aboutsummaryrefslogtreecommitdiffstats
path: root/src/libcharon/sa
Commit message (Expand)AuthorAgeFilesLines
...
* | | Merge branch 'ikev1-mm-retransmits'Martin Willi2013-03-014-45/+55
|\ \ \
| * | | For IKEv1 Main Mode, use message hash to detect early retransmissionsMartin Willi2013-02-251-10/+23
| * | | Move initial message dropping to task managerMartin Willi2013-02-253-19/+27
| * | | Use INIT macro to initialize IKE_SA manager entriesMartin Willi2013-02-251-17/+6
| | |/ | |/|
* | | Merge branch 'tfc-notify'Martin Willi2013-03-011-0/+9
|\ \ \
| * | | Send ESP_TFC_PADDING_NOT_SUPPORTED if the used kernel doesn't support itMartin Willi2013-03-011-0/+9
| | |/ | |/|
* | | Trigger an updown event when destroying an IKE_SA based on INITIAL_CONTACTTobias Brunner2013-02-281-0/+1
| |/ |/|
* | Add a global return_success() method implementationMartin Willi2013-02-141-8/+2
* | Merge branch 'ike-dscp'Martin Willi2013-02-141-1/+26
|\ \
| * | Set configured DSCP value while generating IKE packetsMartin Willi2013-02-061-1/+26
| |/
* / make TNC client authentication type available to IMVsAndreas Steffen2013-02-121-0/+57
|/
* Fix check-in of IKE_SA when IKE_SA_INIT fails and hash table is enabledTobias Brunner2013-01-241-2/+13
* Avoid a deadlock when installing a trap policy failedTobias Brunner2013-01-231-1/+5
* Fix IKE SA inherit API docAdrian-Ken Rueegsegger2013-01-221-2/+1
* Properly send IKEv1 packets if no ike_cfg is known yetTobias Brunner2013-01-141-2/+5
* Merge branch 'ikev1-fragmentation'Tobias Brunner2013-01-125-25/+406
|\
| * Added an option to configure the maximum size of a fragmentTobias Brunner2013-01-121-3/+10
| * Properly detect fragmentation capabilitiesTobias Brunner2013-01-121-3/+27
| * Added an option that allows to force IKEv1 fragmentationTobias Brunner2013-01-122-3/+6
| * Use a connection specific option to en-/disable IKEv1 fragmentationTobias Brunner2012-12-242-10/+7
| * Include source port in init hash for fragmented messagesTobias Brunner2012-12-241-1/+8
| * Add an option to en-/disable IKE fragmentationTobias Brunner2012-12-242-5/+20
| * Split larger messages into fragments if IKE fragmentation is supported by peerTobias Brunner2012-12-241-14/+114
| * Log added NAT-T vendor IDsTobias Brunner2012-12-241-0/+1
| * Detect a peer's support for IKE fragmentationTobias Brunner2012-12-242-0/+9
| * Map fragmented initial initial Main or Aggressive Mode messages to the same I...Tobias Brunner2012-12-241-1/+17
| * Allow ID_PROT/AGGRESSIVE messages for established IKE_SAs if they contain fra...Tobias Brunner2012-12-241-1/+2
| * Don't handle fragmented messages larger than charon.max_packetTobias Brunner2012-12-241-4/+39
| * Don't update an IKE_SA-entry's cached message ID when handling fragmentsTobias Brunner2012-12-241-1/+4
| * Store inbound IKE fragments and reassemble the message when all fragments are...Tobias Brunner2012-12-241-3/+166
* | Streamline debug output when receiving intermediate CA certificates in IKEv1Martin Willi2013-01-111-1/+1
* | Refactored IKEv2 cert/certreq payload processing to multiple functionsMartin Willi2013-01-111-112/+141
* | Refactored IKEv1 cert payload processing to multiple functionsMartin Willi2013-01-111-73/+102
* | IKEv1 support for PKCS#7 wrapped certificatesVolker Rümelin2013-01-111-0/+70
* | Fixed some typos in commentsVolker Rümelin2013-01-111-1/+1
|/
* Add parantheses to avoid compiler warningMartin Willi2012-12-241-1/+1
* Fixed some typos, courtesy of codespellTobias Brunner2012-12-203-3/+3
* Raise an alert if IKE SA is keptAdrian-Ken Rueegsegger2012-12-201-0/+1
* Add support for draft-ietf-ipsec-nat-t-ike-03 and earlierVolker Rümelin2012-12-196-36/+211
* Raise an alert if allocating virtual IPs failsMartin Willi2012-12-191-0/+2
* Raise an alert if kernel policy installation failsMartin Willi2012-12-191-0/+2
* Raise an alert if kernel SA installation failsMartin Willi2012-12-191-0/+2
* Raise an alert on traffic selector mismatchMartin Willi2012-12-191-0/+2
* Raise alerts when enforcing IKE_SA unique policyMartin Willi2012-12-192-0/+2
* Raise an alert if CHILD_SA proposals mismatchMartin Willi2012-12-191-0/+2
* Raise an alert if IKE proposals mismatchMartin Willi2012-12-191-0/+5
* Raise an alert of generating local authentication data failsMartin Willi2012-12-191-6/+10
* Fix traffic selectors also as initiator in case of transport mode over NATTobias Brunner2012-12-131-1/+1
* Fix debug output if responder selected invalid traffic selectors during QMTobias Brunner2012-12-131-2/+2
* Inherit virtual IP and attributes from old to new, not from new to oldMartin Willi2012-12-101-5/+5