Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | Resolve hosts by DNS name in separate threads so we can cancel them | Tobias Brunner | 2012-10-18 | 1 | -1/+2 | |
| | | | | | | | | | | getaddrinfo(3) may block a long time so proper termination of the daemon may block if DNS servers are not reachable. getaddrinfo(3) is an optional cancellation point in posix threads so it might still block a shutdown but at least on Android (with the signal based pthread_cancel implementation) it works, on Linux starter will kill charon anyway after a while. | |||||
* | Added a new alert that is raised if peer does not respond to initial IKE message | Tobias Brunner | 2012-10-16 | 2 | -0/+4 | |
| | ||||||
* | Remove unused this parameter to load_issuer_cert/key(), as it is uninitialized | Martin Willi | 2012-10-16 | 1 | -4/+4 | |
| | ||||||
* | Generate a load-tester certificate only for DN or subjectAltName identities | Martin Willi | 2012-10-16 | 1 | -7/+17 | |
| | ||||||
* | Add a load-tester initiator_match option to match custom initiator_id | Martin Willi | 2012-10-16 | 1 | -2/+15 | |
| | ||||||
* | Encode non-DN load-tester identities as subjectAltNames | Martin Willi | 2012-10-16 | 1 | -1/+16 | |
| | ||||||
* | Add a load-tester digest option for issuing peer certificates | Martin Willi | 2012-10-16 | 1 | -1/+16 | |
| | ||||||
* | Load a multiple load-tester CA certificates from a directory | Martin Willi | 2012-10-16 | 1 | -4/+63 | |
| | ||||||
* | Added load-tester options to read issuing CA certificate and key from files | Martin Willi | 2012-10-16 | 1 | -7/+45 | |
| | ||||||
* | Fixed compilation of android_handler_t | Tobias Brunner | 2012-10-11 | 1 | -0/+1 | |
| | ||||||
* | Fix leak of PINs from ipsec.secrets | Martin Willi | 2012-10-09 | 1 | -1/+2 | |
| | ||||||
* | allow has_noskip_flag to contain TRUE_OR_FALSE | Andreas Steffen | 2012-10-07 | 1 | -1/+1 | |
| | ||||||
* | test first and up in the outer while loop | Andreas Steffen | 2012-10-07 | 1 | -5/+1 | |
| | ||||||
* | Ensure UNSUPPORTED_CRITICAL_PAYLOAD notify contains correct payload type | Tobias Brunner | 2012-09-28 | 1 | -0/+1 | |
| | ||||||
* | Missed one in 6c10cece | Tobias Brunner | 2012-09-28 | 1 | -0/+2 | |
| | ||||||
* | Request is never NULL when responding with an INFORMATIONAL message | Tobias Brunner | 2012-09-28 | 1 | -1/+1 | |
| | ||||||
* | Completed state handling in isakmp_cert_pre | Tobias Brunner | 2012-09-28 | 1 | -0/+4 | |
| | | | | Should not be a problem, but makes static analyzers happy. | |||||
* | Added missing continue statement in ha socket error handling | Tobias Brunner | 2012-09-28 | 1 | -0/+1 | |
| | ||||||
* | Fixed snprintf check in tnc-ifmap plugin | Tobias Brunner | 2012-09-28 | 1 | -1/+1 | |
| | ||||||
* | Use %x to print uint32 as long ints are 64-bit long on x64 Linux | Tobias Brunner | 2012-09-28 | 1 | -1/+1 | |
| | ||||||
* | Make sure first argument is an int when using %.*s to print e.g. chunks | Tobias Brunner | 2012-09-28 | 6 | -21/+22 | |
| | ||||||
* | Avoid memory leak when sending RADIUS accounting start message failed | Tobias Brunner | 2012-09-28 | 1 | -1/+1 | |
| | ||||||
* | Correctly initialize payload length of encrypted payload | Tobias Brunner | 2012-09-28 | 1 | -1/+1 | |
| | ||||||
* | The eap argument of send_response is never NULL | Tobias Brunner | 2012-09-28 | 1 | -13/+11 | |
| | ||||||
* | Properly initialize sockaddr_in struct in fast and dhcp plugins | Tobias Brunner | 2012-09-28 | 1 | -4/+7 | |
| | ||||||
* | Clarified error message if enabling UDP decapsulation fails | Tobias Brunner | 2012-09-27 | 2 | -2/+4 | |
| | ||||||
* | IKE_AUTH_LIFETIME task is not defined if IKEv2 is disabled | Tobias Brunner | 2012-09-25 | 1 | -1/+4 | |
