Tobias Brunner
|
4b2f428f40
|
Do not clone hashes of initial IKE messages when storing them in the hash table.
|
2012-03-20 17:31:40 +01:00 |
|
Tobias Brunner
|
20e3d5ea00
|
Store IKEv2 IKE_SAs by local SPI in the IKE_SA manager hash table.
For IKEv1 the previous behavior of always using the initiator's SPI as
key is maintained.
|
2012-03-20 17:31:40 +01:00 |
|
Tobias Brunner
|
71cf97871f
|
Added separate hashtable for hashes of initial IKE messages.
This does not require us to do a lookup for an SA by SPI first.
|
2012-03-20 17:31:40 +01:00 |
|
Tobias Brunner
|
68611395dc
|
chunk_equals_ptr added to compare chunks given as pointers.
|
2012-03-20 17:31:40 +01:00 |
|
Tobias Brunner
|
1726795fa9
|
Store the major IKE version on ike_sa_id_t.
|
2012-03-20 17:31:40 +01:00 |
|
Tobias Brunner
|
8254e7ecb8
|
Implemented handling of UNITY_LOAD_BALANCE as reauthentication.
|
2012-03-20 17:31:40 +01:00 |
|
Martin Willi
|
a7d3b0e098
|
Check if we actually have a packet before retransmitting it
|
2012-03-20 17:31:40 +01:00 |
|
Martin Willi
|
35852af7b1
|
Use a single set of FDs for all random plugin RNG instances
|
2012-03-20 17:31:40 +01:00 |
|
Tobias Brunner
|
eff331f799
|
Parse IKEv1 Cisco Load Balancing notify (can't act on it yet).
|
2012-03-20 17:31:40 +01:00 |
|
Tobias Brunner
|
3a9d5cbc14
|
Fixed transform numbering in IKEv1 proposal.
|
2012-03-20 17:31:40 +01:00 |
|
Tobias Brunner
|
dcbdc914fa
|
Compiler warning fixed.
|
2012-03-20 17:31:40 +01:00 |
|
Martin Willi
|
182d55b229
|
Use correct enum values to detect three message tasks for retransmission
|
2012-03-20 17:31:40 +01:00 |
|
Martin Willi
|
f98af1ddd5
|
Trigger DPD not before IKE_SA state gets updated
|
2012-03-20 17:31:39 +01:00 |
|
Martin Willi
|
5ed4b727d0
|
Fix mapping of IKEv1 encapsulation mode
|
2012-03-20 17:31:39 +01:00 |
|
Martin Willi
|
7fd7ffc649
|
Use UDP encapsulation even in non-NAT situation if initiator requests it
|
2012-03-20 17:31:39 +01:00 |
|
Martin Willi
|
75e3d90d43
|
Updated ipsec.conf man page for the use of IKEv1 with pluto
|
2012-03-20 17:31:39 +01:00 |
|
Martin Willi
|
c60246a618
|
Support inactivity timeout in IKEv1 CHILD_SAs
|
2012-03-20 17:31:39 +01:00 |
|
Martin Willi
|
a0c17d4157
|
Use a dedicated PRF for HASH/SIG payloads using ECDSA specific hasher
|
2012-03-20 17:31:39 +01:00 |
|
Martin Willi
|
4c685e8850
|
Select public key auth method by checking what key we have
|
2012-03-20 17:31:39 +01:00 |
|
Martin Willi
|
83b152dd4f
|
Support ECDSA signatures in IKEv1 pubkey authenticator
|
2012-03-20 17:31:39 +01:00 |
|
Martin Willi
|
5be386ff8e
|
Exchange certificates when using IKEv1 ECDSA authentication
|
2012-03-20 17:31:39 +01:00 |
|
Martin Willi
|
5aef6bd0f3
|
Accept NULL auth_cfg_t passed to credential_manager_t.get_private()
|
2012-03-20 17:31:39 +01:00 |
|
Martin Willi
|
6261c0c3b7
|
Support encoding of IKEv1 ECDSA proposals
|
2012-03-20 17:31:38 +01:00 |
|
Martin Willi
|
c8d46f2959
|
Dropped support of deprecated authby=eap and eap= options
|
2012-03-20 17:31:38 +01:00 |
|
Martin Willi
|
c791def8c1
|
