index
:
tteras/strongswan
master
tteras
tteras-release
tteras' strongSwan tree
gitolite
about
summary
refs
log
tree
commit
diff
stats
log msg
author
committer
range
path:
root
/
src
/
libcharon
/
sa
Commit message (
Expand
)
Author
Age
Files
Lines
*
Allow IPComp on NATed connections, both for IKEv1 and IKEv2
Martin Willi
2013-06-11
2
-33
/
+10
*
Properly compare CHILD_SAs during rekey collision
Tobias Brunner
2013-06-11
1
-5
/
+12
*
Raise LOCAL_AUTH_FAILED alert after receiving AUTHENTICATION_FAILURE
Martin Willi
2013-05-15
1
-0
/
+1
*
kernel-interface: query SAD for last use time if SPD query didn't yield one
Martin Willi
2013-05-06
1
-5
/
+19
*
child-sa: query SAD/SPD just for what we actually need to update statistics
Martin Willi
2013-05-06
1
-2
/
+5
*
child-sa: pass traffic selector to add_sa() regardless of IPsec mode
Martin Willi
2013-05-06
1
-14
/
+11
*
Raise an ALERT_PROPOSAL_MISMATCH_CHILD also when receiving NO_PROPOSAL_CHOSEN
Martin Willi
2013-05-06
1
-0
/
+20
*
Raise an ALERT_PROPOSAL_MISMATCH_IKE also when receiving NO_PROPOSAL_CHOSEN
Martin Willi
2013-05-06
1
-0
/
+20
*
Don't unset IKE_SA on bus before we released virtual IPs and attributes
Martin Willi
2013-05-06
1
-10
/
+8
*
emit a single assig_vips bus message for all VIPs
Andreas Steffen
2013-04-06
2
-6
/
+10
*
ifmap plugin subscribes to assing_vip bus signal
Andreas Steffen
2013-04-06
1
-0
/
+6
*
Refactor check_for_rekeyed_child() in quick_mode task
Martin Willi
2013-04-03
1
-18
/
+24
*
Reuse reqid of an existing Quick Mode, even if it has been rekeyed
Martin Willi
2013-04-03
1
-1
/
+2
*
Defer CHILD_SA rekeying if allocating an SPI fails
Martin Willi
2013-04-03
2
-12
/
+26
*
Fixed some typos, courtesy of codespell
Tobias Brunner
2013-03-25
1
-1
/
+1
*
Delete IKE_SAs if responder does not initiate XAuth exchange within a certain...
Tobias Brunner
2013-03-19
2
-2
/
+16
*
Make sure that xauth-noauth is not used accidentally
Tobias Brunner
2013-03-19
1
-2
/
+5
*
Added xauth-noauth plugin
Tobias Brunner
2013-03-19
1
-29
/
+37
*
Make check whether to use IKEv1 fragmentation more readable
Martin Willi
2013-03-14
1
-5
/
+14
*
Raise an alert if an IKE_SA could not have been reauthenticated and expires
Martin Willi
2013-03-14
1
-0
/
+4
*
child_sa_t.get_usestats() can additionally return the number of processed pac...
Martin Willi
2013-03-14
5
-7
/
+13
*
kernel_ipsec_t.query_sa() additionally returns the number of processed packets
Martin Willi
2013-03-14
1
-3
/
+15
*
Add missing XAuthRespPSK switch case to IKEv1 key derivation
Martin Willi
2013-03-12
1
-0
/
+1
*
Clean up IKE_SA state if IKE_SA_INIT request does not have message ID 0
Martin Willi
2013-03-11
1
-0
/
+4
*
Ignore fourth Qick Mode message sent by Windows servers.
Martin Willi
2013-03-11
1
-0
/
+9
*
As Quick Mode initiator, select a subset of the proposed and the returned TS
Martin Willi
2013-03-07
1
-4
/
+11
*
Merge branch 'multi-eap'
Martin Willi
2013-03-01
2
-28
/
+50
|
\
|
*
Apply a mutual EAP auth_cfg not before the EAP method completes
Martin Willi
2013-02-26
2
-1
/
+18
|
*
Be a little more verbose why a peer_cfg is inacceptable
Martin Willi
2013-02-26
1
-8
/
+16
|
*
Refactor auth_cfg applying to a common function
Martin Willi
2013-02-26
1
-20
/
+17
*
|
Merge branch 'ikev1-rekeying'
Martin Willi
2013-03-01
1
-0
/
+21
|
\
\
|
*
|
When detecting a duplicate IKEv1 SA, adopt children, as it might be a rekeying
Martin Willi
2013-02-20
1
-0
/
+21
|
|
/
*
|
Merge branch 'opaque-ports'
Martin Willi
2013-03-01
1
-2
/
+2
|
\
\
|
*
|
Use a complete port range in traffic_selector_create_from_{subnet,cidr}
Martin Willi
2013-02-21
1
-2
/
+2
*
|
|
Without MOBIKE, update remote host only if it is behind NAT
Martin Willi
2013-03-01
1
-2
/
+3
*
|
|
Merge branch 'ikev1-mm-retransmits'
Martin Willi
2013-03-01
4
-45
/
+55
|
\
\
\
|
*
|
|
For IKEv1 Main Mode, use message hash to detect early retransmissions
Martin Willi
2013-02-25
1
-10
/
+23
|
*
|
|
Move initial message dropping to task manager
Martin Willi
2013-02-25
3
-19
/
+27
|
*
|
|
Use INIT macro to initialize IKE_SA manager entries
Martin Willi
2013-02-25
1
-17
/
+6
|
|
|
/
|
|
/
|
*
|
|
Merge branch 'tfc-notify'
Martin Willi
2013-03-01
1
-0
/
+9
|
\
\
\
|
*
|
|
Send ESP_TFC_PADDING_NOT_SUPPORTED if the used kernel doesn't support it
Martin Willi
2013-03-01
1
-0
/
+9
|
|
|
/
|
|
/
|
*
|
|
Trigger an updown event when destroying an IKE_SA based on INITIAL_CONTACT
Tobias Brunner
2013-02-28
1
-0
/
+1
|
|
/
|
/
|
*
|
Add a global return_success() method implementation
Martin Willi
2013-02-14
1
-8
/
+2
*
|
Merge branch 'ike-dscp'
Martin Willi
2013-02-14
1
-1
/
+26
|
\
\
|
*
|
Set configured DSCP value while generating IKE packets
Martin Willi
2013-02-06
1
-1
/
+26
|
|
/
*
/
make TNC client authentication type available to IMVs
Andreas Steffen
2013-02-12
1
-0
/
+57
|
/
*
Fix check-in of IKE_SA when IKE_SA_INIT fails and hash table is enabled
Tobias Brunner
2013-01-24
1
-2
/
+13
*
Avoid a deadlock when installing a trap policy failed
Tobias Brunner
2013-01-23
1
-1
/
+5
*
Fix IKE SA inherit API doc
Adrian-Ken Rueegsegger
2013-01-22
1
-2
/
+1
*
Properly send IKEv1 packets if no ike_cfg is known yet
Tobias Brunner
2013-01-14
1
-2
/
+5
[next]