Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | testing: Add ikev2/rw-sig-auth scenario | Tobias Brunner | 2015-03-04 | 12 | -0/+180 | |
| | ||||||
* | testing: Add ikev2/net2net-cert-sha2 scenario | Tobias Brunner | 2015-03-04 | 9 | -0/+104 | |
| | ||||||
* | Implemented improved BLISS-B signature algorithm | Andreas Steffen | 2015-02-25 | 3 | -0/+0 | |
| | ||||||
* | testing: Add a forecast test case | Martin Willi | 2015-02-20 | 11 | -0/+152 | |
| | ||||||
* | testing: Add a connmark plugin test | Martin Willi | 2015-02-20 | 9 | -0/+109 | |
| | | | | | | | | | | In this test two hosts establish a transport mode connection from behind moon. sun uses the connmark plugin to distinguish the flows. This is an example that shows how one can terminate L2TP/IPsec connections from two hosts behind the same NAT. For simplification of the test, we use an SSH connection instead, but this works for any connection initiated flow that conntrack can track. | |||||
* | testing: Update description and test evaluation of host2host-transport-nat | Martin Willi | 2015-02-20 | 3 | -9/+8 | |
| | | | | | | | | As we now reuse the reqid for identical SAs, the behavior changes for transport connections to multiple peers behind the same NAT. Instead of rejecting the SA, we now have two valid SAs active. For the reverse path, however, sun sends traffic always over the newer SA, resembling the behavior before we introduced explicit SA conflicts for different reqids. | |||||
* | testing: Be a little more flexible in testing for established CHILD_SA modes | Martin Willi | 2015-02-20 | 8 | -21/+21 | |
| | | | | | As we now print the reqid parameter in the CHILD_SA details, adapt the grep to still match the CHILD_SA mode and protocol. | |||||
* | testing: Add a test scenario for make-before-break reauth using a virtual IP | Martin Willi | 2015-02-20 | 9 | -0/+100 | |
| | ||||||
* | testing: Add a test scenario for make-before-break reauth without a virtual IP | Martin Willi | 2015-02-20 | 9 | -0/+97 | |
| | ||||||
* | testing: Add tkm xfrmproxy-expire test | Reto Buerki | 2015-02-20 | 11 | -0/+121 | |
| | | | | | | This test asserts that the handling of XFRM expire messages from the kernel are handled correctly by the xfrm-proxy and the Esa Event Service (EES) in charon-tkm. | |||||
* | testing: Assert ees acquire messages in xfrmproxy tests | Reto Buerki | 2015-02-20 | 2 | -0/+2 | |
| | ||||||
* | testing: Assert proper ESA deletion | Reto Buerki | 2015-02-20 | 1 | -0/+4 | |
| | | | | | Extend the tkm/host2host-initiator testcase by asserting proper ESA deletion after connection shutdown. | |||||
* | Updated RFC3779 certificates5.2.2 | Andreas Steffen | 2014-12-28 | 14 | -299/+299 | |
| | ||||||
* | Updated BLISS CA certificate in ikev2/rw-ntru-bliss scenario5.2.2rc1 | Andreas Steffen | 2014-12-12 | 3 | -0/+0 | |
| | ||||||
* | Updated BLISS scenario keys and certificates to new format | Andreas Steffen | 2014-12-12 | 6 | -0/+0 | |
| | ||||||
* | Increased check size du to INITIAL_CONTACT notify | Andreas Steffen | 2014-11-29 | 1 | -1/+1 | |
| | ||||||
* | Renewed expired certificates | Andreas Steffen | 2014-11-29 | 3 | -61/+61 | |
| | ||||||
* | Created ikev2/rw-ntru-bliss scenario | Andreas Steffen | 2014-11-29 | 23 | -0/+188 | |
| | ||||||
* | testing: Update tkm/multiple-clients/evaltest.dat | Reto Buerki | 2014-10-31 | 1 | -2/+1 | |
| | | | | | | Since the CC context is now properly reset in the bus listener plugin, the second connection from host dave re-uses the first CC ID. Adjust the expect string on gateway sun accordingly. | |||||
* | Increased fragment size to 1400 in ipv6/net2net-ikev1 scenario5.2.1 | Andreas Steffen | 2014-10-18 | 2 | -2/+2 | |
| | ||||||
* | Enabled IKEv2 fragmentation in ipv6/net2net-ikev2 scenario | Andreas Steffen | 2014-10-18 | 4 | -2/+6 | |
| | ||||||
* | testing: Lower batch size to demonstrated segmetation of TCG/SWID Tag ID ↵5.2.1rc1 | Andreas Steffen | 2014-10-11 | 1 | -2/+2 | |
| | | | | Inventory attribute | |||||
* | testing: Add ikev2/net2net-fragmentation scenario | Tobias Brunner | 2014-10-10 | 9 | -0/+116 | |
| | ||||||
* | testing: Update ikev1/net2net-fragmentation scenario | Tobias Brunner | 2014-10-10 | 1 | -2/+2 | |
