Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | left|rightrsasigkey accepts SSH keys but the key format has to be specified ↵ | Tobias Brunner | 2013-05-07 | 1 | -12/+22 | |
| | | | | | | | explicitly The default is now PKCS#1. With the dns: and ssh: prefixes other formats can be selected. | |||||
* | Try to load raw keys from ipsec.conf as PKCS#1 blob first | Tobias Brunner | 2013-05-07 | 1 | -5/+12 | |
| | | | | | The DNSKEY builder is quite eager and parses pretty much anything as RSA key, so this has to be done before. | |||||
* | kernel-interface: query SAD for last use time if SPD query didn't yield one | Martin Willi | 2013-05-06 | 1 | -1/+1 | |
| | ||||||
* | socket-default: to bind to one dynamic port on OS X, create v4 socket before v6 | Martin Willi | 2013-05-06 | 1 | -1/+7 | |
| | | | | | It seems that the order of binding sockets of different address families to the same dynamic port must be v6-before-v4 on Linux, but v4-before-v6 on OS X. | |||||
* | socket-default: refactor socket pair opening to a function | Martin Willi | 2013-05-06 | 1 | -27/+23 | |
| | ||||||
* | socket-default: Don't try to send packet if we haven't a socket for given family | Martin Willi | 2013-05-06 | 1 | -3/+4 | |
| | ||||||
* | socket-default: Use -1 if socket is not available, as 0 is actually a valid fd | Martin Willi | 2013-05-06 | 1 | -20/+23 | |
| | ||||||
* | socket-dynamic: when sending from port zero, allocate a free port dynamically | Martin Willi | 2013-05-06 | 1 | -26/+101 | |
| | ||||||
* | Use the GEN silent rule when generating files with sed | Martin Willi | 2013-05-06 | 1 | -1/+1 | |
| | ||||||
* | eap-radius: add an option to disable accounting for tunnels without virtual IP | Martin Willi | 2013-05-06 | 1 | -0/+30 | |
| | ||||||
* | eap-radius: use IKE_SA unique id instead of peer identity to manage virtual IPs | Martin Willi | 2013-05-06 | 3 | -34/+100 | |
| | | | | Fixes some corner cases if multiple tunnels use the same peer identity. | |||||
* | fixed typo | Andreas Steffen | 2013-04-19 | 1 | -1/+1 | |
| | ||||||
* | eap-radius: Add an option to exclude ports from Called/Calling-Station-Id | Martin Willi | 2013-04-10 | 2 | -9/+37 | |
| | ||||||
* | emit a single assig_vips bus message for all VIPs | Andreas Steffen | 2013-04-06 | 3 | -43/+38 | |
| | ||||||
* | ifmap plugin subscribes to assing_vip bus signal | Andreas Steffen | 2013-04-06 | 3 | -2/+76 | |
| | ||||||
* | unity: Check IKE_SA in only after enumerating virtual IPs | Tobias Brunner | 2013-04-05 | 1 | -2/+1 | |
| | ||||||
* | cleaned up XML code in tnccs-11 plugin | Andreas Steffen | 2013-04-04 | 8 | -80/+82 | |
| | ||||||
* | duplicheck: track multiple IKE_SAs in checking state to avoid any races | Martin Willi | 2013-04-04 | 1 | -63/+123 | |
| | | | | | | When two consequent duplicates have been detected, track state of each checking IKE_SA separately, avoiding potential race conditions between the active SA and the different SAs in checking state. | |||||
* | fixed memory leak | Andreas Steffen | 2013-04-03 | 1 | -1/+1 | |
| | ||||||
* | properly handle orphaned renewSession jobs | Andreas Steffen | 2013-04-03 | 5 | -24/+102 | |
| | ||||||
* | support chunked HTTP responses | Andreas Steffen | 2013-04-03 | 4 | -140/+370 | |
| | ||||||
* | implemented periodic IF-MAP RenewSession request | Andreas Steffen | 2013-04-03 | 6 | -1/+181 | |
| | ||||||
