aboutsummaryrefslogtreecommitdiffstats
path: root/src/libcharon
Commit message (Expand)AuthorAgeFilesLines
* treat EAP identities as user IDsAndreas Steffen2013-02-121-3/+3
* make TNC client authentication type available to IMVsAndreas Steffen2013-02-129-27/+204
* determine underlying IF-T transport protocolAndreas Steffen2013-02-1210-62/+184
* make AR identities available to IMVs via IF-IMV 1.4 draftAndreas Steffen2013-02-115-0/+146
* Make IKE/EAP IDs available to TNC server/clientAndreas Steffen2013-02-118-24/+81
* Allow more than one CERTREQ payload for IKEv2Tobias Brunner2013-02-081-2/+2
* Use proper buffer sizes for parse_smartcard()Tobias Brunner2013-01-241-7/+10
* Removed unused command name when printing usage info for lookipTobias Brunner2013-01-241-1/+1
* Fix check-in of IKE_SA when IKE_SA_INIT fails and hash table is enabledTobias Brunner2013-01-241-2/+13
* Avoid a deadlock when installing a trap policy failedTobias Brunner2013-01-231-1/+5
* Fix IKE SA inherit API docAdrian-Ken Rueegsegger2013-01-221-2/+1
* Filter TS list for Split-Includes before printing them to debug logMartin Willi2013-01-211-10/+34
* Properly send IKEv1 packets if no ike_cfg is known yetTobias Brunner2013-01-141-2/+5
* Don't handle right=%any6 as "loose" identity, but as %anyMartin Willi2013-01-141-2/+1
* Merge branch 'ikev1-fragmentation'Tobias Brunner2013-01-1225-55/+832
|\
| * Added an option to configure the maximum size of a fragmentTobias Brunner2013-01-121-3/+10
| * Properly detect fragmentation capabilitiesTobias Brunner2013-01-121-3/+27
| * Added an option that allows to force IKEv1 fragmentationTobias Brunner2013-01-1212-19/+43
| * Use a connection specific option to en-/disable IKEv1 fragmentationTobias Brunner2012-12-2413-25/+47
| * Include source port in init hash for fragmented messagesTobias Brunner2012-12-241-1/+8
| * Add an option to en-/disable IKE fragmentationTobias Brunner2012-12-242-5/+20
| * Split larger messages into fragments if IKE fragmentation is supported by peerTobias Brunner2012-12-241-14/+114
| * Log message size for in- and outbound IKE messagesTobias Brunner2012-12-242-4/+7
| * Add support to create IKE fragmentsTobias Brunner2012-12-242-0/+30
| * Log added NAT-T vendor IDsTobias Brunner2012-12-241-0/+1
| * Detect a peer's support for IKE fragmentationTobias Brunner2012-12-242-0/+9
| * Map fragmented initial initial Main or Aggressive Mode messages to the same I...Tobias Brunner2012-12-241-1/+17
| * Allow ID_PROT/AGGRESSIVE messages for established IKE_SAs if they contain fra...Tobias Brunner2012-12-241-1/+2
| * Don't handle fragmented messages larger than charon.max_packetTobias Brunner2012-12-241-4/+39
| * Don't update an IKE_SA-entry's cached message ID when handling fragmentsTobias Brunner2012-12-241-1/+4
| * Store inbound IKE fragments and reassemble the message when all fragments are...Tobias Brunner2012-12-241-3/+166
| * Add message rules to properly handle IKE fragmentsTobias Brunner2012-12-241-0/+8
| * Reset the encrypted flag when handling IKE messages that contain a fragmentTobias Brunner2012-12-241-0/+6
| * Payload added to handle IKE fragmentsTobias Brunner2012-12-246-11/+314
* | Don't use bio_writer_t.skip() to write length field when appending more dataMartin Willi2013-01-111-4/+4
* | Streamline debug output when receiving intermediate CA certificates in IKEv1Martin Willi2013-01-111-1/+1
* | Refactored IKEv2 cert/certreq payload processing to multiple functionsMartin Willi2013-01-111-112/+141
* | Refactored IKEv1 cert payload processing to multiple functionsMartin Willi2013-01-111-73/+102
* | IKEv1 support for PKCS#7 wrapped certificatesVolker Rümelin2013-01-113-0/+96
* | Fixed some typos in commentsVolker Rümelin2013-01-114-6/+6
|/
* Add parantheses to avoid compiler warningMartin Willi2012-12-241-1/+1
* Send empty CDATA batch if TNC client has no data to sendAndreas Steffen2012-12-231-16/+28
* Fixed some typos, courtesy of codespellTobias Brunner2012-12-207-7/+7
* Raise an alert if IKE SA is keptAdrian-Ken Rueegsegger2012-12-202-0/+3
* Add support for draft-ietf-ipsec-nat-t-ike-03 and earlierVolker Rümelin2012-12-1914-90/+311
* Add missing error_notify_msg.h to distribution tarballMartin Willi2012-12-191-1/+2
* Add an error-notify sample application to listen to error notificationsMartin Willi2012-12-193-0/+66
* Add an error-notify plugin to send catched alerts to listening applicationsMartin Willi2012-12-199-0/+743
* Raise an alert if half-open timeout limit reachedMartin Willi2012-12-192-0/+3
* Raise an alert if an authorize() hook failsMartin Willi2012-12-192-0/+6