Martin Willi
0020b25a45
ikev2: Enforce remote authentication config before proceeding with own authentication
...
Previously the constraints in the authentication configuration of an
initiator were enforced only after all authentication rounds were
complete. This posed a problem if an initiator used EAP or PSK
authentication while the responder was authenticated with a certificate
and if a rogue server was able to authenticate itself with a valid
certificate issued by any CA the initiator trusted.
Because any constraints for the responder's identity (rightid) or other
aspects of the authentication (e.g. rightca) the initiator had were not
enforced until the initiator itself finished its authentication such a rogue
responder was able to acquire usernames and password hashes from the client.
And if a client supported EAP-GTC it was even possible to trick it into
sending plaintext passwords.
This patch enforces the configured constraints right after the responder's
authentication successfully finished for each round and before the initiator
starts with its own authentication.
Fixes CVE-2015-4171.
2015-06-05 13:44:42 +02:00
Martin Willi
e6ba688a35
During libstrongswan initialization, check if memwipe() works as expected
2013-04-18 13:05:37 +02:00
Martin Willi
3e8caf6af6
Make resync/monitoring functionality optional
2010-04-07 13:55:16 +02:00
Martin Willi
f24ca1dd55
Listen to ike_updown/rekey hook instead of ike_state_change
2010-04-07 13:55:16 +02:00
Martin Willi
c866a42737
Request a complete resync after daemon startup
2010-04-07 13:55:16 +02:00
Martin Willi
1466af8556
Do not automatically take over segments, as we need to resync first
2010-04-07 13:55:16 +02:00
Martin Willi
ea249cc6f0
Drop overlapping segments only if we have no active SAs on it
2010-04-07 13:55:16 +02:00
Martin Willi
a05e388540
Do not install iptables rules, they should stay active after shutdown
2010-04-07 13:55:16 +02:00
Martin Willi
e262f4e543
Take over all segments if heartbeat becomes silent
2010-04-07 13:55:15 +02:00
Martin Willi
d87489661c
Renamed ha-sync plugin to ha
2010-04-07 13:55:15 +02:00
Martin Willi
3c82381296
Try to send HA sync messages synchronously
2010-04-07 13:55:15 +02:00
Martin Willi
f4f394e67c
Do not sync a delete for a child in a destroying IKE_SA
2010-04-07 13:55:15 +02:00
Martin Willi
5a0a359b88
Include ICMP traffic in sync tunnel
2010-04-07 13:55:15 +02:00
Martin Willi
874c0bd8b8
Refactored segment enabling/disabling
2010-04-07 13:55:15 +02:00
Martin Willi
5d67259042
Use a connected UDP socket
2010-04-07 13:55:15 +02:00
Martin Willi
06308d9ede
Removed obsolete socket subclasses
2010-04-07 13:55:15 +02:00
Martin Willi
3912fdb1ec
Automatically segment cluster using periodically sent status messages
2010-04-07 13:55:14 +02:00
Martin Willi
b7f15be136
Do not enable/disable our own sync tunnel
2010-04-07 13:55:14 +02:00
Martin Willi
9fdf5f712e
Enable/disable inactive/active segments only
2010-04-07 13:55:14 +02:00
Martin Willi
310498f3de
Deactivate all active segments before shutting down
2010-04-07 13:55:14 +02:00
Martin Willi
4e248733a8
HA kernel interface can mangle netfilter rules, currently with iptables invocation
2010-04-07 13:55:14 +02:00
Martin Willi
dbc91f7c84
Added support for kernel segment manipulation
2010-04-07 13:55:14 +02:00
Martin Willi
6921e8d5a9
Moved segment configuration parsing to ha_sync_plugin
2010-04-07 13:55:14 +02:00
Martin Willi
37459ea928
Propagate segment manipulation to cluster node
2010-04-07 13:55:14 +02:00
Martin Willi
3d672d4b0a
Segment manipulation in HA sync is thread save
2010-04-07 13:55:14 +02:00
Martin Willi
c573b11c55
Passing 0 to segments->(de-)activate enables/disables all segments
2010-04-07 13:55:14 +02:00
Martin Willi
7ceaf50b05
separated auto-tunnel functionality from socket
2010-04-07 13:55:13 +02:00
Martin Willi
f5632db953
create external fifo socket only if "fifo_interface" option is set
2010-04-07 13:55:13 +02:00
Martin Willi
47d365deef
updated linuxdir include variable
2010-04-07 13:55:13 +02:00
Martin Willi
724736ff1c
updated HA sync plugin to new lifetime config
2010-04-07 13:55:13 +02:00
Martin Willi
f825238594
print "none" if not serving any segments
2010-04-07 13:55:13 +02:00
Martin Willi
a33eb8631c
automatically establish a PSK authenticated SA between cluster nodes
