Martin Willi
371a54c7a9
added support for stateful PRFs (such as the FIPS_PRF)
2009-06-12 10:39:47 +02:00
Martin Willi
c66cd00df4
removed pluto test vectors, --disable-self-test option
2009-06-11 20:27:32 +02:00
Martin Willi
701381ceb8
added SHA2 HMAC PRF test vectors
2009-06-11 20:26:01 +02:00
Martin Willi
d94d68e404
added SHA2 test vectors
2009-06-11 18:14:30 +02:00
Martin Willi
f02d144095
added SHA1 test vectors
2009-06-11 17:17:33 +02:00
Martin Willi
2df93f467b
added HMAC SHA1 test vectors
2009-06-11 17:05:56 +02:00
Martin Willi
764708b4e0
added HMAC MD5 test vectors
2009-06-11 16:44:20 +02:00
Martin Willi
c698da8cb4
added RNG test vectors
2009-06-11 15:56:00 +02:00
Martin Willi
e091d5100f
added MD5 test vectors
2009-06-11 15:56:00 +02:00
Martin Willi
54916d79d6
added AES-XCBC test vectors for signer/prf
2009-06-11 15:56:00 +02:00
Martin Willi
005163805d
added test vectors for AES128 CBC
2009-06-11 15:56:00 +02:00
Martin Willi
6f4f83e333
added blowfish test vectors from pluto
2009-06-11 15:56:00 +02:00
Martin Willi
81811a9d8b
added a plugin providing crypto test vectors
2009-06-11 15:55:59 +02:00
Martin Willi
28a0728b67
make use of the crypto_tester in the crypto_factory
...
libstrongswan.crypto.test.on_add to test algorithms during initialization
libstrongswan.crypto.test.on_create to test algorithms on each instantiation
2009-06-11 15:55:48 +02:00
Martin Willi
3e8891667b
implemented a crypto_tester class to test crypto algorithms
...
libstrongswan.crypto.test.required to require at least one test vector to use an algorithm
libstrongswan.crypto.test.rng_true to run RNG tests on RNG_TRUE quality
2009-06-11 15:54:44 +02:00
Martin Willi
6f299040fb
handling hashers and rngs as transform types (in private range)
2009-06-11 14:17:16 +02:00
Martin Willi
e51f607221
gcrypt blowfish supports 128 bit key size only
2009-06-11 14:13:17 +02:00
Martin Willi
25d6c5146b
remove obsolete scripts
2009-06-10 18:31:15 +02:00
Martin Willi
e0069366c8
fixed ecp521 test
2009-06-10 18:07:19 +02:00
Martin Willi
0461a2ff13
added missing RSA 768 test
2009-06-10 17:26:56 +02:00
Martin Willi
6edad5afdd
added convenience scripts for pubkey/dh speed tests
2009-06-10 16:25:32 +02:00
Martin Willi
a4caeac76e
moved publickey speed test to a standalone program
...
This reverts commit 08874d6ae2 .
2009-06-10 16:25:32 +02:00
Martin Willi
3e3de01b28
moved Diffie-Hellman speed test to a standalone program
...
This reverts commit 1e6050bfae .
