Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | swanctl: Properly register --counters commmand | Tobias Brunner | 2017-11-13 | 1 | -1/+1 |
| | | | | Use C instead of c, which is already used for --load-conns. | ||||
* | swanctl: Add --counters command | Tobias Brunner | 2017-11-08 | 1 | -0/+154 |
| | |||||
* | swanctl: Use returned key ID to track loaded private keys | Tobias Brunner | 2017-05-23 | 1 | -13/+6 |
| | | | | | | There was a direct call to load_key() for unencrypted keys that didn't remove the key ID from the hashtable, which caused keys to get unloaded when --load-creds was called multiple times. | ||||
* | swanctl: Add --rekey command | Tobias Brunner | 2017-02-16 | 1 | -0/+125 |
| | |||||
* | vici: Use unique names for CHILD_SAs in the list-sas command | Tobias Brunner | 2017-02-16 | 1 | -2/+3 |
| | | | | | | | | | The original name is returned in the new "name" attribute. This fixes an issue with bindings that map VICI messages to dictionaries. For instance, in roadwarrior scenarios where every CHILD_SA has the same name only the information of the last CHILD_SA would end up in the dictionary for that name. | ||||
* | swanctl: Allow specifying pubkeys directly via 0x/0s prefix | Tobias Brunner | 2017-02-16 | 1 | -28/+38 |
| | |||||
* | vici: Add support to load CA certificates from tokens and paths in authority ↵ | Tobias Brunner | 2017-02-16 | 1 | -4/+4 |
| | | | | sections | ||||
* | swanctl: Add `token` secrets for keys on tokens/smartcards | Tobias Brunner | 2017-02-16 | 1 | -0/+90 |
| | |||||
* | swanctl: Pass optional connection name to --initiate/install/uninstall | Tobias Brunner | 2017-02-16 | 2 | -5/+22 |
| | |||||
* | vici: Add support for NT Hash secrets | Tobias Brunner | 2017-02-16 | 1 | -1/+3 |
| | | | | Fixes #1002. | ||||
* | vici: Add support for certificate policies | Tobias Brunner | 2017-02-16 | 1 | -0/+1 |
| | |||||
* | swanctl: Automatically unload removed shared keys | Tobias Brunner | 2017-02-16 | 1 | -15/+49 |
| | |||||
* | swanctl: Automatically unload removed private keys | Tobias Brunner | 2017-02-16 | 1 | -76/+175 |
| | |||||
* | swanctl: Add possibility to query a specific pool by name | Tobias Brunner | 2017-02-16 | 1 | -3/+11 |
| | |||||
* | swanctl: List CHILD_SA marks, if set | Martin Willi | 2017-02-13 | 1 | -0/+18 |
| | |||||
* | swanctl: Add 'private' directory/section to load any type of private key | Tobias Brunner | 2016-10-05 | 1 | -5/+10 |
| | |||||
* | vici: flush-certs command flushes certificate cache | Andreas Steffen | 2016-09-13 | 1 | -0/+90 |
| | | | | | | | | | | When fresh CRLs are released with a high update frequency (e.g. every 24 hours) or OCSP is used then the certificate cache gets quickly filled with stale CRLs or OCSP responses. The new VICI flush-certs command allows to flush e.g. cached CRLs or OCSP responses only. Without the type argument all kind of certificates (e.g. also received end entity and intermediate CA certificates) are purged. | ||||
* | vici: Increased various string buffers to BUF_LEN (512 bytes) | Andreas Steffen | 2016-07-29 | 1 | -1/+1 |
| | |||||
* | swanctl: indicate initiator and responder in --list-sas | Andreas Steffen | 2016-05-07 | 1 | -2/+5 |
| | |||||
* | swanctl: Do not display rekey times for shunts | Andreas Steffen | 2016-05-05 | 1 | -3/+5 |
| | |||||
* | vici list-conns sends reauthentication and rekeying time information | Andreas Steffen | 2016-05-04 | 1 | -2/+71 |
| | |||||
* | swanctl: --list-conns shows eap_id, xauth_id and aaa_id | Andreas Steffen | 2016-05-04 | 1 | -0/+13 |
| | |||||
* | swanctl: list EAP type in --list-conns | Andreas Steffen | 2016-04-26 | 1 | -3/+10 |
| | |||||
