Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | | | Encode RSA public keys in RFC 3110 DNSKEY format | Andreas Steffen | 2013-02-19 | 8 | -3/+155 | |
| | | | ||||||
* | | | Moved configuration from resolver manager to unbound plugin | Andreas Steffen | 2013-02-19 | 6 | -52/+41 | |
| | | | | | | | | | | | | Also streamlined log messages in unbound plugin. | |||||
* | | | ipseckey: Report IPSECKEYs with invalid DNSSEC security state | Reto Guadagnini | 2013-02-19 | 1 | -2/+12 | |
| | | | ||||||
* | | | ipseckey: Added "enable" option for the IPSECKEY plugin to strongswan.conf | Reto Guadagnini | 2013-02-19 | 1 | -3/+16 | |
| | | | ||||||
* | | | Added ipseckey plugin, which provides support for public keys in IPSECKEY RRs | Reto Guadagnini | 2013-02-19 | 8 | -0/+859 | |
| | | | ||||||
* | | | unbound: Implementation of query method of unbound_resolver_t | Reto Guadagnini | 2013-02-19 | 2 | -7/+64 | |
| | | | ||||||
* | | | unbound: Implemented resolver_response_t as unbound_response_t | Reto Guadagnini | 2013-02-19 | 3 | -1/+316 | |
| | | | ||||||
* | | | Implemented rr_set_t interface | Reto Guadagnini | 2013-02-19 | 3 | -1/+113 | |
| | | | ||||||
* | | | unbound: Implemented rr_t as unbound_rr_t | Reto Guadagnini | 2013-02-19 | 3 | -1/+215 | |
| | | | ||||||
* | | | Added unbound plugin implementing the resolver interface using libunbound | Reto Guadagnini | 2013-02-19 | 6 | -0/+234 | |
| | | | ||||||
* | | | Added manager for DNS resolvers | Reto Guadagnini | 2013-02-19 | 5 | -1/+181 | |
| | | | ||||||
* | | | Added interface for DNS resolvers | Reto Guadagnini | 2013-02-19 | 6 | -0/+548 | |
| | | | ||||||
* | | | added missing return statement | Andreas Steffen | 2013-02-19 | 1 | -0/+1 | |
| | | | ||||||
* | | | Fix encoding of issuerAndSubject while handling SCEP pending state | Martin Willi | 2013-02-19 | 1 | -1/+1 | |
| | | | ||||||
* | | | reject PB-Experimental messages with NOSKIP flag set | Andreas Steffen | 2013-02-19 | 1 | -0/+7 | |
| | | | ||||||
* | | | added parameter descriptions | Andreas Steffen | 2013-02-19 | 1 | -1/+8 | |
| | | | ||||||
* | | | removed superfluous debug output | Andreas Steffen | 2013-02-15 | 2 | -4/+0 | |
| | | | ||||||
* | | | Add a timeout to clean up PDP RADIUS connections | Martin Willi | 2013-02-14 | 1 | -0/+51 | |
| | | | ||||||
* | | | Keep the PDP connections lock while accessing its objects | Martin Willi | 2013-02-14 | 3 | -7/+34 | |
| | | | | | | | | | | | | | | | | | | When we introduce connection timeouts, the state may disappear at any time. This change prevents that, but is not very clear. We probably have to refactor connection handling. | |||||
* | | | Add locking to TNC-PDP connections | Martin Willi | 2013-02-14 | 1 | -7/+23 | |
| | | | ||||||
* | | | Add IF-M message subtype getter to IMC/IMV messages | Martin Willi | 2013-02-14 | 4 | -1/+28 | |
| | | | ||||||
* | | | Use a generic constructor to create PA-TNC error attributes | Martin Willi | 2013-02-14 | 1 | -62/+32 | |
| | | | ||||||
* | | | Add a global return_success() method implementation | Martin Willi | 2013-02-14 | 3 | -8/+15 | |
| | | | ||||||
* | | | Add a convenience method to check pen_type_t for vendor and type | Martin Willi | 2013-02-14 | 1 | -0/+14 | |
| | | | ||||||
* | | | Add a comparison function for pen_type_t | Martin Willi | 2013-02-14 | 1 | -0/+12 | |
| | | | ||||||
* | | | Whitespace and comment cleanups in pen.[ch] | Martin Willi | 2013-02-14 | 2 | -20/+28 | |
| | | | ||||||
