Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | fixed some compiler warnings4.0.4 | Martin Willi | 2006-09-21 | 3 | -10/+10 |
| | |||||
* | extended statusall output | Martin Willi | 2006-09-21 | 3 | -11/+69 |
| | | | | | added job/event-queue statistics added allocation statistics when using LEAK_DETECTIVE | ||||
* | fixed include typo | Martin Willi | 2006-09-21 | 1 | -1/+1 |
| | |||||
* | public declaration of all HASH_SIZEs in hasher.h | Martin Willi | 2006-09-20 | 4 | -14/+13 |
| | |||||
* | support of encrypted private key files | Andreas Steffen | 2006-09-20 | 7 | -28/+61 |
| | |||||
* | support of encrypted private key files | Andreas Steffen | 2006-09-20 | 1 | -1/+19 |
| | |||||
* | added copyright notice to sha2_hasher | Martin Willi | 2006-09-19 | 3 | -4/+5 |
| | | | | included SHA2 in build process | ||||
* | implemented sha2_hasher which supports SHA-256, SHA-384 and SHA-512 | Martin Willi | 2006-09-19 | 7 | -50/+741 |
| | |||||
* | added support for 3DES encryption algorithm in IKE | Martin Willi | 2006-09-19 | 7 | -8/+1613 |
| | |||||
* | fixed the ids parsing bug | Andreas Steffen | 2006-09-19 | 1 | -0/+1 |
| | |||||
* | fixed the ids parsing bug | Andreas Steffen | 2006-09-19 | 1 | -1/+4 |
| | |||||
* | updated TODOs | Martin Willi | 2006-09-18 | 1 | -9/+10 |
| | |||||
* | fixed memleak | Martin Willi | 2006-09-18 | 1 | -10/+27 |
| | | | | | fixed proper handling of id parsing errors proper return value when no PSK found | ||||
* | added HOST_ACCESS for firewall script as default | Martin Willi | 2006-09-18 | 1 | -0/+1 |
| | |||||
* | more debugging output for PSK authentication | Martin Willi | 2006-09-18 | 1 | -3/+11 |
| | |||||
* | some cleanups here and there | Martin Willi | 2006-09-18 | 4 | -13/+9 |
| | |||||
* | added auth_method field | Andreas Steffen | 2006-09-18 | 1 | -0/+29 |
| | |||||
* | added auth_method field | Andreas Steffen | 2006-09-18 | 1 | -0/+1 |
| | |||||
* | cosmetics | Andreas Steffen | 2006-09-18 | 1 | -1/+0 |
| | |||||
* | verify_emsa_pkcs1_signature returns status_t | Andreas Steffen | 2006-09-18 | 1 | -1/+1 |
| | |||||
* | cosmetics | Andreas Steffen | 2006-09-18 | 1 | -2/+1 |
| | |||||
* | added PSK support | Andreas Steffen | 2006-09-18 | 8 | -166/+433 |
| | |||||
* | proper error handling for socket creation | Martin Willi | 2006-09-18 | 1 | -12/+23 |
| | |||||
* | handle certificate parsing error more generous | Martin Willi | 2006-09-14 | 1 | -9/+16 |
| | |||||
* | fixed certificate verification bug! | Martin Willi | 2006-09-14 | 2 | -5/+19 |
| | |||||
* | fixed memleak when receiving invalid certificate | Martin Willi | 2006-09-14 | 1 | -0/+1 |
| | |||||
* | version bump to 4.0.4 | Andreas Steffen | 2006-09-14 | 2 | -1/+7 |
| | |||||
* | implemented updown script to handle firewalling | Martin Willi | 2006-09-12 | 9 | -32/+207 |
| | |||||
* | add priority management for kernel policy | Martin Willi | 2006-09-08 | 12 | -221/+256 |
| | | | | | | | let ROUTED policies installed, until manuall removed introduced new naming scheme to allow proper shutdown of IKE/CHILD_SAs ike_sa_manager cleanups | ||||
