From d46f804b09c4680a56cef0561ecfe43f086cf3b7 Mon Sep 17 00:00:00 2001 From: Tobias Brunner Date: Tue, 17 Dec 2019 12:30:22 +0100 Subject: [PATCH 1/6] nm: Update Glade file for GTK 3.0 That's the version we check for in the configure script. --- .../gnome/properties/nm-strongswan-dialog.ui | 754 ++++++++---------- 1 file changed, 351 insertions(+), 403 deletions(-) diff --git a/src/frontends/gnome/properties/nm-strongswan-dialog.ui b/src/frontends/gnome/properties/nm-strongswan-dialog.ui index 3a04d6e0a..841e70204 100644 --- a/src/frontends/gnome/properties/nm-strongswan-dialog.ui +++ b/src/frontends/gnome/properties/nm-strongswan-dialog.ui @@ -1,24 +1,26 @@ + - - - + + True False 12 + vertical 16 - + True False + vertical 6 True False - 0 <b>Gateway</b> True + 0 False @@ -27,87 +29,75 @@ - + True False - 12 + 12 + 6 + 6 + True - + True False - 2 - 2 - 6 - 6 - - - True - False - 0 - _Address: - True - address-entry - - - GTK_FILL - - - - - - True - True - True - An IP address or hostname the Gateway can be contacted. - False - False - True - True - - - 1 - 2 - - - - - - True - False - 0 - C_ertificate: - True - certificate-button - - - 1 - 2 - GTK_FILL - - - - - - True - False - Gateway or CA certificate to use for gateway authentication. If none is specified, pre-installed CA certificates are used. - - - 1 - 2 - 1 - 2 - - + _Address: + True + 0 + + 0 + 0 + + + + + True + True + An IP address or hostname the Gateway can be contacted. + True + False + False + + + 1 + 0 + + + + + True + False + C_ertificate: + True + 0 + + + 0 + 1 + + + + + True + False + Gateway or CA certificate to use for gateway authentication. If none is specified, pre-installed CA certificates are used. + True + + + 1 + 1 + - True + False True 1 + + + False @@ -116,17 +106,18 @@ - + True False + vertical 6 True False - 0 <b>Client</b> True + 0 False @@ -135,195 +126,170 @@ - + True False - 12 + 12 + 6 + 6 + True - + True False - 6 - 2 - 6 - 6 - - - True - False - Private key to use for client authentication. This key has to match the certificates public key and may be encrypted. - - - 1 - 2 - 2 - 3 - - - - - True - False - 0 - Private _key: - True - userkey-button - - - 2 - 3 - GTK_FILL - - - - - - True - False - 0 - Au_thentication: - True - - - GTK_FILL - - - - - - True - False - 0 - _Username: - True - user-entry - - - 3 - 4 - GTK_FILL - - - - - - True - True - True - The username (identity) to use for authentication against the gateway. - False - False - True - True - - - 1 - 2 - 3 - 4 - - - - - - True - False - 0 - Ce_rtificate: - True - usercert-button - - - 1 - 2 - GTK_FILL - - - - - - True - False - Client certificate to use for client authentication. - - - 1 - 2 - 1 - 2 - - - - - True - False - - - 1 - 2 - - - - - True - False - 0 - _Password: - True - user-entry - - - 4 - 5 - GTK_FILL - - - - - - True - True - True - The password to use for authentication against the gateway (min. 20 characters for PSKs). - False - - - 1 - 2 - 4 - 5 - - - - - - _Show password - True - True - False - True - True - - - 1 - 2 - 5 - 6 - - - - - - + Au_thentication: + True + 0 + + 0 + 0 + + + + + True + False + True + + + 1 + 0 + + + + + True + False + Ce_rtificate: + True + 0 + + + 0 + 1 + + + + + True + False + Client certificate to use for client authentication. + True + + + 1 + 1 + + + + + True + False + Private _key: + True + 0 + + + 0 + 2 + + + + + True + False + Private key to use for client authentication. This