Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | process: Provide an abstraction to spawn child processes with redirected I/O | Martin Willi | 2014-10-06 | 7 | -3/+490 | |
| | ||||||
* | Incremental parsing fixes | Andreas Steffen | 2014-10-05 | 2 | -14/+9 | |
| | ||||||
* | Added add_segment() method to TCG/PTS attributes | Andreas Steffen | 2014-10-05 | 18 | -26/+157 | |
| | ||||||
* | Added add_segment() method to TCG/SEG attributes | Andreas Steffen | 2014-10-05 | 3 | -25/+49 | |
| | ||||||
* | OS IMV proposes IF-M segmentation contract | Andreas Steffen | 2014-10-05 | 6 | -108/+153 | |
| | | | | | | | The OS IMV sends a TCG IF-M Segmentation contract request. All IETF standard attributes support segmentation. Additionally the IETF Installed Packages standard attributes supports incremental processing while segments are received. | |||||
* | SWID IMC proposes IF-M segmentation contracts | Andreas Steffen | 2014-10-05 | 3 | -24/+42 | |
| | ||||||
* | unit-tests: Updated libimcv test suite | Andreas Steffen | 2014-10-05 | 1 | -22/+125 | |
| | ||||||
* | Added add_segment() method to IETF attributes | Andreas Steffen | 2014-10-05 | 12 | -0/+95 | |
| | ||||||
* | Added add_segment() method to ITA attributes | Andreas Steffen | 2014-10-05 | 6 | -0/+47 | |
| | ||||||
* | Implemented incremental processing of SWID tag [ID] inventory attribute | Andreas Steffen | 2014-10-05 | 8 | -199/+253 | |
| | ||||||
* | Implemented add_segment method for PA-TNC attributes | Andreas Steffen | 2014-10-05 | 11 | -90/+208 | |
| | ||||||
* | Added total length parameter in PA-TNC attribute constructor | Andreas Steffen | 2014-10-05 | 91 | -319/+957 | |
| | ||||||
* | Assignment of flags starts with bit 0 | Andreas Steffen | 2014-10-05 | 2 | -5/+5 | |
| | ||||||
* | Register the reception of the AIK attribute | Andreas Steffen | 2014-10-05 | 3 | -2/+9 | |
| | ||||||
* | Unit tests for libimcv | Andreas Steffen | 2014-10-05 | 5 | -0/+649 | |
| | ||||||
* | Compacted chunk creation in ita_attr_command constructor | Andreas Steffen | 2014-10-05 | 1 | -2/+1 | |
| | ||||||
* | Merged libpts into libimcv | Andreas Steffen | 2014-10-05 | 158 | -430/+229 | |
| | ||||||
* | Added out message queue for imv_msg receive method | Andreas Steffen | 2014-10-05 | 8 | -86/+81 | |
| | ||||||
* | Implemented IF-M segmentation | Andreas Steffen | 2014-10-05 | 24 | -320/+1660 | |
| | ||||||
* | Added request variable to get_info_string method | Andreas Steffen | 2014-10-03 | 5 | -11/+12 | |
| | ||||||
* | Implemented IF-M segmentation contracts | Andreas Steffen | 2014-10-03 | 32 | -63/+1354 | |
| | ||||||
* | Allow to treat specified Attribute-Type-Not-Supported errors as non-fatal | Andreas Steffen | 2014-10-03 | 10 | -16/+110 | |
| | ||||||
* | starter: Allow specifying the ipsec.conf location in strongswan.conf | Shea Levy | 2014-10-02 | 1 | -1/+2 | |
| | ||||||
* | stroke: Allow specifying the ipsec.secrets location in strongswan.conf | Shea Levy | 2014-10-02 | 2 | -5/+17 | |
| | ||||||
* | library: Allow specifying the path to strongswan.conf in the STRONGSWAN_CONF ↵ | Shea Levy | 2014-10-02 | 1 | -1/+1 | |
| | | | | env var | |||||
* | Don't fail to install if sysconfdir isn't writable | Shea Levy | 2014-09-26 | 1 | -1/+1 | |
| | ||||||
* | ikev1: Be more verbose if a peer config would match, but is unusable for Mode | Martin Willi | 2014-09-25 | 1 | -0/+12 | |
| | ||||||
* | ikev2: Reorder task activation for established IKE SAs | Tobias Brunner | 2014-09-25 | 1 | -11/+11 | |
| | | | | We now prefer MOBIKE tasks over delete tasks then the rest. | |||||
* | Revert "ikev2: Insert MOBIKE tasks at the front of the queue" | Tobias Brunner | 2014-09-25 | 1 | -6/+1 | |
