aboutsummaryrefslogtreecommitdiffstats
path: root/src/libcharon/sa
Commit message (Collapse)AuthorAgeFilesLines
...
| | * Don't invoke a child_updown hook when a quick mode to delete has been rekeyedMartin Willi2012-03-201-1/+6
| | |
| | * Invoke child_rekey hook instead of child_updown when rekeying a quick modeMartin Willi2012-03-203-2/+36
| | |
| | * Don't invoke updown hook when flushing SAs for IKEv1, tasks will do itMartin Willi2012-03-201-10/+12
| | |
| | * Fix "incoming" flag passed to bus_t.message() hookMartin Willi2012-03-201-1/+1
| | |
| | * Continue with next exchange after sending an INFORMATIONALMartin Willi2012-03-201-1/+2
| | |
| | * Handle retransmission of DPD exchange, both as initiator and responderMartin Willi2012-03-201-22/+37
| | |
| | * Disable DPD checking for peers not supporting itMartin Willi2012-03-203-3/+20
| | |
| | * Added missing DPD task nameMartin Willi2012-03-202-3/+3
| | |
| | * Confirm message reception time only if DPD sequence number validMartin Willi2012-03-202-3/+10
| | |
| | * Simplified DPD handling by using a task for a single message onlyMartin Willi2012-03-208-272/+114
| | |
| | * Check if we have an RNG for IKEv1 task manager before using itMartin Willi2012-03-201-9/+9
| | |
| | * Remove unused DPD sequence number getter on task managerMartin Willi2012-03-202-13/+2
| | |
| | * Don't retransmit, rekey, reauth or DPD check SAs when in PASSIVE stateMartin Willi2012-03-201-0/+24
| | |
| | * Send DPD vendor IDClavister OpenSource2012-03-201-1/+1
| | |
| | * Isakmp_dpd task added.Clavister OpenSource2012-03-2010-9/+445
| | |
| | * Request and handle retransmission of a lost third aggressive mode messageMartin Willi2012-03-201-5/+8
| | |
| | * Streamlined debug output when initiating IKEv1 IKE_SAsMartin Willi2012-03-202-2/+2
| | |
| | * Enforce encapsulation mode of configuration, in case initiator proposes bothMartin Willi2012-03-201-1/+2
| | |
| | * Handle aggressive mode task in IKEv1 task managerMartin Willi2012-03-201-6/+36
| | |
| | * Select IKEv1 configurations by main/aggressive mode optionMartin Willi2012-03-204-5/+8
| | |
| | * Fix sending of CERTREQ/CERT payloads in aggressive modeMartin Willi2012-03-202-2/+12
| | |
| | * Implemented aggressive mode using Phase 1 helper classMartin Willi2012-03-204-0/+682
| | |
| | * Make use of the new Phase 1 helper class in main modeMartin Willi2012-03-201-579/+73
| | |
| | * Implemented a common Phase 1 helper class to use by main and aggressive modesMartin Willi2012-03-202-0/+753
| | |
| | * Fix error handling if no PSK found for main modeMartin Willi2012-03-201-5/+9
| | |
| | * Install quick mode CHILD_SAs with negotiated encapsulation modeMartin Willi2012-03-201-12/+17
| | |
| | * Try to detect reauthentication as responder and adopt children to new SAMartin Willi2012-03-202-0/+7
| | |
| | * Destroy IKE_SA after reauthentication initiatend and lifetime limit reachedMartin Willi2012-03-201-1/+6
| | |
| | * Added an IKE_SA manager method to enumerate IKE_SA IDs filtered by identitiesMartin Willi2012-03-202-34/+59
| | |
| | * Query for XAuth identity in get_other_eap_id(), tooMartin Willi2012-03-201-0/+4
| | |
| | * Set ISAKMP SA state to rekeying after triggering reauthenticationMartin Willi2012-03-201-0/+1
| | |
| | * Include peer config overtime in negotiated ISAKMP SA lifetimeMartin Willi2012-03-201-2/+3
| | |
| | * Initiate IKEv1 reauthentication, take over all childrenMartin Willi2012-03-201-4/+44
| | |
| | * Establish IKE_SA only once as XAuth responderMartin Willi2012-03-201-1/+0
| | |
| | * Support initiation of childless IKEv1 ISAKMP SAsMartin Willi2012-03-201-1/+2
| | |
| | * Don't trigger reauthentication if initiator authenticated using XAuthMartin Willi2012-03-201-0/+1
| | |
| | * Set a condition flag if peer has been authenticated using XAuthMartin Willi2012-03-202-0/+6
| | |
| | * Queue Mode Config tasks after main mode as initiator, not as responderMartin Willi2012-03-201-6/+6
| | |
| | * Setting Mode Cfg identifier for CFG_ACK messages.Clavister OpenSource2012-03-201-0/+7
| | |
| | * As responder, try to reuse the reqid of the CHILD_SA the initiator is rekeyingMartin Willi2012-03-201-0/+38
| | |
| | * Reply quick mode with the same SA lifetime that we receivedMartin Willi2012-03-201-4/+4
| | |
| | * Do not query CHILD_SA during delete if they already expiredMartin Willi2012-03-2012-37/+84
| | |
| | * Implemented CHILD_SA rekeyingMartin Willi2012-03-201-1/+18
| | |
| | * Don't return FAILED if a CHILD_SA to delete could not be foundMartin Willi2012-03-201-1/+1
| | |
| | * Support installing of quick mode SAs with a specific reqidMartin Willi2012-03-203-3/+27
| | |
| | * Double check that we could select a TS as quick mode responderMartin Willi2012-03-201-3/+3
| | |
| | * Implemented responder retransmission, currently enabled for quick mode onlyMartin Willi2012-03-202-57/+117
| | |
| | * Queue IKEv1 INFORMATIONALS with higher priority to process notifies firstMartin Willi2012-03-201-2/+2
| | |
| | * Don't process notifies in quick mode task when we get an INFORMATIONALMartin Willi2012-03-201-1/+2
| | |
| | * Always queue a new passive task when receiving an IKEv1 INFORMATIONALMartin Willi2012-03-201-1/+2
| | |