Commit Graph
100 Commits
Author SHA1 Message Date
Martin Willi 473d5aa868 Key strength checking stores all key sizes in auth_cfg, verifies all in complies() 2011-01-05 16:45:56 +01:00
Martin Willi 37b3fad782 Install "ipsec" script with tools or conftest 2011-01-05 16:45:56 +01:00
Martin Willi 6ffd9f88ce Use subject, not issuer, of CRL issuing certificate 2011-01-05 16:45:56 +01:00
Martin Willi dffb176f2b CRLSign keyUsage or CA basicConstraint are sufficient for CRL validation 2011-01-05 16:45:56 +01:00
Martin Willi ece5ac2271 Parse and encode crlSign keyUsage flag in x509 plugin 2011-01-05 16:45:56 +01:00
Martin Willi bb0cda2fa9 pki tool shows and builds crlSign keyUsage 2011-01-05 16:45:56 +01:00
Martin Willi 6807c0ca2c Added a flag for X509 CRLSign keyUsage 2011-01-05 16:45:56 +01:00
Martin Willi e49bd37b5d Remove x509_flag_names, flags do not work with ENUM() 2011-01-05 16:45:56 +01:00
Martin Willi 7d7beaa1fa Use certificate CRLIssuer information to look up cacched CRLs or CDPs 2011-01-05 16:45:56 +01:00
Martin Willi 630d58724a Added --crlissuer option to pki --issue 2011-01-05 16:45:56 +01:00
Martin Willi 4e508517d7 Added support for CRL Issuers to x509 and OpenSSL plugins 2011-01-05 16:45:55 +01:00
Martin Willi 9992cb1c10 Generate payload to rebuild_auth, works with injected unknown payloads 2011-01-05 16:45:55 +01:00
Martin Willi 5c95bf7b93 Move rebuild_auth functionality to a standalone hook
This reverts commit 3c12b239fd55aa36c59eb60224d27af8b8d915d1.
2011-01-05 16:45:54 +01:00
Martin Willi a73e040cd5 Added key strength constraints support to conftest 2011-01-05 16:45:53 +01:00
Martin Willi 963b4d9477 Added key strength constraints for RSA or ECDSA trustchains 2011-01-05 16:45:53 +01:00
Martin Willi 586070d2ce Implemented hook to log traffic selectors 2011-01-05 16:45:53 +01:00
Martin Willi 6bd3a1c220 The set_reserved() hook rebuilds AUTH if it mangles ID payload fields 2011-01-05 16:45:53 +01:00
Martin Willi 5f15faebc8 Include the used reserved bytes from ID payloads in AUTH calculation 2011-01-05 16:45:53 +01:00
Martin Willi 502edf425f Migrated psk/pubkey_authenticators to INIT/METHOD macros 2011-01-05 16:45:53 +01:00
Martin Willi b5bbc9506c Extended set_reserved hook to mangle sa_payload substructures 2011-01-05 16:45:52 +01:00
Martin Willi 54f2bdd656 Added substructure enumerators to sa_payload, proposal_substructure 2011-01-05 16:45:52 +01:00
Martin Willi 9ca5d0280e Moved check if packet already encoded to ike_sa, avoids message() hook invocation twice 2011-01-05 16:45:52 +01:00
Martin Willi a6da3795d6 The set_ike_version hook supports version flag mangling 2011-01-05 16:45:52 +01:00
Martin Willi 2813be18f5 Added a message method to set the "higher version supported" flag 2011-01-05 16:45:52 +01:00
Martin Willi 357e960e40 Implemented hook to toggle initiator flag in IKE header 2011-01-05 16:45:52 +01:00
Martin Willi 446a4537e5 Implemented a hook to set reserved bits 2011-01-05 16:45:51 +01:00
Martin Willi 166a2a45d9 Added reserved bit mangling wrapper functions to message 2011-01-05 16:45:51 +01:00
Martin Willi 15a612efb2 Use payload_get_field() to look up payload fields 2011-01-05 16:45:51 +01:00
Martin Willi e662d62a76 Implemented a generic payload field lookup function 2011-01-05 16:45:51 +01:00
Martin Willi bf029696c6 Reserved field get parsed/generated like any other bit/byte field 2011-01-05 16:45:51 +01:00
Martin Willi c93c7a7560 Added member fields for reserved bits and bytes in all payloads 2011-01-05 16:45:51 +01:00
Martin Willi 1b671248c2 Migrated vendor_id_payload to INIT/METHOD macros 2011-01-05 16:45:51 +01:00
