Commit Graph
8115 Commits
Author SHA1 Message Date
Martin Willi 2f58f6cba1 Fixed notify enum names 2012-03-20 17:31:25 +01:00
Tobias Brunner 4bc4e8e17b Added support for iKEIntermediate flag to ipsec pki. 2012-03-20 17:31:25 +01:00
Tobias Brunner f29a4f1c64 Added support for iKEIntermediate X.509 extended key usage flag.
Mac OS X requires server certificates to have this flag set.
2012-03-20 17:31:24 +01:00
Tobias Brunner 00cc2188d4 Some whitespace fixes. 2012-03-20 17:31:24 +01:00
Tobias Brunner b46b56fac1 Log parsed unsigned ints with proper format strings. 2012-03-20 17:31:24 +01:00
Martin Willi bf5b1d9e73 Send different notifies if quick mode fails 2012-03-20 17:31:24 +01:00
Martin Willi b64d6423b1 Support flushing of task queue after building message in task fails 2012-03-20 17:31:24 +01:00
Martin Willi fceb20f390 Consider notify errors fatal only during main mode 2012-03-20 17:31:24 +01:00
Martin Willi 767966e70b Delete CHILD_SA if installing SA in third message fails 2012-03-20 17:31:24 +01:00
Martin Willi 53816600ff Added a quick_delete task flag to enforce delete, even if CHILD_SA not found 2012-03-20 17:31:24 +01:00
Martin Willi 429d95fef2 Send delete if Main Mode authentication fails as initiator 2012-03-20 17:31:24 +01:00
Martin Willi 5762c0efeb Send notifies in all error cases of Main Mode 2012-03-20 17:31:24 +01:00
Martin Willi ca26065745 Add some additional IKEv1 notify types 2012-03-20 17:31:23 +01:00
Martin Willi a4cc071364 Do not trust unprotected INFORMATIONALS, just print that we got one 2012-03-20 17:31:23 +01:00
Martin Willi daf7e6bc36 Use (as client) and verify (as server) configured XAuth identities 2012-03-20 17:31:23 +01:00
Martin Willi 7a7efbf9d8 Added an identity getter to XAuth methods to query the actually used identity 2012-03-20 17:31:23 +01:00
Martin Willi 5f6a37eb9b Be a little more verbose about XAuth configs in ipsec statusall 2012-03-20 17:31:23 +01:00
Martin Willi 21a4fc832e Pass ipsec.conf xauth_identity option via stroke to charon configurations 2012-03-20 17:31:23 +01:00
Martin Willi 10a6a5acff Store Main Mode identity even if XAuth-only is used for authentication 2012-03-20 17:31:23 +01:00
Martin Willi f5e5c5edbd Added an XAUTH identity to use or require for XAuth authentication 2012-03-20 17:31:23 +01:00
Martin Willi bdadc5aee2 Check authorization constraints after main mode completed 2012-03-20 17:31:23 +01:00
Martin Willi fd2a491b31 Stop checking once a key size constraint is not fulfilled 2012-03-20 17:31:23 +01:00
Martin Willi ac3bc42e63 Save authentication info collected during main mode authentication 2012-03-20 17:31:23 +01:00
Martin Willi b24b73b7f3 Flush auth configs, if enabled, for both IKEv1 and IKEv2 2012-03-20 17:31:23 +01:00
Martin Willi 4ac137135a Fixed return value if SIG payload missing 2012-03-20 17:31:22 +01:00
Martin Willi 00d8823242 Show auth method of config we are looking for in main mode 2012-03-20 17:31:22 +01:00
Martin Willi 7b1e15ac4e Fixed IKEv1 prf+ keymat expansion beyond 320 bits 2012-03-20 17:31:22 +01:00
Martin Willi 3ba15819ed Remove executable flag from source code files 2012-03-20 17:31:22 +01:00
Martin Willi 91ca35a2d2 Removed IKEv1 specific code from child_delete task 2012-03-20 17:31:22 +01:00
Martin Willi c459dae556 Use IKEv1 specific tasks to close Quick Mode SAs 2012-03-20 17:31:22 +01:00
Martin Willi 5f10938592 Added a dedicated IKEv1 task to delete CHILD_SAs 2012-03-20 17:31:22 +01:00
Martin Willi 07095794a1 Close IKE_SA directly after sending the delete 2012-03-20 17:31:22 +01:00
Martin Willi 0f5b6c6831 Removed IKEv1 specific code from ike_delete task 2012-03-20 17:31:22 +01:00
Martin Willi 5f23be840b Use the IKEv1 specific delete in IKEv1 SAs 2012-03-20 17:31:22 +01:00
Martin Willi 8db202f1b0 Added a dedicated delete task for IKEv1 IKE_SAs 2012-03-20 17:31:21 +01:00
Martin Willi 137c06babf Use a single task_type_t enum name for ME and non-ME variant 2012-03-20 17:31:21 +01:00
Martin Willi 7b25135ecf Send certificates and requests when using Hybrid authentication 2012-03-20 17:31:21 +01:00
Martin Willi d1b986eb48 Look for an XAuth authentication config both in the first and the second round 2012-03-20 17:31:21 +01:00
Martin Willi d548435a02 Added hybrid authentication support to Main Mode 2012-03-20 17:31:21 +01:00
Martin Willi 51da01a722 Support encoding of Hybrid initiator authentication method 2012-03-20 17:31:21 +01:00
Martin Willi 29101ce978 Added a IKEv1 hybrid authenticator based on Pubkey/PSK authenticators 2012-03-20 17:31:21 +01:00
Tobias Brunner a6c328a6e9 Use real ID payload to build HASH_I|R for Main Mode authentication.
This is required for clients like the iPhone which set the protocol
and/or port fields of the ID payload.
2012-03-20 17:31:21 +01:00
Tobias Brunner 19965ffe56 Create authenticators right when they are used during Main Mode. 2012-03-20 17:31:21 +01:00
Tobias Brunner 33493a5253 Added method to get encoded version if ID_V1 payload. 2012-03-20 17:31:21 +01:00
Martin Willi 0b0191e143 Ignore additional TRANSACTION request if we already queued one 2012-03-20 17:31:21 +01:00
Martin Willi fce566a876 Keep a history of received response hashes to detect late retransmissions
If we receive an old response and we already sent out the next request,
we must be able to identify that it is not the response to the new
request.
2012-03-20 17:31:20 +01:00
Martin Willi 3643179535 Narrow down received and configured traffic selector to a common subset 2012-03-20 17:31:20 +01:00
Martin Willi 7b34de45c3 Don't send a retransmit for a request we never have sent a response 2012-03-20 17:31:20 +01:00
Martin Willi f5ef357791 Print unsigned IKEv1 message IDs 2012-03-20 17:31:20 +01:00
Tobias Brunner 6a6e000134 Log selected peer config during Main Mode. 2012-03-20 17:31:20 +01:00