Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | testing: Update tkm to version 0.1.2 | Reto Buerki | 2015-05-05 | 1 | -1/+1 | |
| | ||||||
* | testing: Update tkm-rpc to version 0.2 | Reto Buerki | 2015-05-05 | 1 | -1/+1 | |
| | ||||||
* | testing: Updated carol's certificate from research CA and dave's certificate ↵5.3.1dr1 | Andreas Steffen | 2015-04-26 | 52 | -846/+898 | |
| | | | | from sales CA | |||||
* | testing: Wait for DH crypto tests to complete | Andreas Steffen | 2015-04-26 | 8 | -8/+8 | |
| | ||||||
* | imv_policy_manager: Added capability to execute an allow or block shell ↵ | Andreas Steffen | 2015-04-26 | 7 | -2/+24 | |
| | | | | command string | |||||
* | testing: Migration of KVM framework to Linux 4.x kernel | Andreas Steffen | 2015-04-25 | 3 | -5/+2207 | |
| | ||||||
* | Added tnc/tnccs-20-fail-init and tnc/tnccs-20-fail-resp scenarios | Andreas Steffen | 2015-03-27 | 30 | -0/+404 | |
| | ||||||
* | Added configurations for 3.18 and 3.19 KMV guest kernels | Andreas Steffen | 2015-03-27 | 2 | -0/+4346 | |
| | ||||||
* | Added tnc/tnccs-20-pt-tls scenario | Andreas Steffen | 2015-03-27 | 24 | -5/+114 | |
| | ||||||
* | testing: added tnc/tnccs-20-mutual scenario | Andreas Steffen | 2015-03-23 | 11 | -0/+151 | |
| | ||||||
* | testing: Remove obsolete leftnexthop option from configs | Tobias Brunner | 2015-03-12 | 6 | -6/+0 | |
| | ||||||
* | testing: Don't check for exact IKEv1 fragment size | Martin Willi | 2015-03-10 | 1 | -2/+2 | |
| | | | | | Similar to 7a9c0d51, the exact packet size depends on many factors we don't want to consider in this test case. | |||||
* | testing: Fix active/passive role description in ha/both-active test case | Martin Willi | 2015-03-10 | 1 | -2/+2 | |
| | ||||||
* | testing: Update modified updown scripts to the latest template | Tobias Brunner | 2015-03-06 | 14 | -2589/+993 | |
| | | | | | This avoids confusion and makes identifying the changes needed for each scenario easier. | |||||
* | use SHA512 for moon's BLISS signature | Andreas Steffen | 2015-03-04 | 2 | -2/+3 | |
| | ||||||
* | testing: Test classic public key authentication in ikev2/net2net-cert scenario | Tobias Brunner | 2015-03-04 | 2 | -0/+2 | |
| | ||||||
* | testing: Disable signature authentication on dave in ↵ | Tobias Brunner | 2015-03-04 | 2 | -2/+3 | |
| | | | | openssl-ikev2/ecdsa-certs scenario | |||||
* | testing: Don't check for exact IKEv2 fragment size | Tobias Brunner | 2015-03-04 | 1 | -2/+2 | |
| | | | | | Because SHA-256 is now used for signatures the size of the two IKE_AUTH messages changed. | |||||
* | testing: Update test conditions because signature schemes are now logged | Tobias Brunner | 2015-03-04 | 33 | -58/+58 | |
| | | | | | RFC 7427 signature authentication is now used between strongSwan hosts by default, which causes the actual signature schemes to get logged. | |||||
* | testing: Add ikev2/rw-sig-auth scenario | Tobias Brunner | 2015-03-04 | 12 | -0/+180 | |
| | ||||||
* | testing: Add ikev2/net2net-cert-sha2 scenario | Tobias Brunner | 2015-03-04 | 9 | -0/+104 | |
| | ||||||
* | Implemented improved BLISS-B signature algorithm | Andreas Steffen | 2015-02-25 | 4 | -0/+0 | |
| | ||||||
* | testing: Add a forecast test case | Martin Willi | 2015-02-20 | 11 | -0/+152 | |
| | ||||||
* | testing: Build forecast plugin | Martin Willi | 2015-02-20 | 1 | -0/+1 | |
| | ||||||
* | testing: Add a connmark plugin test | Martin Willi | 2015-02-20 | 9 | -0/+109 | |
| | | | | | | | | | | In this test two hosts establish a transport mode connection from behind moon. sun uses the connmark plugin to distinguish the flows. This is an example that shows how one can terminate L2TP/IPsec connections from two hosts behind the same NAT. For simplification of the test, we use an SSH connection instead, but this works for any connection initiated flow that conntrack can track. | |||||
* | testing: Build strongSwan with the connmark plugin | Martin Willi | 2015-02-20 | 1 | -0/+1 | |
| | ||||||
* | testing: Install iptables-dev to guest images | Martin Willi | 2015-02-20 | 1 | -1/+1 | |
| | ||||||