* | | | resolve dependency on libtls | Andreas Steffen | 2013-02-14 | 1 | -0/+1 | |
| | | | ||||||
* | | | Merge branch 'ike-dscp' | Martin Willi | 2013-02-14 | 26 | -68/+237 | |
|\ \ \ | ||||||
| * | | | Add a ikedscp ipsec.conf option to set DSCP value on outgoing IKE packets | Martin Willi | 2013-02-06 | 7 | -4/+23 | |
| | | | | ||||||
| * | | | Set configured DSCP value while generating IKE packets | Martin Willi | 2013-02-06 | 1 | -1/+26 | |
| | | | | ||||||
| * | | | Add a DSCP configuration value to IKE configs | Martin Willi | 2013-02-06 | 14 | -25/+41 | |
| | | | | ||||||
| * | | | Set DSCP values when sending IP packets in socket-default | Martin Willi | 2013-02-06 | 1 | -1/+65 | |
| | | | | ||||||
| * | | | Don't send a packet in default socket if family is not IPv4 nor IPv6 | Martin Willi | 2013-02-06 | 1 | -12/+18 | |
| | | | | ||||||
| * | | | Add a DSCP value with getter/setter on packet_t | Martin Willi | 2013-02-06 | 3 | -0/+47 | |
| | | | | ||||||
| * | | | Avoid extensive casting of sockaddr types in socket-default by using a union | Martin Willi | 2013-02-06 | 1 | -24/+16 | |
| | | | | | | | | | | | | | | | | Additionally fixes a strict-aliasing rule compiler warning with older gcc. | |||||
| * | | | Set sockaddr family on ifreq instead of casted familiy specific sockaddr | Martin Willi | 2013-02-06 | 1 | -2/+2 | |
| |/ / | | | | | | | | | | Fixes a strict-aliasing rule compiler warning with older gcc. | |||||
* | | | Check if recommendations is set before applying language preference | Martin Willi | 2013-02-14 | 1 | -3/+6 | |
| | | | ||||||
* | | | PT-TLS dispatcher TNCCS constructor takes peer identities to pass to factory | Martin Willi | 2013-02-14 | 2 | -4/+23 | |
| | | | ||||||
* | | | Merge branch 'pt-tls' | Martin Willi | 2013-02-14 | 19 | -94/+1411 | |
|\ \ \ | ||||||
| * | | | Pass a constructor callback to create TNCCS server instances while dispatching | Martin Willi | 2013-01-17 | 4 | -15/+31 | |
| | | | | ||||||
| * | | | Create pt_tls_client with separate server address and identity | Martin Willi | 2013-01-16 | 2 | -28/+19 | |
| | | | | ||||||
| * | | | Create pt_tls_dispatcher with separate server address and identity | Martin Willi | 2013-01-16 | 2 | -17/+13 | |
| | | | | ||||||
| * | | | Add a libpttls providing NEA PT-TLS / TNC IF-T for TLS transport layer | Martin Willi | 2013-01-16 | 10 | -0/+1169 | |
| | | | | ||||||
| * | | | Send TLS close notify during tls_socket_t destruction | Martin Willi | 2013-01-15 | 1 | -2/+25 | |
| | | | | ||||||
| * | | | Send TLS close notify if application returns SUCCESS | Martin Willi | 2013-01-15 | 1 | -2/+6 | |
| | | | | ||||||
| * | | | Block TLS read when sending data, but have to wait for the handshake data first | Martin Willi | 2013-01-15 | 1 | -4/+11 | |
| | | | | ||||||
| * | | | TNCCS plugins don't depend on EAP-TNC, but can be used by other transports, too | Martin Willi | 2013-01-15 | 3 | -9/+0 | |
| | | | | ||||||
| * | | | Add a bio_reader_t constructor variant freeing passed data during destruction | Martin Willi | 2013-01-15 | 2 | -1/+32 | |
| | | | | ||||||
| * | | | Use a more POSIXy tls_socket interface with more flexibility. | Martin Willi | 2013-01-15 | 2 | -81/+165 | |
| | | | | | | | | | | | | | | | | | | | | If an unsufficient read buffer is provided, application data gets cached for subsequent read() calls. | |||||
| * | | | Add a chunk_from_str() initializer that does not include 0-terminator | Martin Willi | 2013-01-15 | 1 | -0/+5 | |
| | |/ | |/| |