Martin Willi 102adb9bfd Migrated ts_payload to INIT/METHOD macros 2011-01-05 16:45:51 +01:00
Martin Willi 1f5b2bec4b Use enumerator instead of deprecated iterator 2011-01-05 16:45:51 +01:00
Martin Willi 9f8ecff2e2 Migrated transform_substructure to INIT/METHOD macros 2011-01-05 16:45:51 +01:00
Martin Willi 6844c156fc Removed obsolete clone mehtod from proposal_substructure 2011-01-05 16:45:51 +01:00
Martin Willi 6b69c03d13 Migrated transform_attribute to INIT/METHOD macros 2011-01-05 16:45:51 +01:00
Martin Willi 423745b652 Migrated traffic_selector_substructre to INIT/METHOD macros 2011-01-05 16:45:51 +01:00
Martin Willi 3f0a2af2a6 Migrated notify_payload to INIT/METHOD macros 2011-01-05 16:45:51 +01:00
Martin Willi e3c4c6a5ac Migrated nonce_payload to INIT/METHOD macros 2011-01-05 16:45:50 +01:00
Martin Willi 19ee0762e7 Migrated ke_payload to INIT/METHOD macros 2011-01-05 16:45:50 +01:00
Martin Willi ffb980572f Migrated id_payload to INIT/METHOD macros 2011-01-05 16:45:50 +01:00
Martin Willi f5705d0fa6 Use standard ID getter in log_id hook 2011-01-05 16:45:50 +01:00
Martin Willi a11cfe2960 Migrated cp_payload to INIT/METHOD macros 2011-01-05 16:45:50 +01:00
Martin Willi bda62cedb9 Migrated configuration_attribute to INIT/METHOD macros 2011-01-05 16:45:50 +01:00
Martin Willi 1cc58e7ed2 Migrated certreq_payload to INIT/METHOD macros 2011-01-05 16:45:50 +01:00
Martin Willi 2aa1bffb02 Migrated cert_payload to INIT/METHOD macros 2011-01-05 16:45:50 +01:00
Martin Willi 9c0ccf5e26 Migrated auth_payload to INIT/METHOD macros 2011-01-05 16:45:50 +01:00
Martin Willi 64293410b7 Implemented a hook to toggle the IKE message request flag 2011-01-05 16:45:50 +01:00
Martin Willi 19a18de98a Implemented hook to modify IKE header SPIs 2011-01-05 16:45:50 +01:00
Martin Willi 6b50b9115d Fixed transport mode configuration option 2011-01-05 16:45:49 +01:00
Martin Willi dbcdd4a46d Disable MOBIKE in conftesting, as it changes port floating behavior 2011-01-05 16:45:49 +01:00
Martin Willi 1535913aed Load plugins only once, even if listed twice 2011-01-05 16:45:49 +01:00
Martin Willi 9a99b745c0 Preload plugins configured in tests 2011-01-05 16:45:49 +01:00
Martin Willi 401818651e Moved generic infrastructure initialization to libcharon_init(), allows us to preload plugins 2011-01-05 16:45:49 +01:00
Martin Willi 74a5dfe537 Added IKE options to configure source/destination ports 2011-01-05 16:45:48 +01:00
Martin Willi 448db6d9c0 Added IKE config option to fake NAT situations 2011-01-05 16:45:48 +01:00
Martin Willi f2116c6de7 Show SPI in proposal logging hook 2011-01-05 16:45:48 +01:00
Martin Willi 42133e33bd Implemented a hook to inject custom proposals 2011-01-05 16:45:48 +01:00
Martin Willi 47e0b50725 Fixed error reporting 2011-01-05 16:45:48 +01:00
Martin Willi 5d82b2d321 Remove unused variable 2011-01-05 16:45:48 +01:00
Martin Willi 7ab6429b3c Added hook to log ID payload type and data 2011-01-05 16:45:47 +01:00
Martin Willi c6f2bac1b8 Added hook to log received KE group 2011-01-05 16:45:47 +01:00
Martin Willi 6dd6b0ef95 Added a hook to modify proposal numbers 2011-01-05 16:45:47 +01:00
Martin Willi 5dca645d46 Added a hook to print received proposals, including number 2011-01-05 16:45:47 +01:00
Martin Willi b080f393ce Added a hook to alter the payload length field of arbitrary payloads 2011-01-05 16:45:47 +01:00
Martin Willi 2ecbd6186e Do not update payload length during generation, allows hooks override payload length 2011-01-05 16:45:47 +01:00
Martin Willi d58127af84 Do not recalculate payload header length after generation, payloads do length calculation 2011-01-05 16:45:47 +01:00
