Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | Exposed the mutli-overlay functionality in the ruby bindings. | Tobias Brunner | 2010-10-12 | 3 | -8/+71 | |
| | | | | | | | | Overlays can be added to individual guests (which overlays exactly the supplied directory) or to all guests (which overlays a subdirectory with the guest's name to each guest). The template functionality is provided as before. | |||||
* | Added support for multiple overlays to the main library. | Tobias Brunner | 2010-10-12 | 2 | -37/+161 | |
| | | | | Also implemented the template functionality using the new overlay functions. | |||||
* | Added support for multiple overlays to guests (replaces the template ↵ | Tobias Brunner | 2010-10-12 | 2 | -25/+47 | |
| | | | | | | | functionality). Compared to a template an overlay is an arbitrary directory, not the parent directory of a directory with the guest's name. | |||||
* | Added support for multiple overlays to the copy-on-write filesystem. | Tobias Brunner | 2010-10-12 | 2 | -80/+200 | |
| | ||||||
* | Do not add additional addresses to MOBIKE path probing messages. | Tobias Brunner | 2010-10-12 | 1 | -10/+12 | |
| | ||||||
* | Change behavior of responder during roaming. | Tobias Brunner | 2010-10-12 | 1 | -16/+17 | |
| | | | | | | If the current source address is not available anymore, the responder uses ike_mobike_t.roam, thus, uses multiple address combinations when trying to notify the initiator. | |||||
* | Allow responder to use ike_mobike_t.roam. | Tobias Brunner | 2010-10-12 | 1 | -1/+7 | |
| | | | | After getting a response the responder updates the IPsec SAs. | |||||
* | Send list of additional addresses even if current path is still valid. | Tobias Brunner | 2010-10-12 | 1 | -0/+11 | |
| | ||||||
* | Extracted path checking in ike_sa_t.roam into separate functions. | Tobias Brunner | 2010-10-12 | 1 | -46/+68 | |
| | ||||||
* | Added support for responders to change their address via MOBIKE. | Tobias Brunner | 2010-10-12 | 1 | -0/+20 | |
| | | | | | | | If the original responder updates its list of additional addresses we check if the remote endpoint changed and update the IPsec SAs if it did, as we assume the original address became unavailable and the responder already updated the SAs on its side. | |||||
* | Explicitly configure MOBIKE tasks to update the list of additional addresses. | Tobias Brunner | 2010-10-12 | 3 | -2/+15 | |
| | ||||||
* | Improved check for first IKE_AUTH message in ike_mobike task. | Tobias Brunner | 2010-10-12 | 1 | -3/+6 | |
| | | | | | If the original responder initiated a MOBIKE exchange, the previous check was not always correct. | |||||
* | Migrated ike_mobike task to INIT/METHOD macros. | Tobias Brunner | 2010-10-12 | 1 | -67/+46 | |
| | ||||||
* | Simplified apply_port function in mobike task. | Tobias Brunner | 2010-10-12 | 1 | -16/+9 | |
| | ||||||
* | Do not fire roam events based on local route changes. | Tobias Brunner | 2010-10-12 | 1 | -2/+3 | |
| | | | | | These kernel events are triggered on address changes, which is problematic when deleting virtual IP addresses. | |||||
* | If a changed route has no src, try to find it via interface. | Tobias Brunner | 2010-10-12 | 1 | -37/+48 | |
| | ||||||
* | Get source address from interface if the route does not provide one. | Tobias Brunner | 2010-10-12 | 1 | -2/+49 | |
| | ||||||
* | Do not update hosts based on retransmitted messages. | Tobias Brunner | 2010-10-12 | 2 | -15/+23 | |
| | ||||||
