Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
| | * | If no IKEv1 shared key found for hosts, try to find one based on config ↵ | Martin Willi | 2012-03-20 | 1 | -17/+68 | |
| | | | | | | | | | | | | identities | |||||
| | * | Log peer cfg enumeration externally for flexibility | Martin Willi | 2012-03-20 | 2 | -2/+7 | |
| | | | ||||||
| | * | Accept NULL identities passed to peer config enumeration | Martin Willi | 2012-03-20 | 1 | -4/+1 | |
| | | | ||||||
| | * | Fixed authentication method selection for main mode PSK authentication | Martin Willi | 2012-03-20 | 1 | -1/+1 | |
| | | | ||||||
| | * | Use virtual IP to substitute dynamic traffic selectors in quick mode | Martin Willi | 2012-03-20 | 1 | -6/+10 | |
| | | | ||||||
| | * | Queue Mode Config tasks when required | Martin Willi | 2012-03-20 | 2 | -10/+27 | |
| | | | ||||||
| | * | Added IKEv1 Mode Config task based on IKEv2 ike_config | Martin Willi | 2012-03-20 | 4 | -0/+471 | |
| | | | ||||||
| | * | Reject quick modes if IKE_SA not yet established | Martin Willi | 2012-03-20 | 1 | -0/+6 | |
| | | | ||||||
| | * | Use a common function to set IKE_SA to established | Martin Willi | 2012-03-20 | 1 | -29/+22 | |
| | | | ||||||
| | * | Implemented responder part of XAUTH task | Martin Willi | 2012-03-20 | 1 | -12/+96 | |
| | | | ||||||
| | * | Implemented initiator part of xauth task | Martin Willi | 2012-03-20 | 1 | -1/+167 | |
| | | | ||||||
| | * | Get first XAuth backend if none configured | Martin Willi | 2012-03-20 | 1 | -1/+2 | |
| | | | ||||||
| | * | Remove unused task swap_initiator method | Martin Willi | 2012-03-20 | 1 | -5/+0 | |
| | | | ||||||
| | * | Use a string to identify xauth backends, no need for integer types | Martin Willi | 2012-03-20 | 4 | -64/+43 | |
| | | | ||||||
| | * | Remove xauth_authenticator, we handle it in the task | Martin Willi | 2012-03-20 | 2 | -230/+0 | |
| | | | ||||||
| | * | Use a second authentication config to configure XAUTH authentication | Martin Willi | 2012-03-20 | 1 | -33/+102 | |
| | | | ||||||
| | * | Replace xauth_request task with a new stub where we reimplement it | Martin Willi | 2012-03-20 | 10 | -880/+238 | |
| | | | ||||||
| | * | Added missing auth_method_t enum names | Martin Willi | 2012-03-20 | 1 | -1/+9 | |
| | | | ||||||
| | * | Defined hybrid IKEv1 authentication methods | Martin Willi | 2012-03-20 | 1 | -0/+10 | |
| | | | ||||||
| | * | Some notification errors added to main_mode process_r | Clavister OpenSource | 2012-03-20 | 1 | -4/+58 | |
| | | | ||||||
| | * | Added possibility to send notification if task_manager->process fails | Clavister OpenSource | 2012-03-20 | 1 | -52/+68 | |
| | | | ||||||
| | * | Handling of initial contact | Clavister OpenSource | 2012-03-20 | 3 | -0/+67 | |
| | | | ||||||
| | * | Added retransmissions for initiator. | Clavister OpenSource | 2012-03-20 | 1 | -10/+23 | |
| | | | ||||||
| | * | Cleaned up quick mode notify processing | Martin Willi | 2012-03-20 | 1 | -21/+33 | |
| | | | ||||||
| | * | Add support for KE payloads in IKEv1 quick mode (PFS) | Martin Willi | 2012-03-20 | 1 | -5/+82 | |
| | | | ||||||
| | * | Use authenticators in IKEv1 main mode | Martin Willi | 2012-03-20 | 1 | -247/+28 | |
| | | | ||||||
| | * | Added a factory function for IKEv1 authenticators | Martin Willi | 2012-03-20 | 2 | -2/+42 | |
| | | | ||||||
| | * | Implemented IKEv1 pubkey SIG payload processing in an authenticator | Martin Willi | 2012-03-20 | 2 | -0/+259 | |
| | | | ||||||
