Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | Removed strayed code fragment | Martin Willi | 2010-03-19 | 1 | -20/+4 | |
| | ||||||
* | ipsec pool --batch command | Heiko Hund | 2010-03-19 | 1 | -60/+200 | |
| | | | | | | | | Introduce the --batch command which reads several ipsec pool commands and their arguments from a file or STDIN. Useful if you need to run serveral commands atomically from a configuration daemon or likewise. Signed-off-by: Heiko Hund <hhund@astaro.com> | |||||
* | ipsec pool error return status | Heiko Hund | 2010-03-19 | 1 | -49/+51 | |
| | | | | | | | Fix the error return status of the ipsec pool command. Also make --del for attributes succeed if no --server option was given. Signed-off-by: Heiko Hund <hhund@astaro.com> | |||||
* | ipsec pool --replace command | Heiko Hund | 2010-03-19 | 1 | -23/+61 | |
| | | | | | | | | | Introduce the pool --replace command as an alternative to --add. Also change the current behavior of allowing duplicate pool names so that, --add with an existing name fails and --replace removes the existing pool before adding the new one. Signed-off-by: Heiko Hund <hhund@astaro.com> | |||||
* | --addresses option for ipsec pool --add command | Heiko Hund | 2010-03-19 | 1 | -5/+187 | |
| | | | | | | | | | Introduce the --addresses option for --add that can be used to add a pool containing non-contiguous addresses. Additionally it allows to preclaim certain addresses for certain roadwarrior IDs. See the second chunk of the patch for a more detailed description. Signed-off-by: Heiko Hund <hhund@astaro.com> | |||||
* | setting the two most significant bits assures an RSA modulus of maximum bit size | Andreas Steffen | 2010-03-15 | 1 | -2/+2 | |
| | ||||||
* | fix 64bit issue with time_t from database | Andreas Steffen | 2010-03-10 | 1 | -2/+8 | |
| | ||||||
* | Provide the Diffie Hellman parameters from a central location, so that we do ↵ | Tobias Brunner | 2010-03-09 | 3 | -730/+34 | |
| | | | | | | | | not have to replicate them in every plugin that implements the DH interface. The main reason for this change is that Android's libcrypto does not include the get_rfcX_prime_Y functions by default. Therefore we would have had to replicate the primes a third time. | |||||
* | Adding a helper function that translates single characters in a string. | Tobias Brunner | 2010-03-08 | 1 | -19/+2 | |
| | ||||||
* | Replaced the deprecated RSA_generate_key with RSA_generate_key_ex. | Tobias Brunner | 2010-03-08 | 1 | -2/+25 | |
| | ||||||
* | Implemented the PRF_KEYED_SHA1 algorithm in the openssl plugin | Martin Willi | 2010-03-08 | 4 | -0/+195 | |
| | ||||||
* | critical keyUsage extension must be parsed | Andreas Steffen | 2010-03-07 | 1 | -0/+3 | |
| | ||||||
* | set Certificate Sign and CRL Sign flags in keyUsage extension if CA is true | Andreas Steffen | 2010-03-07 | 1 | -4/+13 | |
| | ||||||
* | Reverting eba28948a584b9d02474cf5d256b04b8d2adbe6a which was only necessary ↵ | Tobias Brunner | 2010-03-02 | 28 | -42/+7 | |
| | | | | | | | when cross-compiling the plugins for Android 2.0. With the coming monolithic build using Android.mk files this won't be necessary anymore. | |||||
* | Streamlined the source file list formatting in plugin makefiles. | Tobias Brunner | 2010-03-02 | 28 | -52/+96 | |
| | ||||||
* | Link all enabled libstrongswan plugins into the library, link all enabled ↵ | Tobias Brunner | 2010-03-02 | 28 | -50/+155 | |
| | | | | charon plugins into libcharon. | |||||
* | Enabling the plugin loader to be able to load plugins without explicitly ↵ | Tobias Brunner | 2010-03-02 | 1 | -0/+37 | |
| | | | | loading a shared object file first. | |||||
* | Changed plugin constructors from plugin_create to plugin_name_plugin_create. | Tobias Brunner | 2010-03-02 | 30 | -35/+60 | |
