index
:
tteras/strongswan
master
tteras
tteras-release
tteras' strongSwan tree
gitolite
about
summary
refs
log
tree
commit
diff
stats
log msg
author
committer
range
path:
root
/
src
Commit message (
Expand
)
Author
Age
Files
Lines
...
*
charon-nm: Fix typo to actually use random NAT-T port
Tobias Brunner
2017-05-19
1
-1
/
+1
*
af-alg: Fix crypt() definition conflict
Baruch Siach
2017-05-15
1
-2
/
+2
*
x509: Evaluate return codes of parsing functions
Andreas Steffen
2017-05-08
4
-52
/
+149
*
nm: Explicitly prevent the smartcard PIN from being stored
Raphael Geissert
2017-05-08
1
-0
/
+2
*
nm: IKE/ESP proposal customization support
Defunct
2017-05-08
2
-0
/
+202
*
charon-nm: IKE/ESP proposal customization support
Defunct
2017-05-08
1
-5
/
+59
*
eap-simaka-sql: Fixed database column from use to used
Andreas Steffen
2017-04-26
1
-4
/
+7
*
pki: Reset variable so error handling works properly
Tobias Brunner
2017-04-19
1
-0
/
+1
*
vici: Fix type error exception in Python bindings
odi79
2017-04-19
1
-1
/
+1
*
kernel-netlink: Avoid O(n^2) copy operations when concatenating Netlink respo...
Jiri Horky
2017-03-27
1
-7
/
+13
*
libtls: Replace expired certificates for unit tests
Tobias Brunner
2017-03-24
1
-68
/
+66
*
pki: Actually make the default key type KEY_ANY for --self
Tobias Brunner
2017-03-24
1
-1
/
+1
*
addrblock: Narrow selectors when rekeying a CHILD_SA as original responder
Martin Willi
2017-03-24
1
-0
/
+1
*
kernel-wfp: Don't redefine IPPROTO_IP* if already defined
Tobias Brunner
2017-03-23
1
-0
/
+4
*
pki: Cast length derived from pointer arithmetic to int
Tobias Brunner
2017-03-23
1
-1
/
+1
*
vici: Don't fall back to uninstalling traps if a matching shunt was found
Tobias Brunner
2017-03-23
1
-3
/
+7
*
Fixed some typos, courtesy of codespell
Tobias Brunner
2017-03-23
7
-7
/
+7
*
swanctl: Reformulate IKEv1 selector restriction, describe problems with TS na...
Noel Kuntze
2017-03-23
1
-3
/
+10
*
swanctl: Mention including files when referring to strongswan.conf(5)
Tobias Brunner
2017-03-23
1
-1
/
+2
*
Allow x25519 as an alias of the curve25519 KE algorithm
Andreas Steffen
2017-03-20
1
-0
/
+1
*
Reference Edwards-curve signature RFCs
Andreas Steffen
2017-03-20
3
-17
/
+19
*
The tpm plugin offers random number generation
Andreas Steffen
2017-03-20
7
-3
/
+208
*
vici: Document how we pronounce the vici protocol and plugin
Martin Willi
2017-03-20
1
-3
/
+3
*
swanctl: Describe what happens when a FQDN is specified in local|remote_addrs
Tobias Brunner
2017-03-20
1
-0
/
+6
*
ikev1: First do PSK lookups based on identities then fallback to IPs
Tobias Brunner
2017-03-20
1
-36
/
+34
*
ike-sa-manager: Remove superfluous assignment
Thomas Egerer
2017-03-16
1
-4
/
+0
*
ike: Log remote IP when deleting half-open IKE_SAs
Tobias Brunner
2017-03-15
1
-1
/
+2
*
aikpub2: Removed aikpub2 tool
Andreas Steffen
2017-03-06
4
-325
/
+0
*
pki: Add key object handle of smartcard or TPM private key as an argument to ...
Andreas Steffen
2017-03-06
2
-5
/
+25
*
utils: chunk_from_hex() skips optional 0x prefix
Andreas Steffen
2017-03-06
2
-11
/
+18
*
pki: Edited keyid parameter use in various pki man pages and usage outputs
Andreas Steffen
2017-03-06
12
-19
/
+34
*
quick-mode: Correctly prepare NAT-OA payloads as responder
Tobias Brunner
2017-03-06
1
-8
/
+13
*
Add keyid of smartcard or TPM private key as an argument to pki --req
Andreas Steffen
2017-03-02
1
-2
/
+15
*
libipsec: Enforce a minimum of 256 for SPIs
Tobias Brunner
2017-03-02
1
-3
/
+4
*
libipsec: Fix min/max SPI
Tobias Brunner
2017-03-02
1
-2
/
+2
*
controller: Don't listen for CHILD_SA state changes when terminating IKE_SAs
Tobias Brunner
2017-03-02
1
-1
/
+0
*
kernel: Make range of SPIs for IPsec SAs configurable
Tobias Brunner
2017-03-02
4
-8
/
+40
*
settings: Add support for hex integers (0x prefix) via get_int()
Tobias Brunner
2017-03-02
1
-1
/
+6
*
libipsec: Log a packet's ports and protocol in case of a policy mismatch
Tobias Brunner
2017-03-02
1
-5
/
+7
*
host: Don't log port if it is zero
Tobias Brunner
2017-03-02
2
-6
/
+6
*
libipsec: Match IPsec policies against ports of processed packets
Tobias Brunner
2017-03-02
1
-1
/
+21
*
addrblock: Use dynamic TS narrowing instead of rejecting the whole CHILD_SA
Martin Willi
2017-03-02
1
-43
/
+28
*
addrblock: Support an optional non-strict mode accepting certs without addrblock
Martin Willi
2017-03-02
1
-3
/
+11
*
child-cfg: Always apply hosts to traffic selectors if proposing transport mode
Tobias Brunner
2017-02-27
1
-14
/
+19
*
traffic-selector: Allow calling set_address() for any traffic selector
Tobias Brunner
2017-02-27
3
-48
/
+63
*
pki: Add a note about constructing RFC 3779 compliant certificates to manpage
Martin Willi
2017-02-27
2
-0
/
+6
*
pki: Support an --addrblock option for issued certificates
Martin Willi
2017-02-27
2
-1
/
+22
*
pki: Support an --addrblock option for self-signed certificates
Martin Willi
2017-02-27
2
-0
/
+23
*
pki: Add a helper function parse traffic selectors from CIDR subnets or ranges
Martin Willi
2017-02-27
2
-0
/
+31
*
x509: Do not mark generated addrblock extension as critical
Martin Willi
2017-02-27
1
-2
/
+1
[prev]
[next]