Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | eap-radius: Increase buffer for attributes sent in RADIUS accounting messages | Tobias Brunner | 2013-09-27 | 1 | -1/+1 | |
| | | | | 64 bytes might be too short for user names/identities. | |||||
* | load-tester: Fix crash if private key was not loaded successfully | Tobias Brunner | 2013-09-24 | 1 | -1/+1 | |
| | | | | Fixes #417. | |||||
* | Implemented TCG/PB-PDP_Referral message | Andreas Steffen | 2013-09-17 | 1 | -0/+12 | |
| | ||||||
* | stroke: don't remove a matching peer config if used by other child configs | Martin Willi | 2013-09-13 | 1 | -4/+3 | |
| | | | | | When configurations get merged during add, we should not remove peer configs if other connection entries use the same peer config. | |||||
* | sockets: Initialize the whole ancillary data buffer not only the actual struct | Tobias Brunner | 2013-09-10 | 2 | -4/+4 | |
| | | | | | | This avoids uninitialized bytes that Valgrind seems to notice otherwise. Fixes #395. | |||||
* | Fixed double free causing swapped ends to crash5.1.1dr3 | Andreas Steffen | 2013-09-07 | 1 | -1/+0 | |
| | ||||||
* | load-tester: support extended traffic selector syntax, as in leftsubnet | Martin Willi | 2013-09-04 | 1 | -13/+168 | |
| | | | | | In addition the initiator may use %unique as port, using a distinct port for each connection, starting from 1025. | |||||
* | load-tester: add an option to test transport/beet connections | Martin Willi | 2013-09-04 | 1 | -1/+21 | |
| | ||||||
* | ike: support multiple addresses, ranges and subnets in IKE address config | Martin Willi | 2013-09-04 | 9 | -54/+85 | |
| | | | | | | | Replace the allowany semantic by a more powerful subnet and IP range matching. Multiple addresses, DNS names, subnets and ranges can be specified in a comma separated list. Initiators ignore the ranges/subnets, responders match configurations against all addresses, ranges and subnets. | |||||
* | ike-cfg: remove the to be obsoleted allow any parameter in get_my/other_addr | Martin Willi | 2013-09-04 | 3 | -7/+5 | |
| | ||||||
* | stroke: ignore a leftsourceip if a rightsourceip is given as well | Martin Willi | 2013-09-04 | 1 | -1/+7 | |
| | | | | | | As we always negotiate virtual IPs in charon, having both left- and rightsourceip is not allowed. Both in IKEv1 and IKEv2 we support a single configuration payload exchange only. | |||||
* | stroke: re-enable modeconfig keyword | Martin Willi | 2013-09-04 | 1 | -1/+1 | |
| | ||||||
* | peer-cfg: add a pull/push mode option to use with mode config | Martin Willi | 2013-09-04 | 8 | -10/+11 | |
| | ||||||
* | xauth-generic: honor requested XAuth credential types as a client | Martin Willi | 2013-09-03 | 1 | -16/+51 | |
| | | | | Support requesting of XAuth PINs and print XAuth messages. | |||||
* | eap-radius: support XAuth configuration profiles, defining multiple XAuth rounds | Martin Willi | 2013-09-03 | 1 | -22/+157 | |
| | ||||||
* | xauth: add a configuration string option to be passed to XAuth instances | Martin Willi | 2013-09-03 | 11 | -13/+27 | |
| | | | | | | The configuration string is appended to the XAuth backend name, separated by a colon. The configuration string is passed untouched to the backend, where it can change the behavior of the XAuth module. | |||||
* | Selectively enable PT-TLS and/or RADIUS sockets in tnc-pdp plugin | Andreas Steffen | 2013-08-26 | 1 | -76/+95 | |
| | ||||||
* | stroke: stop enumerating IKE_SAs in statusall if output stream gets closed | Martin Willi | 2013-08-23 | 1 | -1/+1 | |
| | | | | | | | If the output stream is not interested in more information, it can close the the stream. Checking for stream errors avoids useless enumeration of IKE_SAs, saving resources. This allows to use "ipsec statusall | head" to monitor the daemon, or stop enumerating IKE_SAs after a specific entry has been found. | |||||
* | Process PB-TNC batches received via PT-TLS asynchronously | Andreas Steffen | 2013-08-19 | 1 | -4/+1 | |
| | ||||||
* | Show host address of peer connecting to PT-TLS socket | Andreas Steffen | 2013-08-15 | 1 | -1/+7 | |
| | ||||||