2010-04-07 13:55:13 +02:00
Martin Willi
80624c79d5
fixed memleak when installing synced virtual IPs
2010-04-07 13:55:13 +02:00
Martin Willi
b1d495f469
do not sync CHILD_SAs without an IKE_SA
2010-04-07 13:55:13 +02:00
Martin Willi
5b7c0f4409
removed $Id$ from ha plugin
2010-04-07 13:55:13 +02:00
Martin Willi
26d08a241a
fixed ike_sa condition/extension parsing
2010-04-07 13:55:12 +02:00
Martin Willi
1f32f61c87
added a copy of the linux jenkins hash to dist
2010-04-07 13:55:12 +02:00
Martin Willi
1e977438af
fixed sync of CHILD_SA delete
2010-04-07 13:55:12 +02:00
Martin Willi
9ffcbea6f1
added HA resync option to (re-)integrate nodes to a cluster
2010-04-07 13:55:12 +02:00
Martin Willi
c81f4fa29d
apply peer config during rekeying
2010-04-07 13:55:12 +02:00
Martin Willi
34d240a6e3
manage synced SAs in IKE_SA Manager, tag them with IKE_PASSIVE state
2010-04-07 13:55:12 +02:00
Martin Willi
d4113a42e9
support for IKE_SA rekeying sync
2010-04-07 13:55:12 +02:00
Martin Willi
aa98188af5
IKE_SA activation/deactivation magic using a fifo socket
2010-04-07 13:55:12 +02:00
Martin Willi
c94fe198e9
syncing of complete IKE/CHILD_SAs works
2010-04-07 13:55:11 +02:00
Martin Willi
7999be5b0e
pushing basic CHILD_SA sync data to backup node
2010-04-07 13:55:11 +02:00
Martin Willi
765935c8f6
basic syncing of IKE_SAs
...
recreating SAs with keymat derivation
2010-04-07 13:55:11 +02:00
Martin Willi
190edaf527
added a dispatcher class to receive HA sync messages
...
simple attribute parser enumerator (probably needs a cleaner implementation)
2010-04-07 13:55:11 +02:00
Martin Willi
12ec91ba3a
generating basic IKE_SA sync messages
...
pushing to statically configured failover node
2010-04-07 13:55:11 +02:00
Martin Willi
e5e91eec29
set up basic infrastructure ha_sync plugin
2010-04-07 13:55:11 +02:00
Martin Willi
e16d76f9a4
added child_sa serialization to ha_sync plugin
2010-04-07 13:55:11 +02:00
Martin Willi
e67f5136c0
HA sync plugin stub
2010-04-07 13:55:11 +02:00
Martin Willi
ed5fc4cafe
Use message instead of attributes in hook
2010-02-26 11:44:34 +01:00
Martin Willi
3e35a6e7a1
Use side-channel secured mpz_powm_sec of libgmp 5, if available
2010-02-18 17:38:59 +01:00
Martin Willi
7d3a830a71
Updated debian package for NetworkManager-strongswan-1.1.2
2010-02-18 09:51:45 +01:00
Martin Willi
e159cd1d1a
Version bump and NEWS for NetworkManager-strongswan-1.1.2 release
2010-02-18 09:51:44 +01:00
Martin Willi
0209179a30
Updated german translation
2010-02-18 09:51:40 +01:00
Martin Willi
7613a68f33
Tooltips are translatable
2010-02-18 09:20:13 +01:00
Martin Willi
d178eee895
Newer glade requires explicit vertical vboxes
2010-02-18 09:03:17 +01:00
Martin Willi
71070c88b7
Fixed lost renaimings in android plugin
2010-02-18 08:31:10 +01:00
Martin Willi
55699f037f
Added Android plugin, currently provides DNS handling on Android
2010-02-17 18:24:11 +01:00
Martin Willi
63b0bc9c2d
Invoke missing message() hook for incoming responses
2010-02-17 18:23:14 +01:00
Martin Willi
2aa553d773
Do not build own authentication data before we've verified others, we need the other identity in EAP
2010-02-09 16:11:07 +01:00
Martin Willi
313a53d4fc
Use destination address of ppp interfaces as nexthop in starters default route lookup
2010-02-05 09:28:31 +01:00
Martin Willi
7481f964ae
Use child_updown hook in updown plugin, fixes doubled invocation of down script
2010-02-03 11:07:53 +01:00
Martin Willi
909c0c3d63
Updated NEWS about per-connection inactivity timeout
2010-01-27 16:08:06 +01:00
Martin Willi
8015c91cb9
Added a ipsec.conf "inactivity" option to configure inactivity timeout for CHILD_SAs
2010-01-27 16:05:11 +01:00
Martin Willi
71da001753
Made inactivity_timeout a per CHILD_SA config option
2010-01-27 15:47:08 +01:00
Martin Willi
db05341916
Refactored EAP payload, avoid unaligned word access
2010-01-21 14:43:07 +01:00
Martin Willi
23d2bf84a3
Added a METHOD2() macro that implements a method for two different interfaces
2010-01-21 14:42:08 +01:00
Martin Willi
47498044c3
Support RADIUS messages up to 4096 bytes, RADIUS EAP-Message fragmentation
2010-01-19 16:47:21 +01:00
Martin Willi
7eab4a1be6
Support TLS client authentication Extended Key Usage in x509 generation
2010-01-14 12:00:43 +01:00
Martin Willi
aa9eeb5deb
Support for closing CHILD/IKE_SA if a CHILD_SA is inactive.
