Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
| | * | Derive IKEv1 CHILD_SA keymat twice, once for each IPsec SA | Martin Willi | 2012-03-20 | 3 | -24/+31 | |
| | | | ||||||
| | * | Fix seed construction for IKEv1 key derivation | Martin Willi | 2012-03-20 | 1 | -1/+1 | |
| | | | ||||||
| | * | Use a dedicated message hash to detect IKEv1 retransmissions | Martin Willi | 2012-03-20 | 1 | -7/+13 | |
| | | | ||||||
| | * | Include hardcoded tunnel mode attribute in porposal, remove ESN attribute | Martin Willi | 2012-03-20 | 1 | -2/+2 | |
| | | | ||||||
| | * | Authenticate and verify Phase 2 IKEv1 messages with appropriate hashes. | Tobias Brunner | 2012-03-20 | 3 | -2/+265 | |
| | | | ||||||
| | * | Fixed verification of DELETE_V1 payloads. | Tobias Brunner | 2012-03-20 | 1 | -4/+13 | |
| | | | ||||||
| | * | Fixed header length calculation of DELETE payload. | Tobias Brunner | 2012-03-20 | 1 | -6/+6 | |
| | | | ||||||
| | * | Fixed conftests after extending CERT payload. | Tobias Brunner | 2012-03-20 | 1 | -2/+4 | |
| | | | ||||||
| | * | Fixed a config reference leak in IKEv2 initiate | Martin Willi | 2012-03-20 | 1 | -1/+0 | |
| | | | ||||||
| | * | XAUTH is initiated based on configuration, no need to call externally | Martin Willi | 2012-03-20 | 3 | -21/+0 | |
| | | | ||||||
| | * | Merged IKEv1 attribute payload/data into configuration payload/attribute | Martin Willi | 2012-03-20 | 14 | -814/+273 | |
| | | | ||||||
| | * | Temp fix for compile error with XAUTH code. | Clavister OpenSource | 2012-03-20 | 1 | -1/+1 | |
| | | | ||||||
| | * | IKEv1 XAUTH: Added ability to configure XAUTH+PSK. Added task to handle ↵ | Clavister OpenSource | 2012-03-20 | 9 | -7/+333 | |
| | | | | | | | | | | | | XAUTH requests. Modified task_manager_v1 to enable it to initiate new tasks immediately after finishing a response. | |||||
| | * | Updates ike_cert_post task with modifications needed for dealing with ↵ | Clavister OpenSource | 2012-03-20 | 1 | -5/+5 | |
| | | | | | | | | | | | | updated cert_payload class. | |||||
| | * | IKEv1 ConfigMode: Added the payload handlers for attribute_payload and ↵ | Clavister OpenSource | 2012-03-20 | 4 | -0/+672 | |
| | | | | | | | | | | | | data_attribute payload types. | |||||
| | * | IKEv1 ConfigMode: Added TRANSACTION exchange type. Added attribute_payload ↵ | Clavister OpenSource | 2012-03-20 | 6 | -20/+78 | |
| | | | | | | | | | | | | (IKEv2 equiv cp_payload) and data_attribute (IKEv2 equiv configuration_attribute) payload types. Did not combine with IKEv2 because it wasn't trivial to do so. This might be a task worth investigating in the future, because there is a decent amount of shared code here. | |||||
| | * | Updated the CERT payload to work for both IKEv1 and IKEv2. | Clavister OpenSource | 2012-03-20 | 2 | -14/+25 | |
| | | | ||||||
| | * | Parse proposal substructure with multiple IKEv1 transforms to multiple proposals | Martin Willi | 2012-03-20 | 3 | -34/+33 | |
| | | | ||||||
| | * | Encode multiple IKEv1 proposals in a single transform substructure | Martin Willi | 2012-03-20 | 3 | -13/+74 | |
| | | | ||||||
| | * | Remove public sa_payload.add_proposal() method | Martin Willi | 2012-03-20 | 2 | -18/+12 | |
| | | | ||||||
| | * | Only add the first algorithm of a kind to IKEv1 transforms | Martin Willi | 2012-03-20 | 1 | -4/+4 | |
| | | | ||||||
| | * | Install negotiated IKEv1 CHILD_SA negotiated in quick mode | Martin Willi | 2012-03-20 | 1 | -0/+163 | |
