aboutsummaryrefslogtreecommitdiffstats
path: root/src/libstrongswan
Commit message (Collapse)AuthorAgeFilesLines
...
* fixed doxygen groupAndreas Steffen2010-04-031-1/+1
|
* change #define to PEM_BUILDER_H_Andreas Steffen2010-04-031-3/+3
|
* Attributes moved from libstrongswan to libhydra.Tobias Brunner2010-03-249-778/+0
| | | | | The attribute_manager_t instance is now located on the new hydra object instead of the lib object.
* Moving attr-sql plugin from libstrongswan to libhydra.Tobias Brunner2010-03-248-1996/+0
|
* Fixed some Doxygen warnings.Tobias Brunner2010-03-241-14/+14
|
* Fixed ipsec pool --batch commandHeiko Hund2010-03-241-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | --batch mode has shown to be buggy in very obscure ways in the first real life tests. For example a batch file --del pool1 --replace pool2 --addresses file1 returned the error "/usr/libexec/ipsec/pool: unrecognized option '--lace'" which was gone after moving the --del behind --replace. With the patch from below applied everything works like a charm. From the info on the man page it seem to be unrelated to this problem, though: A program that scans multiple argument vectors, or rescans the same vector more than once, and wants to make use of GNU extensions such as '+' and '-' at the start of optstring, or changes the value of POSIXLY_CORRECT between scans, must reinitialize getopt() by resetting optind to 0, rather than the traditional value of 1. (Resetting to 0 forces the invocation of an internal initialization routine that rechecks POSIXLY_CORRECT and checks for GNU exten- sions in optstring.) Signed-off-by: Heiko Hund <hhund@astaro.com>
* Use vstr/gmp as shared libraries in the Android build.Tobias Brunner2010-03-231-4/+2
|
* Do not indent the source file lists in Android.mk files so we can easily ↵Tobias Brunner2010-03-191-58/+58
| | | | compare them to the lists in the Makefile.am files.
* Use wildcards to gather plugin source files.Tobias Brunner2010-03-191-90/+31
|
* Removed strayed code fragmentMartin Willi2010-03-191-20/+4
|
* ipsec pool --batch commandHeiko Hund2010-03-191-60/+200
| | | | | | | | Introduce the --batch command which reads several ipsec pool commands and their arguments from a file or STDIN. Useful if you need to run serveral commands atomically from a configuration daemon or likewise. Signed-off-by: Heiko Hund <hhund@astaro.com>
* ipsec pool error return statusHeiko Hund2010-03-191-49/+51
| | | | | | | Fix the error return status of the ipsec pool command. Also make --del for attributes succeed if no --server option was given. Signed-off-by: Heiko Hund <hhund@astaro.com>
* ipsec pool --replace commandHeiko Hund2010-03-191-23/+61
| | | | | | | | | Introduce the pool --replace command as an alternative to --add. Also change the current behavior of allowing duplicate pool names so that, --add with an existing name fails and --replace removes the existing pool before adding the new one. Signed-off-by: Heiko Hund <hhund@astaro.com>
* --addresses option for ipsec pool --add commandHeiko Hund2010-03-191-5/+187
| | | | | | | | | Introduce the --addresses option for --add that can be used to add a pool containing non-contiguous addresses. Additionally it allows to preclaim certain addresses for certain roadwarrior IDs. See the second chunk of the patch for a more detailed description. Signed-off-by: Heiko Hund <hhund@astaro.com>
* EAP-MSCHAPv2 can use stored NT hashes in addition to plaintext passwordsMartin Willi2010-03-171-0/+2
|
* setting the two most significant bits assures an RSA modulus of maximum bit sizeAndreas Steffen2010-03-151-2/+2
|
* fix 64bit issue with time_t from databaseAndreas Steffen2010-03-101-2/+8
|
* Provide the Diffie Hellman parameters from a central location, so that we do ↵Tobias Brunner2010-03-095-733/+380
| | | | | | | | not have to replicate them in every plugin that implements the DH interface. The main reason for this change is that Android's libcrypto does not include the get_rfcX_prime_Y functions by default. Therefore we would have had to replicate the primes a third time.
