Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | implemented proper refcounting using atomic operations | Martin Willi | 2006-07-28 | 2 | -0/+64 |
| | |||||
* | implemented IKE_SA rekeying | Martin Willi | 2006-07-27 | 2 | -0/+56 |
| | | | | | | uses ikelifetime, rekeymargin and rekeyfuzz config settings no handling of simultaneus exchanges yet! | ||||
* | reuse an existing IKE_SA to set up additional CHILD_SAs | Martin Willi | 2006-07-20 | 2 | -20/+20 |
| | |||||
* | introduced refcounting on policy and connections | Martin Willi | 2006-07-20 | 1 | -0/+5 |
| | | | | | | | | | aren't stored in the IKE_SA anymore, they are queried on the fly are immutable now, allows it to share them policy selection based on traffic selectors, leads to valid lookup results rekeying queries the policy based on its traffic selectors | ||||
* | cleanups in kernel interface code | Martin Willi | 2006-07-18 | 3 | -57/+34 |
| | | | | | | added proper traffic selector to string conversion some cleanups here & there | ||||
* | leak detective blanks memory on free & alloc, allows further membug detection | Martin Willi | 2006-07-12 | 2 | -13/+27 |
| | |||||
* | code cleanups | Martin Willi | 2006-07-12 | 2 | -84/+43 |
| | |||||
* | identification_t.matches() supports multiple wildcard counts | Andreas Steffen | 2006-07-11 | 2 | -85/+124 |
| | |||||
* | reenabled check_expiry | Martin Willi | 2006-07-07 | 1 | -6/+6 |
| | |||||
* | updated copyright information | Martin Willi | 2006-07-07 | 48 | -48/+96 |
| | |||||
* | updated whitelist (getprotobynumber) | Martin Willi | 2006-07-05 | 1 | -0/+2 |
| | |||||
* | fixed compiler warnings | Martin Willi | 2006-07-05 | 8 | -30/+26 |
| | |||||
* | updated leak detective whitelist | Martin Willi | 2006-07-04 | 1 | -5/+6 |
| | |||||
* | support of cert payloads | Andreas Steffen | 2006-07-03 | 4 | -11/+119 |
| | |||||
* | added X.509 trust chain verification | Andreas Steffen | 2006-06-27 | 12 | -95/+636 |
| | |||||
* | applied new changes from NATT team | Martin Willi | 2006-06-23 | 1 | -0/+1 |
| | | | | | DPD only done when no IPsec and IKE traffic processed minor changes here and there | ||||
* | fixed identification_t clone to apply function pointers | Martin Willi | 2006-06-23 | 1 | -0/+3 |
| | |||||
* | first merge of NATT code | Martin Willi | 2006-06-22 | 3 | -5/+97 |
| | |||||
* | fixed whitelist detection | Martin Willi | 2006-06-20 | 1 | -4/+8 |
| | |||||
* | reworked function ignore mechanism to not-report whitelist | Martin Willi | 2006-06-20 | 1 | -233/+46 |
| | | | | rather than overriding functions | ||||
* | readded local_credential_store | Martin Willi | 2006-06-20 | 1 | -13/+0 |
| | | | | | | added sendcert policy to connection some other cleanups | ||||
* | implemented rereadcrls rereadcacerts | Andreas Steffen | 2006-06-20 | 3 | -4/+22 |
| | |||||
* | added chunk_equals_or_null() | Andreas Steffen | 2006-06-16 | 2 | -26/+43 |
| | |||||
* | added crl support | Andreas Steffen | 2006-06-16 | 1 | -12/+31 |
| | |||||
* | changed tabs from 8 to 4 spaces | Andreas Steffen | 2006-06-16 | 1 | -1/+1 |
| | |||||
* | added crl support | Andreas Steffen | 2006-06-16 | 2 | -0/+604 |
| | |||||
* | cosmetics | Andreas Steffen | 2006-06-16 | 1 | -7/+21 |
| | |||||
* | cosmetics (space) | Andreas Steffen | 2006-06-16 | 1 | -1/+1 |
| | |||||
* | fixed aes code, we support now aes128, aes192, aes256 in IKE | Martin Willi | 2006-06-15 | 1 | -10/+2 |
| | |||||
* | corrected some descriptions | Andreas Steffen | 2006-06-13 | 1 | -5/+5 |
| | |||||
* | moved RSA key size constraints to definitions.h | Andreas Steffen | 2006-06-13 | 2 | -7/+7 |
| | |||||
* | NULL string argument is treated as %any | Andreas Steffen | 2006-06-12 | 1 | -0/+3 |
| | |||||
* | workaround for peers rekeying at the same time | Martin Willi | 2006-06-12 | 2 | -2/+2 |
| | | | | | loading lifetime policies from ipsec.conf | ||||
* | added support for leftsendcert= and left|rightca= parameters | Andreas Steffen | 2006-06-09 | 1 | -0/+12 |
| | |||||
* | added public methods is_ca() and is_valid() | Andreas Steffen | 2006-06-09 | 2 | -62/+97 |
| | |||||
* | changed ASN.1 CONTROL log output to LEVEL2 | Andreas Steffen | 2006-06-09 | 1 | -8/+8 |
| | |||||
* | cosmetics | Andreas Steffen | 2006-06-09 | 1 | -1/+1 |
| | |||||
* | proper leak detective hook for realloc | Martin Willi | 2006-06-07 | 1 | -9/+36 |
| | | | | | excluded pthread_setspecific from leak detective | ||||
* | minimized prefixed on stroke logger output | Andreas Steffen | 2006-05-31 | 1 | -7/+9 |
| | |||||
* | computation of SHA-1 hash over publicKeyInfo object | Andreas Steffen | 2006-05-30 | 3 | -104/+128 |
| | |||||
* | moved abbreviated thread_id in front of brackets | Andreas Steffen | 2006-05-30 | 1 | -3/+3 |
| | |||||
* | added has_key parameter to log_certificates() | Andreas Steffen | 2006-05-30 | 1 | -2/+4 |
| | |||||
* | log_certificates() now shows keyid and availability of matching private key | Andreas Steffen | 2006-05-30 | 1 | -7/+11 |
| | |||||
* | indented loaded file log entry | Andreas Steffen | 2006-05-30 | 1 | -1/+1 |
| | |||||
* | moved TIMETOA_BUF definition to types.h | Andreas Steffen | 2006-05-30 | 1 | -3/+0 |
| | |||||
* | moved TIMETOA_BUF definition from asn1.h | Andreas Steffen | 2006-05-30 | 1 | -0/+1 |
| | |||||
* | - changed iterator->remove behavior | Martin Willi | 2006-05-29 | 2 | -8/+4 |
| | |||||
* | reworked parsing and matching of subjectAltNames | Andreas Steffen | 2006-05-29 | 4 | -323/+352 |
| | |||||
* | added memeq() macro | Andreas Steffen | 2006-05-29 | 1 | -3/+6 |
| | |||||
* | moved timetoa() from asn1.c to types.c | Andreas Steffen | 2006-05-29 | 4 | -24/+53 |
| |