Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | support of xfrm marks for IKEv2 | Andreas Steffen | 2010-07-02 | 17 | -149/+483 | |
| | ||||||
* | Recreate IKE_SA_INIT related tasks only if they have completed | Martin Willi | 2010-06-30 | 1 | -11/+35 | |
| | ||||||
* | Use enumerator for queued_tasks migration to avoid infinite loop | Thomas Egerer | 2010-06-30 | 1 | -3/+5 | |
| | ||||||
* | Correct check of traffic selectors before destruction | Thomas Egerer | 2010-06-29 | 1 | -2/+2 | |
| | ||||||
* | Migrate queued_tasks tasks, to avoid dangling pointers | Thomas Egerer | 2010-06-29 | 1 | -0/+7 | |
| | ||||||
* | The signature of keystore_get changed again. | Tobias Brunner | 2010-06-28 | 1 | -1/+3 | |
| | | | | | With Android 2.2 (Froyo) the interface of keystore_get was changed once again. The change was made to allow the keys to contain \0 characters. | |||||
* | Compiler warning fixed. | Tobias Brunner | 2010-06-28 | 1 | -1/+3 | |
| | ||||||
* | Show contents of the CP payload in message_t stringification | Martin Willi | 2010-06-24 | 1 | -0/+34 | |
| | ||||||
* | Increased the loglevel for the arguments received via Android control socket. | Tobias Brunner | 2010-06-24 | 1 | -1/+1 | |
| | ||||||
* | Terminate charon from the Android plugin if the tunnel goes down after it ↵ | Tobias Brunner | 2010-06-24 | 1 | -0/+24 | |
| | | | | was initiated successfully. | |||||
* | Initiate the tunnel in the Android plugin asynchronously. | Tobias Brunner | 2010-06-24 | 1 | -6/+39 | |
| | | | | Also track its initiation using the registered listener. | |||||
* | Implement the listener_t interface in the Android plugin to track the status ↵ | Tobias Brunner | 2010-06-24 | 2 | -2/+47 | |
| | | | | of an SA. | |||||
* | Helper function added to notify the Android frontend about status changes. | Tobias Brunner | 2010-06-24 | 1 | -4/+14 | |
| | ||||||
* | Initiate consumes a child_sa reference, so get an additional one. | Tobias Brunner | 2010-06-24 | 1 | -0/+2 | |
| | ||||||
* | Use the same error code constants as in the Java frontend. | Tobias Brunner | 2010-06-24 | 1 | -1/+15 | |
| | ||||||
* | Flush and destroy the send queue before unloading the socket plugins. | Tobias Brunner | 2010-06-24 | 1 | -1/+1 | |
| | ||||||
* | Do not install routes in the PF_KEY kernel interface if interface lookup failed. | Tobias Brunner | 2010-06-23 | 1 | -15/+23 | |
| | ||||||
* | The signature of keystore_get was changed with Android 2.x. | Tobias Brunner | 2010-06-22 | 1 | -2/+12 | |
| | ||||||
* | Avoid a segmentation fault if opening the Android control socket failed. | Tobias Brunner | 2010-06-22 | 1 | -1/+1 | |
| | ||||||
* | Allow to enable the kernel-pfkey plugin via Android.mk. | Tobias Brunner | 2010-06-22 | 1 | -0/+2 | |
| | ||||||
* | Fixing the PF_KEY kernel interface on Android. | Tobias Brunner | 2010-06-22 | 1 | -0/+2 | |
| | | | | In Android's in.h IPPROTO_COMP is not #defined but just an enum member. | |||||
* | Accept IKE packets with any minor version in RAW socket | Martin Willi | 2010-06-22 | 1 | -6/+8 | |
| | ||||||
* | Fixed plugin checks in Android.mk files. | Tobias Brunner | 2010-06-22 | 1 | -2/+2 | |
| | ||||||
* | Use vpn.dns* to store DNS servers (Android manages net.dns* using these). | Tobias Brunner | 2010-06-15 | 1 | -2/+2 | |
| | ||||||
* | Adding an interface that interacts with the Android Settings frontend. | Tobias Brunner | 2010-06-15 | 4 | -0/+326 | |
| | ||||||
* | Adding an Android specific credential set. | Tobias Brunner | 2010-06-15 | 5 | -1/+369 | |
| | ||||||
* | Adding an Android specific logger. | Tobias Brunner | 2010-06-15 | 4 | -3/+163 | |
