Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | | handle case where subject = NULL but keyid is set4.6.2 | Andreas Steffen | 2012-02-20 | 1 | -1/+2 | |
| | | ||||||
* | | fixed attest sql query in list_measurements() | Andreas Steffen | 2012-02-15 | 1 | -1/+1 | |
| | | ||||||
* | | Compiler warnings fixed. | Tobias Brunner | 2012-02-14 | 2 | -2/+2 | |
| | | ||||||
* | | pluto: Print expiry time more properly. | Tobias Brunner | 2012-02-14 | 1 | -2/+3 | |
| | | ||||||
* | | pluto: Drop support for legacy PSK format. | Tobias Brunner | 2012-02-08 | 1 | -15/+2 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Any line in ipsec.secrets starting with " or ' was treated as PSK without ID selectors by pluto. This prevented it from supporting DNs like "C=CH, O=Linux strongSwan, OU=Sales, CN=alice@strongswan.org" as ID selectors. PSKs defined in this legacy format can easily be updated by changing "thisIsASecret" into : PSK "thisIsASecret" | |||||
* | | Double check if a cached suite is available, overwrite any old suite state | Martin Willi | 2012-02-07 | 1 | -2/+3 | |
| | | ||||||
* | | Some Doxygen fixes. | Tobias Brunner | 2012-02-07 | 3 | -11/+11 | |
| | | ||||||
* | | Fix TLS EAP-MSK derivation, uses different order of randoms than key expansion | Martin Willi | 2012-02-07 | 1 | -0/+1 | |
| | | ||||||
* | | Filter TLS suite MAC by HMAC algorithm, as the hash is not necessarily the same | Martin Willi | 2012-02-07 | 1 | -4/+4 | |
| | | ||||||
* | | Update usage for all children in RADIUS accounting just before sending Stop | Martin Willi | 2012-02-06 | 1 | -1/+12 | |
| | | ||||||
* | | Check if ClusterIP directory could be opened before enumerating it | Martin Willi | 2012-02-06 | 1 | -17/+26 | |
| | | ||||||
* | | ipsec attest adds and deletes key/component pairs | Andreas Steffen | 2012-02-05 | 1 | -4/+21 | |
| | | ||||||
* | | check if TNC client has a valid and registered AIK | Andreas Steffen | 2012-02-05 | 5 | -25/+62 | |
| | | ||||||
* | | Trigger DPD not before IKE_SA state gets updated | Martin Willi | 2012-02-02 | 1 | -6/+8 | |
| | | ||||||
* | | Don't retransmit, rekey, reauth or DPD check SAs when in PASSIVE state | Martin Willi | 2012-02-02 | 1 | -0/+26 | |
| | | ||||||
* | | Moved log message for unexpected ASN.1 objects to level 2. | Tobias Brunner | 2012-02-01 | 1 | -1/+1 | |
| | | | | | | | | This avoids error messages if later builders can successfully decode something. | |||||
* | | Added support for PKCS#5 v2 schemes when decrypting PKCS#8 files. | Tobias Brunner | 2012-02-01 | 3 | -61/+323 | |
| | | ||||||
* | | Added support for encrypted PKCS#8 files (for some PKCS#5 v1.5 schemes). | Tobias Brunner | 2012-02-01 | 3 | -4/+261 | |
| | | ||||||
* | | Added support to parse PKCS#8 encoded ECDSA private keys. | Tobias Brunner | 2012-02-01 | 3 | -12/+28 | |
| | | ||||||
* | | OpenSSL plugin parses ECDSA private keys with explicitly specified EC ↵ | Tobias Brunner | 2012-02-01 | 1 | -9/+30 | |
| | | | | | | | | | | | | | | parameters. This is needed in case the key itself does not contain the parameters, which is the case for PKCS#8. | |||||
* | | Add builder part for parameters from algorithmIdentifier. | Tobias Brunner | 2012-02-01 | 2 | -1/+4 | |
| | | ||||||
* | | Return parsed parameters from algorithmIdentifier if they are an OID (aka EC ↵ | Tobias Brunner | 2012-02-01 | 1 | -1/+1 | |
| | | | | | | | | | | | | | | named curve). Explicit EC parameters are not supported with this function, but before this change no parameters were actually ever returned. | |||||
* | | Parse RSA private keys from PKCS#8 encoded blobs. | Tobias Brunner | 2012-02-01 | 4 | -1/+151 | |
| | | ||||||
* | | Added PKCS#8 stub plugin. | Tobias Brunner | 2012-02-01 | 4 | -0/+139 | |
| | | ||||||
* | | Added an option to load CA certificates without CA basic constraint. | Tobias Brunner | 2012-02-01 | 1 | -4/+34 | |
| | | | | | | | | | | | | Enabling this option treats all certificates in ipsec.d/cacerts and ipsec.conf ca sections as CA certificates even if they do not contain a CA basic constraint. | |||||
