aboutsummaryrefslogtreecommitdiffstats
path: root/src
Commit message (Expand)AuthorAgeFilesLines
...
* vici: Don't fall back to uninstalling traps if a matching shunt was foundTobias Brunner2017-03-231-3/+7
* Fixed some typos, courtesy of codespellTobias Brunner2017-03-237-7/+7
* swanctl: Reformulate IKEv1 selector restriction, describe problems with TS na...Noel Kuntze2017-03-231-3/+10
* swanctl: Mention including files when referring to strongswan.conf(5)Tobias Brunner2017-03-231-1/+2
* Allow x25519 as an alias of the curve25519 KE algorithmAndreas Steffen2017-03-201-0/+1
* Reference Edwards-curve signature RFCsAndreas Steffen2017-03-203-17/+19
* The tpm plugin offers random number generationAndreas Steffen2017-03-207-3/+208
* vici: Document how we pronounce the vici protocol and pluginMartin Willi2017-03-201-3/+3
* swanctl: Describe what happens when a FQDN is specified in local|remote_addrsTobias Brunner2017-03-201-0/+6
* ikev1: First do PSK lookups based on identities then fallback to IPsTobias Brunner2017-03-201-36/+34
* ike-sa-manager: Remove superfluous assignmentThomas Egerer2017-03-161-4/+0
* ike: Log remote IP when deleting half-open IKE_SAsTobias Brunner2017-03-151-1/+2
* aikpub2: Removed aikpub2 toolAndreas Steffen2017-03-064-325/+0
* pki: Add key object handle of smartcard or TPM private key as an argument to ...Andreas Steffen2017-03-062-5/+25
* utils: chunk_from_hex() skips optional 0x prefixAndreas Steffen2017-03-062-11/+18
* pki: Edited keyid parameter use in various pki man pages and usage outputsAndreas Steffen2017-03-0612-19/+34
* quick-mode: Correctly prepare NAT-OA payloads as responderTobias Brunner2017-03-061-8/+13
* Add keyid of smartcard or TPM private key as an argument to pki --reqAndreas Steffen2017-03-021-2/+15
* libipsec: Enforce a minimum of 256 for SPIsTobias Brunner2017-03-021-3/+4
* libipsec: Fix min/max SPITobias Brunner2017-03-021-2/+2
* controller: Don't listen for CHILD_SA state changes when terminating IKE_SAsTobias Brunner2017-03-021-1/+0
* kernel: Make range of SPIs for IPsec SAs configurableTobias Brunner2017-03-024-8/+40
* settings: Add support for hex integers (0x prefix) via get_int()Tobias Brunner2017-03-021-1/+6
* libipsec: Log a packet's ports and protocol in case of a policy mismatchTobias Brunner2017-03-021-5/+7
* host: Don't log port if it is zeroTobias Brunner2017-03-022-6/+6
* libipsec: Match IPsec policies against ports of processed packetsTobias Brunner2017-03-021-1/+21
* addrblock: Use dynamic TS narrowing instead of rejecting the whole CHILD_SAMartin Willi2017-03-021-43/+28
* addrblock: Support an optional non-strict mode accepting certs without addrblockMartin Willi2017-03-021-3/+11
* child-cfg: Always apply hosts to traffic selectors if proposing transport modeTobias Brunner2017-02-271-14/+19
* traffic-selector: Allow calling set_address() for any traffic selectorTobias Brunner2017-02-273-48/+63
* pki: Add a note about constructing RFC 3779 compliant certificates to manpageMartin Willi2017-02-272-0/+6
* pki: Support an --addrblock option for issued certificatesMartin Willi2017-02-272-1/+22
* pki: Support an --addrblock option for self-signed certificatesMartin Willi2017-02-272-0/+23
* pki: Add a helper function parse traffic selectors from CIDR subnets or rangesMartin Willi2017-02-272-0/+31
* x509: Do not mark generated addrblock extension as criticalMartin Willi2017-02-271-2/+1
* x509: Support encoding the RFC 3779 addrblock extensionMartin Willi2017-02-271-3/+134
* builder: Define a builder part for X.509 RFC 3779 address blocksMartin Willi2017-02-272-0/+3
* plugin-loader: Fix hashing of registered plugin featuresTobias Brunner2017-02-241-1/+1
* Use of TPM 2.0 private keys for signatures via tpm pluginAndreas Steffen2017-02-228-6/+454
* Implement signatures with private keys bound to TPM 2.0Andreas Steffen2017-02-213-8/+215
* android: New release after fixing potential ANR issueTobias Brunner2017-02-201-2/+2
* android: Send network change events from a separate thread via JNITobias Brunner2017-02-172-4/+68
* ikev1: Respond to DPDs for rekeyed IKE_SAsTobias Brunner2017-02-172-0/+10
* ike-sa: Optionally try to migrate to the best path on routing priority changesMartin Willi2017-02-171-1/+23
* ikev2: Ignore roam events without MOBIKE but static local addressTobias Brunner2017-02-171-0/+10
* ike-cfg: Add helper function to determine if a given IP address was configuredTobias Brunner2017-02-172-2/+46
* vici: Only log messages if there actually is a listenerTobias Brunner2017-02-161-0/+7
* vici: Let has_event_listeners() actually check if clients are registeredTobias Brunner2017-02-161-2/+4
* vici: Add support for mediation extensionTobias Brunner2017-02-162-1/+109
* peer-cfg: Store mediated_by as name and not peer-cfg referenceTobias Brunner2017-02-166-68/+95