index
:
tteras/strongswan
master
tteras
tteras-release
tteras' strongSwan tree
gitolite
about
summary
refs
log
tree
commit
diff
stats
log msg
author
committer
range
path:
root
/
src
Commit message (
Expand
)
Author
Age
Files
Lines
...
*
tkm: Implement hash algorithm storage methods of keymat_v2_t interface
Tobias Brunner
2015-03-04
1
-0
/
+29
*
keymat: Use hash algorithm set
Tobias Brunner
2015-03-04
1
-29
/
+7
*
hash-algorithm-set: Add class to manage a set of hash algorithms
Tobias Brunner
2015-03-04
4
-1
/
+193
*
ikev2: Add an option to disable constraints against signature schemes
Tobias Brunner
2015-03-04
1
-1
/
+11
*
stroke: Enable BLISS-based public key constraints
Tobias Brunner
2015-03-04
1
-4
/
+19
*
credential-manager: Store BLISS key strength in auth config
Tobias Brunner
2015-03-04
1
-0
/
+3
*
auth-cfg: Add BLISS key strength constraint
Tobias Brunner
2015-03-04
2
-21
/
+43
*
ikev2: Fall back to SHA-1 signatures for RSA
Tobias Brunner
2015-03-04
1
-0
/
+7
*
ikev2: Select a signature scheme appropriate for the given key
Tobias Brunner
2015-03-04
1
-18
/
+13
*
public-key: Add helper to determine acceptable signature schemes for keys
Tobias Brunner
2015-03-04
3
-1
/
+122
*
ikev2: Log the actual signature scheme used for RFC 7427 authentication
Tobias Brunner
2015-03-04
1
-4
/
+6
*
ikev2: Store signature scheme used to verify peer in auth_cfg
Tobias Brunner
2015-03-04
1
-0
/
+1
*
ikev2: Add a global option to disable RFC 7427 signature authentication
Tobias Brunner
2015-03-04
1
-2
/
+12
*
ikev2: Remove private AUTH_BLISS method
Tobias Brunner
2015-03-04
3
-18
/
+1
*
ikev2: Handle RFC 7427 signature authentication in pubkey authenticator
Tobias Brunner
2015-03-04
2
-49
/
+179
*
hasher: Add helper to determine hash algorithm from signature scheme
Tobias Brunner
2015-03-04
2
-0
/
+44
*
public-key: Add helper to map signature schemes to ASN.1 OIDs
Tobias Brunner
2015-03-04
2
-3
/
+54
*
public-key: Add helper to determine key type from signature scheme
Tobias Brunner
2015-03-04
2
-0
/
+43
*
ikev2: Enable signature authentication by transmitting supported hash algorithms
Tobias Brunner
2015-03-04
2
-4
/
+88
*
keymat: Add facility to store supported hash algorithms
Tobias Brunner
2015-03-04
2
-1
/
+70
*
hasher: Add filter function for algorithms permitted by RFC 7427
Tobias Brunner
2015-03-04
2
-0
/
+30
*
hasher: Redefine hash algorithms to match values defined by RFC 7427
Tobias Brunner
2015-03-04
2
-27
/
+29
*
ikev2: Add SIGNATURE_HASH_ALGORITHMS notify payload
Tobias Brunner
2015-03-04
2
-6
/
+18
*
ikev2: Add new authentication method defined by RFC 7427
Tobias Brunner
2015-03-04
2
-3
/
+9
*
ikev2: Only accept initial messages in specific states
Tobias Brunner
2015-03-04
1
-10
/
+9
*
ike-sa-manager: Make sure the message ID of initial messages is 0
Tobias Brunner
2015-03-04
1
-1
/
+2
*
ikev2: Don't destroy the SA if an IKE_SA_INIT with unexpected MID is received
Tobias Brunner
2015-03-04
1
-4
/
+0
*
ikev2: Don't adopt any CHILD_SA during make-before-break reauthentication
Martin Willi
2015-03-04
1
-1
/
+2
*
unit-tests: Base attributes get adopted by seg-env/seg-contract
Tobias Brunner
2015-03-03
1
-4
/
+4
*
seg-env: Destroy base attribute if segmentation is not possible
Tobias Brunner
2015-03-03
1
-0
/
+1
*
stroke: Support public key constraints for EAP methods
Martin Willi
2015-03-03
1
-1
/
+8
*
eap-ttls: Support EAP auth information getter in EAP-TTLS
Martin Willi
2015-03-03
1
-0
/
+7
*
eap-tls: Support EAP auth information getter in EAP-TLS
Martin Willi
2015-03-03
1
-0
/
+7
*
libtls: Add getters for TLS handshake authentication details
Martin Willi
2015-03-03
7
-0
/
+49
*
libtls: Merge trustchain auth verification details done during TLS handhsake
Martin Willi
2015-03-03
2
-0
/
+2
*
ikev2: Merge EAP client authentication details if EAP methods provides them
Martin Willi
2015-03-03
1
-0
/
+7
*
eap: Add an optional authentication details getter to the EAP method interface
Martin Willi
2015-03-03
1
-0
/
+12
*
ipsec: Update rereadcacerts/aacerts command description in manpage
Martin Willi
2015-03-03
1
-6
/
+9
*
stroke: Serve ca section CA certificates directly, not over central CA set
Martin Willi
2015-03-03
3
-5
/
+85
*
mem-cred: Add a method to unify certificate references, without adding it
Martin Willi
2015-03-03
2
-0
/
+31
*
stroke: Purge existing CA/AA certificates during reread
Martin Willi
2015-03-03
1
-0
/
+4
*
stroke: Use separate credential sets for CA/AA certificates
Martin Willi
2015-03-03
1
-3
/
+21
*
stroke: Refactor load_certdir function
Martin Willi
2015-03-03
1
-108
/
+158
*
vici: Don't use a default rand_time larger than half of rekey/reauth_time
Martin Willi
2015-03-03
1
-3
/
+11
*
vici: If a IKE reauth_time is configured, disable the default rekey_time
Martin Willi
2015-03-03
2
-2
/
+19
*
ikev2: Schedule a timeout for the delete message following passive IKE rekeying
Martin Willi
2015-03-03
1
-0
/
+6
*
kernel-netlink: Respect kernel routing priorities for IKE routes
Martin Willi
2015-03-03
1
-2
/
+15
*
enum: Extend printf hook to print flags
Thomas Egerer
2015-03-03
3
-8
/
+286
*
unit-tests: Don't fail host_create_from_dns() test if IPv6 not supported
Martin Willi
2015-03-02
1
-4
/
+10
*
bliss: Add generated Huffman codes to the repository
Tobias Brunner
2015-03-02
5
-14
/
+860
[prev]
[next]