Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
| * | | | Log the proper type for virtual EAP methods | Tobias Brunner | 2012-08-31 | 1 | -1/+5 | |
| | | | | ||||||
| * | | | Added an option to prefer types sent by peer in eap-dynamic plugin | Tobias Brunner | 2012-08-31 | 1 | -14/+42 | |
| | | | | ||||||
| * | | | eap-dynamic plugin handles EAP-Nak messages and selects a method supported ↵ | Tobias Brunner | 2012-08-31 | 1 | -1/+72 | |
| | | | | | | | | | | | | | | | | by the peer | |||||
| * | | | Preferred EAP methods for eap-dynamic can be configured | Tobias Brunner | 2012-08-31 | 1 | -1/+59 | |
| | | | | ||||||
| * | | | The eap-dynamic plugin uses the first supported method as default | Tobias Brunner | 2012-08-31 | 1 | -1/+91 | |
| | | | | ||||||
| * | | | Added eap-dynamic plugin which can proxy any other EAP method | Tobias Brunner | 2012-08-31 | 8 | -1/+328 | |
| | | | | ||||||
| * | | | Use eap_vendor_type_from_string() in stroke | Tobias Brunner | 2012-08-31 | 1 | -38/+7 | |
| | | | | ||||||
| * | | | Function added that parses EAP method strings ([eap-]type[-vendor]) | Tobias Brunner | 2012-08-31 | 2 | -0/+86 | |
| | | | | ||||||
| * | | | Added method to enumerate EAP types contained in an EAP-Nak | Tobias Brunner | 2012-08-31 | 2 | -11/+79 | |
| | | | | ||||||
| * | | | Encode EAP-Naks in expanded format if we got an expanded type request | Tobias Brunner | 2012-08-31 | 5 | -6/+19 | |
| | | | | | | | | | | | | | | | | | | | | Since methods defined by the IETF (vendor ID 0) could also be encoded in expanded type format the previous check was insufficient. | |||||
| * | | | Allow clients to request a configured EAP method via EAP-Nak | Tobias Brunner | 2012-08-31 | 5 | -8/+37 | |
| | | | | ||||||
| * | | | Virtual EAP methods handle EAP-Naks themselves | Tobias Brunner | 2012-08-31 | 1 | -5/+17 | |
| | | | | ||||||
| * | | | Send EAP-Nak with supported types if requested type is unsupported | Tobias Brunner | 2012-08-31 | 5 | -12/+81 | |
| | | | | ||||||
| * | | | Filter invalid EAP authentication types when enumerating them | Tobias Brunner | 2012-08-31 | 2 | -1/+10 | |
| | | | | | | | | | | | | | | | | Valid authentication types defined by the IETF are 4-253 and 255. | |||||
| * | | | Move our pseudo EAP types out of the range of valid EAP methods | Tobias Brunner | 2012-08-31 | 2 | -14/+14 | |
| | | | | ||||||
| * | | | Added a method to enumerate registered EAP methods | Tobias Brunner | 2012-08-21 | 2 | -0/+43 | |
| |/ / | ||||||
* | | | Ported tun_device de-/initialization to FreeBSD | Tobias Brunner | 2012-08-29 | 1 | -5/+47 | |
| | | | ||||||
* | | | struct iphdr is Linux specific use struct ip instead | Tobias Brunner | 2012-08-29 | 1 | -6/+6 | |
| | | | ||||||
* | | | Include stdint.h for UINT32_MAX on FreeBSD | Tobias Brunner | 2012-08-29 | 1 | -0/+1 | |
| | | | ||||||
* | | | Ported tun_device initialization to OS X utun | Martin Willi | 2012-08-28 | 1 | -19/+85 | |
| |/ |/| | ||||||
* | | Ewa did the new Polish translation | Andreas Steffen | 2012-08-24 | 1 | -0/+95 | |
| | | ||||||
* | | Log configured IKE_SA proposals as initiator | Tobias Brunner | 2012-08-24 | 1 | -0/+2 | |
| | | ||||||
* | | Log configured CHILD_SA proposals as initiator | Tobias Brunner | 2012-08-24 | 1 | -0/+2 | |
| | | ||||||
* | | Fall back to local address as IKEv1 identity if nothing else is configured | Tobias Brunner | 2012-08-24 | 1 | -2/+14 | |
| | | ||||||
* | | Removed deprecated options from ipsec.conf template | Tobias Brunner | 2012-08-24 | 1 | -9/+1 | |
| | | ||||||
* | | Apply send delay before adding non-ESP marker | Tobias Brunner | 2012-08-24 | 1 | -16/+16 | |
| | | | | | | | | | | Otherwise the packet header could not be parsed correctly when NAT-T is used. | |||||
* | | use pen_type_t for PA Message Subtype | Andreas Steffen | 2012-08-23 | 3 | -32/+29 | |
|/ | ||||||
* | Remove unused src/dst variables in send_no_marker() | Martin Willi | 2012-08-21 | 1 | -5/+0 | |
| | ||||||
