Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
| | * | Map auth_class to auth method and IKEv1 proposal attribute | Martin Willi | 2012-03-20 | 2 | -0/+15 | |
| | | | ||||||
| | * | Exchange IKEv1 ESP SA proposal information | Martin Willi | 2012-03-20 | 1 | -2/+66 | |
| | | | ||||||
| | * | Exchange IKEv1 SA specific proposal data with SA payload | Martin Willi | 2012-03-20 | 1 | -13/+69 | |
| | | | ||||||
| | * | Added not-yet used sa_payload parameters used in IKEv1 | Martin Willi | 2012-03-20 | 5 | -16/+18 | |
| | | | ||||||
| | * | Added a get_rekey/reauth_time() jitter parameter to get time without ↵ | Martin Willi | 2012-03-20 | 1 | -2/+2 | |
| | | | | | | | | | | | | randomization | |||||
| | * | IKEv1 XAuth: Changed the xauth_request task to use the new MIGRATE status. | Clavister OpenSource | 2012-03-20 | 2 | -1/+4 | |
| | | | ||||||
| | * | IKEv1 XAuth: Added new MIGRATE status type to status_t. | Clavister OpenSource | 2012-03-20 | 1 | -0/+48 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | When a task returns this status from a build or process method, it is a signal to the task manager that it should treat it as if the task returned SUCCESS. Additionally it will migrate all remaining tasks from the current queue to a different one, calling swap_initiator for each applicable task. Finally, the task manager will call "initiate", if applicable, to kick off tasks in the "queued_tasks" queue. Task queue relocation mapping: passive_tasks moves to queued_tasks (which is then fed to active by the initiate call). active_tasks moves to passive_tasks | |||||
| | * | IKEv1 XAuth: Added new "swap_initiator" method to the standard task_t ↵ | Clavister OpenSource | 2012-03-20 | 2 | -0/+23 | |
| | | | | | | | | | | | | interface. This is needed for when we move a task from the passive queue to the active one. I'm not a huge fan of this method of doing things. Perhaps we should change task_t to have build_i, build_r, process_i, and process_r methods, and call the appropriate one from the task manager, since we have these methods for most tasks anyways. | |||||
| | * | IKEv1 XAuth: XAuthInitPreShared working for XAuth initiator (Main Mode ↵ | Clavister OpenSource | 2012-03-20 | 1 | -15/+123 | |
| | | | | | | | | | | | | responder). Creates USER/PASS request, retrieves the result and sends status. | |||||
| | * | IKEv1 XAuth: Added ability to initiate the XAuth transactions under a flag, ↵ | Clavister OpenSource | 2012-03-20 | 1 | -1/+5 | |
| | | | | | | | | | | | | default not to initiate XAuth. | |||||
| | * | IKEv1 XAuth: Added ike_vendor task to the ID_PROT exchange type processing. ↵ | Clavister OpenSource | 2012-03-20 | 1 | -0/+3 | |
| | | | | | | | | | | | | We need to process vendor payloads to check to see if our peer understands XAuth before using any of these payload types. | |||||
| | * | IKEv1 XAuth: Added temporary "initiate_xauth" public method to ike_sa_t. ↵ | Clavister OpenSource | 2012-03-20 | 2 | -0/+18 | |
| | | | | | | | | | | | | This allows us to initiate an XAuth password authentication exchange after responding to the final message of Main Mode. This change should be reverted once we have a better method to initiate this exchange. | |||||
| | * | IKEv1 XAuth: Temporarilty add an "initiate_later" flag to the task manager. ↵ | Clavister OpenSource | 2012-03-20 | 2 | -1/+31 | |
| | | | | | | | | | | | | When set to TRUE it will cause "initiate" to be called when the current process_response call is finished. This change should be reverted once we have a better method in place. | |||||
| | * | Use quick mode task initiator flag instead of passing it as parameter | Martin Willi | 2012-03-20 | 1 | -12/+10 | |
| | | | ||||||
| | * | Add quick mode ID payloads only if establishing a non-host2host tunnel | Martin Willi | 2012-03-20 | 1 | -7/+30 | |
| | | | ||||||
| | * | Refactored traffic selector handling in quick mode | Martin Willi | 2012-03-20 | 1 | -122/+143 | |
| | | | ||||||
| | * | Refactored NONCE payload handling in quick mode | Martin Willi | 2012-03-20 | 1 | -47/+48 | |
| | | | ||||||
| | * | No need to build a HASH payload in XAUTH task. | Tobias Brunner | 2012-03-20 | 1 | -30/+0 | |
| | | | | | | | | | | | | It gets added automatically when the message is generated. | |||||
