Tobias Brunner
bab415ec0a
child-cfg: Actually force narrowing TS in transport mode only as initiator
...
Closes strongswan/strongswan#2830
Fixes: ad1ad2159f ("child-cfg: Use traffic selector list")
2025-07-11 14:15:06 +02:00
Tobias Brunner
43b805b2da
openssl: Don't allocate salt if PRF/hash is unknown
...
This can happen if e.g. AES-XCBC is selected.
Fixes: 2dbeecfc02 ("openssl: Fix testing KDF_PRF in the constructor with OpenSSL 3.5.1")
2025-07-11 11:47:51 +02:00
Tobias Brunner
2dbeecfc02
openssl: Fix testing KDF_PRF in the constructor with OpenSSL 3.5.1
...
Setting the salt to NULL now fails, so we set it to hash length's zeroes,
which is the default value for HKDF-Extract if no salt is passed.
Fixes strongswan/strongswan#2828
2025-07-10 19:22:22 +02:00
Tobias Brunner
f88d824114
Fixed some typos, courtesy of codespell
2025-07-08 10:54:49 +02:00
Thomas Egerer
a339468c93
vici: Allow backlog size configuration via compile option
...
Signed-off-by: Thomas Egerer <[email protected] >
2025-07-07 14:20:13 +02:00
orbea
979c57fc30
nm: Don't set DL_LIBS to 'none required' in configure script
...
This copies the AC_SEARCH_LIBS check from the main strongSwan
configure.ac.
When building networkmanager-strongswan with slibtool if fails.
ld: cannot find none: No such file or directory
ld: cannot find required: No such file or directory
This is because configure.ac uses AC_SEARCH_LIBS to find dlopen which
sets the value of $ac_cv_search_dlopen to 'none required' which then
gets set in DL_LIBS and passed to slibtool.
With GNU libtool it silently ignores the unknown arguments.
Gentoo issue: https://bugs.gentoo.org/914100
Closes strongswan/strongswan#2141
Signed-off-by: orbea <[email protected] >
2025-07-01 07:45:12 +02:00
Tobias Brunner
bd4cee82ac
android: New release after adding HTTP proxy configuration
2025-06-27 08:57:45 +02:00
Tobias Brunner
dbcba117ae
android: Apply proxy server setting when creating TUN device
...
This is only available with Android 10+ (SDK 29+).
2025-06-27 08:57:45 +02:00
Tobias Brunner
b944159fcf
android: Avoid proxy settings in the internal fetcher
2025-06-27 08:57:45 +02:00
Tobias Brunner
c7307ccc52
android: Allow setting proxy settings in managed profiles
2025-06-27 08:57:45 +02:00
Tobias Brunner
0f2cd032e1
android: Import proxy server settings
2025-06-27 08:57:45 +02:00
Tobias Brunner
c80819c0ad
android: Make proxy server configurable
2025-06-27 08:57:45 +02:00
Tobias Brunner
a7cb2fcbf6
android: Add properties to VPN profiles for proxy server configuration
2025-06-27 08:57:45 +02:00
Tobias Brunner
059c70e556
android: Don't mention IKEv1 and L2TP in app description
...
Also removed on Play so the app does not show up when people search
for these keywords (they tend to not read the actual description and
then are surprised that neither protocol is supported).
2025-06-27 08:57:45 +02:00
Tobias Brunner
4143e47462
android: Update dependencies
2025-06-27 08:57:38 +02:00
Tobias Brunner
a153626af7
identification: Clarify that ID_USER_FQDN is just an alias for ID_RFC822_ADDR
...
This means userfqdn: is a valid prefix for regular expressions.
2025-06-20 10:37:40 +02:00
Tobias Brunner
e58ef258b5
swanctl: Document that IP-TFS mode is subject to mode negotiation
2025-06-20 10:37:35 +02:00
Tobias Brunner
9dbb15dea9
leak-detective: Remove whitelisted libsoup2.x functions
...
As mentioned in 0f141fb095 , we can't
really whitelist the "leaks" in GLib, so don't even try to do anything
with libsoup3.x.
2025-06-04 19:08:57 +02:00
Mike Gorse
6ddabf52d5
soup: Port to libsoup 3
2025-06-04 19:08:07 +02:00
Tobias Brunner
e864b8a8b1
fetcher: Remove unused FETCH_HTTP_VERSION_1_0 option
...
Was only used by the removed scepclient and does not serve any purpose
nowadays anyway.
2025-06-04 19:07:22 +02:00
Tobias Brunner
82adb5ce0f
unit-tests: Serial number tests depend on X.509 certificate parsing
...
Requires additional plugin features, but if this is available, the
others are usually as well.
2025-06-04 19:07:22 +02:00
Tobias Brunner
71f1091129
wolfssl: Fix build if wolfSSL was built in OpenSSL-compat mode
2025-06-04 19:07:13 +02:00
Juliusz Sosinowicz
f38bb91654
wolfssl: Unlock keys if necessary when using FIPS module
...
Wrap the functions that require it in PRIVATE_KEY_UNLOCK/PRIVATE_KEY_LOCK.
This can't be done at plugin initialization because it needs to be done
for every thread. strongSwan currently doesn't provide on-thread-create
callbacks for plugins so we need to wrap each direct call. Another reason
to do so is that some functions we call (e.g. wc_EccKeyToDer) internally
call PRIVATE_KEY_UNLOCK/PRIVATE_KEY_LOCK and would leave the keys locked
for that particular thread.