key has to match the certificates public key and may be encrypted. + True + + + 1 + 2 + + + + + True + False + _Username: + True + 0 + + + 0 + 3 + + + + + True + True + The username (identity) to use for authentication against the gateway. + True + False + False + + + 1 + 3 + + + + + True + False + _Password: + True + 0 + + + 0 + 4 + + + + + True + True + The password to use for authentication against the gateway (min. 20 characters for PSKs). + True + False + False + False + + + 1 + 4 + + + + + _Show password + True + True + False + True + True + True + + + 1 + 5 + + + + - True + False True 1 + + + False @@ -332,17 +298,18 @@ - + True False + vertical 6 True False - 0 <b>Options</b> True + 0 False @@ -351,74 +318,69 @@ - + True False - 12 + 12 + vertical - + + Request an _inner IP address True - False - - - Request an _inner IP address - True - True - False - True - The Gateway may provide addresses from a pool to use for communication in the Gateways network. Check to request such an address. - True - True - - - True - True - 0 - - - - - En_force UDP encapsulation - True - True - False - True - Some firewalls block ESP traffic. Enforcing UDP capsulation even if no NAT situation is detected might help in such cases. - True - True - - - True - True - 1 - - - - - Use IP c_ompression - True - True - False - True - IPComp compresses raw IP packets before they get encrypted. This saves some bandwidth, but uses more processing power. - True - True - - - True - True - 2 - - + True + False + The Gateway may provide addresses from a pool to use for communication in the Gateways network. Check to request such an address. + True + True + + True + True + 0 + + + + + En_force UDP encapsulation + True + True + False + Some firewalls block ESP traffic. Enforcing UDP capsulation even if no NAT situation is detected might help in such cases. + True + True + + + True + True + 1 + + + + + Use IP c_ompression + True + True + False + IPComp compresses raw IP packets before they get encrypted. This saves some bandwidth, but uses more processing power. + True + True + + + True + True + 2 + - True + False True 1 + + + False @@ -427,17 +389,18 @@ - + True False + vertical 6 True False - 0 <b>Cipher proposals</b> True + 0 False @@ -446,124 +409,109 @@ - + True False - 12 + 12 + vertical - + + _Enable custom proposals + True + True + False + True + True + + + True + True + 0 + + + + True False + 6 + 6 + True - - _Enable custom proposals + True - True - False + False + _IKE: True - True + 0 - True - True - 0 + 0 + 0 - + True - False - 2 - 2 - 6 - 6 - - - True - False - 0 - 1 - _IKE: - True - ike-entry - - - GTK_FILL - - - - - - True - True - True - A list of proposals for IKE separated by ";" - - True - False - False - True - True - - - 1 - 2 - - - - - - True - False - 0 - _ESP: - True - address-entry - - - 1 - 2 - GTK_FILL - - - - - - True - True - True - A list of proposals for ESP separated by ";" - - True - False - False - True - True - - - 1 - 2 - 1 - 2 - - - + True + A list of proposals for IKE separated by ";" + True + + False + False - True - True - 1 + 1 + 0 + + + + + True + False + _ESP: + True + 0 + + + 0 + 1 + + + + + True + True + A list of proposals for ESP separated by ";" + True + + False + False + + + 1 + 1 + + False + True + 1 + + + + - True + False True 1 + + + False From 23de1602f901e0bd71d6cf54e134835c65dd746b Mon Sep 17 00:00:00 2001 From: Tobias Brunner Date: Tue, 17 Dec 2019 