index
:
tteras/strongswan
master
tteras
tteras-release
tteras' strongSwan tree
gitolite
about
summary
refs
log
tree
commit
diff
stats
log msg
author
committer
range
path:
root
/
src
/
libcharon
Commit message (
Expand
)
Author
Age
Files
Lines
...
*
vici: Expose Session as a top-level symbol in python package
Björn Schuberg
2015-03-18
1
-0
/
+1
*
vici: Introduce main API Session class in python package
Björn Schuberg
2015-03-18
1
-1
/
+244
*
vici: Add a python vici command execution handler
Björn Schuberg
2015-03-18
2
-1
/
+134
*
vici: Add vici python protocol handler
Björn Schuberg
2015-03-18
4
-0
/
+199
*
encoding: Verify the length of KE payload data for known groups
Martin Willi
2015-03-18
1
-0
/
+67
*
ikev2: Migrate MOBIKE additional peer addresses to new SA after IKE_SA rekeying
Martin Willi
2015-03-18
1
-0
/
+6
*
ikev2: Immediately initiate queued tasks after establishing rekeyed IKE_SA
Martin Willi
2015-03-18
5
-0
/
+176
*
vici: Use %u to print stats returned by mallinfo(3)
Tobias Brunner
2015-03-13
1
-4
/
+4
*
stroke: Use %u to print stats returned by mallinfo(3)
Tobias Brunner
2015-03-13
1
-1
/
+1
*
eap-radius: Increase Acct-Session-ID string buffer
Martin Willi
2015-03-13
1
-1
/
+1
*
ikev2: Don't set old IKE_SA to REKEYING state during make-before-break reauth
Martin Willi
2015-03-11
1
-1
/
+0
*
ha: Destroy synced IKE_SA if no configuration is found during update
Martin Willi
2015-03-10
1
-0
/
+3
*
ikev1: Don't handle DPD timeout job if IKE_SA got passive
Martin Willi
2015-03-10
1
-0
/
+6
*
libipsec: Pass separate inbound/update flags to the IPsec SA manager
Martin Willi
2015-03-09
1
-1
/
+2
*
kernel-interface: Add a separate "update" flag to add_sa()
Martin Willi
2015-03-09
4
-4
/
+4
*
Revert "child-sa: Remove the obsolete update logic"
Martin Willi
2015-03-09
1
-1
/
+6
*
Revert "ha: Always install the CHILD_SAs with the inbound flag set to FALSE"
Martin Willi
2015-03-09
1
-2
/
+2
*
ikev2: Move code in pubkey authenticator's build() method into separate funct...
Tobias Brunner
2015-03-09
1
-85
/
+123
*
ikev2: Try all eligible signature schemes
Tobias Brunner
2015-03-09
1
-34
/
+71
*
daemon: Remove scheduled jobs before unloading plugins
Tobias Brunner
2015-03-09
1
-1
/
+2
*
Make access requestor IP address available to TNC server
Andreas Steffen
2015-03-08
2
-12
/
+39
*
ikev1: Set protocol ID and SPIs in INITIAL-CONTACT notification payloads
Tobias Brunner
2015-03-06
1
-2
/
+13
*
ikev2: Try all RSA signature schemes if none is configured
Tobias Brunner
2015-03-04
1
-4
/
+19
*
ikev2: Consider signature schemes in rightauth when sending hash algorithms
Tobias Brunner
2015-03-04
1
-14
/
+54
*
keymat: Use hash algorithm set
Tobias Brunner
2015-03-04
1
-29
/
+7
*
ikev2: Add an option to disable constraints against signature schemes
Tobias Brunner
2015-03-04
1
-1
/
+11
*
stroke: Enable BLISS-based public key constraints
Tobias Brunner
2015-03-04
1
-4
/
+19
*
ikev2: Fall back to SHA-1 signatures for RSA
Tobias Brunner
2015-03-04
1
-0
/
+7
*
ikev2: Select a signature scheme appropriate for the given key
Tobias Brunner
2015-03-04
1
-18
/
+13
*
ikev2: Log the actual signature scheme used for RFC 7427 authentication
Tobias Brunner
2015-03-04
1
-4
/
+6
*
ikev2: Store signature scheme used to verify peer in auth_cfg
Tobias Brunner
2015-03-04
1
-0
/
+1
*
ikev2: Add a global option to disable RFC 7427 signature authentication
Tobias Brunner
2015-03-04
1
-2
/
+12
*
ikev2: Remove private AUTH_BLISS method
Tobias Brunner
2015-03-04
3
-18
/
+1
*
ikev2: Handle RFC 7427 signature authentication in pubkey authenticator
Tobias Brunner
2015-03-04
2
-49
/
+179
*
ikev2: Enable signature authentication by transmitting supported hash algorithms
Tobias Brunner
2015-03-04
2
-4
/
+88
*
keymat: Add facility to store supported hash algorithms
Tobias Brunner
2015-03-04
2
-1
/
+70
*
ikev2: Add SIGNATURE_HASH_ALGORITHMS notify payload
Tobias Brunner
2015-03-04
2
-6
/
+18
*
ikev2: Add new authentication method defined by RFC 7427
Tobias Brunner
2015-03-04
2
-3
/
+9
*
ikev2: Only accept initial messages in specific states
Tobias Brunner
2015-03-04
1
-10
/
+9
*
ike-sa-manager: Make sure the message ID of initial messages is 0
Tobias Brunner
2015-03-04
1
-1
/
+2
*
ikev2: Don't destroy the SA if an IKE_SA_INIT with unexpected MID is received
Tobias Brunner
2015-03-04
1
-4
/
+0
*
ikev2: Don't adopt any CHILD_SA during make-before-break reauthentication
Martin Willi
2015-03-04
1
-1
/
+2
*
stroke: Support public key constraints for EAP methods
Martin Willi
2015-03-03
1
-1
/
+8
*
eap-ttls: Support EAP auth information getter in EAP-TTLS
Martin Willi
2015-03-03
1
-0
/
+7
*
eap-tls: Support EAP auth information getter in EAP-TLS
Martin Willi
2015-03-03
1
-0
/
+7
*
ikev2: Merge EAP client authentication details if EAP methods provides them
Martin Willi
2015-03-03
1
-0
/
+7
*
eap: Add an optional authentication details getter to the EAP method interface
Martin Willi
2015-03-03
1
-0
/
+12
*
stroke: Serve ca section CA certificates directly, not over central CA set
Martin Willi
2015-03-03
3
-5
/
+85
*
stroke: Purge existing CA/AA certificates during reread
Martin Willi
2015-03-03
1
-0
/
+4
*
stroke: Use separate credential sets for CA/AA certificates
Martin Willi
2015-03-03
1
-3
/
+21
[prev]
[next]