Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | | | Removed auth_cfg_t.replace_value() and replaced usages with add(). | Tobias Brunner | 2012-04-18 | 3 | -17/+4 | |
| | | | | | | | | | | | | | | | replace_value() was used to replace identities. Since for these the latest is now returned by get(), adding the new identity with add() is sufficient. | |||||
* | | | Store password with remote ID to tie it stronger to a specific connection. | Tobias Brunner | 2012-04-18 | 1 | -12/+50 | |
| | | | ||||||
* | | | Added stroke user-creds command, to set username/password for a connection. | Tobias Brunner | 2012-04-17 | 3 | -1/+166 | |
| | | | ||||||
* | | | Added method to add additional shared secrets to stroke_cred_t. | Tobias Brunner | 2012-04-17 | 2 | -2/+20 | |
| | | | ||||||
* | | | Typo fixed. | Tobias Brunner | 2012-04-17 | 1 | -1/+1 | |
| | | | ||||||
* | | | Keep COOKIEs enabled once threshold is hit, until we see no COOKIEs for a ↵ | Martin Willi | 2012-04-17 | 1 | -5/+43 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | few secs Toggling COOKIEs on/off is problematic: After doing a COOKIE exchange as initiator, we can't know if the completing IKE_SA_INIT message is to our first request or the one with the COOKIE. If the responder just enabled/disabled COOKIEs and packets get retransmitted, both might be true. Avoiding COOKIE behavior toggling improves the situation, but does not solve the problem during the initial COOKIE activation. | |||||
* | | | Added a note about DH/keymat lifecycle for custom implementations | Martin Willi | 2012-04-17 | 1 | -1/+6 | |
| | | | ||||||
* | | | Reuse existing DH value when retrying IKE_SA_INIT with a COOKIE | Martin Willi | 2012-04-17 | 1 | -2/+5 | |
| | | | ||||||
* | | | Use IP address as ID as responder if not configured or no IDr received. | Tobias Brunner | 2012-04-16 | 1 | -3/+11 | |
| | | | ||||||
* | | | Fall back on IP address as IDi if none is configured at all. | Tobias Brunner | 2012-04-16 | 1 | -7/+7 | |
| | | | ||||||
* | | | Use auth_cfg_t.replace_value where appropriate. | Tobias Brunner | 2012-04-16 | 2 | -26/+5 | |
| | | | ||||||
* | | | Fixed IDi in case neither left nor leftid is configured. | Tobias Brunner | 2012-04-16 | 1 | -0/+21 | |
| | | | ||||||
* | | | Don't invoke child_updown hook twice as responder | Martin Willi | 2012-04-11 | 1 | -3/+8 | |
| | | | ||||||
* | | | Accept zero-length certificate request payloads | Martin Willi | 2012-04-11 | 1 | -2/+1 | |
| | | | ||||||
* | | | Properly initialize src in ike_sa_t.is_any_path_valid(). | Tobias Brunner | 2012-04-06 | 1 | -1/+1 | |
| | | | ||||||
* | | | remove leading zero in ASN.1 encoded serial numbers | Andreas Steffen | 2012-04-05 | 1 | -2/+2 | |
| | | | ||||||
* | | | Make AES-CMAC actually usable for IKEv2. | Tobias Brunner | 2012-04-04 | 1 | -0/+5 | |
| | | | ||||||
* | | | moved chunk_skip_zero to chunk.h | Andreas Steffen | 2012-04-03 | 1 | -2/+3 | |
| | | | ||||||
* | | | added IKEv2 Generic Secure Password Authentication Method | Andreas Steffen | 2012-04-03 | 2 | -3/+10 | |
| | | | ||||||
* | | | added IKEv2 Generic Secure Password Authentication Method | Andreas Steffen | 2012-04-03 | 2 | -6/+17 | |
| | | | ||||||
* | | | added GSPM IKEv2 payload | Andreas Steffen | 2012-04-03 | 2 | -8/+20 | |
| | | | ||||||
* | | | Doxygen fixes. | Tobias Brunner | 2012-04-03 | 2 | -2/+2 | |
| | | | ||||||
