Martin Willi
1cc58e7ed2
Migrated certreq_payload to INIT/METHOD macros
2011-01-05 16:45:50 +01:00
Martin Willi
2aa1bffb02
Migrated cert_payload to INIT/METHOD macros
2011-01-05 16:45:50 +01:00
Martin Willi
9c0ccf5e26
Migrated auth_payload to INIT/METHOD macros
2011-01-05 16:45:50 +01:00
Martin Willi
401818651e
Moved generic infrastructure initialization to libcharon_init(), allows us to preload plugins
2011-01-05 16:45:49 +01:00
Martin Willi
2ecbd6186e
Do not update payload length during generation, allows hooks override payload length
2011-01-05 16:45:47 +01:00
Martin Willi
d58127af84
Do not recalculate payload header length after generation, payloads do length calculation
2011-01-05 16:45:47 +01:00
Martin Willi
2a19095e4c
Apply IKE major/minor version set on message to IKE header
2011-01-05 16:45:46 +01:00
Martin Willi
7e7c7c1d84
Added setters for IKE major/minor version to ike_header
2011-01-05 16:45:46 +01:00
Martin Willi
1c22c529a7
Migrated ike_header_t to INIT/METHOD macros
2011-01-05 16:45:46 +01:00
Martin Willi
b0f6b31db8
Fixed length calculation of unknown payload
2011-01-05 16:45:44 +01:00
Martin Willi
c67de660d2
Move critical bit checking to ike_sa, notify payload includes unsupported payload type
2011-01-05 16:45:44 +01:00
Martin Willi
e7099aa24e
Handle all error notifies in CREATE_CHILD_SA exchanges
2011-01-05 16:45:44 +01:00
Martin Willi
24384f352f
Support encoding of UKNOWN_DATA
2011-01-05 16:45:44 +01:00
Martin Willi
958c1d75d7
Moved our substructure identifiers above 255, ignore private payloads properly
2011-01-05 16:45:44 +01:00
Martin Willi
fea3aa5d12
Check for exceeded payload count even if we have a found one flagged as sufficient
2011-01-05 16:45:43 +01:00
Martin Willi
ca93b54e65
Added a constructor for custom uknown payloads
2011-01-05 16:45:43 +01:00
Martin Willi
b6c796464d
Use the payloads actual type in unknown_payload_t
2011-01-05 16:45:43 +01:00
Martin Willi
9431023ce6
Migrated unknown payload to INIT/METHOD macros
2011-01-05 16:45:43 +01:00
Martin Willi
c146c3c4e1
Ingore messages with exchange type altered to UNDEFINED in message() hook
2011-01-05 16:45:42 +01:00
Martin Willi
a30dba9282
Fail silently without INVALID_SYNTAX if message not verified
2011-01-05 16:45:42 +01:00
Martin Willi
89fda1abb5
Moved message()-hook invocation to generate_message(), catch pre-generated IKE_SA_INITs, too
2011-01-05 16:45:41 +01:00
Martin Willi
e6c6a4d304
Support removal of payloads from messages
2011-01-05 16:45:41 +01:00
Martin Willi
363ec8986c
Added a message_t option to disable automatic payload sorting
2011-01-05 16:45:41 +01:00
Martin Willi
dacf658036
Implemented cert payload constructor for custom encoding types
2011-01-05 16:45:41 +01:00
Martin Willi
6c2d466b90
Support manually triggerd DPD check, even if DPD disabled in config
2011-01-05 16:45:40 +01:00
Martin Willi
84f89634ef
Moved logger initialization from libcharon to charon
2011-01-05 16:45:40 +01:00
Andreas Steffen
3d653727a8
removed superfluous s
2011-01-05 04:09:19 +01:00
Andreas Steffen
97613b3b1a
remove private_
2011-01-05 03:44:57 +01:00
Andreas Steffen
d0eb22333e
remove private_
2011-01-05 03:44:28 +01:00
Andreas Steffen
ac46c8be5c
cosmetics in debug output
2011-01-05 02:44:27 +01:00
Andreas Steffen
69e8407d51
detect fragmentation of PB-TNC batch
2011-01-05 02:41:36 +01:00
Andreas Steffen
dcde152265
fixed typo
2011-01-02 06:52:32 +01:00
Andreas Steffen
1c7a729100
set tfcv3 flag TRUE in ha_dispatcher
2010-12-26 23:10:57 +01:00
Andreas Steffen
27a66f9393
implemented wrap around of registered IKEv1 algorithm names
2010-12-26 17:11:02 +01:00
Andreas Steffen
16b6606e5f
wrap list of IKEv2 algorithms after 120 characters per line
2010-12-24 17:29:51 +01:00
Andreas Steffen
cb6be85cfe
Migrated stroke_list_t to INIT/METHOD macros
2010-12-24 14:29:09 +01:00
Andreas Steffen
905ab99fc1
eliminated whitespace
2010-12-21 17:51:27 +01:00
Andreas Steffen
cf16a29dac
Migrated child_create_t to INIT/METHOD macros
2010-12-21 17:49:07 +01:00
Martin Willi
6c302616f1
Added a tfc ipsec.conf keyword to control Traffic Flow Confidentiality
2010-12-20 09:45:39 +01:00
Martin Willi
55df72e6d5
Do not use TFC padding if peer does not support ESPv3
2010-12-20 09:45:39 +01:00
Martin Willi
37788b1d06
Added a TFC padding option to child_cfg
2010-12-20 09:45:39 +01:00
Martin Willi
d86bb6ef4d
Implemented Traffic Flow Confidentiality padding in kernel_interface
2010-12-20 09:45:39 +01:00
Andreas Steffen
5932f41fcc
trace back crypto algorithms to the plugins that registered them
2010-12-18 16:31:12 +01:00
Jiri Bohac
19b7f763b3
Install selectors on transport mode IPsec SAs.
...
This fixes several test cases in IKEv2_Self_Test (part of the IPv6 Ready
Logo Program) which is required for USGv6 certification, namely:
- IKEv2.EN.I.1.1.7.1, IKEv2.EN.I.1.1.7.1: Narrowing the range of members
of the set of traffic selectors
- IKEv2.EN.R.1.1.7.3: Narrowing multiple traffic selector
When traffic selectors of a triggered SA are narrowed by the responder, the
installed policy and the broader trap policy share the same reqid. Without
selectors on the IPsec SA packets matching the trap policy, but not the
narrowed policy, would incorrectly be handled by that IPsec SA. Since only
one selector can be specified per IPsec SA, there is currently no solution
for tunnel mode SAs.
2010-12-13 15:28:40 +01:00
Andreas Steffen
836d9a795b
reverted Connection ID to capital letters
2010-12-12 12:55:14 +01:00
Andreas Steffen
c2e625514d
some more cosmetics
2010-12-12 10:19:54 +01:00
Andreas Steffen
41216e6518
final cosmetics in PB-TNC debug output
2010-12-12 10:17:43 +01:00
Andreas Steffen
54eb669dd5
implemented PB-TNC message parsing checks
2010-12-12 00:42:31 +01:00
Andreas Steffen
3a4695dc5e
some code optimizations
2010-12-11 00:52:53 +01:00
Andreas Steffen
781730b86a
support handshake retry requests
2010-12-10 23:41:12 +01:00