| | * | Create host-to-host traffic selectors if quick mode identities missing | Martin Willi | 2012-03-20 | 1 | -3/+26 | |
| | | | ||||||
| | * | Fixed task_manager_v1 compiler warnings | Martin Willi | 2012-03-20 | 1 | -3/+4 | |
| | | | ||||||
| | * | Generate a new mid only after we start a new task (and exchange) | Martin Willi | 2012-03-20 | 1 | -3/+7 | |
| | | | ||||||
| | * | Derive IKEv1 CHILD_SA keymat twice, once for each IPsec SA | Martin Willi | 2012-03-20 | 3 | -24/+31 | |
| | | | ||||||
| | * | Fix seed construction for IKEv1 key derivation | Martin Willi | 2012-03-20 | 1 | -1/+1 | |
| | | | ||||||
| | * | Use a dedicated message hash to detect IKEv1 retransmissions | Martin Willi | 2012-03-20 | 1 | -7/+13 | |
| | | | ||||||
| | * | Authenticate and verify Phase 2 IKEv1 messages with appropriate hashes. | Tobias Brunner | 2012-03-20 | 2 | -0/+221 | |
| | | | ||||||
| | * | Fixed a config reference leak in IKEv2 initiate | Martin Willi | 2012-03-20 | 1 | -1/+0 | |
| | | | ||||||
| | * | XAUTH is initiated based on configuration, no need to call externally | Martin Willi | 2012-03-20 | 3 | -21/+0 | |
| | | | ||||||
| | * | Merged IKEv1 attribute payload/data into configuration payload/attribute | Martin Willi | 2012-03-20 | 2 | -25/+24 | |
| | | | ||||||
| | * | Temp fix for compile error with XAUTH code. | Clavister OpenSource | 2012-03-20 | 1 | -1/+1 | |
| | | | ||||||
| | * | IKEv1 XAUTH: Added ability to configure XAUTH+PSK. Added task to handle ↵ | Clavister OpenSource | 2012-03-20 | 7 | -6/+327 | |
| | | | | | | | | | | | | XAUTH requests. Modified task_manager_v1 to enable it to initiate new tasks immediately after finishing a response. | |||||
| | * | Updates ike_cert_post task with modifications needed for dealing with ↵ | Clavister OpenSource | 2012-03-20 | 1 | -5/+5 | |
| | | | | | | | | | | | | updated cert_payload class. | |||||
| | * | Install negotiated IKEv1 CHILD_SA negotiated in quick mode | Martin Willi | 2012-03-20 | 1 | -0/+163 | |
| | | | ||||||
| | * | Implemented IKEv1 keymat CHILD_SA key derivation function | Martin Willi | 2012-03-20 | 2 | -0/+131 | |
| | | | ||||||
| | * | Moved keymat key length lookup functions to keymat.c | Martin Willi | 2012-03-20 | 3 | -55/+75 | |
| | | | ||||||
| | * | Extended PRF+ by a non-counting variant as used by IKEv1 | Martin Willi | 2012-03-20 | 1 | -3/+3 | |
| | | | ||||||
| | * | Refactored main mode NONCE/KE payload processing | Martin Willi | 2012-03-20 | 1 | -76/+63 | |
| | | | ||||||
| | * | Refactored main mode HASH payload processing | Martin Willi | 2012-03-20 | 1 | -60/+56 | |
| | | | ||||||
| | * | Skip any payloads in front of SA to extract initiators SA bytes | Martin Willi | 2012-03-20 | 1 | -10/+24 | |
| | | | ||||||
| | * | Implemented quick mode protocol handling, no CHILD_SA or HASH payloads yet | Martin Willi | 2012-03-20 | 2 | -7/+294 | |
| | | | ||||||
| | * | Add missing keymat cast to avoid compiler warning | Martin Willi | 2012-03-20 | 1 | -1/+1 | |
| | | | ||||||
| | * | Don't compare initiator flag in IKE_SA manager, pass initiator parameter to ↵ | Martin Willi | 2012-03-20 | 4 | -19/+11 | |
| | | | | | | | | | | | | IKE_SA constructor | |||||
| | * | Create and verify PSK HASH payloads in IKEv1 main mode | Martin Willi | 2012-03-20 | 1 | -9/+117 | |
| | | | ||||||
| | * | Added keymat_v1_t.get_hash() to calculate authentication hashes | Martin Willi | 2012-03-20 | 2 | -0/+53 | |
| | | | ||||||
| | * | Derive IKE keys as IKEv1 initiator, too | Martin Willi | 2012-03-20 | 1 | -0/+6 | |
| | | | ||||||
| | * | Added IV generation to keymat_v1_t. | Tobias Brunner | 2012-03-20 | 2 | -0/+229 | |
| | | | ||||||
| | * | Use key derivation in IKEv1 main mode (PSK authentication). | Tobias Brunner | 2012-03-20 | 1 | -1/+80 | |
| | | | ||||||
| | * | Added a simple AEAD wrapper for IKEv1 encryption/decryption. | Tobias Brunner | 2012-03-20 | 1 | -1/+155 | |
| | | | ||||||
| | * | Added IKEv1 key derivation with support for AUTH_CLASS_PSK. | Tobias Brunner | 2012-03-20 | 2 | -16/+190 | |
| | | | ||||||
| | * | Update cached hosts on ike_sa_t when processing IKEv1 messages. | Tobias Brunner | 2012-03-20 | 1 | -1/+7 | |
| | | | ||||||
| | * | Provide keymat_t to message_t to encrypt/decrypt data. | Tobias Brunner | 2012-03-20 | 1 | -4/+2 | |
| | | |