* | Do not update remote host if we are behind a NAT. | Tobias Brunner | 2010-10-12 | 1 | -4/+2 | |
| | ||||||
* | *** HISTORICAL MOMENT: IKEv2 becomes the default! *** | Andreas Steffen | 2010-10-09 | 2 | -2/+2 | |
| | ||||||
* | use DBG_TNC for TNC debugging output | Andreas Steffen | 2010-10-09 | 6 | -22/+27 | |
| | ||||||
* | TNCCS debug cosmetics | Andreas Steffen | 2010-10-09 | 1 | -4/+4 | |
| | ||||||
* | revert to standard TNCC/TNCS Initialization function | Andreas Steffen | 2010-10-09 | 2 | -17/+2 | |
| | ||||||
* | implemented TNC isolation via group memberships | Andreas Steffen | 2010-10-09 | 1 | -6/+33 | |
| | ||||||
* | implemented a makeshift non-scalable send buffer | Andreas Steffen | 2010-10-08 | 1 | -25/+82 | |
| | ||||||
* | imc/imv cosmetics | Andreas Steffen | 2010-10-08 | 2 | -4/+7 | |
| | ||||||
* | created tnc-imc and tnc-imv plugins | Andreas Steffen | 2010-10-07 | 9 | -42/+340 | |
| | ||||||
* | deactivate start_phase2_tnc flag after start | Andreas Steffen | 2010-10-07 | 1 | -1/+1 | |
| | ||||||
* | added server side support for EAP-TNC | Andreas Steffen | 2010-10-07 | 1 | -2/+28 | |
| | ||||||
* | Show result of RADIUS authentication along with EAP identity | Martin Willi | 2010-10-07 | 1 | -5/+6 | |
| | ||||||
* | added --debug-tls to charon usage() function | Andreas Steffen | 2010-10-07 | 1 | -1/+1 | |
| | ||||||
* | configure tnc_config path and preferred_language via strongswan.conf | Andreas Steffen | 2010-10-05 | 1 | -2/+8 | |
| | ||||||
* | created hull for TNCCS 2.0 plugin | Andreas Steffen | 2010-10-05 | 6 | -0/+256 | |
| | ||||||
* | use group membership to implement access/isolate redirection in filter-based ↵ | Andreas Steffen | 2010-10-05 | 1 | -4/+14 | |
| | | | | TNC scenario | |||||
* | moved CHILD_SA selection out of attribute loop | Andreas Steffen | 2010-10-05 | 1 | -5/+6 | |
| | ||||||
* | receive name of preferred CHILD_SA via RADIUS Filter-Id attribute | Andreas Steffen | 2010-10-05 | 1 | -0/+59 | |
| | ||||||
* | set EAP-TTLS/TNC version also in acknowledgement packets | Andreas Steffen | 2010-10-04 | 1 | -0/+11 | |
| | ||||||
* | Fixed status_t enum names definition | Martin Willi | 2010-10-04 | 1 | -1/+1 | |
| | ||||||
* | print XML as plaintext and process recieved TNCCS Batch | Andreas Steffen | 2010-09-30 | 1 | -11/+28 | |
| | ||||||
* | started use of libtnc library | Andreas Steffen | 2010-09-29 | 2 | -19/+81 | |
| | ||||||
* | NOTIFY error message types include 16383 | Andreas Steffen | 2010-09-29 | 1 | -1/+1 | |
| | ||||||
* | moved TNCCS layer out of eap_tnc plugin | Andreas Steffen | 2010-09-28 | 14 | -48/+450 | |
| | ||||||
* | fixed release of virtual IP for XAUTH identities | Andreas Steffen | 2010-09-26 | 1 | -2/+5 | |
| | ||||||
* | draft-ietf-ipsecme-eap-mutual will be released as RFC 5998. | Tobias Brunner | 2010-09-16 | 1 | -1/+1 | |
| | ||||||
* | added notify messages defined in RFC 5996 | Andreas Steffen | 2010-09-15 | 2 | -6/+13 | |
| | ||||||
* | show validity of OCSP responses | Andreas Steffen | 2010-09-10 | 1 | -2/+15 | |
| | ||||||
* | Moved man pages for config files to a separate directory. | Tobias Brunner | 2010-09-10 | 6 | -1531/+3 | |
| | ||||||
* | fixed memory leak | Andreas Steffen | 2010-09-09 | 1 | -0/+1 | |
| | ||||||
* | Compare subject against all key identifiers in has_subject() | Martin Willi | 2010-09-09 | 2 | -10/+26 | |
| | ||||||
* | has_subject() now resolves ID_KEY_IDs | Andreas Steffen | 2010-09-09 | 1 | -4/+14 | |
| |