| | ||||||
* | Adding support for the native Linux capabilities interface. | Tobias Brunner | 2010-06-15 | 1 | -8/+31 | |
| | | | | | Note that this interface is deprecated and mainly added to support Android. Use libcap, if possible. | |||||
* | Explicitly refer to LIBCAP in Makefiles. | Tobias Brunner | 2010-06-15 | 1 | -1/+1 | |
| | ||||||
* | Explicitly include stdint.h for UINT64_MAX. | Tobias Brunner | 2010-06-15 | 1 | -0/+2 | |
| | | | | This is required on FreeBSD 8. | |||||
* | Check for SADB_X_NAT_T_NEW_MAPPING in PF_KEY kernel interface. | Tobias Brunner | 2010-06-15 | 1 | -4/+4 | |
| | | | | | FreeBSD 8 does not support SADB_X_NAT_T_NEW_MAPPING whereas Linux and the previous FreeBSD NAT-T patch both do. | |||||
* | Set the ports of all hosts installed via the PF_KEY kernel interface to zero. | Tobias Brunner | 2010-06-15 | 1 | -15/+37 | |
| | ||||||
* | Adding a basic unit test for hashtable_t. | Tobias Brunner | 2010-06-07 | 3 | -1/+114 | |
| | ||||||
* | Add extra information in debug output for IKE_SA check{out, in} | Thomas Egerer | 2010-06-07 | 2 | -10/+27 | |
| | | | | | | | This output helps tracing checkout and checkin of IKE_SAs when there is more than one IKE_SAs with the same name. I also added the type of in-air-exchange to the debug output issued by the task_manager in case a task initiation is delayed, came in handy for me. | |||||
* | traffic_selector_t is gone into libstrongswan, migrate printf hook ↵ | Martin Willi | 2010-06-07 | 1 | -5/+0 | |
| | | | | registration, too. | |||||
* | Flush auth configs, create new keymat during SA reset | Martin Willi | 2010-06-07 | 1 | -12/+16 | |
| | ||||||
* | Recreate IKE_INIT/IKE_NATD/IKE_VENDOR tasks if we reset SA during IKE_AUTH | Martin Willi | 2010-06-07 | 1 | -0/+11 | |
| | ||||||
* | Reacquire keymat from new IKE_SA during task migration | Martin Willi | 2010-06-07 | 1 | -0/+1 | |
| | ||||||
* | Flush certificate cache on CA delete | Martin Willi | 2010-06-07 | 1 | -1/+2 | |
| | ||||||
* | Log non-empty task queues in statusall | Martin Willi | 2010-06-07 | 1 | -0/+31 | |
| | ||||||
* | Wrap task enumerator in ike_sa | Martin Willi | 2010-06-07 | 2 | -1/+16 | |
| | ||||||
* | Migrated ike_sa_t to INIT/METHOD macros | Martin Willi | 2010-06-07 | 1 | -407/+239 | |
| | ||||||
* | Added support for task enumeration in task_manager_t | Martin Willi | 2010-06-07 | 2 | -0/+38 | |
| | ||||||
* | Migrated task_manager_t to INIT/METHOD macros | Martin Willi | 2010-06-07 | 1 | -65/+45 | |
| | ||||||
* | Accept ARP requests with an ethernet trailer, but trim it | Martin Willi | 2010-06-03 | 1 | -2/+2 | |
| | ||||||
* | Added a EAP-SIM/AKA backend reading triplets/quintuplets from a SQL database | Martin Willi | 2010-06-02 | 11 | -0/+682 | |
| | ||||||
* | Disable close action for a redundant CHILD_SA resulting from a rekey collision | Martin Willi | 2010-06-02 | 1 | -0/+5 | |
| | | | | | | | | If a rekey collision is detected, the winning peer of the nonce compare will delete the redundant CHILD_SA. The other peer should not enforce the close action on this CHILD, as it would reestablish the redundat CHILD_SA. Thanks to Thomas Egerer from secunet for pointing this out and the initial patchset. | |||||
* | Use wrapped getters for close/dpd action | Martin Willi | 2010-06-02 | 2 | -8/+10 | |
| | ||||||
* | Wrap getters for dpd/close action into CHILD_SA, allows us to override them | Martin Willi | 2010-06-02 | 2 | -0/+76 | |
| | ||||||
* | Do not install trap policy if remote host is %any. | Tobias Brunner | 2010-05-28 | 1 | -1/+1 | |
| |