* | | Support RADIUS accounting messages containing Framed-IP and ↵ | Martin Willi | 2012-01-30 | 4 | -0/+376 | |
| | | | | | | | | Inbound/Outbound-Octets | |||||
* | | Open RADIUS accounting sockets to exchange accounting messages | Martin Willi | 2012-01-30 | 5 | -46/+91 | |
| | | ||||||
* | | Support signing of RADIUS accounting messages | Martin Willi | 2012-01-30 | 3 | -10/+26 | |
| | | ||||||
* | | RADIUS message constructor accepts a message code parameter | Martin Willi | 2012-01-30 | 3 | -7/+8 | |
| | | ||||||
* | | Disable crypto benchmarking if CLOCK_THREAD_CPUTIME_ID is not available. | Tobias Brunner | 2012-01-30 | 1 | -0/+10 | |
| | | ||||||
* | | Cache list of plugin names to further simplify its usage. | Tobias Brunner | 2012-01-19 | 8 | -73/+62 | |
| | | | | | | | | Also helpful for ipsec statusall to avoid having to enumerate plugins. | |||||
* | | Log list of loaded plugins in main PKI help output. | Tobias Brunner | 2012-01-19 | 1 | -0/+8 | |
| | | ||||||
* | | Simplified logging of list of loaded plugins. | Tobias Brunner | 2012-01-19 | 5 | -59/+22 | |
| | | ||||||
* | | Function added to plugin_loader to get a list of the names of loaded plugins. | Tobias Brunner | 2012-01-19 | 2 | -1/+34 | |
| | | ||||||
* | | Use correct time_t variables to store ARG_TIME options | Martin Willi | 2012-01-18 | 2 | -4/+4 | |
| | | ||||||
* | | Destroy active task list before queued tasks | Thomas Egerer | 2012-01-18 | 1 | -3/+3 | |
| | | | | | | | | | | | | | | Since active task's destruction might result in adopting tasks from a rekeyed ike sa it seems better to first destroy the active task list and then destroy all queued tasks. This way adoption is possible at all, while otherwise the queued task list would be empty. | |||||
* | | Various style, typo and whitespace corrections | Adrian-Ken Rueegsegger | 2012-01-13 | 1 | -3/+2 | |
| | | ||||||
* | | Starter depends on whack/stroke on Android. | Tobias Brunner | 2012-01-12 | 1 | -0/+5 | |
| | | | | | | | | | | With this change whack and stroke get installed automatically if starter is enabled. | |||||
* | | Android 4 requires LOCAL_MODULE_TAGS to be set for all modules. | Tobias Brunner | 2012-01-12 | 12 | -0/+24 | |
| | | | | | | | | | | | | | | Because all packages are now marked as optional executables that are to be installed on the final system have to be added to PRODUCT_PACKAGES in build/target/product/core.mk. Dependencies (such as libraries) are installed automatically. | |||||
* | | Fixed additional typos in comments and log messages. | Tobias Brunner | 2012-01-12 | 14 | -19/+19 | |
| | | ||||||
* | | Fix whitespaces | Adrian-Ken Rueegsegger | 2012-01-12 | 2 | -16/+16 | |
| | | ||||||
* | | Some documentation corrections | Adrian-Ken Rueegsegger | 2012-01-12 | 8 | -33/+32 | |
| | | ||||||
* | | Fix gettid() on Android, which is defined in unistd.h there. | Tobias Brunner | 2012-01-12 | 1 | -3/+4 | |
| | | ||||||
* | | Use native gettid() if available (which is the case on Android). | Tobias Brunner | 2012-01-10 | 1 | -3/+11 | |
| | | ||||||
* | | pluto: Use srand() to initialize the C library PRNG. | Tobias Brunner | 2012-01-04 | 1 | -0/+3 | |
| | | | | | | | | Otherwise rekey and DPD times would always be the same after a restart. | |||||
* | | Added a tls_socket_t.splice method to wrap a file descriptor into TLS | Martin Willi | 2011-12-31 | 2 | -5/+107 | |
| | | ||||||
* | | Implemented TLS session resumption both as client and as server | Martin Willi | 2011-12-31 | 14 | -105/+273 | |
| | | ||||||
* | | Implemented a TLS session cache | Martin Willi | 2011-12-31 | 3 | -0/+316 | |
| | | ||||||
* | | Check for cipherspec changes after each handshake message | Martin Willi | 2011-12-31 | 1 | -2/+6 | |
| | | ||||||
* | | Separated cipherspec checking and switching, allowing us to defer the second | Martin Willi | 2011-12-31 | 4 | -33/+49 | |
| | |