index
:
tteras/strongswan
master
tteras
tteras-release
tteras' strongSwan tree
gitolite
about
summary
refs
log
tree
commit
diff
stats
log msg
author
committer
range
path:
root
/
src
/
libcharon
Commit message (
Expand
)
Author
Age
Files
Lines
...
*
|
Add missing XAuthRespPSK switch case to IKEv1 key derivation
Martin Willi
2013-03-12
1
-0
/
+1
*
|
Support mutliple subnets and ranges as external load-tester addresses
Martin Willi
2013-03-11
1
-15
/
+59
*
|
Clean up IKE_SA state if IKE_SA_INIT request does not have message ID 0
Martin Willi
2013-03-11
1
-0
/
+4
*
|
Ignore fourth Qick Mode message sent by Windows servers.
Martin Willi
2013-03-11
1
-0
/
+9
*
|
As Quick Mode initiator, select a subset of the proposed and the returned TS
Martin Willi
2013-03-07
1
-4
/
+11
*
|
instead of cloning use extract_buf() method
Andreas Steffen
2013-03-04
1
-1
/
+1
*
|
Fixed Doxygen comments after scanning complete src directory
Tobias Brunner
2013-03-02
4
-5
/
+5
*
|
Removed backend for old Android frontend patch
Tobias Brunner
2013-03-02
12
-923
/
+82
*
|
added ERX_SUPPORTED IKEv2 Notify
Andreas Steffen
2013-03-02
2
-7
/
+11
*
|
Merge branch 'multi-eap'
Martin Willi
2013-03-01
2
-28
/
+50
|
\
\
|
*
|
Apply a mutual EAP auth_cfg not before the EAP method completes
Martin Willi
2013-02-26
2
-1
/
+18
|
*
|
Be a little more verbose why a peer_cfg is inacceptable
Martin Willi
2013-02-26
1
-8
/
+16
|
*
|
Refactor auth_cfg applying to a common function
Martin Willi
2013-02-26
1
-20
/
+17
*
|
|
Merge branch 'multi-cert'
Martin Willi
2013-03-01
1
-15
/
+32
|
\
\
\
|
*
|
|
Load multiple comma seperarated certificates in the leftcert option
Martin Willi
2013-01-18
1
-15
/
+32
*
|
|
|
Merge branch 'systime'
Martin Willi
2013-03-01
6
-0
/
+452
|
\
\
\
\
|
*
|
|
|
systime-fix disables certificate lifetime validation if system time not synced
Martin Willi
2013-02-19
4
-0
/
+326
|
*
|
|
|
Add a stub for systime-fix, a plugin handling certificate lifetimes gracefully
Martin Willi
2013-02-19
4
-0
/
+126
|
|
|
_
|
/
|
|
/
|
|
*
|
|
|
Merge branch 'ikev1-rekeying'
Martin Willi
2013-03-01
1
-0
/
+21
|
\
\
\
\
|
*
|
|
|
When detecting a duplicate IKEv1 SA, adopt children, as it might be a rekeying
Martin Willi
2013-02-20
1
-0
/
+21
*
|
|
|
|
Merge branch 'vip-shunts'
Martin Willi
2013-03-01
1
-11
/
+6
|
\
\
\
\
\
|
*
|
|
|
|
Include local address for Unity Split-Exclude shunt policies
Martin Willi
2013-02-20
1
-10
/
+5
|
|
/
/
/
/
*
|
|
|
|
Merge branch 'opaque-ports'
Martin Willi
2013-03-01
7
-12
/
+18
|
\
\
\
\
\
|
*
|
|
|
|
Don't reject OPAQUE ports while verifying traffic selector substructure
Martin Willi
2013-02-21
1
-1
/
+5
|
*
|
|
|
|
Pass complete port range over stroke interface for more flexibility
Martin Willi
2013-02-21
1
-14
/
+4
|
*
|
|
|
|
Use a complete port range in traffic_selector_create_from_{subnet,cidr}
Martin Willi
2013-02-21
6
-14
/
+24
|
|
|
/
/
/
|
|
/
|
|
|
*
|
|
|
|
Without MOBIKE, update remote host only if it is behind NAT
Martin Willi
2013-03-01
1
-2
/
+3
*
|
|
|
|
Merge branch 'ikev1-mm-retransmits'
Martin Willi
2013-03-01
4
-45
/
+55
|
\
\
\
\
\
|
*
|
|
|
|
For IKEv1 Main Mode, use message hash to detect early retransmissions
Martin Willi
2013-02-25
1
-10
/
+23
|
*
|
|
|
|
Move initial message dropping to task manager
Martin Willi
2013-02-25
3
-19
/
+27
|
*
|
|
|
|
Use INIT macro to initialize IKE_SA manager entries
Martin Willi
2013-02-25
1
-17
/
+6
|
|
|
/
/
/
|
|
/
|
|
|
*
|
|
|
|
Merge branch 'tfc-notify'
Martin Willi
2013-03-01
1
-0
/
+9
|
\
\
\
\
\
|
*
|
|
|
|
Send ESP_TFC_PADDING_NOT_SUPPORTED if the used kernel doesn't support it
Martin Willi
2013-03-01
1
-0
/
+9
|
|
|
/
/
/
|
|
/
|
|
|
*
|
|
|
|
Trigger an updown event when destroying an IKE_SA based on INITIAL_CONTACT
Tobias Brunner
2013-02-28
1
-0
/
+1
|
|
_
|
_
|
/
|
/
|
|
|
*
|
|
|
Android.mk updated to latest Makefiles
Tobias Brunner
2013-02-26
1
-1
/
+1
|
|
/
/
|
/
|
|
*
|
|
treat IF-M and IF-TNCCS remediation instructions/parameters in an equal way
Andreas Steffen
2013-02-19
3
-97
/
+198
*
|
|
Streamlined log messages in ipseckey plugin
Andreas Steffen
2013-02-19
2
-58
/
+30
*
|
|
ipseckey: Report IPSECKEYs with invalid DNSSEC security state
Reto Guadagnini
2013-02-19
1
-2
/
+12
*
|
|
ipseckey: Added "enable" option for the IPSECKEY plugin to strongswan.conf
Reto Guadagnini
2013-02-19
1
-3
/
+16
*
|
|
Added ipseckey plugin, which provides support for public keys in IPSECKEY RRs
Reto Guadagnini
2013-02-19
8
-0
/
+859
*
|
|
added missing return statement
Andreas Steffen
2013-02-19
1
-0
/
+1
*
|
|
reject PB-Experimental messages with NOSKIP flag set
Andreas Steffen
2013-02-19
1
-0
/
+7
*
|
|
Add a timeout to clean up PDP RADIUS connections
Martin Willi
2013-02-14
1
-0
/
+51
*
|
|
Keep the PDP connections lock while accessing its objects
Martin Willi
2013-02-14
3
-7
/
+34
*
|
|
Add locking to TNC-PDP connections
Martin Willi
2013-02-14
1
-7
/
+23
*
|
|
Add a global return_success() method implementation
Martin Willi
2013-02-14
1
-8
/
+2
*
|
|
Merge branch 'ike-dscp'
Martin Willi
2013-02-14
13
-59
/
+163
|
\
\
\
|
*
|
|
Add a ikedscp ipsec.conf option to set DSCP value on outgoing IKE packets
Martin Willi
2013-02-06
1
-1
/
+1
|
*
|
|
Set configured DSCP value while generating IKE packets
Martin Willi
2013-02-06
1
-1
/
+26
|
*
|
|
Add a DSCP configuration value to IKE configs
Martin Willi
2013-02-06
11
-21
/
+38
[prev]
[next]