Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | Starter unroutes removed or changed connections before loading and routing ↵ | Tobias Brunner | 2012-10-18 | 3 | -0/+19 | |
| | | | | new ones | |||||
* | Update routed connections in trap manager | Tobias Brunner | 2012-10-18 | 1 | -37/+39 | |
| | | | | | | Before this change, modified configs that have been updated with ipsec reload, could properly be started manually, but the old config would get used if triggered via trap policies. | |||||
* | Reload logger configuration on SIGHUP | Tobias Brunner | 2012-10-18 | 6 | -208/+400 | |
| | | | | | | Besides changing the configuration this allows to easily rotate log files. Also moved logger initialization back to daemon_t. | |||||
* | Make syslog and file loggers configurable at runtime | Tobias Brunner | 2012-10-18 | 8 | -80/+185 | |
| | ||||||
* | Store loggers in conftest separately, not on charon | Tobias Brunner | 2012-10-18 | 2 | -6/+19 | |
| | ||||||
* | Added an option to reload certificates from PKCS#11 tokens on SIGHUP | Tobias Brunner | 2012-10-18 | 1 | -0/+16 | |
| | ||||||
* | Copy the name of pkcs11_library_t objects | Tobias Brunner | 2012-10-18 | 2 | -2/+3 | |
| | | | | | Strings returned by settings_t.create_section_enumerator will be freed when the config is reloaded. | |||||
* | New Android release after adding MOBIKE support | Tobias Brunner | 2012-10-18 | 1 | -2/+2 | |
| | ||||||
* | Merge branch 'android-mobility' | Tobias Brunner | 2012-10-18 | 33 | -199/+1218 | |
|\ | | | | | | | | | | | | | | | | | This brings support for MOBIKE to the Android app. The app also tries to keep the connection up as long as possible. DNS queries are now handled by a new class that uses independent threads to resolve them, this allows to cancel them e.g. if no network connectivity is available (otherwise the app would block until the DNS query returns). | |||||
| * | Use a shortcut to resolve numeric IP addresses (no need for separate threads) | Tobias Brunner | 2012-10-18 | 1 | -0/+33 | |
| | | ||||||
| * | Use native threads in host resolver so that it works even if processor has ↵ | Tobias Brunner | 2012-10-18 | 1 | -45/+77 | |
| | | | | | | | | no threads | |||||
| * | Terminate unused resolver threads after a timeout | Tobias Brunner | 2012-10-18 | 3 | -9/+35 | |
| | | ||||||
| * | Only create more threads if needed in host_resolver_t | Tobias Brunner | 2012-10-18 | 1 | -1/+9 | |
| | | ||||||
| * | Use a helper function to add milliseconds to timeval structs | Tobias Brunner | 2012-10-18 | 6 | -37/+22 | |
| | | ||||||
| * | android: Ignore if peer is unreachable when reestablishing an SA | Tobias Brunner | 2012-10-18 | 1 | -2/+7 | |
| | | ||||||
| * | android: Use a shorter timeout for retransmits | Tobias Brunner | 2012-10-18 | 1 | -1/+1 | |
| | | ||||||
| * | android: Use keyingtries=%forever and dpd|closeaction=restart | Tobias Brunner | 2012-10-18 | 2 | -12/+4 | |
| | | | | | | | | | | | | | | We also ignore the CHILD_SA_DOWN event. This should allow us to keep the connection up as long as the user does not manually disconnect. | |||||
| * | Resolve hosts by DNS name in separate threads so we can cancel them | Tobias Brunner | 2012-10-18 | 8 | -50/+373 | |
| | | | | | | | | | | | | | | | | | | | | getaddrinfo(3) may block a long time so proper termination of the daemon may block if DNS servers are not reachable. getaddrinfo(3) is an optional cancellation point in posix threads so it might still block a shutdown but at least on Android (with the signal based pthread_cancel implementation) it works, on Linux starter will kill charon anyway after a while. | |||||
| * | android: Handle unreachable peers via alert | Tobias Brunner | 2012-10-16 | 1 | -17/+5 | |
| | | ||||||
