Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
| * | | Load multiple comma seperarated certificates in the leftcert option | Martin Willi | 2013-01-18 | 1 | -15/+32 | |
| | | | ||||||
* | | | Merge branch 'systime' | Martin Willi | 2013-03-01 | 5 | -0/+445 | |
|\ \ \ | | | | | | | | | | | | | | | | | | | | | Add a systime-fix plugin allowing an embedded system to validate certificates if the system time has not been synchronized after boot. Certificates of established tunnels can be re-validated after the system time gets valid. | |||||
| * | | | systime-fix disables certificate lifetime validation if system time not synced | Martin Willi | 2013-02-19 | 4 | -0/+326 | |
| | | | | | | | | | | | | | | | | | | | | | | | | The system time can be periodically checked. If it gets valid, certificates get rechecked with the current lifetime. If certificates are invalid, associated IKE_SAs can be closed or reauthenticated. | |||||
| * | | | Add a stub for systime-fix, a plugin handling certificate lifetimes gracefully | Martin Willi | 2013-02-19 | 3 | -0/+119 | |
| | |/ | |/| | ||||||
* | | | Merge branch 'vip-shunts' | Martin Willi | 2013-03-01 | 1 | -11/+6 | |
|\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Installs bypass policies for the physical address if a virtual address is assigned, and installs a proper source route to actually use the physical address for bypassed destinations. Conflicts: src/libcharon/plugins/unity/unity_handler.c | |||||
| * | | | Include local address for Unity Split-Exclude shunt policies | Martin Willi | 2013-02-20 | 1 | -10/+5 | |
| | | | | | | | | | | | | | | | | | | | | If we use a virtual IP, having a shunt policy for just that wouldn't work, as we want a shunt bypass using the local address. | |||||
* | | | | Merge branch 'opaque-ports' | Martin Willi | 2013-03-01 | 5 | -9/+11 | |
|\ \ \ \ | |/ / / |/| | | | | | | | | | | | Adds a %opaque port option and support for port ranges in left/rightprotoport. Currently not supported by any of our kernel backends. | |||||
| * | | | Pass complete port range over stroke interface for more flexibility | Martin Willi | 2013-02-21 | 1 | -14/+4 | |
| | | | | ||||||
| * | | | Use a complete port range in traffic_selector_create_from_{subnet,cidr} | Martin Willi | 2013-02-21 | 5 | -12/+22 | |
| |/ / | ||||||
* | | | treat IF-M and IF-TNCCS remediation instructions/parameters in an equal way | Andreas Steffen | 2013-02-19 | 3 | -97/+198 | |
| | | | ||||||
* | | | Streamlined log messages in ipseckey plugin | Andreas Steffen | 2013-02-19 | 2 | -58/+30 | |
| | | | ||||||
* | | | ipseckey: Report IPSECKEYs with invalid DNSSEC security state | Reto Guadagnini | 2013-02-19 | 1 | -2/+12 | |
| | | | ||||||
* | | | ipseckey: Added "enable" option for the IPSECKEY plugin to strongswan.conf | Reto Guadagnini | 2013-02-19 | 1 | -3/+16 | |
| | | | ||||||
* | | | Added ipseckey plugin, which provides support for public keys in IPSECKEY RRs | Reto Guadagnini | 2013-02-19 | 7 | -0/+852 | |
| | | | ||||||
* | | | added missing return statement | Andreas Steffen | 2013-02-19 | 1 | -0/+1 | |
| | | | ||||||
* | | | reject PB-Experimental messages with NOSKIP flag set | Andreas Steffen | 2013-02-19 | 1 | -0/+7 | |
| | | | ||||||
* | | | Add a timeout to clean up PDP RADIUS connections | Martin Willi | 2013-02-14 | 1 | -0/+51 | |
| | | | ||||||
* | | | Keep the PDP connections lock while accessing its objects | Martin Willi | 2013-02-14 | 3 | -7/+34 | |
| | | | | | | | | | | | | | | | | | | When we introduce connection timeouts, the state may disappear at any time. This change prevents that, but is not very clear. We probably have to refactor connection handling. | |||||
* | | | Add locking to TNC-PDP connections | Martin Willi | 2013-02-14 | 1 | -7/+23 | |
| | | | ||||||
* | | | Merge branch 'ike-dscp' | Martin Willi | 2013-02-14 | 10 | -56/+114 | |
|\ \ \ | ||||||
| * | | | Add a ikedscp ipsec.conf option to set DSCP value on outgoing IKE packets | Martin Willi | 2013-02-06 | 1 | -1/+1 | |
| | | | | ||||||
| * | | | Add a DSCP configuration value to IKE configs | Martin Willi | 2013-02-06 | 9 | -19/+15 | |
| | | | | ||||||