* | use pen_type_t for attribute request entries | Andreas Steffen | 2012-08-21 | 1 | -25/+4 | |
| | ||||||
* | define pen_type_t as a vendor-specific type | Andreas Steffen | 2012-08-20 | 35 | -624/+301 | |
| | ||||||
* | Don't use POSIX semaphores if a MONOTONIC clock is available | Martin Willi | 2012-08-20 | 1 | -0/+8 | |
| | | | | | | POSIX semaphores use CLOCK_REALTIME, but our semaphore_t abstraction expects CLOCK_MONOTONIC based times. Use the mutex/condvar based fallback if time_monotonic() actuall returns monotonic times. | |||||
* | Remove the unused second IKE_SA entry match function argument | Martin Willi | 2012-08-20 | 1 | -4/+4 | |
| | | | | LLVMs clang complains about this parameter, so remove it. | |||||
* | Add a mutex/condvar based semaphore implementation if sem_timedwait is ↵ | Martin Willi | 2012-08-20 | 1 | -2/+67 | |
| | | | | | | unavailable Fixes #214. | |||||
* | added IBM and OpenPTS Private Enterprise Numbers | Andreas Steffen | 2012-08-20 | 2 | -2/+8 | |
| | ||||||
* | Add keymat_t constructor registration function | Adrian-Ken Rueegsegger | 2012-08-20 | 2 | -3/+45 | |
| | | | | | | Using the register_constructor function enables custom keymat_t implementations per IKE version. If no constructor is registered the default behavior is preserved. | |||||
* | fixed caption | Andreas Steffen | 2012-08-20 | 1 | -1/+1 | |
| | ||||||
* | implemented IETF Attribute Request attribute | Andreas Steffen | 2012-08-20 | 4 | -3/+383 | |
| | ||||||
* | openssl: Fix registration of the PUBKEY builder | Tobias Brunner | 2012-08-18 | 1 | -1/+1 | |
| | | | | | libtls drops support for RSA suites if it does not find an RSA backend (final builder for RSA public keys). | |||||
* | Without the ties to PAM we can build eap-gtc on Android | Tobias Brunner | 2012-08-17 | 1 | -1/+1 | |
| | ||||||
* | CAP_AUDIT_WRITE is now required by xauth-pam not eap-gtc plugin | Tobias Brunner | 2012-08-17 | 2 | -7/+7 | |
| | ||||||
* | Removed manual EAP method registration in eap-gtc plugin | Tobias Brunner | 2012-08-17 | 1 | -5/+0 | |
| | ||||||
* | Enable build of eap-tls, eap-ttls and eap-peap on Android | Tobias Brunner | 2012-08-17 | 1 | -0/+20 | |
| | ||||||
* | Add a wrapper around vstr_add_fmt() to avoid having to link libcharon ↵ | Tobias Brunner | 2012-08-17 | 2 | -2/+31 | |
| | | | | | | against libvstr At least on Android the latter would be required. | |||||
* | starter: Restore original config in case also= is used (which reads the same ↵ | Tobias Brunner | 2012-08-16 | 1 | -20/+30 | |
| | | | | values) | |||||
* | Increased log level when listing interfaces and IP addresses during startup | Tobias Brunner | 2012-08-16 | 2 | -6/+6 | |
| | | | | | This avoids confusing log messages in starter and ipsec statusall already lists the available addresses anyway. | |||||
* | Only load kernel plugins in starter when flushing SAD/SPD entries | Tobias Brunner | 2012-08-16 | 2 | -9/+8 | |
| | | | | | | | | This avoids keeping the kernel sockets open when they are not actually needed, which could lead to resource problems (in particular with PF_KEY where all open sockets receive all messages). Fixes #217. | |||||
* | Enable UDP decapsulation for both address families | Tobias Brunner | 2012-08-16 | 2 | -9/+11 | |
| | | | | | | | | Since the 3.5 Linux kernel both UDP implementations have a separate static flag to indicate whether ANY sockets enabled UDP decapsulation. As we only ever enabled it for one address family (in earlier versions IPv4 only, now for IPv6, if supported, and for IPv4 otherwise) UDP decapsulation wouldn't work anymore (at least for one address family). | |||||
* | Correctly transmit EAP-MSCHAPv2 user name if it contains a domain part | Tobias Brunner | 2012-08-16 | 1 | -11/+12 | |
| | ||||||
* | fall through to evidence measurements if no file measurements must be done | Andreas Steffen | 2012-08-16 | 1 | -1/+7 | |
| | ||||||
* | upgraded to Ubuntu 12.04.1 LTS | Andreas Steffen | 2012-08-16 | 2 | -1/+37 | |
| |