Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | Support RADIUS accounting when using IKEv1 with xauth-eap and eap-radius | Martin Willi | 2012-09-11 | 1 | -2/+10 | |
| | ||||||
* | Fix leak while enumerating RADIUS Framed-IPs from IKE_SA | Martin Willi | 2012-09-11 | 1 | -0/+1 | |
| | ||||||
* | Add uniqueids=never to ignore INITIAL_CONTACT notifies | Tobias Brunner | 2012-09-10 | 5 | -5/+12 | |
| | | | | | | With uniqueids=no the daemon still deletes any existing IKE_SA with the same peer if an INITIAL_CONTACT notify is received. With this new option it also ignores these notifies. | |||||
* | Add strongswan.conf runtime options for /dev/[u]random files | Martin Willi | 2012-09-10 | 1 | -2/+7 | |
| | | | | Fixes #221. | |||||
* | Use the proper types for comma separated attributes read from strongswan.conf | Tobias Brunner | 2012-09-10 | 1 | -27/+25 | |
| | | | | | | Attributes of different address families previously were mapped to the same attribute type (the one derived from the address family of the first address). | |||||
* | Print the name of mem pools instead of the confusing <base>/<size> | Tobias Brunner | 2012-09-10 | 1 | -2/+4 | |
| | ||||||
* | Properly remove broadcast address from mem pools | Tobias Brunner | 2012-09-10 | 1 | -1/+1 | |
| | ||||||
* | use base IMC ID if src IMC ID is not supported | Andreas Steffen | 2012-09-10 | 3 | -5/+11 | |
| | ||||||
* | make sending of IETF Assessment Result attributes configurable | Andreas Steffen | 2012-09-09 | 1 | -11/+13 | |
| | ||||||
* | introduced sending of standard IETF Assessment Result PA-TNC attribute by IMVs | Andreas Steffen | 2012-09-09 | 20 | -81/+633 | |
| | ||||||
* | Only initiate an exchange from send_dpd() if a task was actually queued | Tobias Brunner | 2012-09-07 | 1 | -2/+8 | |
| | | | | | Otherwise, the initiator would prematurely initiate Quick Mode if it has DPD enabled and XAuth is used. | |||||
* | android: New release after adding certificate authentication and reauth fix | Tobias Brunner | 2012-09-06 | 1 | -2/+2 | |
| | ||||||
* | Trigger ike_updown event caused by retransmits only after reestablish() has ↵ | Tobias Brunner | 2012-09-06 | 3 | -10/+5 | |
| | | | | | | | | been called This allows listeners to migrate to the new IKE_SA with the ike_reestablish event without having to worry about an ike_updown event for the old IKE_SA. | |||||
* | android: Properly handle reauthentication initiated by the client | Tobias Brunner | 2012-09-06 | 1 | -7/+42 | |
| | ||||||
* | android: Create a new VpnService.Builder after VPN has been established | Tobias Brunner | 2012-09-06 | 1 | -9/+20 | |
| | ||||||
* | Add ike_reestablish() event that is triggered when an IKE_SA is reestablished | Tobias Brunner | 2012-09-06 | 4 | -0/+49 | |
| | | | | | This is particularly useful during reauthentication to get the new IKE_SA. | |||||
* | Add a new condition to mark IKE_SAs that are currently being reauthenticated | Tobias Brunner | 2012-09-06 | 2 | -9/+9 | |
| | ||||||
* | starter: Load config again when restarting charon | Tobias Brunner | 2012-09-05 | 1 | -0/+16 | |
| | | | | This got lost in 041e763b. | |||||
* | Clear virtual IPs before storing assigned ones on the IKE_SA | Tobias Brunner | 2012-09-05 | 5 | -1/+43 | |
| | | | | | Otherwise we'll end up with duplicate or invalid VIPs stored on the IKE_SA. | |||||
* | In mode_config, destroy temporary pool list instead of the virtual IP list twice | Martin Willi | 2012-09-05 | 1 | -1/+1 | |
| | ||||||
* | Merge branch 'android-client-cert' | Tobias Brunner | 2012-09-04 | 25 | -181/+929 | |
|\ | | | | | | | Introduces IKEv2 client certificate authentication for the Android App. | |||||
| * | android: Native parts handle ikev2-cert VPN type | Tobias Brunner | 2012-08-31 | 3 | -16/+71 | |
| | | ||||||
| * | android: android_creds_t can provide a user's private key and certificate | Tobias Brunner | 2012-08-31 | 2 | -3/+89 | |