* | | | Don't cast second argument of mem_printf_hook (%b) to size_t. | Tobias Brunner | 2012-03-27 | 5 | -12/+17 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Also treat the given number as unsigned int. Due to the printf hook registration the second argument of mem_printf_hook (if called via printf etc.) is always of type int*. Casting this to a size_t pointer and then dereferencing that as int does not work on big endian machines if int is smaller than size_t (e.g. on ppc64). In order to make this change work if the argument is of a type larger than int, size_t for instance, the second argument for %b has to be casted to (u_)int. | |||||
* | | | smp: Use proper signed type to get return value of read(2). | Tobias Brunner | 2012-03-27 | 1 | -1/+1 | |
| | | | ||||||
* | | | Don't include individual glib headers in nm plugin. | Tobias Brunner | 2012-03-26 | 1 | -1/+1 | |
| | | | | | | | | | | | | | | | Expections are glib/gi18n.h, glib/gi18n-lib.h, glib/gprintf.h and glib/gstdio.h. | |||||
* | | | fixed parsing of IF-MAP SOAP responses | Andreas Steffen | 2012-03-21 | 1 | -35/+30 | |
|/ / | ||||||
* | | added the strongswan.conf options of the tnc-pdp plugin | Andreas Steffen | 2012-03-16 | 1 | -1/+1 | |
| | | ||||||
* | | eliminate unneeded private variable | Andreas Steffen | 2012-03-14 | 1 | -3/+3 | |
| | | ||||||
* | | use MAX_RADIUS_ATTRIBUTE_SIZE constant from radius_message header file | Andreas Steffen | 2012-03-14 | 2 | -4/+3 | |
| | | ||||||
* | | make the mppe salt unique | Andreas Steffen | 2012-03-14 | 1 | -8/+18 | |
| | | ||||||
* | | implemented MS_MPPE encryption | Andreas Steffen | 2012-03-13 | 1 | -14/+93 | |
| | | ||||||
* | | use RADIUS_TUNNEL_TYPE_ESP defined in header file | Andreas Steffen | 2012-03-13 | 1 | -3/+1 | |
| | | ||||||
* | | implemented RADIUS Filter-ID attribute | Andreas Steffen | 2012-03-13 | 3 | -24/+87 | |
| | | ||||||
* | | removed double library entry | Andreas Steffen | 2012-03-13 | 1 | -2/+0 | |
| | | ||||||
* | | adapted debug output | Andreas Steffen | 2012-03-13 | 1 | -1/+1 | |
| | | ||||||
* | | keep a list of RADIUS connections with EAP method states | Andreas Steffen | 2012-03-13 | 4 | -12/+320 | |
| | | ||||||
* | | apply maximum RADIUS attribute size to outbound EAP messages | Andreas Steffen | 2012-03-13 | 1 | -0/+9 | |
| | | ||||||
* | | read PDP server name from strongswan.conf | Andreas Steffen | 2012-03-13 | 1 | -7/+29 | |
| | | ||||||
* | | define MAX_RADIUS_ATTRIBUTE_SIZE | Andreas Steffen | 2012-03-13 | 1 | -4/+5 | |
| | | ||||||
* | | define peer and server identities | Andreas Steffen | 2012-03-13 | 1 | -2/+9 | |
| | | ||||||
* | | added EAP_SUCCESS/FAILURE message to RADIUS Accept/Reject | Andreas Steffen | 2012-03-13 | 1 | -2/+7 | |
| | | ||||||
* | | added msg_auth flag in radius_message_t sign() method | Andreas Steffen | 2012-03-13 | 2 | -2/+2 | |
| | | ||||||
* | | simple RADIUS server example works | Andreas Steffen | 2012-03-13 | 1 | -14/+187 | |
| | | ||||||
* | | first use of libradius | Andreas Steffen | 2012-03-13 | 1 | -2/+2 | |
| | | ||||||
* | | created libradius shared by eap-radius and tnc-pdp plugins | Andreas Steffen | 2012-03-13 | 3 | -2/+19 | |
| | | ||||||
* | | created tnc-pdp policy decision point plugin | Andreas Steffen | 2012-03-13 | 6 | -0/+464 | |
| | | ||||||
* | | Fixed crash and locking issues while unrouting connections via stroke | Martin Willi | 2012-03-13 | 1 | -7/+8 | |
| | | ||||||
* | | Clear peer addresses during HA update. | Tobias Brunner | 2012-03-09 | 1 | -1/+6 | |
| | | ||||||
* | | Simplified some route lookups now that we store all peer addresses in a list. | Tobias Brunner | 2012-03-09 | 2 | -25/+9 | |
| | | ||||||
* | | Renamed list of additional peer addresses as it now stores all known addresses. | Tobias Brunner | 2012-03-09 | 7 | -43/+42 | |
| | |