Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | | Support signing of RADIUS response messages | Martin Willi | 2012-03-05 | 3 | -15/+26 | |
| | | ||||||
* | | Act on RADIUS DAE Disconnect requests | Martin Willi | 2012-03-05 | 1 | -1/+56 | |
| | | ||||||
* | | Verify received RADIUS DAE requests | Martin Willi | 2012-03-05 | 1 | -9/+51 | |
| | | ||||||
* | | Support verification of RADIUS request messages | Martin Willi | 2012-03-05 | 2 | -3/+10 | |
| | | ||||||
* | | Rename RADIUS message constructors to handle both, requests and responses | Martin Willi | 2012-03-05 | 6 | -15/+15 | |
| | | ||||||
* | | Enable RADIUS DAE listening if configured | Martin Willi | 2012-03-05 | 1 | -0/+13 | |
| | | ||||||
* | | Added infrastructure to listen to RADIUS Dynamic Authorization Extension ↵ | Martin Willi | 2012-03-05 | 3 | -0/+228 | |
| | | | | | | | | requests | |||||
* | | Added Dynamic Authorization Extension RADIUS message codes | Martin Willi | 2012-03-05 | 2 | -1/+14 | |
| | | ||||||
* | | Set IKE_SA lifetime based on RADIUS Session-Timeout attribute | Martin Willi | 2012-03-05 | 1 | -0/+26 | |
| | | ||||||
* | | Set hard timeouts when setting a lifetime | Martin Willi | 2012-03-05 | 1 | -7/+14 | |
| | | ||||||
* | | Fix IKE_SA timeout debug output on 64bit platforms | Martin Willi | 2012-03-05 | 1 | -3/+4 | |
| | | ||||||
* | | Added support for untruncated MD5 and SHA1 HMACs in ESP as used in RFC 4595. | Tobias Brunner | 2012-02-27 | 3 | -3/+25 | |
| | | | | | | | | This requires a Linux kernel >= 2.6.33. | |||||
* | | Encode IPv6 virtual IPs in a Framed-IPv6-Prefix attribute | Martin Willi | 2012-02-24 | 1 | -1/+9 | |
| | | ||||||
* | | Refactored construction of RADIUS accounting messages | Martin Willi | 2012-02-24 | 1 | -23/+21 | |
| | | ||||||
* | | Include port numbers in Calling-Station-Id, too | Martin Willi | 2012-02-24 | 1 | -2/+2 | |
| | | ||||||
* | | Use large enough buffers for IPv6 addresses in Calling-Station-Id | Martin Willi | 2012-02-24 | 1 | -2/+2 | |
| | | ||||||
* | | Send client external address as Calling-Station-Id in RADIUS accounting | Martin Willi | 2012-02-24 | 1 | -6/+11 | |
| | | ||||||
* | | handle case where subject = NULL but keyid is set4.6.2 | Andreas Steffen | 2012-02-20 | 1 | -1/+2 | |
| | | ||||||
* | | fixed attest sql query in list_measurements() | Andreas Steffen | 2012-02-15 | 1 | -1/+1 | |
| | | ||||||
* | | Compiler warnings fixed. | Tobias Brunner | 2012-02-14 | 2 | -2/+2 | |
| | | ||||||
* | | pluto: Print expiry time more properly. | Tobias Brunner | 2012-02-14 | 1 | -2/+3 | |
| | | ||||||
* | | pluto: Drop support for legacy PSK format. | Tobias Brunner | 2012-02-08 | 1 | -15/+2 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Any line in ipsec.secrets starting with " or ' was treated as PSK without ID selectors by pluto. This prevented it from supporting DNs like "C=CH, O=Linux strongSwan, OU=Sales, CN=alice@strongswan.org" as ID selectors. PSKs defined in this legacy format can easily be updated by changing "thisIsASecret" into : PSK "thisIsASecret" | |||||
* | | Double check if a cached suite is available, overwrite any old suite state | Martin Willi | 2012-02-07 | 1 | -2/+3 | |
| | | ||||||
* | | Some Doxygen fixes. | Tobias Brunner | 2012-02-07 | 3 | -11/+11 | |
| | | ||||||
* | | Fix TLS EAP-MSK derivation, uses different order of randoms than key expansion | Martin Willi | 2012-02-07 | 1 | -0/+1 | |
| | | ||||||
* | | Filter TLS suite MAC by HMAC algorithm, as the hash is not necessarily the same | Martin Willi | 2012-02-07 | 1 | -4/+4 | |
| | | ||||||
