | -1/+1 | |
| | | | ||||||
| | * | Added an aggressive mode peer_cfg option | Martin Willi | 2012-03-20 | 10 | -12/+13 | |
| | | | ||||||
| | * | Try all matching XAuth secrets we find, not only the first one | Martin Willi | 2012-03-20 | 1 | -11/+23 | |
| | | | ||||||
| | * | Do not query CHILD_SA during delete if they already expired | Martin Willi | 2012-03-20 | 1 | -1/+2 | |
| | | | ||||||
| | * | Handle initiation of not supported IKE versions properly | Martin Willi | 2012-03-20 | 3 | -4/+25 | |
| | | | ||||||
| | * | Added description for the xauth-eap plugin | Martin Willi | 2012-03-20 | 1 | -2/+8 | |
| | | | ||||||
| | * | Added an XAuth plugin that forwards authentication to EAP methods | Martin Willi | 2012-03-20 | 5 | -0/+452 | |
| | | | ||||||
| | * | Added a flag to register local credential sets exclusively, disabling all others | Martin Willi | 2012-03-20 | 1 | -4/+4 | |
| | | | ||||||
| | * | Moved eap/xauth classes out of protocol specific subdirectories | Martin Willi | 2012-03-20 | 18 | -18/+18 | |
| | | | ||||||
| | * | Separated libcharon/sa directory with ikev1 and ikev2 subfolders | Martin Willi | 2012-03-20 | 18 | -18/+18 | |
| | | | ||||||
| | * | Pass IKE version to peer config enumerator, filter configs | Martin Willi | 2012-03-20 | 4 | -9/+10 | |
| | | | ||||||
| | * | Support an "any" IKE version for both IKEv1 or IKEv2 | Martin Willi | 2012-03-20 | 2 | -2/+2 | |
| | | | ||||||
| | * | Added support for iKEIntermediate X.509 extended key usage flag. | Tobias Brunner | 2012-03-20 | 1 | -2/+2 | |
| | | | | | | | | | | | | Mac OS X requires server certificates to have this flag set. | |||||
| | * | Added an identity getter to XAuth methods to query the actually used identity | Martin Willi | 2012-03-20 | 1 | -12/+16 | |
| | | | ||||||
| | * | Be a little more verbose about XAuth configs in ipsec statusall | Martin Willi | 2012-03-20 | 1 | -5/+16 | |
| | | | ||||||
| | * | Pass ipsec.conf xauth_identity option via stroke to charon configurations | Martin Willi | 2012-03-20 | 2 | -0/+7 | |
| | | | ||||||
| | * | Log configured IKE version in stroke plugin. | Tobias Brunner | 2012-03-20 | 1 | -0/+1 | |
| | | | ||||||
| | * | Fixed leak of shared keys in xauth-generic plugin | Martin Willi | 2012-03-20 | 1 | -0/+2 | |
| | | | ||||||
| | * | Added generic XAuth backend, using secrets provided by credential sets. | Tobias Brunner | 2012-03-20 | 5 | -0/+391 | |
| | | | ||||||
| | * | Removed xauth-null dummy plugin. | Tobias Brunner | 2012-03-20 | 5 | -304/+0 | |
| | | | ||||||
| | * | Ask for a username/password in xauth-null as XAUTH initiator | Martin Willi | 2012-03-20 | 1 | -11/+12 | |
| | | | ||||||
| | * | Accept a xauth backend name appended to left/rightauth | Martin Willi | 2012-03-20 | 1 | -1/+8 | |
| | | | ||||||
| | * | Use a string to identify xauth backends, no need for integer types | Martin Willi | 2012-03-20 | 3 | -13/+5 | |
| | | | ||||||
| | * | Use a second authentication config to configure XAUTH authentication | Martin Willi | 2012-03-20 | 1 | -6/+2 | |
| | | | ||||||
| | * | IKEv1 XAuth: Added a "NULL" XAuth plugin which sends a hardcoded user/pass, ↵ | Clavister OpenSource | 2012-03-20 | 5 | -0/+311 | |
| | | | | | | | | | | | | and blindly accepts whatever user/pass is sent it. Changed the xauth_request task to use this new plugin. Add --enable-xauth-null to your configure line to build with the new plugin. | |||||