* | testing: Update description and test evaluation of host2host-transport-nat | Martin Willi | 2015-02-20 | 3 | -9/+8 | |
| | | | | | | | | As we now reuse the reqid for identical SAs, the behavior changes for transport connections to multiple peers behind the same NAT. Instead of rejecting the SA, we now have two valid SAs active. For the reverse path, however, sun sends traffic always over the newer SA, resembling the behavior before we introduced explicit SA conflicts for different reqids. | |||||
* | testing: Be a little more flexible in testing for established CHILD_SA modes | Martin Willi | 2015-02-20 | 8 | -21/+21 | |
| | | | | | As we now print the reqid parameter in the CHILD_SA details, adapt the grep to still match the CHILD_SA mode and protocol. | |||||
* | testing: Add a test scenario for make-before-break reauth using a virtual IP | Martin Willi | 2015-02-20 | 9 | -0/+100 | |
| | ||||||
* | testing: Add a test scenario for make-before-break reauth without a virtual IP | Martin Willi | 2015-02-20 | 9 | -0/+97 | |
| | ||||||
* | testing: Add tkm xfrmproxy-expire test | Reto Buerki | 2015-02-20 | 11 | -0/+121 | |
| | | | | | | This test asserts that the handling of XFRM expire messages from the kernel are handled correctly by the xfrm-proxy and the Esa Event Service (EES) in charon-tkm. | |||||
* | testing: Assert ees acquire messages in xfrmproxy tests | Reto Buerki | 2015-02-20 | 2 | -0/+2 | |
| | ||||||
* | testing: Assert proper ESA deletion | Reto Buerki | 2015-02-20 | 1 | -0/+4 | |
| | | | | | Extend the tkm/host2host-initiator testcase by asserting proper ESA deletion after connection shutdown. | |||||
* | Updated RFC3779 certificates5.2.2 | Andreas Steffen | 2014-12-28 | 32 | -309/+440 | |
| | ||||||
* | Updated BLISS CA certificate in ikev2/rw-ntru-bliss scenario5.2.2rc1 | Andreas Steffen | 2014-12-12 | 3 | -0/+0 | |
| | ||||||
* | Updated BLISS scenario keys and certificates to new format | Andreas Steffen | 2014-12-12 | 8 | -0/+0 | |
| | ||||||
* | Increased check size du to INITIAL_CONTACT notify | Andreas Steffen | 2014-11-29 | 1 | -1/+1 | |
| | ||||||
* | Renewed expired certificates | Andreas Steffen | 2014-11-29 | 19 | -171/+223 | |
| | ||||||
* | Created ikev2/rw-ntru-bliss scenario | Andreas Steffen | 2014-11-29 | 27 | -2/+193 | |
| | ||||||
* | testing: Update tkm/multiple-clients/evaltest.dat | Reto Buerki | 2014-10-31 | 1 | -2/+1 | |
| | | | | | | Since the CC context is now properly reset in the bus listener plugin, the second connection from host dave re-uses the first CC ID. Adjust the expect string on gateway sun accordingly. | |||||
* | Increased fragment size to 1400 in ipv6/net2net-ikev1 scenario5.2.1 | Andreas Steffen | 2014-10-18 | 2 | -2/+2 | |
| | ||||||
* | Enabled IKEv2 fragmentation in ipv6/net2net-ikev2 scenario | Andreas Steffen | 2014-10-18 | 4 | -2/+6 | |
| | ||||||
* | testing: Enable nat table for iptables on 3.17 kernels | Tobias Brunner | 2014-10-13 | 1 | -2/+5 | |
| | ||||||
* | testing: Lower batch size to demonstrated segmetation of TCG/SWID Tag ID ↵5.2.1rc1 | Andreas Steffen | 2014-10-11 | 1 | -2/+2 | |
| | | | | Inventory attribute | |||||
* | Added KVM config for 3.16 and 3.17 kernels | Andreas Steffen | 2014-10-11 | 2 | -0/+4229 | |
| | ||||||
* | testing: Ensure no guest is running when modifying images | Tobias Brunner | 2014-10-10 | 5 | -0/+16 | |
| | | | | | Sometimes guests are not stopped properly. If images are then modified they will be corrupted. | |||||
* | testing: Enable virtio console for guests | Tobias Brunner | 2014-10-10 | 9 | -16/+87 | |
| | | | | | | | | | | | This allows accessing the guests with `virsh console <name>`. Using a serial console would also be possible but our kernel configs have no serial drivers enabled, CONFIG_VIRTIO_CONSOLE is enabled though. So to avoid having to recompile the kernels let's do it this way, only requires rebuilding the guest images. References #729. | |||||
* | testing: Add ikev2/net2net-fragmentation scenario | Tobias Brunner | 2014-10-10 | 9 | -0/+116 | |
| | ||||||
* | testing: Update ikev1/net2net-fragmentation scenario | Tobias Brunner | 2014-10-10 | 1 | -2/+2 | |
| |