16:03:08 +0100 Subject: [PATCH 2/6] nm: Replace the term "gateway" with "server" --- .../gnome/properties/nm-strongswan-dialog.ui | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/src/frontends/gnome/properties/nm-strongswan-dialog.ui b/src/frontends/gnome/properties/nm-strongswan-dialog.ui index 841e70204..1567c5fb8 100644 --- a/src/frontends/gnome/properties/nm-strongswan-dialog.ui +++ b/src/frontends/gnome/properties/nm-strongswan-dialog.ui @@ -18,7 +18,7 @@ True False - <b>Gateway</b> + <b>Server</b> True 0 @@ -53,7 +53,7 @@ True True - An IP address or hostname the Gateway can be contacted. + An IP address or hostname of the VPN server. True False False @@ -80,7 +80,7 @@ True False - Gateway or CA certificate to use for gateway authentication. If none is specified, pre-installed CA certificates are used. + Server or CA certificate to use for server authentication. If none is specified, pre-installed CA certificates are used. True @@ -224,7 +224,7 @@ True True - The username (identity) to use for authentication against the gateway. + The username (identity) to use for authentication against the server. True False False @@ -251,7 +251,7 @@ True True - The password to use for authentication against the gateway (min. 20 characters for PSKs). + The password to use for authentication against the server (min. 20 characters for PSKs). True False False @@ -329,7 +329,7 @@ True True False - The Gateway may provide addresses from a pool to use for communication in the Gateways network. Check to request such an address. + The server may provide addresses from a pool to use for communication in the VPN. Check to request such an address. True True From f9956ca633a76a172a1d6c2ec697eaacf03c0c5e Mon Sep 17 00:00:00 2001 From: Tobias Brunner Date: Tue, 17 Dec 2019 16:16:08 +0100 Subject: [PATCH 3/6] nm: Add hint regarding password storage policy Requires targeting GTK 3.2. --- src/frontends/gnome/properties/nm-strongswan-dialog.ui | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/src/frontends/gnome/properties/nm-strongswan-dialog.ui b/src/frontends/gnome/properties/nm-strongswan-dialog.ui index 1567c5fb8..8681c42eb 100644 --- a/src/frontends/gnome/properties/nm-strongswan-dialog.ui +++ b/src/frontends/gnome/properties/nm-strongswan-dialog.ui @@ -1,7 +1,7 @@ - + True False @@ -256,6 +256,7 @@ False False False + (Use icon to change password storage policy) 1 From 19e64e101d3f4580f43d6e30ae9bc8c1381d4752 Mon Sep 17 00:00:00 2001 From: Tobias Brunner Date: Tue, 17 Dec 2019 16:26:34 +0100 Subject: [PATCH 4/6] charon-nm: Add support for a specific remote identity --- src/charon-nm/nm/nm_service.c | 33 +++++++++++++++++++-------------- 1 file changed, 19 insertions(+), 14 deletions(-) diff --git a/src/charon-nm/nm/nm_service.c b/src/charon-nm/nm/nm_service.c index 5e539b3fe..fcf79faa0 100644 --- a/src/charon-nm/nm/nm_service.c +++ b/src/charon-nm/nm/nm_service.c @@ -492,14 +492,6 @@ static gboolean connect_(NMVpnServicePlugin *plugin, NMConnection *connection, return FALSE; } priv->creds->add_certificate(priv->creds, cert); - - x509 = (x509_t*)cert; - if (!