Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | parse xfrm and pf_key acquire messages and subscribe to migrate messages | Andreas Steffen | 2008-10-31 | 4 | -37/+216 | |
| | ||||||
* | reverted changeset 4529: | Martin Willi | 2008-10-30 | 1 | -2/+1 | |
| | | | | | Camellia is 22 in IKEv1, but not-yet defined in IKEv2 in IKEv2, 22 is reserved for AES-XTS | |||||
* | added hooks for IKE and CHILD keymat | Martin Willi | 2008-10-30 | 9 | -44/+179 | |
| | ||||||
* | store plain skd, not the prf | Martin Willi | 2008-10-30 | 2 | -23/+19 | |
| | ||||||
* | added Camellia CBC to list of encryption algorithms | Andreas Steffen | 2008-10-30 | 1 | -1/+2 | |
| | ||||||
* | corrected parameter description | Andreas Steffen | 2008-10-30 | 1 | -1/+1 | |
| | ||||||
* | moved CHILD_SA key derivation to keymat_t | Martin Willi | 2008-10-29 | 7 | -440/+438 | |
| | | | | passing key chunks to CHILD_SA, not the PRF | |||||
* | prf handles zero-length allocations graceful | Martin Willi | 2008-10-29 | 1 | -3/+10 | |
| | ||||||
* | do not store DH redundant in keymat | Martin Willi | 2008-10-29 | 3 | -52/+30 | |
| | ||||||
* | upgrade to linux-2.6.28 headers with support for kmaddress struct | Andreas Steffen | 2008-10-29 | 2 | -1/+29 | |
| | ||||||
* | moved key derivation and management into keymat object | Martin Willi | 2008-10-28 | 13 | -585/+748 | |
| | | | | | | allows secured implementation of key management (e.g. in kernel or HW) only IKE keys for now | |||||
* | store IKE proposal implicitly during derive_keys | Martin Willi | 2008-10-28 | 4 | -46/+18 | |
| | ||||||
* | fixed reauthentication time in statusall | Martin Willi | 2008-10-28 | 1 | -1/+1 | |
| | ||||||
* | refining changeset 4483 by introducing charon.dh_exponent_ansi_x9_42 key | Andreas Steffen | 2008-10-28 | 3 | -27/+62 | |
| | ||||||
* | use more generic stats getter, introducing new stats | Martin Willi | 2008-10-27 | 4 | -80/+62 | |
| | ||||||
* | including a "none" tundev to make NM happy | Martin Willi | 2008-10-27 | 1 | -44/+28 | |
| | ||||||
* | fixed some compiler warnings | Martin Willi | 2008-10-27 | 6 | -9/+11 | |
| | ||||||
* | remove unused local DH_EXPONENT_ENTROPY definition | Andreas Steffen | 2008-10-27 | 1 | -2/+0 | |
| | ||||||
* | use 512 bits of entropy for secret DH exponents | Andreas Steffen | 2008-10-26 | 4 | -2/+10 | |
| | ||||||
* | additional getters for ipcomp and UDP encap | Martin Willi | 2008-10-24 | 3 | -7/+37 | |
| | ||||||
* | more CHILD_SA refactorings | Martin Willi | 2008-10-24 | 4 | -131/+135 | |
| | ||||||
* | initiate connections simultaneously in load tester | Martin Willi | 2008-10-22 | 1 | -2/+9 | |
| | ||||||
* | a load testing plugin, to: | Martin Willi | 2008-10-21 | 10 | -0/+836 | |
| | | | | | find multi-threading issues do performance profiling | |||||
* | fixed enumeration of CHILD_SA traffic selectors | Martin Willi | 2008-10-21 | 1 | -24/+25 | |
| | ||||||
* | reset threads IKE_SA after checking other IKE_SAs | Martin Willi | 2008-10-20 | 4 | -9/+26 | |