| | * | Implemented IKEv1 PSK HASH payload processing in separated authenticator | Martin Willi | 2012-03-20 | 2 | -0/+198 | |
| | | | ||||||
| | * | Handle incoming delete messages | Clavister OpenSource | 2012-03-20 | 3 | -6/+43 | |
| | | | ||||||
| | * | Implemented post-authentication certificate handling for IKEv1 | Martin Willi | 2012-03-20 | 4 | -1/+406 | |
| | | | ||||||
| | * | Cleanup CERT payload constructors | Martin Willi | 2012-03-20 | 1 | -5/+5 | |
| | | | ||||||
| | * | Implemented pre-authentication certificate handling for IKEv1 | Martin Willi | 2012-03-20 | 4 | -4/+576 | |
| | | | ||||||
| | * | Added task types for IKEv1 certificate handling | Martin Willi | 2012-03-20 | 2 | -0/+8 | |
| | | | ||||||
| | * | Reverted ike_cert tasks to IKEv2 only, we use dedicated IKEv1 tasks | Martin Willi | 2012-03-20 | 2 | -497/+41 | |
| | | | ||||||
| | * | Install SAs with UDP encapsulation during Quick Mode. | Tobias Brunner | 2012-03-20 | 1 | -16/+9 | |
| | | | ||||||
| | * | Fix support for plain RSA authentication in IKEv1, both as initiator and ↵ | Martin Willi | 2012-03-20 | 2 | -30/+39 | |
| | | | | | | | | | | | | responder | |||||
| | * | Fix referencing of multiple CERTREQ payload with IKEv1, other cleanups | Martin Willi | 2012-03-20 | 1 | -60/+53 | |
| | | | ||||||
| | * | XAUTH additions for certificates. | Clavister OpenSource | 2012-03-20 | 1 | -6/+17 | |
| | | | ||||||
| | * | signature payload handling. | Clavister OpenSource | 2012-03-20 | 1 | -10/+188 | |
| | | | ||||||
| | * | certificate tasks added to passive list for responder | Clavister OpenSource | 2012-03-20 | 1 | -0/+6 | |
| | | | ||||||
| | * | certificate handling for XAuth responder. | Clavister OpenSource | 2012-03-20 | 2 | -43/+506 | |
| | | | ||||||
| | * | keymat: derive_ike_keys updated with XAUTH RSA:s | Clavister OpenSource | 2012-03-20 | 1 | -1/+7 | |
| | | | ||||||
| | * | IKEv1: Added basic support for INFORMATIONAL exchange types, and for ↵ | Clavister OpenSource | 2012-03-20 | 2 | -2/+69 | |
| | | | | | | | | | | | | NOTIFY_V1 messages in the 3rd message in quick_mode. | |||||
| | * | Don't stop processing tasks if one returns SUCCESS. | Tobias Brunner | 2012-03-20 | 1 | -3/+8 | |
| | | | | | | | | | | | | Only send a response if at least one of the tasks requires it. | |||||
| | * | IKEv1 XAuth: Added a "NULL" XAuth plugin which sends a hardcoded user/pass, ↵ | Clavister OpenSource | 2012-03-20 | 2 | -17/+38 | |
| | | | | | | | | | | | | and blindly accepts whatever user/pass is sent it. Changed the xauth_request task to use this new plugin. Add --enable-xauth-null to your configure line to build with the new plugin. | |||||
| | * | IKEv1 XAuth: Added plugin support for XAuth, which allows us to have plugins ↵ | Clavister OpenSource | 2012-03-20 | 6 | -0/+647 | |
| | | | | | | | | | | | | to talk to servers with different quirks for XAuth authentication. | |||||
| | * | Add NAT-OA payloads during Quick Mode if transport mode is used. | Tobias Brunner | 2012-03-20 | 1 | -2/+44 | |
| | | | | | | | | | | | | | | | We don't parse them currently, as the Linux kernel does not need them to fix the IP header checksum. | |||||
| | * | Negotiate UDP encapsulation during Quick Mode if NAT is detected. | Tobias Brunner | 2012-03-20 | 1 | -2/+14 | |
| | | | ||||||
| | * | Task added for IKEv1 NAT detection. | Tobias Brunner | 2012-03-20 | 6 | -2/+502 | |
| | | | | | | | | | | | | There is already support for both Main and Aggressive Mode. |