| | | | | | | | | This reverts commit 3293d146289d7c05e6c6089ae1f7cdbcea378e63. The position of tasks in the queue does not actually determine the order in which they are activated. Instead this is determined by the statements in task_manager_v2_t.initiate(). | |||||
* | curl: For SSL features, depend on thread-safety provided by our crypto plugins | Martin Willi | 2014-09-24 | 3 | -7/+57 | |
| | | | | | | | | | To use SSL in curl, we need to initialize the SSL library in a thread-safe manner and provide the appropriate callbacks. As we already do that in our crypto plugins using these libraries, we depend on these features. This implies that we need the same plugin enabled (openssl, gcrypt) as the curl backend is configured to use to fetch from HTTPS URIs. | |||||
* | curl: Dynamically query supported protocols and register appropriate features | Martin Willi | 2014-09-24 | 1 | -10/+64 | |
| | ||||||
* | leak-detective: Whitelist libssl SSL_COMP_get_compression_methods() | Martin Willi | 2014-09-24 | 1 | -0/+2 | |
| | | | | | This function is called by libcurl initialization with SSL, and uses a static allocation of compression algorithms not freed. | |||||
* | curl: Try to initialize with SSL support to handle https:// URIs | Martin Willi | 2014-09-24 | 1 | -1/+6 | |
| | | | | If initialization fails, we fall back to the old behavior. | |||||
* | watcher: Add a method to query the watcher state | Martin Willi | 2014-09-24 | 2 | -7/+45 | |
| | | | | | This allows a user to check if the watcher is actually running, and potentially perform read operations directly instead of relying on watcher. | |||||
* | kernel-netlink: Define and use rtnetlink message types | Martin Willi | 2014-09-24 | 1 | -1/+22 | |
| | ||||||
* | kernel-netlink: Pass protocol specific enum names to socket constructor | Martin Willi | 2014-09-24 | 4 | -12/+13 | |
| | | | | | This avoid the hard dependency on enum names, and makes kernel_netlink_shared independent of kernel_netlink_ipsec. | |||||
* | kernel-netlink: Clean up socket initialization, handle 0 as valid socket fd | Martin Willi | 2014-09-24 | 1 | -9/+6 | |
| | ||||||
* | kernel-netlink: Clean up response buffer management | Martin Willi | 2014-09-24 | 1 | -24/+16 | |
| | ||||||
* | kernel-netlink: Use recv() instead of recvfrom() | Martin Willi | 2014-09-24 | 1 | -11/+3 | |
| | | | | | As we are not interested in the returned address, there is really no need in passing that argument. | |||||
* | kernel-netlink: Avoid casting the NLMSG_DATA() return value | Martin Willi | 2014-09-24 | 3 | -26/+26 | |
| | | | | There is really no need for doing so, and it makes the code just unreadable. | |||||
* | kernel-netlink: Define netlink buffer as an union having a netlink header | Martin Willi | 2014-09-24 | 4 | -21/+24 | |
| | | | | | This allows us to streamline the netlink buffers, and avoid extensive casting. | |||||
* | systemd: Discover and check systemd libraries with pkg-config during configure | Martin Willi | 2014-09-22 | 1 | -1/+2 | |
| | ||||||
* | systemd: Add a native systemd journal logger | Martin Willi | 2014-09-22 | 2 | -2/+186 | |
| | ||||||
* | plugin-loader: Support a reload() callback for static features | Martin Willi | 2014-09-22 | 9 | -12/+44 | |
| | ||||||
* | systemd: Provide a charon-systemd daemon targeting full systemd integration | Martin Willi | 2014-09-22 | 4 | -0/+242 | |
| | ||||||
* | swanctl: Complete --load-creds command summary | Martin Willi | 2014-09-22 | 1 | -1/+1 | |
| | ||||||
* | swanctl: Fix description of load-pools command summary | Martin Willi | 2014-09-22 | 1 | -1/+1 | |
| | ||||||
* | swanctl: Add a --load-all command, performing --load-{creds,pools,conns} | Martin Willi | 2014-09-22 | 10 | -97/+329 | |
| | ||||||
* | swanctl: Add a --reload-settings command | Martin Willi | 2014-09-22 | 5 | -2/+93 | |
| | ||||||
* | vici: Add a command to reload strongswan.conf | Martin Willi | 2014-09-22 | 1 | -0/+12 | |
| |