aboutsummaryrefslogtreecommitdiffstats
path: root/src/libcharon
Commit message (Expand)AuthorAgeFilesLines
...
* make maximum PB-TNC batch size configurableAndreas Steffen2012-07-111-2/+11
* limit the size of a PB-TNC batch to the maximum EAP-TNC packet sizeAndreas Steffen2012-07-1110-88/+134
* eliminate message length field in EAP-TNCAndreas Steffen2012-07-112-2/+2
* due to single fragment, total length does not have to be includedAndreas Steffen2012-07-111-3/+1
* EAP-TNC does not support fragmentationAndreas Steffen2012-07-111-12/+14
* Send cert request based on peers configured authentication classMartin Willi2012-07-101-3/+30
* Don't send CERTREQs when initiating aggressive mode PSKMartin Willi2012-07-091-0/+4
* Refactored heavily #ifdefd capability code to its own libstrongswan classMartin Willi2012-07-0410-123/+19
* Use spin locks to update IKE_SAs in controller_tTobias Brunner2012-07-041-4/+38
* Fixed job handling in controller_tTobias Brunner2012-07-041-110/+128
* As a responder, don't start a TRANSACTION request if we expect one from the i...Martin Willi2012-06-292-2/+4
* IMCs and IMVs might depend on X.509 certificates or trusted public keysAndreas Steffen2012-06-282-0/+4
* Show some uname() info in "ipsec statusall"Martin Willi2012-06-281-3/+10
* libcharon also requires kernel interfaces and a socket implementationTobias Brunner2012-06-271-0/+3
* Defer quick mode initiation if we expect a mode config requestMartin Willi2012-06-271-1/+20
* Queue a mode config task as responder if we need a virtual IPMartin Willi2012-06-272-4/+16
* Add basic support for XAuth responder authenticationMartin Willi2012-06-272-8/+10
* Map XAuth responder authentication methods between IKEv1 and IKEv2Martin Willi2012-06-271-1/+13
* Show remote EAP/XAuth identity in "statusall" on a separate lineMartin Willi2012-06-271-1/+12
* Use static plugin features in libcharon to define essential dependenciesTobias Brunner2012-06-271-1/+10
* Ignore a received %any virtual IP for installationMartin Willi2012-06-261-1/+2
* Also build charon's IKEv1 implementation on AndroidTobias Brunner2012-06-261-0/+23
* Missing source file added to libcharon's Android.mkTobias Brunner2012-06-261-0/+1
* Make rescheduling a job more predictableTobias Brunner2012-06-252-12/+5
* Centralized thread cancellation in processor_tTobias Brunner2012-06-2518-182/+97
* Give processor_t more control over the lifecycle of a jobTobias Brunner2012-06-2520-64/+60
* support Cisco Unity VIDAndreas Steffen2012-06-252-3/+11
* Enforce uniqueids=keep based on XAuth identityMartin Willi2012-06-251-0/+6
* Don't send XAUTH_OK if a hook prevents SA to establishMartin Willi2012-06-251-4/+14
* Enforce uniqueids=keep only for non-XAuth Main/Agressive ModesMartin Willi2012-06-252-28/+28
* Show EAP/XAuth identity in "ipsec status", if availableMartin Willi2012-06-251-1/+1
* Use XAuth/EAP remote identity for uniqueness checkMartin Willi2012-06-253-4/+6
* Add missing XAuth name variable when complaining about missing XAuth backendMartin Willi2012-06-251-1/+1
* Fix SIGSEGV if kernel install fails during Quick Mode as responder.Tobias Brunner2012-06-221-4/+8
* Fixed compile error because of charon->name in certexpire plugin.Tobias Brunner2012-06-211-0/+1
* Select requested virtual IP family based on remote TS, if no local TS availableMartin Willi2012-06-201-1/+12
* Adopt children as XAuth initiator (which is IKE responder)Martin Willi2012-06-141-2/+2
* Show what kind of *Swan we run in "ipsec status"Martin Willi2012-06-141-3/+16
* Require a scary option to respond to Aggressive Mode PSK requestsMartin Willi2012-06-141-0/+17
* Use proper defines for IPV6_PKTINFO on Mac OS X Lion and newer.Tobias Brunner2012-06-131-0/+2
* Added signature scheme options left/rightauthMartin Willi2012-06-121-11/+99
* certificate_t->issued_by takes an argument to receive signature schemeMartin Willi2012-06-122-3/+3
* added missing parameter in get_my_addr() and get_other_addr() callsAndreas Steffen2012-06-091-2/+4
* implemented the right|leftallowany featureAndreas Steffen2012-06-0815-73/+131
* Enforce uniqueness policy in IKEv1 main and aggressive modesMartin Willi2012-06-082-0/+29
* Try to rekey without KE exchange if peer returns INVALID_KE_PAYLOAD(NONE)Martin Willi2012-06-081-1/+8
* While checking for redundant quick modes, compare traffic selectorsMartin Willi2012-06-081-0/+22
* Store shorter soft lifetime of in- and outbound SAs onlyMartin Willi2012-06-081-1/+8
* Initiate quick mode rekeying with narrowed traffic selectorsMartin Willi2012-06-081-1/+18
* Use traffic selectors passed to quick mode constructor as initiatorMartin Willi2012-06-081-2/+10