* | List all stroke counters when "all" is given, and report if connection not known | Martin Willi | 2013-04-03 | 1 | -30/+88 | |
| | ||||||
* | allow retrieval of private keys from other credential sets | Andreas Steffen | 2013-04-02 | 2 | -9/+26 | |
| | ||||||
* | improve checking of sent and received http messages | Andreas Steffen | 2013-04-02 | 1 | -3/+7 | |
| | ||||||
* | Load raw keys before possibly destroying the identity | Tobias Brunner | 2013-04-01 | 1 | -12/+11 | |
| | | | | | | | | If no identity (or %any) is configured the identification_t object is destroyed and an invalid object was associated with the created pubkey certificate. Actually using %any does not work as the certificate would not match when the client later provides an identity. | |||||
* | ipseckey: Use proper daemon name for enable option | Tobias Brunner | 2013-04-01 | 1 | -1/+1 | |
| | ||||||
* | Properly handle situation if no resolver plugins are loaded | Tobias Brunner | 2013-04-01 | 1 | -3/+2 | |
| | ||||||
* | fixed capability metadata | Andreas Steffen | 2013-03-31 | 1 | -1/+2 | |
| | ||||||
* | renamed tnc_ifmap2 plugin to tnc_ifmap | Andreas Steffen | 2013-03-31 | 10 | -177/+177 | |
| | ||||||
* | removed obsoleted tnc_ifmap plugin | Andreas Steffen | 2013-03-31 | 7 | -1337/+0 | |
| | ||||||
* | implemented http basic authentication | Andreas Steffen | 2013-03-31 | 3 | -46/+80 | |
| | ||||||
* | parse IF-MAP server URI | Andreas Steffen | 2013-03-31 | 3 | -41/+105 | |
| | ||||||
* | implemented publish_enforcement_report and endSession methods | Andreas Steffen | 2013-03-30 | 1 | -6/+58 | |
| | ||||||
* | implemented publish_ike_sa method | Andreas Steffen | 2013-03-30 | 1 | -6/+252 | |
| | ||||||
* | ifmap message type is known | Andreas Steffen | 2013-03-30 | 3 | -12/+7 | |
| | ||||||
* | implemented publish_device_ip method | Andreas Steffen | 2013-03-30 | 1 | -13/+132 | |
| | ||||||
* | added IF-MAP SOAP error handling | Andreas Steffen | 2013-03-30 | 1 | -9/+32 | |
| | ||||||
* | created tnc_ifmap2_soap_msg class | Andreas Steffen | 2013-03-29 | 4 | -220/+343 | |
| | ||||||
* | implement NewSession and PurgePublisher messages using the libxml2 library | Andreas Steffen | 2013-03-29 | 3 | -79/+265 | |
| | ||||||
* | set up a new IF-MAP session | Andreas Steffen | 2013-03-29 | 8 | -0/+877 | |
| | ||||||
* | Fixed Doxygen comment in eap_radius plugin | Tobias Brunner | 2013-03-27 | 1 | -2/+3 | |
| | ||||||
* | error-notify: Close file descriptors in case clients are still connected | Tobias Brunner | 2013-03-25 | 1 | -0/+6 | |
| | ||||||
* | ipseckey: NULL pointer dereference fixed in error case | Tobias Brunner | 2013-03-25 | 1 | -0/+1 | |
| | ||||||
* | Fixed some typos, courtesy of codespell | Tobias Brunner | 2013-03-25 | 1 | -2/+2 | |
| | ||||||
* | enforce singular of packets | Andreas Steffen | 2013-03-22 | 1 | -4/+6 | |
| | ||||||
* | asprintf(3) requires _GNU_SOURCE to be defined5.0.3rc1 | Tobias Brunner | 2013-03-22 | 1 | -0/+2 | |
| | ||||||
* | Check return value of asprintf(3) when converting AR identity | Tobias Brunner | 2013-03-22 | 1 | -2/+4 | |
| | | | | | Using chunk_t.ptr as target was also not optimal as it resulted in a compiler warning. | |||||
* | Switch encoding of AR Identity Value from binary to UTF-8 | Andreas Steffen | 2013-03-22 | 1 | -8/+7 | |
| | ||||||
* | Add a load-tester option to keep allocated external address until shutdown | Martin Willi | 2013-03-21 | 2 | -1/+50 | |
| |