| | | ||||||
| * | android: Added JNI method to retrieve user certificate and private key | Tobias Brunner | 2012-08-31 | 3 | -13/+109 | |
| | | | | | | | | | | To simplify things the private key, the user certificate and the CA certificates are all put into the same list. | |||||
| * | android: Don't show the password dialog if not required | Tobias Brunner | 2012-08-31 | 1 | -1/+2 | |
| | | ||||||
| * | android: Enable pkcs8 plugin | Tobias Brunner | 2012-08-31 | 2 | -1/+3 | |
| | | ||||||
| * | android: Pass the type of VPN to the native parts | Tobias Brunner | 2012-08-31 | 2 | -6/+10 | |
| | | ||||||
| * | android: Make sure NULL jstrings are converted properly | Tobias Brunner | 2012-08-31 | 1 | -5/+8 | |
| | | ||||||
| * | android: Display the selected certificate alias in the profile list | Tobias Brunner | 2012-08-31 | 2 | -1/+29 | |
| | | ||||||
| * | android: Allow configuration of a user certificate | Tobias Brunner | 2012-08-31 | 8 | -9/+198 | |
| | | ||||||
| * | android: Remove NOT NULL constraint from username column | Tobias Brunner | 2012-08-31 | 1 | -3/+27 | |
| | | ||||||
| * | android: Separate view added to select certificates | Tobias Brunner | 2012-08-31 | 3 | -38/+48 | |
| | | ||||||
| * | android: Don't try to load the profile with ID 0 | Tobias Brunner | 2012-08-31 | 1 | -1/+1 | |
| | | ||||||
| * | android: Spinner added to select the VPN type | Tobias Brunner | 2012-08-31 | 9 | -24/+158 | |
| | | ||||||
| * | android: Field added to store the type of a VPN profile | Tobias Brunner | 2012-08-27 | 2 | -1/+22 | |
| | | ||||||
| * | android: Enum added for VPN types | Tobias Brunner | 2012-08-27 | 1 | -0/+87 | |
| | | ||||||
| * | android: Simplified handling of error dialog that is displayed if VpnService ↵ | Tobias Brunner | 2012-08-27 | 1 | -44/+24 | |
| | | | | | | | | API is not supported | |||||
| * | android: LoginDialog refactored so it also works when the device is rotated | Tobias Brunner | 2012-08-27 | 1 | -20/+29 | |
| | | ||||||
| * | android: Added a field to store selected user certificate | Tobias Brunner | 2012-08-27 | 2 | -9/+27 | |
| | | ||||||
* | | Merge branch 'multi-vip' | Martin Willi | 2012-08-31 | 69 | -727/+1947 | |
|\ \ | | | | | | | | | | | | | | | | | | | Brings support for multiple virtual IPs and multiple pools in left/rigthsourceip definitions. Also introduces the new left/rightdns options to configure requested DNS server address family and respond with multiple connection specific servers. | |||||
| * | | Added a note to _updown for the new PLUTO_MY_SOURCEIP* variables | Martin Willi | 2012-08-30 | 1 | -2/+6 | |
| | | | ||||||
| * | | Be less verbose if IP allocation for a single pool fails | Martin Willi | 2012-08-30 | 1 | -4/+0 | |
| | | | ||||||
| * | | DHCP plugin returns virtual IPs for IPv4 requests only | Martin Willi | 2012-08-30 | 1 | -2/+2 | |
| | | | ||||||
| * | | Check address family in HA virtual IP backend | Martin Willi | 2012-08-30 | 1 | -0/+6 | |
| | | | ||||||
| * | | Strictly enforce address family match while acquiring mem_pool IPs | Martin Willi | 2012-08-30 | 1 | -3/+1 | |
| | | | ||||||
| * | | Don't parse comma separated pool names in attr-sql | Martin Willi | 2012-08-30 | 1 | -77/+26 | |
| | | | | | | | | | | | | | | | We now handle multiple pools at a deeper level, making that special handling obsolete. Comma separated pools are parsed in stroke. | |||||
| * | | Handle comma separated pools as multiple pool names in SQL plugin | Martin Willi | 2012-08-30 | 1 | -1/+9 | |
| | | | ||||||
| * | | Request and acquire multiple virtual IPs in IKEv1 Mode Config | Martin Willi | 2012-08-30 | 1 | -47/+61 | |
| | | | ||||||
| * | | Request and acquire multiple virtual IPs in IKEv2 configuration payload | Martin Willi | 2012-08-30 | 1 | -49/+67 | |
| | | | ||||||
| * | | Pass all configured pool names to attribute provider enumerator | Martin Willi | 2012-08-30 | 9 | -26/+42 | |
| | | |