| | | | | invoke updown script only if we have valid IKE_SA | |||||
* | re-established all previous AUD level messages | Andreas Steffen | 2008-10-17 | 3 | -6/+7 | |
| | ||||||
* | fixed perl oid generation | Martin Willi | 2008-10-16 | 1 | -2/+2 | |
| | ||||||
* | moved updown script invocation to an optional plugin | Martin Willi | 2008-10-16 | 11 | -243/+351 | |
| | ||||||
* | bus uses finally recusive locking | Martin Willi | 2008-10-16 | 1 | -47/+58 | |
| | | | | other small fixes | |||||
* | condvar->wait() can handle recursive mutex | Martin Willi | 2008-10-16 | 1 | -20/+76 | |
| | ||||||
* | added a guest.mconsole() method to script mconsole (e.g. add additional conX=) | Martin Willi | 2008-10-15 | 5 | -14/+33 | |
| | ||||||
* | cache keys for in and outbound ESP SAs | Martin Willi | 2008-10-15 | 4 | -202/+241 | |
| | | | | | removed redundant storing of traffic selectors in CHILD_SA (sa_policy_t) creating TS pairs dynamically using create_policy_enumerator() | |||||
* | store ESP keys in CHILD_SA | Martin Willi | 2008-10-15 | 4 | -57/+78 | |
| | ||||||
* | passing chunks, not prf+, to kernel interface | Martin Willi | 2008-10-14 | 7 | -210/+263 | |
| | | | | gives us better control of keymat in CHILD_SA | |||||
* | typos | Tobias Brunner | 2008-10-14 | 1 | -6/+6 | |
| | ||||||
* | reintegrated bus-refactoring branch | Martin Willi | 2008-10-14 | 30 | -911/+939 | |
| | ||||||
* | merging kernel_pfkey plugin back from kernel-interface branch | Tobias Brunner | 2008-10-14 | 22 | -274/+2176 | |
| | ||||||
* | version bump to 4.2.9 | Andreas Steffen | 2008-10-14 | 2 | -1/+3 | |
| | ||||||
* | set guest-specific kernel parameters | Martin Willi | 2008-10-10 | 6 | -47/+41 | |
| | | | | removed memory setting, use mem= instead | |||||
* | reintegrated two-sim branch providing SIM card plugin API | Martin Willi | 2008-10-10 | 19 | -423/+1154 | |
| | ||||||
* | use busybox compatible kill | Martin Willi | 2008-10-10 | 1 | -4/+4 | |
| | ||||||
* | fixed MOBIKE roaming if clients address changes | Martin Willi | 2008-10-09 | 2 | -5/+20 | |
| | ||||||
* | faster implementation of addr_in_subnet() | Andreas Steffen | 2008-10-09 | 1 | -13/+14 | |
| | ||||||
* | added proposal parsing of uncommon DH groups 3072/6144 | Martin Willi | 2008-10-08 | 1 | -0/+8 | |
| | ||||||
* | ignore routing events for our own routes | Martin Willi | 2008-10-08 | 1 | -0/+6 | |
| | ||||||
* | mobike: try to keep existing source address before switching to another | Martin Willi | 2008-10-08 | 7 | -29/+43 | |
| | ||||||
* | implemented ipsec listalgs as a stroke command | Andreas Steffen | 2008-10-08 | 7 | -21/+81 | |
| | ||||||
* | correct fix that replaces Changeset 4378 | Andreas Steffen | 2008-10-08 | 1 | -4/+6 | |
| | ||||||
* | removing fix applied by Changeset 4378 | Andreas Steffen | 2008-10-08 | 1 | -4/+2 | |
| | ||||||
* | get_subject() of a CERT_TRUSTED_PUBKEY object returns ID_PUBKEY_INFO_SHA1 ↵ | Andreas Steffen | 2008-10-08 | 1 | -1/+1 | |
| | | | | hash consistent with the IKEv2 keyid philosophy |