aboutsummaryrefslogtreecommitdiffstats
path: root/src/libcharon/sa
Commit message (Collapse)AuthorAgeFilesLines
...
| | * Renamed ike_vendor_v1 to isakmp_vendorMartin Willi2012-03-206-29/+29
| | |
| | * Renamed ike_natd_v1 to isakmp_natdMartin Willi2012-03-206-36/+36
| | |
| | * Renamed ike_cert_pre_v1 to isakmp_cert_preMartin Willi2012-03-206-39/+39
| | |
| | * Renamed ike_cert_post_v1 to isakmp_cert_postMartin Willi2012-03-206-35/+35
| | |
| | * Doxygen fixesMartin Willi2012-03-204-0/+4
| | |
| | * Initiate IKE_ANY configurations with IKEv2Martin Willi2012-03-201-0/+5
| | |
| | * Pass IKE version to peer config enumerator, filter configsMartin Willi2012-03-202-3/+3
| | |
| | * Support an "any" IKE version for both IKEv1 or IKEv2Martin Willi2012-03-202-2/+5
| | |
| | * Send different notifies if quick mode failsMartin Willi2012-03-201-13/+14
| | |
| | * Support flushing of task queue after building message in task failsMartin Willi2012-03-201-4/+14
| | |
| | * Consider notify errors fatal only during main modeMartin Willi2012-03-201-1/+4
| | |
| | * Delete CHILD_SA if installing SA in third message failsMartin Willi2012-03-201-1/+6
| | |
| | * Added a quick_delete task flag to enforce delete, even if CHILD_SA not foundMartin Willi2012-03-204-5/+12
| | |
| | * Send delete if Main Mode authentication fails as initiatorMartin Willi2012-03-202-4/+32
| | |
| | * Send notifies in all error cases of Main ModeMartin Willi2012-03-201-33/+30
| | |
| | * Use (as client) and verify (as server) configured XAuth identitiesMartin Willi2012-03-201-17/+42
| | |
| | * Added an identity getter to XAuth methods to query the actually used identityMartin Willi2012-03-201-0/+7
| | |
| | * Store Main Mode identity even if XAuth-only is used for authenticationMartin Willi2012-03-201-4/+4
| | |
| | * Check authorization constraints after main mode completedMartin Willi2012-03-201-5/+48
| | |
| | * Save authentication info collected during main mode authenticationMartin Willi2012-03-201-1/+26
| | |
| | * Flush auth configs, if enabled, for both IKEv1 and IKEv2Martin Willi2012-03-201-5/+15
| | |
| | * Fixed return value if SIG payload missingMartin Willi2012-03-201-1/+1
| | |
| | * Show auth method of config we are looking for in main modeMartin Willi2012-03-201-1/+2
| | |
| | * Remove executable flag from source code filesMartin Willi2012-03-2010-0/+0
| | |
| | * Removed IKEv1 specific code from child_delete taskMartin Willi2012-03-201-17/+3
| | |
| | * Use IKEv1 specific tasks to close Quick Mode SAsMartin Willi2012-03-203-6/+14
| | |
| | * Added a dedicated IKEv1 task to delete CHILD_SAsMartin Willi2012-03-204-0/+272
| | |
| | * Close IKE_SA directly after sending the deleteMartin Willi2012-03-201-4/+12
| | |
| | * Removed IKEv1 specific code from ike_delete taskMartin Willi2012-03-201-21/+2
| | |
| | * Use the IKEv1 specific delete in IKEv1 SAsMartin Willi2012-03-203-7/+15
| | |
| | * Added a dedicated delete task for IKEv1 IKE_SAsMartin Willi2012-03-204-0/+200
| | |
| | * Use a single task_type_t enum name for ME and non-ME variantMartin Willi2012-03-201-30/+2
| | |
| | * Send certificates and requests when using Hybrid authenticationMartin Willi2012-03-202-1/+19
| | |
| | * Look for an XAuth authentication config both in the first and the second roundMartin Willi2012-03-201-4/+8
| | |
| | * Added hybrid authentication support to Main ModeMartin Willi2012-03-202-1/+11
| | |
| | * Added a IKEv1 hybrid authenticator based on Pubkey/PSK authenticatorsMartin Willi2012-03-203-0/+175
| | |
| | * Use real ID payload to build HASH_I|R for Main Mode authentication.Tobias Brunner2012-03-209-27/+60
| | | | | | | | | | | | | | | This is required for clients like the iPhone which set the protocol and/or port fields of the ID payload.
| | * Create authenticators right when they are used during Main Mode.Tobias Brunner2012-03-201-24/+43
| | |
| | * Ignore additional TRANSACTION request if we already queued oneMartin Willi2012-03-201-2/+7
| | |
| | * Keep a history of received response hashes to detect late retransmissionsMartin Willi2012-03-201-4/+33
| | | | | | | | | | | | | | | | | | If we receive an old response and we already sent out the next request, we must be able to identify that it is not the response to the new request.
| | * Narrow down received and configured traffic selector to a common subsetMartin Willi2012-03-201-11/+15
| | |
| | * Don't send a retransmit for a request we never have sent a responseMartin Willi2012-03-201-12/+19
| | |
| | * Print unsigned IKEv1 message IDsMartin Willi2012-03-201-3/+3
| | |
| | * Log selected peer config during Main Mode.Tobias Brunner2012-03-201-0/+4
| | |
| | * Added a bunch of well known IKEv1 vendor IDs to databaseMartin Willi2012-03-201-0/+25
| | |
| | * Use a generic IKEv1 vendor ID database to send and receive vendor IDsMartin Willi2012-03-201-54/+54
| | |
| | * Fixed compiler warning (set but unused variable)Martin Willi2012-03-201-1/+1
| | |
| | * Queue a TRANSACTION message for later processing if Main Mode not yet completedMartin Willi2012-03-201-0/+36
| | |
| | * Reset task manager state when build() completes an exchange (quick mode)Martin Willi2012-03-201-3/+5
| | |
| | * Include COOKIES in IKEv1 delete payloadsMartin Willi2012-03-201-0/+4
| | |