| * | | | Set DSCP values when sending IP packets in socket-default | Martin Willi | 2013-02-06 | 1 | -1/+65 | |
| | | | | ||||||
| * | | | Don't send a packet in default socket if family is not IPv4 nor IPv6 | Martin Willi | 2013-02-06 | 1 | -12/+18 | |
| | | | | ||||||
| * | | | Avoid extensive casting of sockaddr types in socket-default by using a union | Martin Willi | 2013-02-06 | 1 | -24/+16 | |
| |/ / | | | | | | | | | | Additionally fixes a strict-aliasing rule compiler warning with older gcc. | |||||
* | | | Check if recommendations is set before applying language preference | Martin Willi | 2013-02-14 | 1 | -3/+6 | |
| | | | ||||||
* | | | Merge branch 'pt-tls' | Martin Willi | 2013-02-14 | 3 | -9/+0 | |
|\ \ \ | ||||||
| * | | | TNCCS plugins don't depend on EAP-TNC, but can be used by other transports, too | Martin Willi | 2013-01-15 | 3 | -9/+0 | |
| | |/ | |/| | ||||||
* | | | Fix 'stroke loglevel any' | Tobias Brunner | 2013-02-13 | 1 | -4/+11 | |
| | | | | | | | | | | | | | | | | | | | | | Before b46a5cd4 this worked if debug_t was unsigned. In that case -1, as returned by enum_from_name(), would result in a large positive number. So any unknown debug group (including 'any') had the same effect that was only intended for 'any'. | |||||
* | | | treat EAP identities as user IDs | Andreas Steffen | 2013-02-12 | 1 | -3/+3 | |
| | | | ||||||
* | | | make TNC client authentication type available to IMVs | Andreas Steffen | 2013-02-12 | 7 | -26/+146 | |
| | | | ||||||
* | | | determine underlying IF-T transport protocol | Andreas Steffen | 2013-02-12 | 10 | -62/+184 | |
| | | | ||||||
* | | | make AR identities available to IMVs via IF-IMV 1.4 draft | Andreas Steffen | 2013-02-11 | 5 | -0/+146 | |
| | | | ||||||
* | | | Make IKE/EAP IDs available to TNC server/client | Andreas Steffen | 2013-02-11 | 8 | -24/+81 | |
| |/ |/| | ||||||
* | | Use proper buffer sizes for parse_smartcard() | Tobias Brunner | 2013-01-24 | 1 | -7/+10 | |
| | | ||||||
* | | Removed unused command name when printing usage info for lookip | Tobias Brunner | 2013-01-24 | 1 | -1/+1 | |
| | | ||||||
* | | Filter TS list for Split-Includes before printing them to debug log | Martin Willi | 2013-01-21 | 1 | -10/+34 | |
|/ | ||||||
* | Don't handle right=%any6 as "loose" identity, but as %any | Martin Willi | 2013-01-14 | 1 | -2/+1 | |
| | ||||||
* | Merge branch 'ikev1-fragmentation' | Tobias Brunner | 2013-01-12 | 9 | -12/+20 | |
|\ | | | | | | | | | | | | | This adds support for the proprietary IKEv1 fragmentation extension. Conflicts: NEWS | |||||
| * | Added an option that allows to force IKEv1 fragmentation | Tobias Brunner | 2013-01-12 | 8 | -11/+18 | |
| | | ||||||
| * | Use a connection specific option to en-/disable IKEv1 fragmentation | Tobias Brunner | 2012-12-24 | 9 | -12/+13 | |
| | | ||||||
* | | Fixed some typos in comments | Volker RĂ¼melin | 2013-01-11 | 1 | -1/+1 | |
|/ | ||||||
* | Send empty CDATA batch if TNC client has no data to send | Andreas Steffen | 2012-12-23 | 1 | -16/+28 | |
| | ||||||
* | Fixed some typos, courtesy of codespell | Tobias Brunner | 2012-12-20 | 2 | -2/+2 | |
| | ||||||
* | Add missing error_notify_msg.h to distribution tarball | Martin Willi | 2012-12-19 | 1 | -1/+2 | |
| | ||||||
* | Add an error-notify sample application to listen to error notifications | Martin Willi | 2012-12-19 | 3 | -0/+66 | |
| | ||||||
* | Add an error-notify plugin to send catched alerts to listening applications | Martin Willi | 2012-12-19 | 8 | -0/+736 | |
| | ||||||
* | Raise alerts when enforcing IKE_SA unique policy | Martin Willi | 2012-12-19 | 1 | -0/+1 | |
| | ||||||
* | Fix deadlock in IMC/IMV managers | Tobias Brunner | 2012-12-18 | 2 | -8/+36 | |
| | | | | | | | | | Since reserve_id() might be called from e.g. notify_connection_change() using a write lock will not work as this can't be acquired while holding the read lock. Also, with the previous code it was possible that two IMCs/IMVs added by two threads at the same time would get the same ID assigned. | |||||
* | Properly select IMC/IMV according to given primary ID in reserve_id() | Tobias Brunner | 2012-12-18 | 2 | -2/+2 | |
| |