| | | | | Fixes #229. | |||||
* | Don't check interface of inbound message if interfaces are not filtered | Tobias Brunner | 2012-09-24 | 1 | -2/+3 | |
| | | | | | We don't have a proper kernel-net interface on Android yet, so the check for a usable interface does not work there. | |||||
* | Made IP address enumeration more flexible | Tobias Brunner | 2012-09-21 | 5 | -5/+5 | |
| | | | | Also added an option to enumerate addresses on ignored interfaces. | |||||
* | Drop packets received on ignored interfaces | Tobias Brunner | 2012-09-21 | 1 | -2/+12 | |
| | ||||||
* | Make it easy to check if an address is locally usable via changed ↵ | Tobias Brunner | 2012-09-21 | 2 | -18/+9 | |
| | | | | get_interface() method | |||||
* | Don't ignore loopback devices and allow addresses on them being enumerated | Tobias Brunner | 2012-09-21 | 5 | -7/+7 | |
| | ||||||
* | Make sure we propose a dynamic TS if we don't have hosts to derive a TS from | Tobias Brunner | 2012-09-21 | 1 | -10/+8 | |
| | | | | 7ee37114 removed this behavior. | |||||
* | As Unity responder, don't change the proposed TS at all, racoon doesn't like ↵ | Martin Willi | 2012-09-18 | 2 | -7/+8 | |
| | | | | that | |||||
* | Don't complain about multiple TS in IKEv1, as it supported with Unity | Martin Willi | 2012-09-18 | 1 | -5/+0 | |
| | ||||||
* | As initiator, narrow received Unity attributes to configured TS | Martin Willi | 2012-09-18 | 1 | -4/+11 | |
| | ||||||
* | When using Unity, bump up remote TS as initiator to 0.0.0.0/0, too | Martin Willi | 2012-09-18 | 1 | -5/+8 | |
| | ||||||
* | Enable Cisco Unity only if Unity vendor id received | Martin Willi | 2012-09-18 | 3 | -2/+5 | |
| | ||||||
* | Exchange 0.0.0.0/0 traffic selectors with Unity, narrowing after exchange | Martin Willi | 2012-09-18 | 1 | -22/+87 | |
| | ||||||
* | Add a Unity attribute provider that adds Split-Includes for TS | Martin Willi | 2012-09-18 | 4 | -1/+232 | |
| | ||||||
* | Check if subset calculation actually yields a TS in Unity narrowing | Martin Willi | 2012-09-18 | 1 | -1/+5 | |
| | ||||||
* | Request Unity configuration attributes for IKEv1 only | Martin Willi | 2012-09-18 | 1 | -0/+6 | |
| | ||||||
* | Add Cisco Unity client support for Split-Include and Local-LAN | Martin Willi | 2012-09-18 | 8 | -0/+781 | |
| | ||||||
* | Derive a dynamic TS to multiple virtual IPs | Martin Willi | 2012-09-18 | 8 | -118/+160 | |
| | ||||||
* | Use the vararg list constructor in quick mode task | Martin Willi | 2012-09-18 | 1 | -16/+8 | |
| | ||||||
* | Make stroke user-creds work with XAuth configs | Tobias Brunner | 2012-09-18 | 1 | -9/+18 | |
| | ||||||
* | Set AUTH_RULE_IDENTITY_LOOSE for rightid=%<identity> | Tobias Brunner | 2012-09-18 | 1 | -0/+10 | |
| | ||||||
* | Add AUTH_RULE_IDENTITY_LOOSE which allows to use IDr loosely as initiator | Tobias Brunner | 2012-09-18 | 1 | -1/+2 | |
| | | | | | | If it is set on an auth config IDr will not be sent, and later the configured identity will not only be checked against the returned IDr, but also against other identities contained in the responder's certificate. | |||||
* | Removed the unneeded socket-raw plugin | Tobias Brunner | 2012-09-14 | 7 | -885/+0 | |
| | ||||||
* | Change traffic selectors during Quick Mode in case of a NAT in transport mode | Tobias Brunner | 2012-09-14 | 1 | -9/+19 | |
| | | | | | | | | | Windows 7 sends its internal address as TSi. While we don't support the NAT-T drafts as used by Windows XP it is interesting to note that the client there omits the TSi payload which then would automatically get set to the public IP address of the client. Fixes #220. |