Martin Willi 90994a8a5c Support loading of certificate revocation lists 2011-01-05 16:45:46 +01:00
Martin Willi 00d8b9a638 Implemented a hook that recreates a valid incoming IKE_AUTH response, even if AUTH_FAILED 2011-01-05 16:45:46 +01:00
Martin Willi 2a19095e4c Apply IKE major/minor version set on message to IKE header 2011-01-05 16:45:46 +01:00
Martin Willi 7e7c7c1d84 Added setters for IKE major/minor version to ike_header 2011-01-05 16:45:46 +01:00
Martin Willi 1c22c529a7 Migrated ike_header_t to INIT/METHOD macros 2011-01-05 16:45:46 +01:00
Martin Willi a0a760795e Added hook to set arbitrary IKE major/minor versions in message headers 2011-01-05 16:45:45 +01:00
Martin Willi 2712b113c7 Prefer test specific over suite specific configuration 2011-01-05 16:45:45 +01:00
Martin Willi e330360f77 Added a force_hookie hook that requests a COOKIE independent of our COOKIE mechanism 2011-01-05 16:45:45 +01:00
Martin Willi 1f42c80942 The add_payload hook supports replacing existing payloads of the same type 2011-01-05 16:45:45 +01:00
Martin Willi 60b14332b3 Fix insertion of non hex encoded payload data 2011-01-05 16:45:44 +01:00
Martin Willi b0f6b31db8 Fixed length calculation of unknown payload 2011-01-05 16:45:44 +01:00
Martin Willi 50b28ad8a4 Added a hook to set the critical bit on arbitrary payloads 2011-01-05 16:45:44 +01:00
Martin Willi c67de660d2 Move critical bit checking to ike_sa, notify payload includes unsupported payload type 2011-01-05 16:45:44 +01:00
Martin Willi e7099aa24e Handle all error notifies in CREATE_CHILD_SA exchanges 2011-01-05 16:45:44 +01:00
Martin Willi 24384f352f Support encoding of UKNOWN_DATA 2011-01-05 16:45:44 +01:00
Martin Willi 958c1d75d7 Moved our substructure identifiers above 255, ignore private payloads properly 2011-01-05 16:45:44 +01:00
Martin Willi fea3aa5d12 Check for exceeded payload count even if we have a found one flagged as sufficient 2011-01-05 16:45:43 +01:00
Martin Willi 9b2ed9501f Added a hook to inject custom payloads with critical bit 2011-01-05 16:45:43 +01:00
Martin Willi ca93b54e65 Added a constructor for custom uknown payloads 2011-01-05 16:45:43 +01:00
Martin Willi b6c796464d Use the payloads actual type in unknown_payload_t 2011-01-05 16:45:43 +01:00
Martin Willi 9431023ce6 Migrated unknown payload to INIT/METHOD macros 2011-01-05 16:45:43 +01:00
Martin Willi 7814c74970 Added a short README about the conftest utility 2011-01-05 16:45:43 +01:00
Martin Willi a784c9e030 Specify the type of the certificate to load, currently X509 only 2011-01-05 16:45:43 +01:00
Martin Willi 4a2f7f05df Be a little more verbose about cert payload injection 2011-01-05 16:45:43 +01:00
Martin Willi a60b892841 Support hook suffixes to use the same hook multiple times 2011-01-05 16:45:42 +01:00
Martin Willi e5e71e46d9 Support arbitrary suffixes for actions, same action multiple times 2011-01-05 16:45:42 +01:00
Martin Willi cf594ca411 Added a hook to ignore specific messages 2011-01-05 16:45:42 +01:00
Martin Willi c146c3c4e1 Ingore messages with exchange type altered to UNDEFINED in message() hook 2011-01-05 16:45:42 +01:00
Martin Willi 81b213499d Added a hook to send unencrypted notifies in established IKE_SAs 2011-01-05 16:45:42 +01:00
Martin Willi a30dba9282 Fail silently without INVALID_SYNTAX if message not verified 2011-01-05 16:45:42 +01:00
Martin Willi 1009e5c3bc Include suiteb test suite config in distribution 2011-01-05 16:45:42 +01:00
Martin Willi b70abdac2b Fixed loading of credentials using a relative path 2011-01-05 16:45:42 +01:00