2009-06-10 14:58:58 +02:00
Martin Willi
260158e53e
properly shut down and unref nm mainloop, fixes crash at shutdown
2009-06-09 15:13:10 +02:00
Martin Willi
4d8ddefb78
remove stale pidfile if no such process found
2009-06-09 14:56:31 +02:00
Martin Willi
fd0b7903e6
fix inclusion of private_key_t in nm plugin
2009-06-09 14:03:48 +02:00
Martin Willi
1e6050bfae
implemented a speed test for diffie-hellman
2009-06-09 11:27:35 +02:00
Martin Willi
08874d6ae2
implemented a speed test for public key algorithms
2009-06-09 11:27:34 +02:00
Martin Willi
3240cab978
gcrypt RSA public key implementation
2009-06-09 11:27:26 +02:00
Martin Willi
ff8d3ba355
gcrypt RSA private key implementation
2009-06-09 11:27:11 +02:00
Martin Willi
ccd1464586
use autoconf macro provided by libgcrypt
2009-06-09 11:18:57 +02:00
Martin Willi
1111088aa7
gcrypt mpi based Diffie-Hellman implementation
2009-06-09 11:18:57 +02:00
Martin Willi
a41d0932c2
gcrypt rng implementation
2009-06-09 11:18:57 +02:00
Martin Willi
8e97e32705
use abstract mutex_t for gcrypt locking callbacks
2009-06-09 11:18:56 +02:00
Martin Willi
80862c4637
gcrypt crypter implementation
2009-06-09 11:18:56 +02:00
Martin Willi
f908ff9f91
gcrypt hasher implementation
2009-06-09 11:18:56 +02:00
Martin Willi
513a1a2835
initialize gcrypt threadsave, currently for pthread only
2009-06-09 11:18:56 +02:00
Martin Willi
4977018c23
added skeleton for libgcrypt based crypto plugin
2009-06-09 11:18:56 +02:00
Martin Willi
86ab0bb65e
fixed crash in openssl private_key->get_public_key(), using encode/load workaround
2009-06-09 11:03:35 +02:00
Martin Willi
b00fbdb55a
updated medcli/medsrv plugins to use new auth_cfg API, fixes compilation
2009-06-05 14:15:39 +02:00
Martin Willi
ec0b9ac97c
added missing identification.h include
2009-06-04 13:49:51 +02:00
Martin Willi
2fdca5e3cb
apply is_anyaddr fix from socket also to socket-raw
2009-06-03 17:56:55 +02:00
Martin Willi
c4f59ccec0
fixed ENUM naming of XCBC prf
2009-06-02 14:41:53 +02:00
Martin Willi
9474a0d90c
added a charon.install_virtual_ip option to disable IP installation for testing
2009-06-02 13:45:29 +02:00
Martin Willi
178bf4c5e9
register the already implemented AUTH_HMAC_SHA1_160 algorithm
2009-05-28 15:03:57 +02:00
Martin Willi
92f5956790
show strongSwan version in statusall
2009-05-26 14:10:45 +02:00
Martin Willi
66b8345f9f
added generated extconf.rb to .gitignore, removed it from distribution
2009-05-25 15:45:05 +02:00
Martin Willi
a13c013b6f
include TSi/TSr of triggering packet in acquire
2009-05-20 11:44:43 +02:00
Martin Willi
cd37e13133
properly terminate EAP authentication if EAP method fails
2009-05-20 09:24:18 +02:00
Martin Willi
8affd7ac65
fixed dumping of integers in generator
2009-05-20 09:04:10 +02:00
Martin Willi
c6c842e9ad
added Debian specific packaging files to NM applet
2009-05-19 14:01:40 +02:00
Martin Willi
bf9e1d4444
new NM applet release 1.1.1
2009-05-19 14:01:39 +02:00
Martin Willi
ef56ba51d4
fixed compiler warnings
2009-05-19 12:23:21 +02:00
Martin Willi
f920bd1861
replaced deprecated g_strcasecmp()
2009-05-19 12:23:21 +02:00
Martin Willi
9e2d7f962f
updated build system to newer autotool/gnome conventions
2009-05-19 12:23:20 +02:00
Martin Willi
39ded7128c
do not write to unaligned memory in MSCHAPv2
2009-05-18 14:41:16 +02:00
Martin Willi
3f7611c59d
cleanup of generator code
2009-05-18 14:06:48 +02:00
Martin Willi
79a2afedd5
removed unused 64-bit integer parsing rule
2009-05-18 13:36:56 +02:00
Martin Willi
4274885855
do not access unaligned words/half-words directly
2009-05-18 13:34:09 +02:00
Martin Willi
57ae766af8
cleaned up parser code
2009-05-18 13:13:12 +02:00
Martin Willi
12806574b8
removed trailing spaces/tabs
2009-05-18 13:13:12 +02:00
Martin Willi
09dbca9fbf
fixed typos
2009-05-18 10:49:50 +02:00
Martin Willi
047b2e42df
added NEWS for 4.3.1
2009-05-18 10:42:16 +02:00
Martin Willi
24cd2ca6ee
moved very stroke specific x509 flag handling out of core library
2009-05-18 10:42:16 +02:00
Martin Willi
0ed6b7a7d7
If the NM gateway certificate has the CA constraint set, we use the gateway address as its identity.
...
To allow the same certificate deployment for Windows 7 and NetworkManager clients,
the NM plugin now accepts CA certificates. To prevent any certificate holder
to act as a gateway, we bind the identity to the entered gateway address. The
gateways certificate therefore must contain the IP/DNS of the gateway
as subjectAltName.