* Adding the OpenSSL plugin to the Android build.Tobias Brunner2010-03-083-2/+20
|
* Adding a helper function that translates single characters in a string.Tobias Brunner2010-03-083-19/+32
|
* Replaced the deprecated RSA_generate_key with RSA_generate_key_ex.Tobias Brunner2010-03-081-2/+25
|
* Implemented the PRF_KEYED_SHA1 algorithm in the openssl pluginMartin Willi2010-03-085-7/+202
|
* critical keyUsage extension must be parsedAndreas Steffen2010-03-071-0/+3
|
* set Certificate Sign and CRL Sign flags in keyUsage extension if CA is trueAndreas Steffen2010-03-072-5/+14
|
* Build libstrongswan before building any plugins during the non-monolithic ↵Tobias Brunner2010-03-051-0/+4
| | | | build (as it was before).
* The parsed timeval is unsigned.Tobias Brunner2010-03-031-2/+2
|
* The return value of snprintf is int not size_t.Tobias Brunner2010-03-032-3/+4
|
* Add braces around empty body in if statementMartin Willi2010-03-031-1/+1
|
* Use "static const", some GCCs don't like "const static"Martin Willi2010-03-031-2/+2
|
* Adding Android.mk files to build charon and libstrongswan with the Android ↵Tobias Brunner2010-03-033-1/+178
| | | | build system.
* Reverting eba28948a584b9d02474cf5d256b04b8d2adbe6a which was only necessary ↵Tobias Brunner2010-03-0228-42/+7
| | | | | | | when cross-compiling the plugins for Android 2.0. With the coming monolithic build using Android.mk files this won't be necessary anymore.
* Streamlined the source file list formatting in plugin makefiles.Tobias Brunner2010-03-0228-52/+96
|
* Fixing some includes by replacing <> with "".Tobias Brunner2010-03-0217-44/+38
| | | | I changed only the includes needed to fix the build on Android, which has an utils.h system header file, but we should probably change all the local includes in libstrongswan to "" and relative paths.
* Link all enabled libstrongswan plugins into the library, link all enabled ↵Tobias Brunner2010-03-0229-51/+240
| | | | charon plugins into libcharon.
* Enabling the plugin loader to be able to load plugins without explicitly ↵Tobias Brunner2010-03-021-0/+37
| | | | loading a shared object file first.
* Changed plugin constructors from plugin_create to plugin_name_plugin_create.Tobias Brunner2010-03-0230-35/+60
|
* Removing the plugin constructor declarations from the header files.Tobias Brunner2010-03-0228-140/+0
|
* Link all plugins to libstrongswan.Tobias Brunner2010-02-2528-7/+28
|
* Use side-channel secured mpz_powm_sec of libgmp 5, if availableMartin Willi2010-02-183-0/+14
|
* Adding support for AES GMAC (RFC4543).Tobias Brunner2010-02-121-89/+92
|
* initialize variables to avoid compiler warningAndreas Steffen2010-02-051-2/+2
|
* corrected captionsAndreas Steffen2010-02-011-2/+2
|
* Added a METHOD2() macro that implements a method for two different interfacesMartin Willi2010-01-211-1/+11
|
* Support TLS client authentication Extended Key Usage in x509 generationMartin Willi2010-01-144-18/+30
|
* Added a "double" getter to libstrongswan settingsMartin Willi2010-01-112-0/+35
|
* Cast unaligned memcpy() args to char*, avoids over-optimization on ARMMartin Willi2010-01-111-4/+10
| | | | See http://infocenter.arm.com/help/index.jsp?topic=/com.arm.doc.faqs/ka3934.html
* added some recent new attributes registered with IANAAndreas Steffen2010-01-072-3/+9
|
* ipsec pki --self|issue supports --pathlen option setting a path length ↵Andreas Steffen2009-12-313-2/+21
| | | | constraint
* Added a workaround for the missing pthread_cancel on Android.Tobias Brunner2009-12-231-0/+35
|
* Use pthread_cond_timedwait_monotonic on Android.Tobias Brunner2009-12-232-2/+9
|