(x509->get_flags(x509) & X509_CA)) - { /* For a gateway certificate, we use the cert subject as identity. */ - gateway = cert->get_subject(cert); - gateway = gateway->clone(gateway); - DBG1(DBG_CFG, "using gateway certificate, identity '%Y'", gateway); - } } else { @@ -507,16 +499,29 @@ static gboolean connect_(NMVpnServicePlugin *plugin, NMConnection *connection, priv->creds->load_ca_dir(priv->creds, lib->settings->get_str( lib->settings, "charon-nm.ca_dir", NM_CA_DIR)); } - if (!gateway) + + str = nm_setting_vpn_get_data_item(vpn, "remote-identity"); + if (str) { - /* If the user configured a CA certificate, we use the IP/DNS - * of the gateway as its identity. This identity will be used for - * certificate lookup and requires the configured IP/DNS to be - * included in the gateway certificate. */ + gateway = identification_create_from_string((char*)str); + } + else if (cert) + { + x509 = (x509_t*)cert; + if (!(x509->get_flags(x509) & X509_CA)) + { /* for server certificates, we use the subject as identity */ + gateway = cert->get_subject(cert); + gateway = gateway->clone(gateway); + } + } + if (!gateway || gateway->get_type(gateway) == ID_ANY) + { + /* if the user configured a CA certificate (or an invalid identity), + * we use the IP/hostname of the server */ gateway = identification_create_from_string(ike.remote); - DBG1(DBG_CFG, "using CA certificate, gateway identity '%Y'", gateway); loose_gateway_id = TRUE; } + DBG1(DBG_CFG, "using gateway identity '%Y'", gateway); if (auth_class == AUTH_CLASS_EAP || auth_class == AUTH_CLASS_PSK) From a7bda9a95ec12ccaf7c1ec2df9eafd1f59cb2530 Mon Sep 17 00:00:00 2001 From: Tobias Brunner Date: Tue, 17 Dec 2019 16:28:00 +0100 Subject: [PATCH 5/6] nm: Make remote identity editable in GUI --- .../gnome/properties/nm-strongswan-dialog.ui | 28 +++++++++++++++++++ .../gnome/properties/nm-strongswan.c | 12 ++++++++ 2 files changed, 40 insertions(+) diff --git a/src/frontends/gnome/properties/nm-strongswan-dialog.ui b/src/frontends/gnome/properties/nm-strongswan-dialog.ui index 8681c42eb..0d9d62da3 100644 --- a/src/frontends/gnome/properties/nm-strongswan-dialog.ui +++ b/src/frontends/gnome/properties/nm-strongswan-dialog.ui @@ -88,6 +88,34 @@ 1 + + + True + False + _Identity: + True + 0 + + + 0 + 2 + + + + + True + True + Defaults to the server address or the server certificate's subject DN (if configured). Custom values are explicitly sent to the server and enforced during authentication. + True + False + False + (Defaults to address or certificate subject) + + + 1 + 2 + + False diff --git a/src/frontends/gnome/properties/nm-strongswan.c b/src/frontends/gnome/properties/nm-strongswan.c index d261dcb7a..5204d9a8f 100644 --- a/src/frontends/gnome/properties/nm-strongswan.c +++ b/src/frontends/gnome/properties/nm-strongswan.c @@ -299,6 +299,12 @@ init_plugin_ui (StrongswanPluginUiWidget *self, NMConnection *connection, GError gtk_file_chooser_set_filename (GTK_FILE_CHOOSER (widget), value); g_signal_connect (G_OBJECT (widget), "selection-changed", G_CALLBACK (settings_changed_cb), self); + widget = GTK_WIDGET (gtk_builder_get_object (priv->builder, "remote-identity-entry")); + value = nm_setting_vpn_get_data_item (settings, "remote-identity"); + if (value) + gtk_entry_set_text (GTK_ENTRY (widget), value); + g_signal_connect (G_OBJECT (widget), "changed", G_CALLBACK (settings_changed_cb), self); + widget = GTK_WIDGET (gtk_builder_get_object (priv->builder, "user-entry")); value = nm_setting_vpn_get_data_item (settings, "user"); if (value) @@ -483,6 +489,12 @@ update_connection (NMVpnEditor *iface, nm_setting_vpn_add_data_item (settings, "certificate", str); } + widget = GTK_WIDGET (gtk_builder_get_object (priv->builder, "remote-identity-entry")); + str = (char *) gtk_entry_get_text (GTK_ENTRY (widget)); + if (str && strlen (str)) { + nm_setting_vpn_add_data_item (settings, "remote-identity", str); + } + widget = GTK_WIDGET (gtk_builder_get_object (priv->builder, "method-combo")); switch (gtk_combo_box_get_active (GTK_COMBO_BOX (widget))) { From 7c6bb331514ec3b76a054aef9a5f3eed5e5c89cf Mon Sep 17 00:00:00 2001 From: Tobias Brunner Date: Tue, 17 Dec 2019 17:20:36 +0100 Subject: [PATCH 6/6] nm: Update German translation --- src/frontends/gnome/po/de.po | 145 ++++++++++++++++++++--------------- 1 file changed, 83 insertions(+), 62 deletions(-) diff --git a/src/frontends/gnome/po/de.po b/src/frontends/gnome/po/de.po index 5ac87082a..4159cc0d3 100644 --- a/src/frontends/gnome/po/de.po +++ b/src/frontends/gnome/po/de.po @@ -1,15 +1,17 @@ # Translations for NetworkManager-strongswan. -# Copyright (C) 2010 Martin Willi +# Copyright (C) 2010-2019 Tobias Brunner +# Copyright (C) 2010 Martin Willi # This file is distributed under the same license as the # NetworkManager-strongswan package. +# msgid "" msgstr "" "Project-Id-Version: NetworkManager-strongswan\n" "Report-Msgid-Bugs-To: \n" -"POT-Creation-Date: 2018-02-23 15:27+0100\n" -"PO-Revision-Date: 2010-02-18 09:20+0100\n" -"Last-Translator: Martin Willi \n" -"Language-Team: de \n" +"POT-Creation-Date: 2019-12-18 17:10+0100\n" +"PO-Revision-Date: 2019-12-18 17:10+0100\n" +"Last-Translator: Tobias Brunner\n" +"Language-Team: de \n" "Language: German\n" "MIME-Version: 1.0\n" "Content-Type: text/plain; charset=UTF-8\n" @@ -23,37 +25,37 @@ msgstr "IPsec/IKEv2 (strongswan)" msgid "IPsec with the IKEv2 key exchange protocol." msgstr "IPsec mit dem IKEv2 Protokoll." -#: ../properties/nm-strongswan.c:318 +#: ../properties/nm-strongswan.c:324 msgid "Certificate/private key" msgstr "Zertifikat/Privater Schlüssel" -#: ../properties/nm-strongswan.c:319 +#: ../properties/nm-strongswan.c:325 msgid "Certificate/ssh-agent" msgstr "Zertifikat/ssh-agent" -#: ../properties/nm-strongswan.c:320 +#: ../properties/nm-strongswan.c:326 msgid "Smartcard" msgstr "Smartcard" -#: ../properties/nm-strongswan.c:321 +#: ../properties/nm-strongswan.c:327 msgid "EAP" msgstr "EAP" -#: ../properties/nm-strongswan.c:322 +#: ../properties/nm-strongswan.c:328 msgid "Pre-shared key" msgstr "Pre-shared Key" #: ../properties/nm-strongswan-dialog.ui.h:1 -msgid "Gateway" -msgstr "Gateway" +msgid "Server" +msgstr "Server" #: ../properties/nm-strongswan-dialog.ui.h:2 msgid "_Address:" msgstr "_Adresse:" #: ../properties/nm-strongswan-dialog.ui.h:3 -msgid "An IP address or hostname the Gateway can be contacted." -msgstr "Ein IP-Adresse oder einen Rechnernamen des Gateways." +msgid "An IP address or hostname of the VPN server." +msgstr "Eine IP-Adresse oder ein Hostname des VPN Servers." #: ../properties/nm-strongswan-dialog.ui.h:4 msgid "C_ertificate:" @@ -61,17 +63,51 @@ msgstr "Z_ertifikat:" #: ../properties/nm-strongswan-dialog.ui.h:5 msgid "" -"Gateway or CA certificate to use for gateway authentication. If none is " +"Server or CA certificate to use for server authentication. If none is " "specified, pre-installed CA certificates are used." msgstr "" -"Gateway- oder CA-Zertifikat für die Authentisierung des Gateways. Ohne " -"Angabe eines Zertifikates werden die CA-Zertifikate des Systems verwendet." +"Server- oder CA-Zertifikat für die Authentisierung des Servers. Ohne Angabe " +"eines Zertifikates werden die CA-Zertifikate des Systems