2010-01-12 10:23:42 +01:00
Martin Willi
bc6ff2fc99
Added strongswan.conf options to configure retransmission timeouts
2010-01-11 16:42:12 +01:00
Martin Willi
527f7f9b1c
Added a "double" getter to libstrongswan settings
2010-01-11 16:39:28 +01:00
Martin Willi
dbee988e28
Cast unaligned memcpy() args to char*, avoids over-optimization on ARM
...
See http://infocenter.arm.com/help/index.jsp?topic=/com.arm.doc.faqs/ka3934.html
2010-01-11 15:35:41 +01:00
Martin Willi
aca9f9ab5a
Added NEWS about mutual EAP-only authentication
2010-01-07 16:16:22 +01:00
Martin Willi
34948b9971
EAP-MSCHAPv2 is indeed mutual, but is prone to MITM dictionary attacks
2010-01-07 15:56:11 +01:00
Martin Willi
f34702ff3f
Support EAP-only authentication for mutual and key deriving EAP methods
2010-01-07 15:51:30 +01:00
Martin Willi
12fca6cc9f
Indicate and dected support for EAP-only authentication
2010-01-07 14:30:28 +01:00
Martin Willi
cdad91de49
Added NEWS for the new Vendor ID requirement for private use allocations
2010-01-07 11:14:33 +01:00
Martin Willi
023fd8f135
Match to private use algorithms only if we know we are talking to strongSwan
2010-01-07 11:07:53 +01:00
Martin Willi
b3349c5694
Interpret private use BEET mode notify only if we know we are talking to strongSwan
2010-01-07 09:37:38 +00:00
Martin Willi
a5a0bcaa04
Add an option to send a vendor ID, allows us to properly support private extensions
2010-01-07 09:37:27 +00:00
Martin Willi
f8f4f31a77
Fixed untoh32 function
2009-12-23 13:08:56 +01:00
Martin Willi
2fcb2cc653
Migrated identification_t to INIT/METHOD macros
2009-12-21 15:24:08 +01:00
Martin Willi
83b760cb42
Migrated curl_fetcher to INIT/METHOD macros
2009-12-17 13:53:25 +01:00
Martin Willi
1a1ff9d127
Added a METHOD() macro to define methods with both public and private signatures
2009-12-17 13:53:24 +01:00
Martin Willi
74eed73a40
Added a INIT() macro to initialize class instances
2009-12-17 13:53:24 +01:00
Martin Willi
6ec949e022
Fixed BEET mode by installing SAs with negotiated address in traffic selector
2009-12-17 10:52:07 +01:00
Martin Willi
0be12e3546
Added htoun16/32 and untoh16/32 to read/write unaligned network order integers
2009-12-15 13:39:01 +01:00
Martin Willi
fc85786921
Install v6 routes via outgoing interface for now
2009-12-14 14:44:24 +01:00
Martin Willi
a6225e4936
Improved libfast session management, using a hashtable
2009-12-08 19:31:02 +01:00
Martin Willi
4e90d9de9f
Removed obsolete curl interface specific destructor
2009-12-08 16:21:58 +01:00
Martin Willi
89d236f0da
Support "_" and "-" variants of NetworkManager pkg-config packages
2009-12-08 14:36:22 +01:00
Martin Willi
f469754f7f
Undef PACKAGE_BUG/URL of strongSwan before including ruby variants
2009-12-08 14:36:22 +01:00
Martin Willi
88dbccc842
Remove generated config.h.in from source tree
2009-12-08 14:36:21 +01:00
Martin Willi
cd51437e43
Do not execute the callback job if it has been cancelled since registration
2009-12-03 08:00:43 +01:00
Martin Willi
c636bc7e17
Cleanup library if daemon initialization fails
2009-12-03 08:00:43 +01:00
Martin Willi
65c8bff7a1
To build strongSwan from git sources, gettext is required
2009-12-02 11:49:11 +01:00
Martin Willi
376a11db3c
Do not install invalid 0.0.0.0 DNS servers
2009-12-01 15:46:56 +01:00