| | | | ||||||
| | * | Implemented IKEv1 keymat CHILD_SA key derivation function | Martin Willi | 2012-03-20 | 2 | -0/+131 | |
| | | | ||||||
| | * | Moved keymat key length lookup functions to keymat.c | Martin Willi | 2012-03-20 | 3 | -55/+75 | |
| | | | ||||||
| | * | Extended PRF+ by a non-counting variant as used by IKEv1 | Martin Willi | 2012-03-20 | 1 | -3/+3 | |
| | | | ||||||
| | * | Hardcode some SA lifetimes until we can configure them dynamically | Martin Willi | 2012-03-20 | 1 | -0/+12 | |
| | | | ||||||
| | * | Added missing comma after ME_CONNECT declaration. | Tobias Brunner | 2012-03-20 | 1 | -13/+14 | |
| | | | ||||||
| | * | Fixed creation of endpoint notifies. | Tobias Brunner | 2012-03-20 | 1 | -1/+1 | |
| | | | ||||||
| | * | Fixed diagram of IKEv1 encrypted "payload". | Tobias Brunner | 2012-03-20 | 1 | -2/+0 | |
| | | | ||||||
| | * | Refactored main mode NONCE/KE payload processing | Martin Willi | 2012-03-20 | 1 | -76/+63 | |
| | | | ||||||
| | * | Refactored main mode HASH payload processing | Martin Willi | 2012-03-20 | 1 | -60/+56 | |
| | | | ||||||
| | * | Skip any payloads in front of SA to extract initiators SA bytes | Martin Willi | 2012-03-20 | 1 | -10/+24 | |
| | | | ||||||
| | * | Implemented quick mode protocol handling, no CHILD_SA or HASH payloads yet | Martin Willi | 2012-03-20 | 2 | -7/+294 | |
| | | | ||||||
| | * | Partially implemented IKEv1 ESP proposal en-/decoding | Martin Willi | 2012-03-20 | 1 | -2/+73 | |
| | | | ||||||
| | * | Add missing keymat cast to avoid compiler warning | Martin Willi | 2012-03-20 | 1 | -1/+1 | |
| | | | ||||||
| | * | Don't compare initiator flag in IKE_SA manager, pass initiator parameter to ↵ | Martin Willi | 2012-03-20 | 5 | -20/+13 | |
| | | | | | | | | | | | | IKE_SA constructor | |||||
| | * | Create and verify PSK HASH payloads in IKEv1 main mode | Martin Willi | 2012-03-20 | 1 | -9/+117 | |
| | | | ||||||
| | * | Added keymat_v1_t.get_hash() to calculate authentication hashes | Martin Willi | 2012-03-20 | 2 | -0/+53 | |
| | | | ||||||
| | * | Register HASH_V1 in payload factory | Martin Willi | 2012-03-20 | 1 | -0/+3 | |
| | | | ||||||
| | * | Derive IKE keys as IKEv1 initiator, too | Martin Willi | 2012-03-20 | 1 | -0/+6 | |
| | | | ||||||
| | * | Fix payload length of id_payload created from a traffic selector | Martin Willi | 2012-03-20 | 1 | -0/+1 | |
| | | | ||||||
| | * | String for ENCRYPTED_DATA fixed. | Tobias Brunner | 2012-03-20 | 1 | -1/+1 | |
| | | | ||||||
| | * | Strings for ENCRYPTED_V1 payload added. | Tobias Brunner | 2012-03-20 | 1 | -10/+14 | |
| | | | ||||||
| | * | Set flags on message according to IKE version when parsing header. | Tobias Brunner | 2012-03-20 | 1 | -2/+8 | |
| | | | ||||||
| | * | Encrypt IKEv1 messages. | Tobias Brunner | 2012-03-20 | 1 | -17/+66 | |
| | | | ||||||
| | * | Decrypt IKEv1 messages. | Tobias Brunner | 2012-03-20 | 1 | -3/+43 | |
| | | | ||||||
| | * | Added IV generation to keymat_v1_t. | Tobias Brunner | 2012-03-20 | 2 | -0/+229 | |
| | | | ||||||
| | * | Use modified encryption payload to encrypt/decrypt complete IKEv1 messages. | Tobias Brunner | 2012-03-20 | 8 | -15/+156 | |
| | | | ||||||
| | * | Use key derivation in IKEv1 main mode (PSK authentication). | Tobias Brunner | 2012-03-20 | 1 | -1/+80 | |
| | | | ||||||
| | * | Added a simple AEAD wrapper for IKEv1 encryption/decryption. | Tobias Brunner | 2012-03-20 | 1 | -1/+155 | |
| | | |