aboutsummaryrefslogtreecommitdiffstats
path: root/src
Commit message (Expand)AuthorAgeFilesLines
...
* Newer CRLs replace older versions of the CRL in the cacheAndreas Steffen2016-10-261-0/+39
* connmark: Add CAP_NET_RAW to capabilities keep listTim Kent2016-10-251-0/+6
* nm: Enable IKE fragmentationTobias Brunner2016-10-201-1/+1
* added XOF dependencies of bliss and ntru pluginsAndreas Steffen2016-10-182-4/+26
* newhope: Fix Doxygen group nameTobias Brunner2016-10-141-1/+1
* libnttfft: Fix Doxygen groupTobias Brunner2016-10-141-1/+3
* Fixed some typos, courtesy of codespellTobias Brunner2016-10-142-3/+3
* newhope: Properly release allocated arrays if RNG can't be createdTobias Brunner2016-10-141-8/+8
* nm: Add D-Bus policy to the distributionTobias Brunner2016-10-141-0/+2
* nm: Version bump to 1.4.1Tobias Brunner2016-10-142-1/+6
* kernel-netlink: Fix get_route() interface determinationChristophe Gouault2016-10-121-2/+2
* Save both base and delta CRLs to diskAndreas Steffen2016-10-112-2/+9
* vici: strongswan.conf cache_crls = yes saves fetched CRLs to diskAndreas Steffen2016-10-116-4/+83
* mem-cred: Support storing a delta CRL together with its baseTobias Brunner2016-10-111-8/+30
* revocation: Cache valid CRL also if certificate is revokedTobias Brunner2016-10-111-10/+25
* pki: Don't remove zero bytes in CRL serials anymoreTobias Brunner2016-10-111-6/+7
* pki: Use serial of base CRL for delta CRLsTobias Brunner2016-10-111-1/+4
* openssl: Fix AES-GCM with BoringSSLTobias Brunner2016-10-111-3/+3
* android: Identifiers for SHA2-base RSA signature schemes got renamedTobias Brunner2016-10-111-4/+4
* android: MGF1 implementation was moved to a pluginTobias Brunner2016-10-111-2/+1
* ldap: Fix crash in case of empty LDAP response for CRL fetchYannick CANN2016-10-061-2/+1
* libimcv: Add Debian 8.6 to databaseTobias Brunner2016-10-051-0/+18
* task-manager: Only trigger retransmit cleared alert if there was at least one...Tobias Brunner2016-10-052-2/+2
* unit-tests: Enable optional logging in libcharon unit testsTobias Brunner2016-10-051-0/+17
* unit-tests: Add more tests for proposal creationTobias Brunner2016-10-051-8/+62
* proposal: Correctly add AES-GMAC for AH proposalsTobias Brunner2016-10-051-0/+41
* proposal: Enforce separate proposals for AEAD and classic encryption algorithmsTobias Brunner2016-10-051-16/+22
* proposal: Make sure there is a PRF defined in IKE proposalsTobias Brunner2016-10-051-14/+34
* proposal: Make DH groups mandatory in IKE proposals parsed from stringsTobias Brunner2016-10-052-21/+40
* ikev2: Respond with NO_PROPOSAL_CHOSEN if proposal without DH group was selectedTobias Brunner2016-10-051-0/+1
* kernel-netlink: Consider RTA_SRC when looking for a source addressTobias Brunner2016-10-051-52/+134
* swanctl: Add 'private' directory/section to load any type of private keyTobias Brunner2016-10-054-5/+26
* pki: Add generic 'priv' key type that loads any type of private keyTobias Brunner2016-10-0512-28/+59
* openssl: Add a generic private key loaderTobias Brunner2016-10-057-18/+129
* pkcs1: Support building of KEY_ANY private keysTobias Brunner2016-10-052-5/+73
* pki: Drop -priv suffix to specify private key typesTobias Brunner2016-10-054-16/+23
* ikev2: Only add NAT-D notifies to DPDs as initiatorTobias Brunner2016-10-041-8/+15
* pkcs11: Look for the CKA_ID of the cert if it doesn't match the subjectKeyIdRaphael Geissert2016-10-041-4/+152
* nm: Make global CA directory configurableTobias Brunner2016-10-041-1/+2
* ikev1: Activate task to delete the IKE_SA in state IKE_REKEYINGTobias Brunner2016-10-041-0/+8
* ikev1: Delete Quick Mode SAs before the ISAKMP SATobias Brunner2016-10-041-2/+2
* ikev1: Send DELETE for rekeyed IKE_SAsTobias Brunner2016-10-041-9/+5
* starter: Install an empty ipsec.secrets fileTobias Brunner2016-10-042-1/+3
* starter: Don't generate a key/certificate if ipsec.secrets does not existTobias Brunner2016-10-042-70/+0
* watcher: Avoid allocations due to enumeratorsTobias Brunner2016-10-041-37/+83
* vici: Enable IKE fragmentation by defaultTobias Brunner2016-10-042-4/+4
* starter: Enable IKE fragmentation by defaultTobias Brunner2016-10-041-0/+1
* ike: Set default IKE fragment size to 1280Tobias Brunner2016-10-041-1/+1
* ikev2: Send derived CHILD_SA keys to the busTobias Brunner2016-10-041-26/+43
* ikev2: Send derived IKE_SA keys to busTobias Brunner2016-10-041-26/+30