| | ||||||
* | Removing the plugin constructor declarations from the header files. | Tobias Brunner | 2010-03-02 | 28 | -140/+0 | |
| | ||||||
* | Link all plugins to libstrongswan. | Tobias Brunner | 2010-02-25 | 28 | -7/+28 | |
| | ||||||
* | Use side-channel secured mpz_powm_sec of libgmp 5, if available | Martin Willi | 2010-02-18 | 3 | -0/+14 | |
| | ||||||
* | initialize variables to avoid compiler warning | Andreas Steffen | 2010-02-05 | 1 | -2/+2 | |
| | ||||||
* | Support TLS client authentication Extended Key Usage in x509 generation | Martin Willi | 2010-01-14 | 1 | -8/+16 | |
| | ||||||
* | ipsec pki --self|issue supports --pathlen option setting a path length ↵ | Andreas Steffen | 2009-12-31 | 1 | -2/+18 | |
| | | | | constraint | |||||
* | Using the thread wrapper in charon, libstrongswan and their plugins. | Tobias Brunner | 2009-12-23 | 2 | -12/+9 | |
| | ||||||
* | Separated the public interfaces of the threading primitives. | Tobias Brunner | 2009-12-23 | 4 | -4/+4 | |
| | ||||||
* | Moved mutex.c to a separate folder in order to cleanly wrap other threading ↵ | Tobias Brunner | 2009-12-23 | 4 | -4/+4 | |
| | | | | primitives (and utils/mutex.h is now threading.h). | |||||
* | X509_IP_ADDR_BLOCKS flag signals the presence of an ipAddrBlock certificate ↵ | Andreas Steffen | 2009-12-22 | 1 | -1/+2 | |
| | | | | extension | |||||
* | added create_ipAddrBlock_enumerator() method to x509_t | Andreas Steffen | 2009-12-22 | 1 | -0/+9 | |
| | ||||||
* | traffic_selector supports RFC 3779 address range format | Andreas Steffen | 2009-12-21 | 1 | -7/+75 | |
| | ||||||
* | parse RFC 3779 addressFamily | Andreas Steffen | 2009-12-20 | 1 | -2/+16 | |
| | ||||||
* | plugin name is x509 | Andreas Steffen | 2009-12-20 | 1 | -1/+1 | |
| | ||||||
* | discard certificate with unknown critical extensions | Andreas Steffen | 2009-12-20 | 1 | -0/+8 | |
| | ||||||
* | use traffic_selector_t object to represent ipAddrBlocks | Andreas Steffen | 2009-12-20 | 1 | -1/+2 | |
| | ||||||
* | parse ipAddrBlocks | Andreas Steffen | 2009-12-17 | 1 | -1/+69 | |
| | ||||||
* | Migrated curl_fetcher to INIT/METHOD macros | Martin Willi | 2009-12-17 | 1 | -22/+18 | |
| | ||||||
* | ipsec pool manages dns and nbns servers | Andreas Steffen | 2009-12-16 | 1 | -15/+298 | |
| | ||||||
* | cosmetics | Andreas Steffen | 2009-12-16 | 1 | -1/+1 | |
| | ||||||
* | provide attributes from SQL database | Andreas Steffen | 2009-12-16 | 1 | -1/+21 | |
| | ||||||
* | Removed obsolete curl interface specific destructor | Martin Willi | 2009-12-08 | 1 | -5/+0 | |
| | ||||||
* | Give plugins more control of which configuration attributes to request, and ↵ | Martin Willi | 2009-11-17 | 1 | -1/+1 | |
| | | | | pass received attributes back to the requesting handler | |||||
* | Prefer MODP2048/1536 over ECP Diffie-Hellman groups | Martin Willi | 2009-11-12 | 1 | -11/+9 | |
| | ||||||
* | added some debugging to pgp certificate parsing | Andreas Steffen | 2009-11-10 | 2 | -8/+35 | |
| | ||||||
* | accept PGP v3 or v4 fingerprint as alternative to PGP user_id | Andreas Steffen | 2009-11-09 | 1 | -2/+11 | |
| | ||||||
* | list v3 or v4 fingerprint | Andreas Steffen | 2009-11-08 | 1 | -3/+54 | |
| | ||||||
* | define TIME_32_BITS_SIGNED_MAX in utils.h | Andreas Steffen | 2009-11-08 | 1 | -2/+2 | |
| | ||||||
* | implemented path length constraint checkinf for IKEv2 | Andreas Steffen | 2009-11-04 | 1 | -1/+1 | |
| | ||||||
* | output optional pathLenConstraint in ipsec listcacerts | Andreas Steffen | 2009-11-04 | 1 | -0/+9 | |
| | ||||||
* | implemented parsing of pathLenConstraint | Andreas Steffen | 2009-11-04 | 1 | -11/+36 | |
| | ||||||
* | Fixed all doxygen warnings | Martin Willi | 2009-10-22 | 12 | -16/+16 | |
| |