Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | stroke: Don't log unspecified options of conn and ca sections | Tobias Brunner | 2014-06-30 | 1 | -37/+50 | |
| | ||||||
* | utils: Helper macros to define overloaded macros based on number of arguments | Tobias Brunner | 2014-06-30 | 1 | -0/+26 | |
| | ||||||
* | pki: Document --online option for pki --verify and all exit codes | Tobias Brunner | 2014-06-30 | 1 | -5/+11 | |
| | ||||||
* | autoconf: Replace --disable-tools option with --disable-scepclient | Tobias Brunner | 2014-06-30 | 4 | -4/+4 | |
| | | | | | Since using a separate option for pki this was the only tool that was still enabled by that option. | |||||
* | checksum: Fix checksum generation for pki if tools are disabled | Tobias Brunner | 2014-06-30 | 1 | -0/+3 | |
| | ||||||
* | swid: Fix parameter documentation in Doxygen comments | Tobias Brunner | 2014-06-30 | 2 | -2/+2 | |
| | ||||||
* | windows: Fix parameter name in Doxygen comment | Tobias Brunner | 2014-06-30 | 1 | -1/+1 | |
| | ||||||
* | enum: Replace þ with p in Doxygen comments | Tobias Brunner | 2014-06-30 | 1 | -2/+2 | |
| | ||||||
* | libvici: Add missing argument to Doxygen comment | Tobias Brunner | 2014-06-30 | 1 | -0/+1 | |
| | ||||||
* | starter: Add starter group and fix formatting of conf_parser_section_t enum | Tobias Brunner | 2014-06-30 | 1 | -2/+4 | |
| | | | | Make use of the Markdown support in recent Doxygen versions. | |||||
* | swanctl: Fix Doxygen group assignment | Tobias Brunner | 2014-06-30 | 1 | -1/+1 | |
| | ||||||
* | Fixed some typos | Tobias Brunner | 2014-06-30 | 5 | -5/+5 | |
| | ||||||
* | Added Android 4.4.4 to IMV database | Andreas Steffen | 2014-06-27 | 1 | -0/+12 | |
| | ||||||
* | kernel-pfkey: Use address in TS to determine interface for shunt routes | Tobias Brunner | 2014-06-26 | 1 | -6/+9 | |
| | ||||||
* | kernel-pfkey: Use subnet and prefix when determining nexthop for shunt ↵ | Tobias Brunner | 2014-06-26 | 1 | -2/+12 | |
| | | | | | | policy routes This is basically the same as 88f125f5605e54b38cf8913df79e32ec6bddff10. | |||||
* | kernel-pfkey: Install routes for shunt policies | Tobias Brunner | 2014-06-26 | 1 | -4/+4 | |
| | ||||||
* | starter: Ingore %default conn and ca sections | Tobias Brunner | 2014-06-26 | 2 | -0/+60 | |
| | ||||||
* | Updated build-database.sh to 3.13.0-30-generic Ubuntu kernel | Andreas Steffen | 2014-06-26 | 1 | -1/+1 | |
| | ||||||
* | updown: Force subnet address to be numeric | Tobias Brunner | 2014-06-25 | 1 | -2/+2 | |
| | ||||||
* | windows: Include <sys/stat.h> explicitly before overloading memset()/memcpy() | Martin Willi | 2014-06-25 | 1 | -0/+1 | |
| | | | | | | fstat() in newer MinGWs is defined as non-static inline. With our new static inline memset()/memcpy() overloads, this raises a warning. To avoid it, explicitly include <sys/stat.h> once before defining these overloads. | |||||
* | eap-radius: Increase buffer for accounting attributes to maximum attribute size | Martin Willi | 2014-06-25 | 1 | -1/+1 | |
| | | | | Fixes #624. | |||||
* | kernel-netlink: Cast IPv6 address blobs to the proper type | Tobias Brunner | 2014-06-24 | 1 | -3/+3 | |
| | | | | On Android these macros are defined as functions. | |||||
* | android: Define HAVE_DLADDR as plugin loader checks for it | Tobias Brunner | 2014-06-24 | 2 | -2/+1 | |
| | ||||||
* | android: Update Android.mk files to match changes due to the Windows port | Tobias Brunner | 2014-06-24 | 2 | -7/+19 | |
| | | | | Makes them easier to compare to the original Makefile.am. | |||||
* | charon: Set CLOEXEC flag on daemon PID file and /dev/(u)random source FDs | Martin Willi | 2014-06-24 | 2 | -0/+15 | |
| | | | | | | | | | | | | | On Fedora, SELinux complains about these open file descriptors when the updown script invokes iptables. While it seems difficult to set the flag on all file descriptors, this at least fixes those covered by the SELinux policy. As these two cases are in code executed while the daemon is still single threaded, we avoid the use of atomic but not fully portable fdopen("e") or open(O_CLOEXEC) calls. Fixes #519. | |||||
* | utils: Add wrappers for memcpy(3), memmove(3) and memset(3) | Tobias Brunner | 2014-06-24 | 1 | -1/+33 | |
