Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | Migrated notify_payload to INIT/METHOD macros | Martin Willi | 2011-01-05 | 1 | -121/+80 | |
| | ||||||
* | Migrated nonce_payload to INIT/METHOD macros | Martin Willi | 2011-01-05 | 1 | -92/+63 | |
| | ||||||
* | Migrated ke_payload to INIT/METHOD macros | Martin Willi | 2011-01-05 | 2 | -119/+61 | |
| | ||||||
* | Migrated id_payload to INIT/METHOD macros | Martin Willi | 2011-01-05 | 2 | -187/+65 | |
| | ||||||
* | Migrated cp_payload to INIT/METHOD macros | Martin Willi | 2011-01-05 | 1 | -91/+65 | |
| | ||||||
* | Migrated configuration_attribute to INIT/METHOD macros | Martin Willi | 2011-01-05 | 1 | -60/+39 | |
| | ||||||
* | Migrated certreq_payload to INIT/METHOD macros | Martin Willi | 2011-01-05 | 1 | -88/+66 | |
| | ||||||
* | Migrated cert_payload to INIT/METHOD macros | Martin Willi | 2011-01-05 | 1 | -95/+68 | |
| | ||||||
* | Migrated auth_payload to INIT/METHOD macros | Martin Willi | 2011-01-05 | 2 | -137/+69 | |
| | ||||||
* | Moved generic infrastructure initialization to libcharon_init(), allows us ↵ | Martin Willi | 2011-01-05 | 1 | -11/+9 | |
| | | | | to preload plugins | |||||
* | Do not update payload length during generation, allows hooks override ↵ | Martin Willi | 2011-01-05 | 8 | -58/+12 | |
| | | | | payload length | |||||
* | Do not recalculate payload header length after generation, payloads do ↵ | Martin Willi | 2011-01-05 | 1 | -291/+19 | |
| | | | | length calculation | |||||
* | Apply IKE major/minor version set on message to IKE header | Martin Willi | 2011-01-05 | 1 | -0/+4 | |
| | ||||||
* | Added setters for IKE major/minor version to ike_header | Martin Willi | 2011-01-05 | 2 | -0/+28 | |
| | ||||||
* | Migrated ike_header_t to INIT/METHOD macros | Martin Willi | 2011-01-05 | 1 | -165/+114 | |
| | ||||||
* | Fixed length calculation of unknown payload | Martin Willi | 2011-01-05 | 1 | -0/+5 | |
| | ||||||
* | Move critical bit checking to ike_sa, notify payload includes unsupported ↵ | Martin Willi | 2011-01-05 | 5 | -26/+62 | |
| | | | | payload type | |||||
* | Handle all error notifies in CREATE_CHILD_SA exchanges | Martin Willi | 2011-01-05 | 1 | -0/+14 | |
| | ||||||
* | Support encoding of UKNOWN_DATA | Martin Willi | 2011-01-05 | 1 | -0/+4 | |
| | ||||||
* | Moved our substructure identifiers above 255, ignore private payloads properly | Martin Willi | 2011-01-05 | 1 | -6/+6 | |
| | ||||||
* | Check for exceeded payload count even if we have a found one flagged as ↵ | Martin Willi | 2011-01-05 | 1 | -3/+4 | |
| | | | | sufficient | |||||
* | Added a constructor for custom uknown payloads | Martin Willi | 2011-01-05 | 2 | -2/+29 | |
| | ||||||
* | Use the payloads actual type in unknown_payload_t | Martin Willi | 2011-01-05 | 6 | -40/+53 | |
| | ||||||
* | Migrated unknown payload to INIT/METHOD macros | Martin Willi | 2011-01-05 | 1 | -80/+54 | |
| | ||||||
* | Ingore messages with exchange type altered to UNDEFINED in message() hook | Martin Willi | 2011-01-05 | 1 | -0/+8 | |
| | ||||||
* | Fail silently without INVALID_SYNTAX if message not verified | Martin Willi | 2011-01-05 | 1 | -10/+8 | |
| | ||||||
* | Moved message()-hook invocation to generate_message(), catch pre-generated ↵ | Martin Willi | 2011-01-05 | 2 | -2/+1 | |