2025-06-02 09:15:05 +02:00
Juliusz Sosinowicz
85eb5c7812
wolfssl: Properly initialize ECC private key object
2025-06-02 09:15:05 +02:00
Tobias Brunner
879e3ce05a
wolfssl: Set a dummy key when testing KDF implementations
...
In FIPS mode, wolfSSL enforces a minimum key size for these algorithms.
2025-06-02 09:15:05 +02:00
Tobias Brunner
757e00c0ae
test-vectors: Remove HMAC PRF test vectors with key size 4
...
Some implementations enforce a minimum key size (e.g. wolfSSL in FIPS
mode) and in practice, the keys will be longer anyway (e.g. our nonces
are 32 bytes).
2025-06-02 09:15:05 +02:00
Tobias Brunner
d0292a6f50
wolfssl: Include settings.h in case WOLFSSL_USER_SETTINGS is defined
2025-06-02 09:15:05 +02:00
Tobias Brunner
217049606b
wolfssl: Use consistent defines for ECC public/private key loading
...
HAVE_ECC_KEY_IMPORT can be defined while HAVE_ECC_SIGN is not.
So just use the same defines we use when defining the load functions.
2025-06-02 09:15:04 +02:00
Tobias Brunner
7bfd81d78a
wolfssl: Call wc_SetSeed_Cb() as required for FIPS-mode
2025-06-02 09:15:04 +02:00
Tobias Brunner
46525cdc4f
child-create: Negotiate IP-TFS mode if configured
2025-05-28 16:37:46 +02:00
Tobias Brunner
f5f7424e1d
notify-payload: Add notify type for IP-TFS/AGGFRAG
2025-05-28 16:37:46 +02:00
Tobias Brunner
6372b2890f
kernel-netlink: Support IPTFS mode and attributes
2025-05-28 16:37:46 +02:00
Tobias Brunner
f32773b3a8
child-sa: Allow disabling fragmenting packets across AGGFRAG payloads
...
This is necessary if the peer isn't able to handle such fragments.
2025-05-28 16:37:46 +02:00
Tobias Brunner
33db7a200f
kernel-ipsec: Add flag to disable sending fragments across AGGFRAG payloads
...
We have to set this if the peer indicates that it doesn't support
handling such fragments in the notify.
2025-05-28 16:37:46 +02:00
Tobias Brunner
1afc76dd56
vici: Make IP-TFS mode configurable
2025-05-28 16:37:46 +02:00
Tobias Brunner
e175abaf89
include: Add XFRM mode and attributes for IP-TFS
2025-05-28 16:37:46 +02:00
Tobias Brunner
419528f2ac
ipsec-types: Add new mode for IP-TFS
...
Added at the end as the numeric mode is e.g. used in SQL databases.
2025-05-28 16:37:27 +02:00
Tobias Brunner
d83fbe82e4
kernel-netlink: Suppress NAT mapping updates for per-CPU SAs
...
As we set the remote port to 0, we'd get a mapping change message with
every packet. Setting the threshold avoids all kernel messages after the
first, which we suppress explicitly as well.
2025-05-28 16:35:27 +02:00
Tobias Brunner
14e1ec2b77
child-sa: Configure UDP encapsulation for per-CPU SAs
...
As the kernel does not support processing UDP-encapsulated and plain ESP
for the same SA, we require forcing UDP encapsulation if there is no NAT.
2025-05-28 16:35:27 +02:00
Tobias Brunner
73083503f2
vici: Make UDP encapsulation for per-CPU SAs configurable
2025-05-28 16:35:27 +02:00
Tobias Brunner
d594171d9e
child-cfg: Add flag to enable UDP encapsulation for per-CPU SAs
2025-05-28 16:35:27 +02:00
Tobias Brunner
f95bdb6fb0
swanctl: Report per-CPU information in --list-sas
2025-05-28 16:35:27 +02:00
Tobias Brunner
c176d32a73
vici: Report per-CPU SA information
2025-05-28 16:35:27 +02:00
Tobias Brunner
fbfae44dd1
vici: Make per-CPU CHILD_SAs configurable
2025-05-28 16:35:27 +02:00
Tobias Brunner
a950ca3ec2
kernel-netlink: Forward CPU ID from acquires
2025-05-28 16:35:27 +02:00
Tobias Brunner
4a595508b7
trap-manager: Add support to handle acquires for per-CPU SAs
2025-05-28 16:35:27 +02:00
Tobias Brunner
65b7f9d563
kernel-handler: Log CPU ID that's passed with an acquire
2025-05-28 16:35:27 +02:00
Tobias Brunner
d6eed3979b
kernel-interface: Optionally pass CPU ID for which an acquire was triggered
2025-05-28 16:35:27 +02:00
Tobias Brunner
2082fa5dd2
ike-sa: Accept optional CPU ID when initiating CHILD_SAs
2025-05-28 16:35:26 +02:00
Tobias Brunner
8e7f379f71
ike-sa: Sort CHILD_SAs by CPU ID
...
This might make debugging easier and also ensures that a possible
fallback SA without CPU ID is established first when reestablishing
an IKE_SA. Because even if such an SA is established first initially,
that might change later depending on when per-CPU SAs are rekeyed.
2025-05-28 16:35:26 +02:00