2009-05-15 16:35:14 +02:00
Martin Willi
d4b403e2f3
updated glade dialog, using tooltip instead of tooltip_text
2009-05-15 16:04:07 +02:00
Martin Willi
6b967fb762
implemented save_secrets hook to avoid crash
2009-05-15 16:04:07 +02:00
Martin Willi
a61395676f
added .gitignore files to NM applet
2009-05-15 15:33:19 +02:00
Martin Willi
9caceb6ed5
updated prf identifiers
2009-05-15 13:49:05 +02:00
Martin Willi
b79ca7858b
updated integrity algorithm identifiers
2009-05-15 13:48:44 +02:00
Martin Willi
832427064c
added a "purgeike" command to stroke, deleting all IKE_SAs without a CHILD_SA
2009-05-15 11:02:56 +02:00
Martin Willi
5cb3210acf
stroke accepts "down conn1{*}/[*]" to delete all CHILD/IKE_SAs using a given config
2009-05-15 10:18:43 +02:00
Martin Willi
c296e51c40
added eap_start option to radius plugin
...
EAP-Start sends an empty EAP message to initiate EAP conversation
before doing EAP-Identity.
2009-05-14 14:14:29 +02:00
Martin Willi
64e8ca281f
simplified SPI allocation after refactorings
2009-05-14 10:28:18 +02:00
Martin Willi
d50746febe
identation cleanups
2009-05-13 15:57:31 +02:00
Martin Willi
ad65a713e4
fixed identation
2009-05-13 14:55:35 +02:00
Martin Willi
0a3ca29021
fixed cleanup of traffic selector lists
2009-05-12 17:13:09 +02:00
Martin Willi
8f0ab613e5
do not destroy packet twice if message generation failed
2009-05-12 14:38:48 +02:00
Martin Willi
e1fa02bc62
properly end CERT_PRE task after detecting the final authentication round
2009-05-12 11:26:50 +02:00
Martin Willi
9dd2b42728
do not report increasing rekey times if rekeying currently active
2009-05-12 10:56:49 +02:00
Martin Willi
37974979bc
do not report a CHILD_SA rekey time if rekeying disabled
2009-05-12 10:56:48 +02:00
Martin Willi
4a0c97e7d4
also update permission in template/guest folders
...
some identation cleanups
2009-05-11 17:26:13 +02:00
Martin Willi
db879fdfac
removed @brief doxygen keywords
2009-05-11 17:24:51 +02:00
Martin Willi
5d47f284b8
list available templates using "template" alias
2009-05-11 17:20:01 +02:00
Martin Willi
47a9a48f5b
ruby bindings for template enumerator
2009-05-11 17:19:36 +02:00
Martin Willi
608046c09c
added a Dumm template enumerator
2009-05-11 17:18:59 +02:00
Martin Willi
05ac17f0e1
allow "others" to read created dumm files/folders
2009-05-11 16:38:04 +02:00
Martin Willi
496064ba45
hand out a IPv4 virtual address if %any6 is requested
2009-05-11 13:33:55 +02:00
Martin Willi
30fc989c9c
fixed configuration payload type as responder
2009-05-11 13:23:15 +02:00
Martin Willi
a3d692ca87
never send a CERT payload in EAP
2009-05-11 11:37:58 +02:00
Martin Willi
5775283f8b
updated MSK calculation in MSCHAPv2, compatible with Win7/2008 RC.
2009-05-11 10:42:53 +02:00
Martin Willi
25f2d52f30
Fixed EAP authentication regression
...
Use correct nonce/init message again for EAP AUTH payload
sent from responder to initiator.
2009-05-11 10:42:52 +02:00
Martin Willi
b81917ea00
fixed memleak
2009-05-11 10:42:52 +02:00
Martin Willi
9d737ecfc5
drop acquires we already have a pending connection attempt
2009-05-08 10:04:01 +02:00
Martin Willi
c3626c2ce6
initiate trapped CHILD_SAs with same reqid
2009-05-08 10:04:00 +02:00
Martin Willi
fda97f2140
removed $Id$ from new template generated files
2009-05-08 10:04:00 +02:00
Martin Willi
56d461a1f1
listing routed connection in statusall
2009-05-08 10:04:00 +02:00
Martin Willi
17339b9a86
removed obsolete route/unroute code from ike_sa/controller
2009-05-08 10:03:59 +02:00
Martin Willi
8c99451ae1
make use of the new trap-manager
2009-05-08 10:03:58 +02:00
Martin Willi
eb8ed130af
added a trap-manager to handle routed policies outside of IKE_SAs
2009-05-08 10:03:58 +02:00