aboutsummaryrefslogtreecommitdiffstats
path: root/src/libcharon
Commit message (Collapse)AuthorAgeFilesLines
...
| | * Don't invoke a child_updown hook when a quick mode to delete has been rekeyedMartin Willi2012-03-201-1/+6
| | |
| | * Invoke child_rekey hook instead of child_updown when rekeying a quick modeMartin Willi2012-03-203-2/+36
| | |
| | * Don't invoke updown hook when flushing SAs for IKEv1, tasks will do itMartin Willi2012-03-201-10/+12
| | |
| | * Fix "incoming" flag passed to bus_t.message() hookMartin Willi2012-03-201-1/+1
| | |
| | * Continue with next exchange after sending an INFORMATIONALMartin Willi2012-03-201-1/+2
| | |
| | * Handle retransmission of DPD exchange, both as initiator and responderMartin Willi2012-03-201-22/+37
| | |
| | * Disable DPD checking for peers not supporting itMartin Willi2012-03-203-3/+20
| | |
| | * Added missing DPD task nameMartin Willi2012-03-202-3/+3
| | |
| | * Confirm message reception time only if DPD sequence number validMartin Willi2012-03-202-3/+10
| | |
| | * Simplified DPD handling by using a task for a single message onlyMartin Willi2012-03-208-272/+114
| | |
| | * Added missing short enum names for DPD notify typesMartin Willi2012-03-201-1/+4
| | |
| | * Print IKEv1 notify types in message summaryMartin Willi2012-03-201-1/+2
| | |
| | * Support IKEv1 notifies in message_t.get_notify()Martin Willi2012-03-201-1/+2
| | |
| | * Check if we have an RNG for IKEv1 task manager before using itMartin Willi2012-03-201-9/+9
| | |
| | * Remove unused DPD sequence number getter on task managerMartin Willi2012-03-202-13/+2
| | |
| | * Don't retransmit, rekey, reauth or DPD check SAs when in PASSIVE stateMartin Willi2012-03-201-0/+24
| | |
| | * Send DPD vendor IDClavister OpenSource2012-03-201-1/+1
| | |
| | * Isakmp_dpd task added.Clavister OpenSource2012-03-2011-9/+446
| | |
| | * DPD_R_U_THERE defines addedClavister OpenSource2012-03-202-1/+14
| | |
| | * Request and handle retransmission of a lost third aggressive mode messageMartin Willi2012-03-201-5/+8
| | |
| | * Streamlined debug output when initiating IKEv1 IKE_SAsMartin Willi2012-03-202-2/+2
| | |
| | * Accept unencrypted Aggressive Mode messages.Tobias Brunner2012-03-201-1/+2
| | | | | | | | | | | | Racoon does not encrypt the third message during Aggressive Mode.
| | * Enforce encapsulation mode of configuration, in case initiator proposes bothMartin Willi2012-03-201-1/+2
| | |
| | * Added a "aggressive" ipsec.conf connection optionMartin Willi2012-03-201-1/+1
| | |
| | * Handle aggressive mode task in IKEv1 task managerMartin Willi2012-03-201-6/+36
| | |
| | * Select IKEv1 configurations by main/aggressive mode optionMartin Willi2012-03-204-5/+8
| | |
| | * Added an aggressive mode peer_cfg optionMartin Willi2012-03-2012-18/+40
| | |
| | * Fix sending of CERTREQ/CERT payloads in aggressive modeMartin Willi2012-03-202-2/+12
| | |
| | * Encrypt payloads of third aggressive mode messageMartin Willi2012-03-201-3/+3
| | |
| | * Implemented aggressive mode using Phase 1 helper classMartin Willi2012-03-205-0/+683
| | |
| | * Make use of the new Phase 1 helper class in main modeMartin Willi2012-03-201-579/+73
| | |
| | * Implemented a common Phase 1 helper class to use by main and aggressive modesMartin Willi2012-03-203-0/+754
| | |
| | * Fix error handling if no PSK found for main modeMartin Willi2012-03-201-5/+9
| | |
| | * Install quick mode CHILD_SAs with negotiated encapsulation modeMartin Willi2012-03-201-12/+17
| | |
| | * Support IKEv1 proposal encodings having both lifebytes and a lifetimeMartin Willi2012-03-201-67/+58
| | |
| | * Try to detect reauthentication as responder and adopt children to new SAMartin Willi2012-03-205-1/+233
| | |
| | * Destroy IKE_SA after reauthentication initiatend and lifetime limit reachedMartin Willi2012-03-201-1/+6
| | |
| | * Added an IKE_SA manager method to enumerate IKE_SA IDs filtered by identitiesMartin Willi2012-03-202-34/+59
| | |
| | * Query for XAuth identity in get_other_eap_id(), tooMartin Willi2012-03-201-0/+4
| | |
| | * Set ISAKMP SA state to rekeying after triggering reauthenticationMartin Willi2012-03-201-0/+1
| | |
| | * Include peer config overtime in negotiated ISAKMP SA lifetimeMartin Willi2012-03-201-2/+3
| | |
| | * Initiate IKEv1 reauthentication, take over all childrenMartin Willi2012-03-201-4/+44
| | |
| | * Establish IKE_SA only once as XAuth responderMartin Willi2012-03-201-1/+0
| | |
| | * Support initiation of childless IKEv1 ISAKMP SAsMartin Willi2012-03-201-1/+2
| | |
| | * Don't trigger reauthentication if initiator authenticated using XAuthMartin Willi2012-03-201-0/+1
| | |
| | * Set a condition flag if peer has been authenticated using XAuthMartin Willi2012-03-202-0/+6
| | |
| | * Queue Mode Config tasks after main mode as initiator, not as responderMartin Willi2012-03-201-6/+6
| | |
| | * Setting Mode Cfg identifier for CFG_ACK messages.Clavister OpenSource2012-03-201-0/+7
| | |
| | * Add functions to set mode cfg identifierClavister OpenSource2012-03-202-0/+27
| | |
| | * Try all matching XAuth secrets we find, not only the first oneMartin Willi2012-03-201-11/+23
| | |