index
:
tteras/strongswan
master
tteras
tteras-release
tteras' strongSwan tree
gitolite
about
summary
refs
log
tree
commit
diff
stats
log msg
author
committer
range
path:
root
/
src
/
libcharon
Commit message (
Expand
)
Author
Age
Files
Lines
...
*
ikev2: Don't set old IKE_SA to REKEYING state during make-before-break reauth
Martin Willi
2015-03-11
1
-1
/
+0
*
ha: Destroy synced IKE_SA if no configuration is found during update
Martin Willi
2015-03-10
1
-0
/
+3
*
ikev1: Don't handle DPD timeout job if IKE_SA got passive
Martin Willi
2015-03-10
1
-0
/
+6
*
libipsec: Pass separate inbound/update flags to the IPsec SA manager
Martin Willi
2015-03-09
1
-1
/
+2
*
kernel-interface: Add a separate "update" flag to add_sa()
Martin Willi
2015-03-09
4
-4
/
+4
*
Revert "child-sa: Remove the obsolete update logic"
Martin Willi
2015-03-09
1
-1
/
+6
*
Revert "ha: Always install the CHILD_SAs with the inbound flag set to FALSE"
Martin Willi
2015-03-09
1
-2
/
+2
*
ikev2: Move code in pubkey authenticator's build() method into separate funct...
Tobias Brunner
2015-03-09
1
-85
/
+123
*
ikev2: Try all eligible signature schemes
Tobias Brunner
2015-03-09
1
-34
/
+71
*
daemon: Remove scheduled jobs before unloading plugins
Tobias Brunner
2015-03-09
1
-1
/
+2
*
Make access requestor IP address available to TNC server
Andreas Steffen
2015-03-08
2
-12
/
+39
*
ikev1: Set protocol ID and SPIs in INITIAL-CONTACT notification payloads
Tobias Brunner
2015-03-06
1
-2
/
+13
*
ikev2: Try all RSA signature schemes if none is configured
Tobias Brunner
2015-03-04
1
-4
/
+19
*
ikev2: Consider signature schemes in rightauth when sending hash algorithms
Tobias Brunner
2015-03-04
1
-14
/
+54
*
keymat: Use hash algorithm set
Tobias Brunner
2015-03-04
1
-29
/
+7
*
ikev2: Add an option to disable constraints against signature schemes
Tobias Brunner
2015-03-04
1
-1
/
+11
*
stroke: Enable BLISS-based public key constraints
Tobias Brunner
2015-03-04
1
-4
/
+19
*
ikev2: Fall back to SHA-1 signatures for RSA
Tobias Brunner
2015-03-04
1
-0
/
+7
*
ikev2: Select a signature scheme appropriate for the given key
Tobias Brunner
2015-03-04
1
-18
/
+13
*
ikev2: Log the actual signature scheme used for RFC 7427 authentication
Tobias Brunner
2015-03-04
1
-4
/
+6
*
ikev2: Store signature scheme used to verify peer in auth_cfg
Tobias Brunner
2015-03-04
1
-0
/
+1
*
ikev2: Add a global option to disable RFC 7427 signature authentication
Tobias Brunner
2015-03-04
1
-2
/
+12
*
ikev2: Remove private AUTH_BLISS method
Tobias Brunner
2015-03-04
3
-18
/
+1
*
ikev2: Handle RFC 7427 signature authentication in pubkey authenticator
Tobias Brunner
2015-03-04
2
-49
/
+179
*
ikev2: Enable signature authentication by transmitting supported hash algorithms
Tobias Brunner
2015-03-04
2
-4
/
+88
*
keymat: Add facility to store supported hash algorithms
Tobias Brunner
2015-03-04
2
-1
/
+70
*
ikev2: Add SIGNATURE_HASH_ALGORITHMS notify payload
Tobias Brunner
2015-03-04
2
-6
/
+18
*
ikev2: Add new authentication method defined by RFC 7427
Tobias Brunner
2015-03-04
2
-3
/
+9
*
ikev2: Only accept initial messages in specific states
Tobias Brunner
2015-03-04
1
-10
/
+9
*
ike-sa-manager: Make sure the message ID of initial messages is 0
Tobias Brunner
2015-03-04
1
-1
/
+2
*
ikev2: Don't destroy the SA if an IKE_SA_INIT with unexpected MID is received
Tobias Brunner
2015-03-04
1
-4
/
+0
*
ikev2: Don't adopt any CHILD_SA during make-before-break reauthentication
Martin Willi
2015-03-04
1
-1
/
+2
*
stroke: Support public key constraints for EAP methods
Martin Willi
2015-03-03
1
-1
/
+8
*
eap-ttls: Support EAP auth information getter in EAP-TTLS
Martin Willi
2015-03-03
1
-0
/
+7
*
eap-tls: Support EAP auth information getter in EAP-TLS
Martin Willi
2015-03-03
1
-0
/
+7
*
ikev2: Merge EAP client authentication details if EAP methods provides them
Martin Willi
2015-03-03
1
-0
/
+7
*
eap: Add an optional authentication details getter to the EAP method interface
Martin Willi
2015-03-03
1
-0
/
+12
*
stroke: Serve ca section CA certificates directly, not over central CA set
Martin Willi
2015-03-03
3
-5
/
+85
*
stroke: Purge existing CA/AA certificates during reread
Martin Willi
2015-03-03
1
-0
/
+4
*
stroke: Use separate credential sets for CA/AA certificates
Martin Willi
2015-03-03
1
-3
/
+21
*
stroke: Refactor load_certdir function
Martin Willi
2015-03-03
1
-108
/
+158
*
vici: Don't use a default rand_time larger than half of rekey/reauth_time
Martin Willi
2015-03-03
1
-3
/
+11
*
vici: If a IKE reauth_time is configured, disable the default rekey_time
Martin Willi
2015-03-03
1
-1
/
+16
*
ikev2: Schedule a timeout for the delete message following passive IKE rekeying
Martin Willi
2015-03-03
1
-0
/
+6
*
vici: Support ruby gem out-of-tree builds
Martin Willi
2015-02-27
1
-1
/
+3
*
ha: Always install the CHILD_SAs with the inbound flag set to FALSE
Martin Willi
2015-02-27
1
-2
/
+2
*
forecast: Explicitly cast sockaddr to fix compiler warning
Tobias Brunner
2015-02-23
1
-1
/
+1
*
configure: Use pkg-config to detect libiptc used by connmark/forecast
Tobias Brunner
2015-02-23
2
-4
/
+4
*
forecast: Add the broadcast/multicast forwarding plugin called forecast
Martin Willi
2015-02-20
8
-0
/
+1479
*
connmark: Add CONNMARK rules to select correct output SA based on conntrack
Martin Willi
2015-02-20
4
-0
/
+611
[prev]
[next]