aboutsummaryrefslogtreecommitdiffstats
path: root/src/starter/keywords.h
Commit message (Collapse)AuthorAgeFilesLines
* Add a ikedscp ipsec.conf option to set DSCP value on outgoing IKE packetsMartin Willi2013-02-061-1/+1
|
* Use a connection specific option to en-/disable IKEv1 fragmentationTobias Brunner2012-12-241-0/+1
|
* Remove unused ipsec.conf left/rightnatip keywordMartin Willi2012-08-211-3/+0
|
* Add a left/rightdns keyword to configure connection specific DNS attributesMartin Willi2012-08-211-0/+3
|
* Add an ipsec.conf leftgroups2 parameter for the second authentication roundMartin Willi2012-07-261-0/+3
|
* ldaphost and ldapbase ca section keywords are deprecatedTobias Brunner2012-06-251-2/+0
|
* starter: Print additional help texts for selected deprecated keywords.Tobias Brunner2012-06-121-0/+2
|
* starter: Improved how deprecated keywords are handled.Tobias Brunner2012-06-121-7/+13
| | | | We only throw a warning now instead of rejecting the config.
* starter: Removed all unsupported keywords.Tobias Brunner2012-06-111-41/+8
|
* starter: Remove left|rightsubnetwithin option (charon narrows ↵Tobias Brunner2012-06-111-3/+0
| | | | left|rightsubnet down accordingly).
* starter: Don't resolve any addresses in starter.Tobias Brunner2012-06-111-2/+1
| | | | Also removed remains of some unknown iface option.
* starter: Removed pfs and pfsgroup options (handled via esp option).Tobias Brunner2012-06-111-2/+0
|
* starter: Remove left|rightnexthop option.Tobias Brunner2012-06-111-3/+0
| | | | Charon does this lookup dynamically.
* Dropped support of deprecated authby=eap and eap= optionsMartin Willi2012-03-201-1/+0
|
* Added a "aggressive" ipsec.conf connection optionMartin Willi2012-03-201-0/+1
|
* Add a closeaction ipsec.conf keyword to configure close actionMartin Willi2011-06-071-0/+1
|
* Added a left/rightcertpolicy keyword to specify certificatePolicy requirementsMartin Willi2011-01-071-0/+3
|
* Added a tfc ipsec.conf keyword to control Traffic Flow ConfidentialityMartin Willi2010-12-201-1/+2
|
* Fixed left-/rightnexthop ipsec.conf options.Tobias Brunner2010-09-031-1/+1
|
* Added support for the ipsec.conf aaa_identity keywordMartin Willi2010-08-311-0/+1
|
* configuration of different marks for inbound and outbound directionAndreas Steffen2010-07-091-1/+3
|
* support of xfrm marks for IKEv2Andreas Steffen2010-07-021-1/+2
|
* introduced xauth_identity keywordAndreas Steffen2010-05-151-0/+1
|
* Add reqid keyword to config connection section.Reto Buerki2010-05-041-1/+2
|
* Fixed starter left-/rightikeport keywordMartin Willi2010-02-261-0/+1
|
* Added left-/rightikeport ipsec.conf options to use custom IKE portsMartin Willi2010-02-261-0/+2
|
* Added a ipsec.conf "inactivity" option to configure inactivity timeout for ↵Martin Willi2010-01-271-0/+1
| | | | CHILD_SAs
* Added keywords for the new lifetime limits to starter.Tobias Brunner2009-09-011-1/+5
|
* fixe KW_END_FIRST..KW_END_LAST keyword rangeAndreas Steffen2009-07-281-0/+5
|
* removing svn keyword $Id$ from all filesTobias Brunner2009-04-301-2/+0
|
* conversion from 8 spaces to 4 spaces per tabAndreas Steffen2009-04-191-165/+165
|
* merged multi-auth branch back into trunkMartin Willi2009-04-141-0/+10
|
* preliminary support of Mobile IPv6Andreas Steffen2008-11-111-0/+1
|
* ported parts of two-sim branchMartin Willi2008-08-221-0/+1
| | | | | | eap_identity parameter to exchange in eap_identity some auth_info/peer_cfg refactorings fixed some bugs, introduced new ones
* support of plutostderrlog keywordAndreas Steffen2008-05-111-0/+1
|
* support for hash and URL encoded certificate payloads in charonTobias Brunner2008-04-181-2/+2
|
* support of force_keepalive parameterAndreas Steffen2008-04-021-0/+1
|
* changed external interface to the mediation extension.Tobias Brunner2008-03-271-2/+2
|
* mediation extension adapted to the naming convention of the current version ↵Tobias Brunner2008-03-261-4/+4
| | | | of the draft. note: the external interface (config, autotools) has not yet been changed
* merged the modularization branch (credentials) back to trunkMartin Willi2008-03-131-1/+0
|
* added RCSIDAndreas Steffen2007-10-081-1/+1
|
* experimental P2P-NAT-T for IKEv2 merged back from branchTobias Brunner2007-10-031-1/+5
|
* renamed force_encap to forceencaps (as it is named in openswan)Martin Willi2007-10-021-1/+1
|
* implemented IKEv2 force_encap connection parameterMartin Willi2007-10-011-0/+1
| | | | | enforces UDP encapsulation by faking NAT detection payloads to hurdle restrictive firewalls
* added mobike=yes|no connection optionMartin Willi2007-08-291-0/+1
| | | | | | | yes: include mobike support notifies as initiator no: only enable mobike as responder when initiator supports it default: yes
* support of PKCS#11 init arguments required by NSS softoken, patch ↵Andreas Steffen2007-07-031-0/+1
| | | | contributed by Robert Varga
* cosmeticsAndreas Steffen2007-06-271-2/+2
|
* support of right|leftallowany flagAndreas Steffen2007-06-181-0/+3
|
* last CA keyword is KW_OCSPURI2Andreas Steffen2007-02-241-1/+1
|
* support of ca info recordsAndreas Steffen2007-02-231-0/+1
|