| | | | | IKE_SA_INITs, too | |||||
* | Support removal of payloads from messages | Martin Willi | 2011-01-05 | 2 | -0/+14 | |
| | ||||||
* | Added a message_t option to disable automatic payload sorting | Martin Willi | 2011-01-05 | 2 | -1/+21 | |
| | ||||||
* | Implemented cert payload constructor for custom encoding types | Martin Willi | 2011-01-05 | 2 | -0/+21 | |
| | ||||||
* | Support manually triggerd DPD check, even if DPD disabled in config | Martin Willi | 2011-01-05 | 1 | -11/+10 | |
| | ||||||
* | Moved logger initialization from libcharon to charon | Martin Willi | 2011-01-05 | 2 | -155/+13 | |
| | ||||||
* | removed superfluous s | Andreas Steffen | 2011-01-05 | 8 | -8/+8 | |
| | ||||||
* | remove private_ | Andreas Steffen | 2011-01-05 | 1 | -1/+1 | |
| | ||||||
* | remove private_ | Andreas Steffen | 2011-01-05 | 4 | -4/+4 | |
| | ||||||
* | cosmetics in debug output | Andreas Steffen | 2011-01-05 | 1 | -1/+1 | |
| | ||||||
* | detect fragmentation of PB-TNC batch | Andreas Steffen | 2011-01-05 | 1 | -4/+11 | |
| | ||||||
* | fixed typo | Andreas Steffen | 2011-01-02 | 1 | -2/+2 | |
| | ||||||
* | set tfcv3 flag TRUE in ha_dispatcher | Andreas Steffen | 2010-12-26 | 1 | -4/+4 | |
| | ||||||
* | implemented wrap around of registered IKEv1 algorithm names | Andreas Steffen | 2010-12-26 | 1 | -3/+1 | |
| | ||||||
* | wrap list of IKEv2 algorithms after 120 characters per line | Andreas Steffen | 2010-12-24 | 1 | -20/+43 | |
| | ||||||
* | Migrated stroke_list_t to INIT/METHOD macros | Andreas Steffen | 2010-12-24 | 1 | -25/+21 | |
| | ||||||
* | eliminated whitespace | Andreas Steffen | 2010-12-21 | 1 | -1/+1 | |
| | ||||||
* | Migrated child_create_t to INIT/METHOD macros | Andreas Steffen | 2010-12-21 | 1 | -83/+55 | |
| | ||||||
* | Added a tfc ipsec.conf keyword to control Traffic Flow Confidentiality | Martin Willi | 2010-12-20 | 1 | -1/+1 | |
| | ||||||
* | Do not use TFC padding if peer does not support ESPv3 | Martin Willi | 2010-12-20 | 3 | -11/+31 | |
| | ||||||
* | Added a TFC padding option to child_cfg | Martin Willi | 2010-12-20 | 12 | -12/+36 | |
| | ||||||
* | Implemented Traffic Flow Confidentiality padding in kernel_interface | Martin Willi | 2010-12-20 | 2 | -2/+3 | |
| | ||||||
* | trace back crypto algorithms to the plugins that registered them | Andreas Steffen | 2010-12-18 | 3 | -17/+35 | |
| | ||||||
* | Install selectors on transport mode IPsec SAs. | Jiri Bohac | 2010-12-13 | 1 | -1/+1 | |
| | | | | | | | | | | | | | | | | This fixes several test cases in IKEv2_Self_Test (part of the IPv6 Ready Logo Program) which is required for USGv6 certification, namely: - IKEv2.EN.I.1.1.7.1, IKEv2.EN.I.1.1.7.1: Narrowing the range of members of the set of traffic selectors - IKEv2.EN.R.1.1.7.3: Narrowing multiple traffic selector When traffic selectors of a triggered SA are narrowed by the responder, the installed policy and the broader trap policy share the same reqid. Without selectors on the IPsec SA packets matching the trap policy, but not the narrowed policy, would incorrectly be handled by that IPsec SA. Since only one selector can be specified per IPsec SA, there is currently no solution for tunnel mode SAs. |