Commit Graph
8138 Commits
Author SHA1 Message Date
Martin Willi 3ed148b37e Moved IKE_SA delete task creation to protocol specific task manager 2012-03-20 17:31:27 +01:00
Martin Willi 83c5fda053 Moved CHILD_SA delete task creation to protocol specific task manager 2012-03-20 17:31:27 +01:00
Martin Willi 463a73cc0f Moved CHILD_SA rekey task creation to protocol specific task manager 2012-03-20 17:31:27 +01:00
Martin Willi fe43d9a237 Moved CHILD_SA initiate task creation to protocol specific task manager 2012-03-20 17:31:27 +01:00
Martin Willi a60daa07f6 Moved IKE_SA initiate task creation to protocol specific task manager 2012-03-20 17:31:27 +01:00
Martin Willi 244d715de5 Moved liveness checking task creation to protocol specific task manager 2012-03-20 17:31:27 +01:00
Martin Willi 7d0a3a427d Factories honor charon IKEv1/IKEv2 protocol support flags 2012-03-20 17:31:26 +01:00
Martin Willi e51a28fda8 Added a --disable-ikev2 option to disable IKEv2 support in charon 2012-03-20 17:31:26 +01:00
Martin Willi 15a682f4c2 Separated libcharon/sa directory with ikev1 and ikev2 subfolders 2012-03-20 17:31:26 +01:00
Martin Willi 2e3c9f8799 Renamed ike_vendor_v1 to isakmp_vendor 2012-03-20 17:31:26 +01:00
Martin Willi 79d6fc7f72 Renamed ike_natd_v1 to isakmp_natd 2012-03-20 17:31:26 +01:00
Martin Willi 824dc0adad Renamed ike_cert_pre_v1 to isakmp_cert_pre 2012-03-20 17:31:26 +01:00
Martin Willi 0aa2af5efc Renamed ike_cert_post_v1 to isakmp_cert_post 2012-03-20 17:31:26 +01:00
Martin Willi 26a758ffcb Fixed fix for XAuth plugin feature matching 2012-03-20 17:31:25 +01:00
Martin Willi 8833068877 Doxygen fixes 2012-03-20 17:31:25 +01:00
Martin Willi ef32c6866e Removed obsolete XAuth job 2012-03-20 17:31:25 +01:00
Martin Willi 26b02f50f4 Always use a transform number of 1 when encoding a single transform 2012-03-20 17:31:25 +01:00
Martin Willi 5d0458af0a Another set of cleanups in message.c 2012-03-20 17:31:25 +01:00
Martin Willi 2ee83c2778 Fix XAuth plugin feature matching 2012-03-20 17:31:25 +01:00
Martin Willi ef175c92d9 Initiate IKE_ANY configurations with IKEv2 2012-03-20 17:31:25 +01:00
Martin Willi ac009df132 Pass IKE version to peer config enumerator, filter configs 2012-03-20 17:31:25 +01:00
Martin Willi d94c923648 Support an "any" IKE version for both IKEv1 or IKEv2 2012-03-20 17:31:25 +01:00
Martin Willi b9a707e696 Some coding style cleanups 2012-03-20 17:31:25 +01:00
Martin Willi 2f58f6cba1 Fixed notify enum names 2012-03-20 17:31:25 +01:00
Tobias Brunner 4bc4e8e17b Added support for iKEIntermediate flag to ipsec pki. 2012-03-20 17:31:25 +01:00
Tobias Brunner f29a4f1c64 Added support for iKEIntermediate X.509 extended key usage flag.
Mac OS X requires server certificates to have this flag set.
2012-03-20 17:31:24 +01:00
Tobias Brunner 00cc2188d4 Some whitespace fixes. 2012-03-20 17:31:24 +01:00
Tobias Brunner b46b56fac1 Log parsed unsigned ints with proper format strings. 2012-03-20 17:31:24 +01:00
Martin Willi bf5b1d9e73 Send different notifies if quick mode fails 2012-03-20 17:31:24 +01:00
Martin Willi b64d6423b1 Support flushing of task queue after building message in task fails 2012-03-20 17:31:24 +01:00
Martin Willi fceb20f390 Consider notify errors fatal only during main mode 2012-03-20 17:31:24 +01:00
Martin Willi 767966e70b Delete CHILD_SA if installing SA in third message fails 2012-03-20 17:31:24 +01:00
Martin Willi 53816600ff Added a quick_delete task flag to enforce delete, even if CHILD_SA not found 2012-03-20 17:31:24 +01:00
Martin Willi 429d95fef2 Send delete if Main Mode authentication fails as initiator 2012-03-20 17:31:24 +01:00
Martin Willi 5762c0efeb Send notifies in all error cases of Main Mode 2012-03-20 17:31:24 +01:00
Martin Willi ca26065745 Add some additional IKEv1 notify types 2012-03-20 17:31:23 +01:00
Martin Willi a4cc071364 Do not trust unprotected INFORMATIONALS, just print that we got one 2012-03-20 17:31:23 +01:00
Martin Willi daf7e6bc36 Use (as client) and verify (as server) configured XAuth identities 2012-03-20 17:31:23 +01:00
Martin Willi 7a7efbf9d8 Added an identity getter to XAuth methods to query the actually used identity 2012-03-20 17:31:23 +01:00
Martin Willi 5f6a37eb9b Be a little more verbose about XAuth configs in ipsec statusall 2012-03-20 17:31:23 +01:00
Martin Willi 21a4fc832e Pass ipsec.conf xauth_identity option via stroke to charon configurations 2012-03-20 17:31:23 +01:00
Martin Willi 10a6a5acff Store Main Mode identity even if XAuth-only is used for authentication 2012-03-20 17:31:23 +01:00
Martin Willi f5e5c5edbd Added an XAUTH identity to use or require for XAuth authentication 2012-03-20 17:31:23 +01:00
Martin Willi bdadc5aee2 Check authorization constraints after main mode completed 2012-03-20 17:31:23 +01:00
Martin Willi fd2a491b31 Stop checking once a key size constraint is not fulfilled 2012-03-20 17:31:23 +01:00
Martin Willi ac3bc42e63 Save authentication info collected during main mode authentication 2012-03-20 17:31:23 +01:00
Martin Willi b24b73b7f3 Flush auth configs, if enabled, for both IKEv1 and IKEv2 2012-03-20 17:31:23 +01:00
Martin Willi 4ac137135a Fixed return value if SIG payload missing 2012-03-20 17:31:22 +01:00
Martin Willi 00d8823242 Show auth method of config we are looking for in main mode 2012-03-20 17:31:22 +01:00
Martin Willi 7b1e15ac4e Fixed IKEv1 prf+ keymat expansion beyond 320 bits 2012-03-20 17:31:22 +01:00