Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | Allow responder to use ike_mobike_t.roam. | Tobias Brunner | 2010-10-12 | 1 | -1/+7 | |
| | | | | After getting a response the responder updates the IPsec SAs. | |||||
* | Send list of additional addresses even if current path is still valid. | Tobias Brunner | 2010-10-12 | 1 | -0/+11 | |
| | ||||||
* | Extracted path checking in ike_sa_t.roam into separate functions. | Tobias Brunner | 2010-10-12 | 1 | -46/+68 | |
| | ||||||
* | Added support for responders to change their address via MOBIKE. | Tobias Brunner | 2010-10-12 | 1 | -0/+20 | |
| | | | | | | | If the original responder updates its list of additional addresses we check if the remote endpoint changed and update the IPsec SAs if it did, as we assume the original address became unavailable and the responder already updated the SAs on its side. | |||||
* | Explicitly configure MOBIKE tasks to update the list of additional addresses. | Tobias Brunner | 2010-10-12 | 3 | -2/+15 | |
| | ||||||
* | Improved check for first IKE_AUTH message in ike_mobike task. | Tobias Brunner | 2010-10-12 | 1 | -3/+6 | |
| | | | | | If the original responder initiated a MOBIKE exchange, the previous check was not always correct. | |||||
* | Migrated ike_mobike task to INIT/METHOD macros. | Tobias Brunner | 2010-10-12 | 1 | -67/+46 | |
| | ||||||
* | Simplified apply_port function in mobike task. | Tobias Brunner | 2010-10-12 | 1 | -16/+9 | |
| | ||||||
* | Do not update hosts based on retransmitted messages. | Tobias Brunner | 2010-10-12 | 2 | -15/+23 | |
| | ||||||
* | Do not update remote host if we are behind a NAT. | Tobias Brunner | 2010-10-12 | 1 | -4/+2 | |
| | ||||||
* | use DBG_TNC for TNC debugging output | Andreas Steffen | 2010-10-09 | 3 | -21/+21 | |
| | ||||||
* | TNCCS debug cosmetics | Andreas Steffen | 2010-10-09 | 1 | -4/+4 | |
| | ||||||
* | revert to standard TNCC/TNCS Initialization function | Andreas Steffen | 2010-10-09 | 2 | -17/+2 | |
| | ||||||
* | implemented TNC isolation via group memberships | Andreas Steffen | 2010-10-09 | 1 | -6/+33 | |
| | ||||||
* | implemented a makeshift non-scalable send buffer | Andreas Steffen | 2010-10-08 | 1 | -25/+82 | |
| | ||||||
* | imc/imv cosmetics | Andreas Steffen | 2010-10-08 | 2 | -4/+7 | |
| | ||||||
* | created tnc-imc and tnc-imv plugins | Andreas Steffen | 2010-10-07 | 9 | -42/+340 | |
| | ||||||
* | deactivate start_phase2_tnc flag after start | Andreas Steffen | 2010-10-07 | 1 | -1/+1 | |
| | ||||||
* | added server side support for EAP-TNC | Andreas Steffen | 2010-10-07 | 1 | -2/+28 | |
| | ||||||
* | Show result of RADIUS authentication along with EAP identity | Martin Willi | 2010-10-07 | 1 | -5/+6 | |
| | ||||||
* | configure tnc_config path and preferred_language via strongswan.conf | Andreas Steffen | 2010-10-05 | 1 | -2/+8 | |
| | ||||||
* | created hull for TNCCS 2.0 plugin | Andreas Steffen | 2010-10-05 | 6 | -0/+256 | |
| | ||||||
* | use group membership to implement access/isolate redirection in filter-based ↵ | Andreas Steffen | 2010-10-05 | 1 | -4/+14 | |
| | | | | TNC scenario | |||||
* | moved CHILD_SA selection out of attribute loop | Andreas Steffen | 2010-10-05 | 1 | -5/+6 | |
| | ||||||
