aboutsummaryrefslogtreecommitdiffstats
path: root/src
Commit message (Expand)AuthorAgeFilesLines
...
* smp: Correctly return IKE SPIs stored in network orderTobias Brunner2016-03-041-4/+4
* vici: Correctly return IKE SPIs stored in network orderTobias Brunner2016-03-041-2/+4
* stroke: Correctly print IKE SPIs stored in network orderTobias Brunner2016-03-041-2/+4
* byteorder: Simplify htoun64/untoh64 functionsTobias Brunner2016-03-041-27/+0
* byteorder: Always define be64toh/htobe64 macrosTobias Brunner2016-03-041-20/+30
* swanctl: Document signature scheme constraintsTobias Brunner2016-03-041-1/+30
* vici: Add support for pubkey constraints with EAP-TLSTobias Brunner2016-03-041-0/+8
* auth-cfg: Make IKE signature schemes configurableTobias Brunner2016-03-047-42/+194
* ikev2: Always store signature scheme in auth-cfgTobias Brunner2016-03-041-12/+1
* ikev2: Diversify signature scheme ruleThomas Egerer2016-03-044-33/+72
* ike-init: Verify REDIRECT notify before processing IKE_SA_INIT messageTobias Brunner2016-03-041-7/+51
* ikev2: Allow tasks to verify request messages before processing themTobias Brunner2016-03-041-4/+47
* ikev2: Allow tasks to verify response messages before processing themTobias Brunner2016-03-041-1/+27
* task: Add optional pre_process() methodTobias Brunner2016-03-041-1/+13
* ike-init: Ignore notifies related to redirects during rekeyingTobias Brunner2016-03-041-3/+13
* ike-sa: Add limit for the number of redirects within a defined time periodTobias Brunner2016-03-042-0/+54
* ike-sa: Reauthenticate to the same addresses we currently useTobias Brunner2016-03-041-2/+5
* vici: Don't redirect all SAs if no selectors are givenTobias Brunner2016-03-041-1/+1
* vici: Match subnets and ranges against peer IP in redirect commandTobias Brunner2016-03-043-13/+43
* vici: Match identity with wildcards against remote ID in redirect commandTobias Brunner2016-03-043-6/+10
* swanctl: Add --redirect commandTobias Brunner2016-03-044-1/+138
* vici: Add redirect commandTobias Brunner2016-03-045-0/+150
* redirect-job: Add job to redirect an active IKE_SATobias Brunner2016-03-044-0/+159
* ike-sa: Add redirect() method to actively redirect an IKE_SATobias Brunner2016-03-042-0/+50
* ike-redirect: Add task to redirect active IKE_SAsTobias Brunner2016-03-047-0/+220
* ike-auth: Handle REDIRECT notifies during IKE_AUTHTobias Brunner2016-03-041-22/+44
* ike-sa: Handle redirect requests for established SAs as reestablishmentTobias Brunner2016-03-041-82/+174
* ike-auth: Send REDIRECT notify during IKE_AUTH if requested by providersTobias Brunner2016-03-041-27/+51
* ike-config: Do not assign attributes for redirected IKE_SAsTobias Brunner2016-03-041-0/+5
* child-create: Don't create CHILD_SA if the IKE_SA got redirected in IKE_AUTHTobias Brunner2016-03-041-0/+4
* ike-sa: Add a condition to mark redirected IKE_SAsTobias Brunner2016-03-041-0/+5
* ike-init: Handle REDIRECTED_FROM similar to REDIRECT_SUPPORTED as serverTobias Brunner2016-03-041-0/+17
* ike-init: Send REDIRECTED_FROM instead of REDIRECT_SUPPORTED if appropriateTobias Brunner2016-03-041-1/+19
* ike-sa: Keep track of the address of the gateway that redirected usTobias Brunner2016-03-042-1/+27
* ikev2: Add option to disable following redirects as clientTobias Brunner2016-03-042-1/+20
* ikev2: Handle REDIRECT notifies during IKE_SA_INITTobias Brunner2016-03-043-0/+64
* ike-init: Send REDIRECT notify during IKE_SA_INIT if requested by providersTobias Brunner2016-03-041-0/+17
* redirect-manager: Add helper function to create and parse REDIRECT notify dataTobias Brunner2016-03-042-11/+162
* redirect-manager: Verify type of returned gateway IDTobias Brunner2016-03-041-1/+12
* ike-init: Send REDIRECT_SUPPORTED as initiatorTobias Brunner2016-03-041-0/+5
* ike-init: Enable redirection extension if client sends REDIRECT_SUPPORTED notifyTobias Brunner2016-03-041-0/+4
* ike-sa: Add new extension for IKEv2 redirection (RFC 5685)Tobias Brunner2016-03-041-1/+6
* daemon: Create global redirect manager instanceTobias Brunner2016-03-042-0/+8
* redirect-manager: Add manager for redirect providersTobias Brunner2016-03-044-2/+223
* redirect-provider: Add interface to redirect clients during initial messagesTobias Brunner2016-03-043-0/+61
* Set PLUTO port variables to 0 in the case of no port restrictionsAndreas Steffen2016-03-041-1/+1
* Port range support in updown scriptAndreas Steffen2016-03-041-13/+37
* Implemented port ranges in kernel_netlink interfaceAndreas Steffen2016-03-041-7/+19
* thread: Allow thread ID to be value returned by gettid()Thomas Egerer2016-03-043-14/+32
* Request missing SWID tags in a directed PA-TNC messageAndreas Steffen2016-03-043-20/+47