| | ||||||
* | testing: Don't check for the actual number of SWID tags in PDP scenarios | Tobias Brunner | 2014-10-07 | 2 | -8/+8 | |
| | | | | | The number of SWID tags varies depending on the base image, but lets assume the number is in the hundreds. | |||||
* | testing: Make TNC scenarios agnostic to the actual Debian version | Tobias Brunner | 2014-10-07 | 18 | -45/+52 | |
| | | | | | The scenarios will work with new or old base images as long as the version in use is included as product in the master data (src/libimcv/imv/data.sql). | |||||
* | testing: Updated certificates and keys in sql scenarios | Andreas Steffen | 2014-10-06 | 35 | -121/+121 | |
| | ||||||
* | Updated revoked certificate in ikev2/ocsp-revoked scenario | Andreas Steffen | 2014-10-05 | 2 | -42/+42 | |
| | ||||||
* | The critical-extension scenarios need the old private keys | Andreas Steffen | 2014-10-05 | 4 | -0/+108 | |
| | ||||||
* | testing: Wait a bit in swanctl scenarios before interacting with the daemon | Tobias Brunner | 2014-10-03 | 7 | -9/+16 | |
| | ||||||
* | testing: Make sure the whitelist plugin is ready before configuring it | Tobias Brunner | 2014-10-03 | 1 | -1/+3 | |
| | ||||||
* | testing: Update PKCS#12 containers | Tobias Brunner | 2014-10-03 | 4 | -0/+0 | |
| | ||||||
* | testing: Update PKCS#8 keys | Tobias Brunner | 2014-10-03 | 3 | -81/+81 | |
| | ||||||
* | testing: Update public keys in DNSSEC scenarios | Tobias Brunner | 2014-10-03 | 3 | -0/+0 | |
| | | | | | The tests are successful even if the public keys are not stored locally, but an additional DNS query is required to fetch them. | |||||
* | testing: Update carols certificate in several test cases | Tobias Brunner | 2014-10-03 | 6 | -129/+129 | |
| | ||||||
* | testing: Add some notes about how to reissue attribute certificates | Martin Willi | 2014-10-03 | 3 | -0/+61 | |
| | ||||||
* | testing: Reissue attribute certificates for the new holder certificates | Martin Willi | 2014-10-03 | 8 | -72/+72 | |
| | | | | | | Due to the expired and reissued holder certificates of carol and dave, new attribute certificates are required to match the holder certificates serial in the ikev2/acert-{cached,fallback,inline} tests. | |||||
* | configure: Load fetcher plugins after crypto base plugins | Martin Willi | 2014-09-24 | 669 | -681/+676 | |
| | | | | | | | | | | Some fetcher plugins (such as curl) might build upon OpenSSL to implement HTTPS fetching. As we set (and can't unset) threading callbacks in our openssl plugin, we must ensure that OpenSSL functions don't get called after openssl plugin unloading. We achieve that by loading curl and all other fetcher plugins after the base crypto plugins, including openssl. | |||||
* | testing: Update certs and keys in tkm tests | Reto Buerki | 2014-09-17 | 6 | -0/+0 | |
| | | | | References #705. | |||||
* | Generated new test certificates | Andreas Steffen | 2014-08-28 | 2 | -42/+42 | |
| | ||||||
* | testing: Add sql/shunt-policies-nat-rw scenario | Tobias Brunner | 2014-06-26 | 18 | -0/+740 | |
| | ||||||
* | testing: Add pfkey/shunt-policies-nat-rw scenario | Tobias Brunner | 2014-06-26 | 13 | -0/+175 | |
| | ||||||
* | testing: Remove obsolete shunt-policies scenarios | Tobias Brunner | 2014-06-26 | 24 | -688/+0 | |
| | ||||||
* | Updated description of TNC scenarios concerning RFC 7171 PT-EAP support | Andreas Steffen | 2014-06-26 | 6 | -24/+30 | |
| | ||||||
* | Removed django.db from swid scenarios | Andreas Steffen | 2014-06-26 | 2 | -0/+0 | |
| | ||||||
* | testing: Add ikev2/shunt-policies-nat-rw scenario | Tobias Brunner | 2014-06-19 | 12 | -0/+171 | |
| | ||||||
* | testing: Remove ikev2/shunt-policies scenario | Tobias Brunner | 2014-06-19 | 10 | -166/+0 | |
| | | | | | This scenario doesn't really apply anymore (especially its use of drop policies). | |||||
* | Added swanctl/net2net-route scenario | Andreas Steffen | 2014-06-18 | 9 | -0/+145 | |
| | ||||||
* | Added swanctl/net2net-start scenario | Andreas Steffen | 2014-06-18 | 9 | -0/+140 | |
| | ||||||
* | Minor changes in swanctl scenarios | Andreas Steffen | 2014-06-18 | 7 | -5/+8 | |
| |