* | receive name of preferred CHILD_SA via RADIUS Filter-Id attribute | Andreas Steffen | 2010-10-05 | 1 | -0/+59 | |
| | ||||||
* | print XML as plaintext and process recieved TNCCS Batch | Andreas Steffen | 2010-09-30 | 1 | -11/+28 | |
| | ||||||
* | started use of libtnc library | Andreas Steffen | 2010-09-29 | 2 | -19/+81 | |
| | ||||||
* | NOTIFY error message types include 16383 | Andreas Steffen | 2010-09-29 | 1 | -1/+1 | |
| | ||||||
* | moved TNCCS layer out of eap_tnc plugin | Andreas Steffen | 2010-09-28 | 14 | -48/+450 | |
| | ||||||
* | draft-ietf-ipsecme-eap-mutual will be released as RFC 5998. | Tobias Brunner | 2010-09-16 | 1 | -1/+1 | |
| | ||||||
* | added notify messages defined in RFC 5996 | Andreas Steffen | 2010-09-15 | 2 | -6/+13 | |
| | ||||||
* | show validity of OCSP responses | Andreas Steffen | 2010-09-10 | 1 | -2/+15 | |
| | ||||||
* | debug output of inbound and outbound TNCCS batches | Andreas Steffen | 2010-09-09 | 1 | -9/+14 | |
| | ||||||
* | support non EAP-TTLS conformant RADIUS-type attribute segmentation | Andreas Steffen | 2010-09-09 | 1 | -13/+79 | |
| | ||||||
* | Fixed copy/paste error. | Tobias Brunner | 2010-09-09 | 1 | -1/+1 | |
| | ||||||
* | added explanatory comments | Andreas Steffen | 2010-09-09 | 1 | -3/+7 | |
| | ||||||
* | send well-formed TNCCS-Batch | Andreas Steffen | 2010-09-08 | 1 | -1/+9 | |
| | ||||||
* | max max_message_count configurable and move it into tls_eap_t | Andreas Steffen | 2010-09-08 | 3 | -36/+12 | |
| | ||||||
* | Added a simple led plugin to control Linux LEDs based on IKE activity | Martin Willi | 2010-09-08 | 6 | -0/+422 | |
| | ||||||
* | moved tls_t existance test into tls_eap_create() again | Andreas Steffen | 2010-09-08 | 3 | -15/+0 | |
| | ||||||
* | generalized tls_eap_t to support EAP_TNC wrapping the TNC_IF_TNCCS protocol | Andreas Steffen | 2010-09-08 | 6 | -94/+250 | |
| | ||||||
* | Scheduler and processor have been moved to libstrongswan. | Tobias Brunner | 2010-09-02 | 1 | -1/+1 | |
| | | | | | Also reverts 0c21dc000d3cd5c82eb22c4481e6459978456364 as the dependency to libcharon is no longer required. | |||||
* | Adapted child_sa_t to changed kernel interface. | Tobias Brunner | 2010-09-02 | 1 | -25/+49 | |
| | ||||||
* | Fixing installation of trap policies (SPI=0) in kernel interface. | Tobias Brunner | 2010-09-02 | 1 | -3/+2 | |
| | ||||||
* | Added an option to specify the type of a policy to kernel_ipsec.add_policy. | Tobias Brunner | 2010-09-02 | 1 | -18/+18 | |
| | | | | | This will later allow us to support pluto's passthrough and drop policies in charon. | |||||
* | Replaced the protocol argument in add_policy with an optional SPI for an AH SA. | Tobias Brunner | 2010-09-02 | 2 | -19/+38 | |
| | ||||||
* | Refer to scheduler and processor via lib and not hydra. | Tobias Brunner | 2010-09-02 | 30 | -89/+67 | |
| | ||||||
* | Moved all kernel plugins to libhydra. | Tobias Brunner | 2010-09-02 | 27 | -10728/+0 | |
| | ||||||
* | Moved ipsec_transform_t to kernel_ipsec.h in libhydra. | Tobias Brunner | 2010-09-02 | 2 | -26/+0 | |
| | | | | | Because of this libfreeswan, pluto, starter etc. now depend on that file (and libhydra). This resolved some duplicate declarations. | |||||
* | Refer to kernel interface via hydra and not charon. | Tobias Brunner | 2010-09-02 | 24 | -144/+161 | |
| |