* | enabled SASL PLAIN authentication | Andreas Steffen | 2013-08-15 | 1 | -2/+2 | |
| | ||||||
* | PT-TLS connection is properly terminated | Andreas Steffen | 2013-08-15 | 1 | -3/+2 | |
| | ||||||
* | moved tnc_imv plugin to libtnccs thanks to recommendation callback function | Andreas Steffen | 2013-08-15 | 12 | -1887/+79 | |
| | ||||||
* | Moved tnc-tnccs, tnc-imc, tnccs-11, tnccs-20 and tnccs-dynamic libcharon ↵ | Andreas Steffen | 2013-08-15 | 66 | -10629/+0 | |
| | | | | plugins to libtnccs | |||||
* | rapid PT-TLS AR/PDP prototype | Andreas Steffen | 2013-08-15 | 5 | -60/+254 | |
| | ||||||
* | Add PT-TLS interface to strongSwan PDP | Andreas Steffen | 2013-08-15 | 4 | -39/+68 | |
| | ||||||
* | updown: remove description of unsupported PLUTO_ variables | Martin Willi | 2013-08-08 | 1 | -1/+0 | |
| | | | | These have been set by pluto, but are not by charons updown plugin. | |||||
* | tnc-pdp: Initialize struct msghdr properly when reading RADIUS messages5.1.0 | Tobias Brunner | 2013-07-31 | 1 | -10/+10 | |
| | | | | | Before this e.g. msg_controllen was not initialized properly which could cause invalid reads. | |||||
* | whitelist: Fix compilation on FreeBSD | Tobias Brunner | 2013-07-31 | 1 | -0/+2 | |
| | ||||||
* | Callback job is not needed any more | Andreas Steffen | 2013-07-31 | 1 | -4/+0 | |
| | ||||||
* | unity: Handle multi-valued UNITY_SPLIT_INCLUDE/UNITY_LOCAL_LAN attributes | Tobias Brunner | 2013-07-29 | 1 | -50/+97 | |
| | | | | | | | Cisco devices seem to add 6 bytes of padding between each address/mask pair. Fixes #366. | |||||
* | tnc-pdp now uses watcher_t | Andreas Steffen | 2013-07-29 | 1 | -92/+63 | |
| | ||||||
* | eap-radius: do RADIUS/IKE attribute forwarding in XAuth backend | Martin Willi | 2013-07-29 | 2 | -1/+5 | |
| | ||||||
* | eap-radius: support plain XAuth RADIUS authentication using User-Password | Martin Willi | 2013-07-29 | 4 | -0/+253 | |
| | ||||||
* | eap-radius: export function to build common attributes of Access-Request | Martin Willi | 2013-07-29 | 2 | -24/+39 | |
| | ||||||
* | eap-radius: export function to process common attributes of Access-Accept | Martin Willi | 2013-07-29 | 2 | -31/+36 | |
| | ||||||
* | socket-dynamic: Properly initialize IPv6 address | Tobias Brunner | 2013-07-24 | 1 | -1/+1 | |
| | ||||||
* | tnc-ifmap: Use proper cast for length when using %.*s | Tobias Brunner | 2013-07-24 | 1 | -5/+6 | |
| | ||||||
* | coupling: Fix call to call_hook() | Tobias Brunner | 2013-07-22 | 1 | -1/+1 | |
| | ||||||
* | tnc-pdp: Fix reading port setting from strongswan.conf | Tobias Brunner | 2013-07-22 | 1 | -1/+1 | |
| | ||||||
* | stream-service: move CAP_CHOWN check from plugins to service constructor | Martin Willi | 2013-07-18 | 6 | -39/+2 | |
| | | | | | A plugin service can be a TCP socket now, so it does not make much sense to strictly check for CAP_CHOWN. | |||||
* | certexpire: add an option to enforce exporting trustchains having a private key | Martin Willi | 2013-07-18 | 1 | -15/+83 | |
| | ||||||
* | error-notify: catch and forward some alerts related to certificate validation | Martin Willi | 2013-07-18 | 2 | -0/+25 | |
| | ||||||
* | credmgr: introduce a hook function to catch trust chain validation errors | Martin Willi | 2013-07-18 | 2 | -1/+10 | |
| | ||||||
* | lookip: double size of id field in message | Martin Willi | 2013-07-18 | 1 | -1/+1 | |
| | ||||||
* | error-notify: increase size of string/identity fields in messages | Martin Willi | 2013-07-18 | 1 | -2/+2 | |
| | ||||||
* | whitelist: use a read-copy when listing entries | Martin Willi | 2013-07-18 | 1 | -19/+44 | |
| | | | | | While this requires a little more overhead, we can free the lock should the stream block, allowing other threads to add/remove entries. | |||||
* | whitelist: fix error handling when creating the socket fails | Martin Willi | 2013-07-18 | 1 | -0/+6 | |
| | ||||||
* | lookip: fix error handling when creating the socket fails | Martin Willi | 2013-07-18 | 1 | -1/+7 | |
| | ||||||
* | error-notify: fix error handling when creating the socket fails | Martin Willi | 2013-07-18 | 1 | -0/+6 | |
| |