| * | Added a new alert that is raised if peer does not respond to initial IKE message | Tobias Brunner | 2012-10-16 | 2 | -0/+4 | |
| | | ||||||
| * | android: Use 0.0.0.0/0 as local traffic selector | Tobias Brunner | 2012-10-16 | 1 | -1/+2 | |
| | | | | | | | | | | This is helpful if the responder also wants to tunnel e.g. multicast packages. | |||||
| * | Log IP addresses for discarded inbound IPsec packets | Tobias Brunner | 2012-10-16 | 1 | -1/+3 | |
| | | ||||||
| * | android: Bypass/protect previously bypassed sockets if connectivity changes | Tobias Brunner | 2012-10-16 | 3 | -4/+30 | |
| | | ||||||
| * | android: Support for IPsec SA update added | Tobias Brunner | 2012-10-16 | 1 | -1/+2 | |
| | | ||||||
| * | Use pointers for lookups in IPsec SA manager | Tobias Brunner | 2012-10-16 | 1 | -16/+16 | |
| | | ||||||
| * | IPsec SA manager implements update_sa() | Tobias Brunner | 2012-10-16 | 2 | -0/+60 | |
| | | ||||||
| * | Setter for src and destination address of ipsec_sa_t added | Tobias Brunner | 2012-10-16 | 2 | -0/+30 | |
| | | ||||||
| * | android: Trigger roam events in case connectivity changes | Tobias Brunner | 2012-10-16 | 1 | -0/+63 | |
| | | ||||||
| * | android: Register NetworkManager as BroadcastReceiver and relay events via JNI | Tobias Brunner | 2012-10-16 | 5 | -8/+184 | |
| | | ||||||
| * | android: Determine source address dynamically | Tobias Brunner | 2012-10-16 | 6 | -64/+48 | |
| | | ||||||
| * | android: Added NetworkManager class which allows to retrieve a local IP address | Tobias Brunner | 2012-10-16 | 4 | -0/+274 | |
| | | ||||||
| * | android: Increase compile warnings | Tobias Brunner | 2012-10-16 | 1 | -0/+3 | |
| | | ||||||
| * | android: Fixed "Configure" button in Android VPN dialog | Tobias Brunner | 2012-10-16 | 1 | -1/+1 | |
| | | ||||||
| * | android: Don't use the default ESP proposal as it includes unsupported ↵ | Tobias Brunner | 2012-10-16 | 1 | -1/+4 | |
| | | | | | | | | algorithms | |||||
* | | no need to include pa_tnc_msg.h | Andreas Steffen | 2012-10-18 | 6 | -7/+1 | |
| | | ||||||
* | | refactored PA-TNC message handling by IMVs | Andreas Steffen | 2012-10-17 | 14 | -617/+992 | |
| | | ||||||
* | | refactored PA-TNC message handling by IMCs | Andreas Steffen | 2012-10-17 | 15 | -607/+899 | |
| | | ||||||
* | | removed unused variable | Andreas Steffen | 2012-10-17 | 1 | -1/+0 | |
|/ | ||||||
* | Remove unused this parameter to load_issuer_cert/key(), as it is uninitialized | Martin Willi | 2012-10-16 | 1 | -4/+4 | |
| | ||||||
* | Generate a load-tester certificate only for DN or subjectAltName identities | Martin Willi | 2012-10-16 | 1 | -7/+17 | |
| | ||||||
* | Add a load-tester initiator_match option to match custom initiator_id | Martin Willi | 2012-10-16 | 1 | -2/+15 | |
| | ||||||
* | Encode non-DN load-tester identities as subjectAltNames | Martin Willi | 2012-10-16 | 1 | -1/+16 | |
| | ||||||
* | Add a load-tester digest option for issuing peer certificates | Martin Willi | 2012-10-16 | 1 | -1/+16 | |
| | ||||||
* | Load a multiple load-tester CA certificates from a directory | Martin Willi | 2012-10-16 | 1 | -4/+63 | |
| | ||||||
* | Added load-tester options to read issuing CA certificate and key from files | Martin Willi | 2012-10-16 | 1 | -7/+45 | |
| | ||||||
* | Use proper offset when adding mark attribute in kernel-netlink plugin | Tobias Brunner | 2012-10-15 | 1 | -1/+1 | |
| | ||||||
* | Also add mark when querying current replay state in kernel-netlink plugin | Tobias Brunner | 2012-10-15 | 1 | -2/+21 | |
| | ||||||
* | allow registration of multiple message type | Andreas Steffen | 2012-10-14 | 12 | -138/+175 | |
| | ||||||
* | implemented IETF Operational Status attribute | Andreas Steffen | 2012-10-13 | 8 | -2/+501 | |
| | ||||||
* | corrected class description | Andreas Steffen | 2012-10-13 | 3 | -3/+3 | |
| |