verwendet." #: ../properties/nm-strongswan-dialog.ui.h:6 +msgid "_Identity:" +msgstr "_Identität:" + +#: ../properties/nm-strongswan-dialog.ui.h:7 +msgid "" +"Defaults to the server address or the server certificate's subject DN (if " +"configured). Custom values are explicitly sent to the server and enforced " +"during authentication." +msgstr "" +"Standardwert ist die Server-Adresse oder der Inhaber DN des Server-" +"Zertifikats (falls konfiguriert). Eigene Werte werden explizit an den Server " +"gesendet und während der Authentifizierung erzwungen." + +#: ../properties/nm-strongswan-dialog.ui.h:8 +msgid "(Defaults to address or certificate subject)" +msgstr "(Standardwert ist die Adresse oder die Zertifikats-Identität)" + +#: ../properties/nm-strongswan-dialog.ui.h:9 msgid "Client" msgstr "Client" -#: ../properties/nm-strongswan-dialog.ui.h:7 +#: ../properties/nm-strongswan-dialog.ui.h:10 +msgid "Au_thentication:" +msgstr "Au_thentisierung:" + +#: ../properties/nm-strongswan-dialog.ui.h:11 +msgid "Ce_rtificate:" +msgstr "Ze_rtifikat:" + +#: ../properties/nm-strongswan-dialog.ui.h:12 +msgid "Client certificate to use for client authentication." +msgstr "Zertifikat des Clients für dessen Authentisierung." + +#: ../properties/nm-strongswan-dialog.ui.h:13 +msgid "Private _key:" +msgstr "Privater _Schlüssel:" + +#: ../properties/nm-strongswan-dialog.ui.h:14 msgid "" "Private key to use for client authentication. This key has to match the " "certificates public key and may be encrypted." @@ -79,68 +115,56 @@ msgstr "" "Privater Schlüssel für die Authentisierung des Clients. Dieser Schlüssel " "muss zum konfigurierten Zertifikat passen und kann verschlüsselt sein." -#: ../properties/nm-strongswan-dialog.ui.h:8 -msgid "Private _key:" -msgstr "Privater _Schlüssel:" - -#: ../properties/nm-strongswan-dialog.ui.h:9 -msgid "Au_thentication:" -msgstr "Au_thentisierung:" - -#: ../properties/nm-strongswan-dialog.ui.h:10 +#: ../properties/nm-strongswan-dialog.ui.h:15 msgid "_Username:" msgstr "_Benutzername:" -#: ../properties/nm-strongswan-dialog.ui.h:11 -msgid "The username (identity) to use for authentication against the gateway." -msgstr "Benutzername/Identität für die Authentisierung gegenüber dem Gateway." +#: ../properties/nm-strongswan-dialog.ui.h:16 +msgid "The username (identity) to use for authentication against the server." +msgstr "Benutzername/Identität für die Authentisierung gegenüber dem Server." -#: ../properties/nm-strongswan-dialog.ui.h:12 -msgid "Ce_rtificate:" -msgstr "Ze_rtifikat:" - -#: ../properties/nm-strongswan-dialog.ui.h:13 -msgid "Client certificate to use for client authentication." -msgstr "Zertifikat des Clients für dessen Authentisierung." - -#: ../properties/nm-strongswan-dialog.ui.h:14 +#: ../properties/nm-strongswan-dialog.ui.h:17 msgid "_Password:" msgstr "_Passwort:" -#: ../properties/nm-strongswan-dialog.ui.h:15 +#: ../properties/nm-strongswan-dialog.ui.h:18 msgid "" -"The password to use for authentication against the gateway (min. 20 " +"The password to use for authentication against the server (min. 20 " "characters for PSKs)." msgstr "" -"Das Passwort für die Authentisierung gegenüber dem Gateway (min. 20 Zeichen " +"Das Passwort für die Authentisierung gegenüber dem Server (min. 20 Zeichen " "für PSKs)." -#: ../properties/nm-strongswan-dialog.ui.h:16 +#: ../properties/nm-strongswan-dialog.ui.h:19 +msgid "(Use icon to change password storage policy)" +msgstr "(Icon verwenden, um Passwort-Richtlinie zu ändern)" + +#: ../properties/nm-strongswan-dialog.ui.h:20 msgid "_Show password" msgstr "Passwort _anzeigen" -#: ../properties/nm-strongswan-dialog.ui.h:17 +#: ../properties/nm-strongswan-dialog.ui.h:21 msgid "Options" msgstr "Optionen" -#: ../properties/nm-strongswan-dialog.ui.h:18 +#: ../properties/nm-strongswan-dialog.ui.h:22 msgid "Request an _inner IP address" msgstr "_Innere IP-Adresse beziehen" -#: ../properties/nm-strongswan-dialog.ui.h:19 +#: ../properties/nm-strongswan-dialog.ui.h:23 msgid "" -"The Gateway may provide addresses from a pool to use for communication in " -"the Gateways network. Check to request such an address." +"The server may provide addresses from a pool to use for communication in the " +"VPN. Check to request such an address." msgstr "" -"Der Gateway kann IP-Adressen bereitstellen, welche der Client für die " +"Der Server kann IP-Adressen bereitstellen, welche der Client für die " "Kommunikation im dahinterliegenden Netz verwenden kann. Aktivieren, um eine " "solche Adresse zu beziehen." -#: ../properties/nm-strongswan-dialog.ui.h:20 +#: ../properties/nm-strongswan-dialog.ui.h:24 msgid "En_force UDP encapsulation" msgstr "Erzwingen einer zusätzlichen Einbettung der Datenpakete in _UDP" -#: ../properties/nm-strongswan-dialog.ui.h:21 +#: ../properties/nm-strongswan-dialog.ui.h:25 msgid "" "Some firewalls block ESP traffic. Enforcing UDP capsulation even if no NAT " "situation is detected might help in such cases." @@ -149,11 +173,11 @@ msgstr "" "erzwingen einer zustzlichen Einbettung in UDP, auch wenn kein NAT-Router " "detektiert wurde, kann in solchen Situationen hilfreich sein." -#: ../properties/nm-strongswan-dialog.ui.h:22 +#: ../properties/nm-strongswan-dialog.ui.h:26 msgid "Use IP c_ompression" msgstr "IP-Pakete k_omprimieren" -#: ../properties/nm-strongswan-dialog.ui.h:23 +#: ../properties/nm-strongswan-dialog.ui.h:27 msgid "" "IPComp compresses raw IP packets before they get encrypted. This saves some " "bandwidth, but uses more processing power." @@ -161,27 +185,27 @@ msgstr "" "IPComp komprimiert IP-Pakete, bevor sie verschlüsselt werden. Diese Option " "kann Bandbreite sparen, benötigt jedoch zusätzliche Rechenleistung." -#: ../properties/nm-strongswan-dialog.ui.h:24 +#: ../properties/nm-strongswan-dialog.ui.h:28 msgid "Cipher proposals" msgstr "Algorithmen" -#: ../properties/nm-strongswan-dialog.ui.h:25 +#: ../properties/nm-strongswan-dialog.ui.h:29 msgid "_Enable custom proposals" msgstr "_Eigene Algorithmen verwenden" -#: ../properties/nm-strongswan-dialog.ui.h:26 +#: ../properties/nm-strongswan-dialog.ui.h:30 msgid "_IKE:" msgstr "_IKE:" -#: ../properties/nm-strongswan-dialog.ui.h:27 +#: ../properties/nm-strongswan-dialog.ui.h:31 msgid "A list of proposals for IKE separated by \";\"" msgstr "Eine Liste von Proposals für IKE getrennt mit \";\"" -#: ../properties/nm-strongswan-dialog.ui.h:28 +#: ../properties/nm-strongswan-dialog.ui.h:32 msgid "_ESP:" msgstr "_ESP:" -#: ../properties/nm-strongswan-dialog.ui.h:29 +#: ../properties/nm-strongswan-dialog.ui.h:33 msgid "A list of proposals for ESP separated by \";\"" msgstr "Eine Liste von Proposals für ESP getrennt mit \";\"" @@ -256,6 +280,3 @@ msgstr "" #: ../NetworkManager-strongswan.appdata.xml.in.h:5 msgid "strongSwan Developers" msgstr "strongSwan Entwickler" - -#~ msgid "VPN password required" -#~ msgstr "VPN Passwort notwendig"