Added support for authby/xauth_server legacy options
|
2012-03-20 17:31:38 +01:00 |
|
Martin Willi
|
c390569a76
|
Renamed CONFIGURATION_ATTRIBUTE_LENGTH to streamline it with other ATTRIBUTE rules
|
2012-03-20 17:31:38 +01:00 |
|
Martin Willi
|
05cb240215
|
Use ATTRIBUTE_VALUE rule in configuration attribute to parse it with correct length
|
2012-03-20 17:31:38 +01:00 |
|
Martin Willi
|
a994050e9c
|
Don't re-resolve addresses during initiate if they have already been set
|
2012-03-20 17:31:38 +01:00 |
|
Martin Willi
|
aa3b53e716
|
Adopt children after syncing a rekeyed IKEv1 SA
|
2012-03-20 17:31:38 +01:00 |
|
Martin Willi
|
fed5c33440
|
Synchronize IKEv1 DPD sequence numbers
|
2012-03-20 17:31:38 +01:00 |
|
Martin Willi
|
fd6fbf1764
|
Setting message ID on task manager sets DPD sequence numbers in IKEv1
|
2012-03-20 17:31:38 +01:00 |
|
Martin Willi
|
783c496966
|
Update state before triggering DPD, as we cancel it if PASSIVE
|
2012-03-20 17:31:38 +01:00 |
|
Martin Willi
|
a46b8e16ad
|
Set thread specific SA on bus for each enumerated IKE_SA
|
2012-03-20 17:31:38 +01:00 |
|
Martin Willi
|
b226fd300d
|
Sync remote virtual IP for IKEv1 SAs
|
2012-03-20 17:31:38 +01:00 |
|
Martin Willi
|
868d92a402
|
Sync new IKE_SA condition/extension flags
|
2012-03-20 17:31:37 +01:00 |
|
Martin Willi
|
c8531b7e69
|
Added support for Phase1 IV synchronization to HA plugin
|
2012-03-20 17:31:37 +01:00 |
|
Martin Willi
|
47b8f6ef4b
|
Invoke bus_t.message hook twice, once plain and parsed, once encoded and encrypted
|
2012-03-20 17:31:37 +01:00 |
|
Martin Willi
|
ae92641806
|
Create IKEv1 keymat hasher explicitly on sync
|
2012-03-20 17:31:37 +01:00 |
|
Martin Willi
|
a0fa7a7f64
|
Clear initiator flag when checking out initial IKEv1 SA from message
|
2012-03-20 17:31:37 +01:00 |
|
Martin Willi
|
8bcd9bd161
|
Added support to sync IKEv1 SAs key material in HA plugin
|
2012-03-20 17:31:37 +01:00 |
|
Martin Willi
|
23f9e7a18d
|
Pass IKEv1 specific keymat to ike_keys hook
|
2012-03-20 17:31:37 +01:00 |
|
Martin Willi
|
264514826c
|
Use a more complete implementation of a HA specific diffie_hellman_t
|
2012-03-20 17:31:37 +01:00 |
|
Martin Willi
|
5763367cac
|
Show IKE version in ipsec statusall
|
2012-03-20 17:31:37 +01:00 |
|
Martin Willi
|
c3f1839ab7
|
Apply proposal to a HA synced IKE_SA
|
2012-03-20 17:31:37 +01:00 |
|
Martin Willi
|
3624b09e21
|
Set selected proposal on IKEv1 SA, don't pass it separately to Phase 1 helper
|
2012-03-20 17:31:37 +01:00 |
|
Martin Willi
|
6bc6f67b0f
|
Updated HA plugin to new IKEv2 specific keymat functions
|
2012-03-20 17:31:37 +01:00 |
|
Martin Willi
|
3957a6e4f3
|
Get a reference for the child_cfg passed to child_create_create()
|
2012-03-20 17:31:36 +01:00 |
|
Martin Willi
|
696fa8e003
|
Invoke bus_t.narrow hook in quick mode exchange
|
2012-03-20 17:31:36 +01:00 |
|
Martin Willi
|
f420f51f55
|
Invoke authorization hooks for IKEv1 connections
|
2012-03-20 17:31:36 +01:00 |
|
Martin Willi
|
1a0648490c
|
Invoke ike_updown hooks for reauthenticated IKEv1 SAs
|
2012-03-20 17:31:36 +01:00 |
|