| | | | | | | | | These wrappers guarantee that calls to these functions are noops if the number of bytes is 0, as calling them with NULL pointers is undefined according to the C standard, even if the number of bytes is 0 (most implementations probably ignore the pointers anyway in this case, but lets make sure). | |||||
* | pki: Also check for MAX_COMMANDS when building getopt_long arguments | Tobias Brunner | 2014-06-24 | 1 | -1/+1 | |
| | | | | Completes 87e53819a6 and 0a8c399a21. | |||||
* | Auxiliary swid_tagstats table boosts performance | Andreas Steffen | 2014-06-23 | 1 | -0/+14 | |
| | ||||||
* | unit-tests: Add tests for DH factory | Tobias Brunner | 2014-06-20 | 1 | -0/+157 | |
| | ||||||
* | crypto-factory: Only sort RNGs by algorithm identifier | Tobias Brunner | 2014-06-20 | 1 | -5/+13 | |
| | | | | | Others remain in the order in which they were added, grouped by algorithm identifier and sorted by benchmarking speed, if provided. | |||||
* | unit-tests: Add test for crypto_factory_t's rng_create method | Tobias Brunner | 2014-06-20 | 3 | -0/+157 | |
| | ||||||
* | kernel-netlink: Install virtual IPv6 addresses as deprecated | Tobias Brunner | 2014-06-20 | 1 | -0/+11 | |
| | | | | | | | | This should prevent the kernel's IPv6 source address selection algorithm from using this address unless it is forced to by our source route. This is helpful if split tunneling is used. Fixes #598. | |||||
* | vici: Install libvici in ipseclibdir like we do with other libraries | Tobias Brunner | 2014-06-19 | 1 | -1/+1 | |
| | ||||||
* | kernel-netlink: Pass prefix when looking up next hop for shunt policies | Tobias Brunner | 2014-06-19 | 1 | -1/+12 | |
| | ||||||
* | kernel-netlink: Add support for destination prefix when determining next hop | Tobias Brunner | 2014-06-19 | 1 | -20/+35 | |
| | ||||||
* | kernel-interface: Add destination prefix to get_nexthop() | Tobias Brunner | 2014-06-19 | 10 | -13/+18 | |
| | | | | | This allows to determine the next hop to reach a subnet, for instance, when installing routes for shunt policies. | |||||
* | shunt-manager: Install passthrough policies with highest priority | Tobias Brunner | 2014-06-19 | 1 | -9/+34 | |
| | | | | | | This avoids conflicts with regular IPsec policies. Similarly, use the lowest priority for drop policies. | |||||
* | libipsec: Add support for new policy priority class | Tobias Brunner | 2014-06-19 | 1 | -1/+4 | |
| | ||||||
* | kernel-pfkey: Add support for new policy priority class | Tobias Brunner | 2014-06-19 | 1 | -2/+5 | |
| | ||||||
* | kernel-netlink: Add support for new policy priority class | Tobias Brunner | 2014-06-19 | 1 | -2/+5 | |
| | ||||||
* | ipsec: Add a fourth priority class for bypass policies | Tobias Brunner | 2014-06-19 | 1 | -1/+3 | |
| | ||||||
* | Remove kernel-klips plugin | Tobias Brunner | 2014-06-19 | 7 | -3164/+0 | |
| | ||||||
* | kernel-netlink: Follow RFC 6724 when selecting IPv6 source addresses | Tobias Brunner | 2014-06-19 | 1 | -26/+170 | |
| | | | | | | | | Instead of using the first address we find on an interface we should consider properties like an address' scope or whether it is temporary or public. Fixes #543. | |||||
* | starter: Don't directly refer to source files in Makefile for unit tests | Tobias Brunner | 2014-06-19 | 2 | -5/+8 | |
| | | | | | Older versions of automake have trouble recursively cleaning such constructs properly. | |||||
* | starter: Explicitly allow @# at the beginning of strings | Tobias Brunner | 2014-06-19 | 2 | -1/+4 | |
| | | | | | Since we treat everything after # as comment identities of type ID_KEY_ID couldn't be parsed otherwise, unless quoted. | |||||
* | starter: Add --conftest option to test ipsec.conf syntax | Tobias Brunner | 2014-06-19 | 1 | -0/+27 | |
| | ||||||
* | starter: Remove old parser | Tobias Brunner | 2014-06-19 | 6 | -545/+4 | |
| | ||||||
* | starter: Use new parser to read config file | Tobias Brunner | 2014-06-19 | 4 | -769/+493 | |
| | ||||||
* | starter: Move kw_entry_t definition | Tobias Brunner | 2014-06-19 | 2 | -9/+10 | |
| | ||||||
* | starter: Remove unused ARG_LST argument type | Tobias Brunner | 2014-06-19 | 2 | -147/+5 | |
| |