| | * | Map auth_class to auth method and IKEv1 proposal attribute | Martin Willi | 2012-03-20 | 1 | -0/+4 | |
| | | | ||||||
| | * | IKEv1 XAUTH: Added ability to configure XAUTH+PSK. Added task to handle ↵ | Clavister OpenSource | 2012-03-20 | 1 | -0/+4 | |
| | | | | | | | | | | | | XAUTH requests. Modified task_manager_v1 to enable it to initiate new tasks immediately after finishing a response. | |||||
| | * | Don't compare initiator flag in IKE_SA manager, pass initiator parameter to ↵ | Martin Willi | 2012-03-20 | 1 | -1/+2 | |
| | | | | | | | | | | | | IKE_SA constructor | |||||
| | * | Do not ignore configs for IKEv1 in charon anymore | Martin Willi | 2012-03-20 | 3 | -31/+1 | |
| | | | ||||||
| | * | Store IKE version of an SA on ike_sa_t. | Tobias Brunner | 2012-03-20 | 1 | -1/+1 | |
| | | | ||||||
| | * | Fix unaligned aliasing warning in raw socket | Martin Willi | 2012-03-20 | 1 | -5/+4 | |
| | | | ||||||
| | * | Use enum to define IKE version on peer_cfg_t. | Tobias Brunner | 2012-03-20 | 13 | -22/+23 | |
| | | | | | | | | | | | | Replaced all those magic numbers. | |||||
* | | | add AUTH_RULE_SUBJECT_CERT for raw public keys4.6.3 | Andreas Steffen | 2012-04-30 | 1 | -0/+4 | |
| | | | ||||||
* | | | Typo fixed. | Tobias Brunner | 2012-04-30 | 1 | -1/+1 | |
| | | | ||||||
* | | | output validity of raw public key if available | Andreas Steffen | 2012-04-30 | 1 | -2/+34 | |
| | | | ||||||
* | | | added support for raw RSA public keys to stroke | Andreas Steffen | 2012-04-30 | 5 | -1/+100 | |
| | | | ||||||
* | | | Fixed null-pointer dereference in smp plugin. | Tobias Brunner | 2012-04-26 | 1 | -3/+7 | |
| | | | ||||||
* | | | Removed auth_cfg_t.replace_value() and replaced usages with add(). | Tobias Brunner | 2012-04-18 | 1 | -5/+1 | |
| | | | | | | | | | | | | | | | replace_value() was used to replace identities. Since for these the latest is now returned by get(), adding the new identity with add() is sufficient. | |||||
* | | | Store password with remote ID to tie it stronger to a specific connection. | Tobias Brunner | 2012-04-18 | 1 | -12/+50 | |
| | | | ||||||
* | | | Added stroke user-creds command, to set username/password for a connection. | Tobias Brunner | 2012-04-17 | 3 | -1/+166 | |
| | | | ||||||
* | | | Added method to add additional shared secrets to stroke_cred_t. | Tobias Brunner | 2012-04-17 | 2 | -2/+20 | |
| | | | ||||||
* | | | Typo fixed. | Tobias Brunner | 2012-04-17 | 1 | -1/+1 | |
| | | | ||||||
* | | | remove leading zero in ASN.1 encoded serial numbers | Andreas Steffen | 2012-04-05 | 1 | -2/+2 | |
| | | | ||||||
* | | | moved chunk_skip_zero to chunk.h | Andreas Steffen | 2012-04-03 | 1 | -2/+3 | |
| | | | ||||||
* | | | Doxygen fixes. | Tobias Brunner | 2012-04-03 | 2 | -2/+2 | |
| | | | ||||||
* | | | Don't cast second argument of mem_printf_hook (%b) to size_t. | Tobias Brunner | 2012-03-27 | 3 | -10/+15 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Also treat the given number as unsigned int. Due to the printf hook registration the second argument of mem_printf_hook (if called via printf etc.) is always of type int*. Casting this to a size_t pointer and then dereferencing that as int does not work on big endian machines if int is smaller than size_t (e.g. on ppc64). In order to make this change work if the argument is of a type larger than int, size_t for instance, the second argument for %b has to be casted to (u_)int. |