* | | Update usage for all children in RADIUS accounting just before sending Stop | Martin Willi | 2012-02-06 | 1 | -1/+12 | |
| | | ||||||
* | | Check if ClusterIP directory could be opened before enumerating it | Martin Willi | 2012-02-06 | 1 | -17/+26 | |
| | | ||||||
* | | ipsec attest adds and deletes key/component pairs | Andreas Steffen | 2012-02-05 | 1 | -4/+21 | |
| | | ||||||
* | | check if TNC client has a valid and registered AIK | Andreas Steffen | 2012-02-05 | 5 | -25/+62 | |
| | | ||||||
* | | Trigger DPD not before IKE_SA state gets updated | Martin Willi | 2012-02-02 | 1 | -6/+8 | |
| | | ||||||
* | | Don't retransmit, rekey, reauth or DPD check SAs when in PASSIVE state | Martin Willi | 2012-02-02 | 1 | -0/+26 | |
| | | ||||||
* | | Moved log message for unexpected ASN.1 objects to level 2. | Tobias Brunner | 2012-02-01 | 1 | -1/+1 | |
| | | | | | | | | This avoids error messages if later builders can successfully decode something. | |||||
* | | Added support for PKCS#5 v2 schemes when decrypting PKCS#8 files. | Tobias Brunner | 2012-02-01 | 3 | -61/+323 | |
| | | ||||||
* | | Added support for encrypted PKCS#8 files (for some PKCS#5 v1.5 schemes). | Tobias Brunner | 2012-02-01 | 3 | -4/+261 | |
| | | ||||||
* | | Added support to parse PKCS#8 encoded ECDSA private keys. | Tobias Brunner | 2012-02-01 | 3 | -12/+28 | |
| | | ||||||
* | | OpenSSL plugin parses ECDSA private keys with explicitly specified EC ↵ | Tobias Brunner | 2012-02-01 | 1 | -9/+30 | |
| | | | | | | | | | | | | | | parameters. This is needed in case the key itself does not contain the parameters, which is the case for PKCS#8. | |||||
* | | Add builder part for parameters from algorithmIdentifier. | Tobias Brunner | 2012-02-01 | 2 | -1/+4 | |
| | | ||||||
* | | Return parsed parameters from algorithmIdentifier if they are an OID (aka EC ↵ | Tobias Brunner | 2012-02-01 | 1 | -1/+1 | |
| | | | | | | | | | | | | | | named curve). Explicit EC parameters are not supported with this function, but before this change no parameters were actually ever returned. | |||||
* | | Parse RSA private keys from PKCS#8 encoded blobs. | Tobias Brunner | 2012-02-01 | 4 | -1/+151 | |
| | | ||||||
* | | Added PKCS#8 stub plugin. | Tobias Brunner | 2012-02-01 | 4 | -0/+139 | |
| | | ||||||
* | | Added an option to load CA certificates without CA basic constraint. | Tobias Brunner | 2012-02-01 | 1 | -4/+34 | |
| | | | | | | | | | | | | Enabling this option treats all certificates in ipsec.d/cacerts and ipsec.conf ca sections as CA certificates even if they do not contain a CA basic constraint. | |||||
* | | Support RADIUS accounting messages containing Framed-IP and ↵ | Martin Willi | 2012-01-30 | 4 | -0/+376 | |
| | | | | | | | | Inbound/Outbound-Octets | |||||
* | | Open RADIUS accounting sockets to exchange accounting messages | Martin Willi | 2012-01-30 | 5 | -46/+91 | |
| | | ||||||
* | | Support signing of RADIUS accounting messages | Martin Willi | 2012-01-30 | 3 | -10/+26 | |
| | | ||||||
* | | RADIUS message constructor accepts a message code parameter | Martin Willi | 2012-01-30 | 3 | -7/+8 | |
| | | ||||||
* | | Disable crypto benchmarking if CLOCK_THREAD_CPUTIME_ID is not available. | Tobias Brunner | 2012-01-30 | 1 | -0/+10 | |
| | | ||||||
* | | Cache list of plugin names to further simplify its usage. | Tobias Brunner | 2012-01-19 | 8 | -73/+62 | |
| | | | | | | | | Also helpful for ipsec statusall to avoid having to enumerate plugins. | |||||
* | | Log list of loaded plugins in main PKI help output. | Tobias Brunner | 2012-01-19 | 1 | -0/+8 | |
| | | ||||||
* | | Simplified logging of list of loaded plugins. | Tobias Brunner | 2012-01-19 | 5 | -59/+22 | |
| | |