* | implemented handling of dpdaction and dpddelay ipsec.conf parameters | Martin Willi | 2006-09-08 | 11 | -26/+156 |
| | |||||
* | reuse reqid when a ROUTED child_sa gets INSTALLED | Martin Willi | 2006-09-05 | 35 | -477/+552 |
| | | | | | | | | | fixed a bug in retransmission code added support for the "keyingtries" ipsec.conf parameter added support for the "dpddelay" ipsec.conf parameter done some work for "dpdaction" behavior some other cleanups and fixes | ||||
* | fixed a at-least-one-year-old bug which caused crashed in the scheduler | Martin Willi | 2006-08-31 | 3 | -8/+10 |
| | |||||
* | added raw socket filter for IPv6 | Martin Willi | 2006-08-31 | 2 | -23/+16 |
| | |||||
* | implemented NAT detection for IPv6 | Martin Willi | 2006-08-31 | 1 | -36/+19 |
| | |||||
* | removed unneeded constructor | Martin Willi | 2006-08-31 | 2 | -30/+2 |
| | |||||
* | initial support for IPv6 (more testing needed) | Martin Willi | 2006-08-30 | 16 | -374/+1074 |
| | | | | | | | | | socket works (without v6 filter) traffic selector handle IPv4/v4 cleanly improvements in traffic selector code kernel interface accepts v6 traffic selectors and hosts host_t class has full IPv6 support | ||||
* | added stddef.h include for compilers which do not support the offsetof() ↵ | Martin Willi | 2006-08-28 | 1 | -0/+2 |
| | | | | directive | ||||
* | moved interface enumeration code to socket, where it belongs | Martin Willi | 2006-08-28 | 12 | -348/+207 |
| | | | | | query interfaces every time we need it to respect changes in network config added address listing on startup and "ipsec statusall" | ||||
* | fixed crash bug when doing "ipsec down" with an unknown connection | Martin Willi | 2006-08-25 | 1 | -2/+5 |
| | |||||
* | added name property in CHILD_SA, allows proper status output | Martin Willi | 2006-08-25 | 5 | -14/+75 |
| | |||||
* | (no commit message) | Martin Willi | 2006-08-25 | 1 | -5/+0 |
| | |||||
* | fixed bug which prevented port float when nat is detected | Martin Willi | 2006-08-25 | 1 | -0/+8 |
| | |||||
* | 'sha' and 'sha1' are now treated as synonyms | Andreas Steffen | 2006-08-23 | 1 | -0/+8 |
| | |||||
* | updated Changelog and other docs | Martin Willi | 2006-08-23 | 2 | -11/+10 |
| | |||||
* | fixed rekeying behavior when proposing an inacceptable DH group ↵4.0.3 | Martin Willi | 2006-08-23 | 2 | -35/+26 |
| | | | | (INVALID_KE_PAYLOAD) | ||||
* | implement proper handling of most simultaneous IKE_SA rekeying cases | Martin Willi | 2006-08-23 | 8 | -57/+288 |
| | |||||
* | implemented proper refcounting using atomic operations | Martin Willi | 2006-07-28 | 8 | -6/+79 |
| | |||||
* | implemented IKE_SA rekeying | Martin Willi | 2006-07-27 | 30 | -317/+1696 |
| | | | | | | uses ikelifetime, rekeymargin and rekeyfuzz config settings no handling of simultaneus exchanges yet! | ||||
* | added possibility to route CHILD_SAs, without to set them up | Martin Willi | 2006-07-21 | 26 | -142/+1011 |
| | | | | | | | support for auto=route parameter support for ipsec route and ipsec unroute initiating of CHILD and/or IKE_SAs based on kernel acquires | ||||
* | reuse an existing IKE_SA to set up additional CHILD_SAs | Martin Willi | 2006-07-20 | 19 | -263/+344 |
| |