* | swanctl: log errors to stderr | Andreas Steffen | 2016-04-24 | 3 | -3/+3 |
| | |||||
* | Include manual policy priorities and restriction to interfaces in vici ↵ | Andreas Steffen | 2016-04-09 | 1 | -0/+13 |
| | | | | list-conn command | ||||
* | Display IKE ports with swanctl --list-sas | Andreas Steffen | 2016-03-05 | 1 | -4/+9 |
| | |||||
* | vici: Match subnets and ranges against peer IP in redirect command | Tobias Brunner | 2016-03-04 | 1 | -1/+1 |
| | |||||
* | vici: Match identity with wildcards against remote ID in redirect command | Tobias Brunner | 2016-03-04 | 1 | -1/+1 |
| | |||||
* | swanctl: Add --redirect command | Tobias Brunner | 2016-03-04 | 1 | -0/+132 |
| | |||||
* | swanctl: Load pubkeys with load-creds | Andreas Steffen | 2016-01-09 | 1 | -0/+1 |
| | |||||
* | vici: list-cert sends subject, not-before and not-after attributes for pubkeys | Andreas Steffen | 2016-01-09 | 1 | -5/+36 |
| | |||||
* | vici: Support of raw public keys | Andreas Steffen | 2016-01-09 | 1 | -1/+8 |
| | |||||
* | swanctl: Slightly change usage summary for --list-certs | Tobias Brunner | 2015-12-16 | 1 | -4/+3 |
| | |||||
* | swanctl --stats lists loaded plugins | Andreas Steffen | 2015-12-13 | 1 | -0/+12 |
| | |||||
* | Refactored certificate management for the vici and stroke interfaces5.4.0dr1 | Andreas Steffen | 2015-12-12 | 2 | -52/+59 |
| | |||||
* | Removed VICI protocol versioning | Andreas Steffen | 2015-12-11 | 1 | -14/+7 |
| | |||||
* | Use of certificate_printer by swanctl --list-certs command | Andreas Steffen | 2015-12-11 | 1 | -495/+19 |
| | |||||
* | Share vici_cert_info.c with vici_cred.c | Andreas Steffen | 2015-12-11 | 1 | -6/+17 |
| | |||||
* | Use VICI 2.0 protocol version for certificate queries | Andreas Steffen | 2015-12-11 | 2 | -80/+124 |
| | |||||
* | swanctl: Add --list-algs command to query loaded algorithms | Tobias Brunner | 2015-11-30 | 1 | -0/+104 |
| | |||||
* | swanctl: Add option to query leases with --get-pools | Tobias Brunner | 2015-11-10 | 1 | -3/+29 |
| | |||||
* | swanctl: List virtual IPs in --list-sas | Tobias Brunner | 2015-11-10 | 1 | -1/+11 |
| | |||||
* | Improved legibility of swanctl CRL listings5.3.3dr1 | Andreas Steffen | 2015-07-22 | 1 | -1/+4 |
| | |||||
* | vici: Certification Authority support added. | Andreas Steffen | 2015-07-21 | 4 | -1/+567 |
| | | | | | | CDP and OCSP URIs for a one or multiple certification authorities can be added via the VICI interface. swanctl allows to read definitions from a new authorities section. | ||||
* | swanctl: Implement monitoring of IKE_SA and CHILD_SA changes | Timo Teräs | 2015-05-04 | 1 | -1/+83 |
| | | | | Signed-off-by: Timo Teräs <timo.teras@iki.fi> | ||||
* | swanctl: Add missing unit in install-time log | Romain Francoise | 2015-05-04 | 1 | -1/+1 |
| | |||||
* | swanctl: Append /ESN to proposal for a CHILD_SA using Extended Sequence Numbers | Martin Willi | 2015-03-23 | 1 | -1/+1 |
| | | | | | | | We previously printed just the value for the "esn" keyword, which is "1", and not helpful as such. Fixes #904. | ||||
* | vici: Return authentication rounds with unique names | Martin Willi | 2015-03-18 | 1 | -2/+3 |
| | | | | | | To simplify handling of authentication rounds in dictionaries/hashtables on the client side, we assign unique names to each authentication round when listing connection. | ||||
* | swanctl: Cache entered PKCS#12 decryption secret | Martin Willi | 2015-03-18 | 1 | -6/+23 |
| | | | | | It is usually used more than once, but most likely the same for decryption and MAC verification. | ||||
* | swanctl: Support loading PKCS#12 containers from a pkcs12 swanctl directory | Martin Willi | 2015-03-18 | 1 | -0/+113 |
| |