Martin Willi
dbff6373e1
include: Update xfrm.h to Linux v4.3
...
We strip the newly introduced <linux/in6.h> include, as this clashes with the
<netinet/in6.h> include.
2016-09-30 14:51:58 +02:00
Martin Willi
518a5b2ece
configure: Check for and explicitly link against -latomic
...
Some C libraries, such as uClibc, require an explicit link for some atomic
functions. Check for any libatomic, and explcily link it.
2016-06-14 14:27:20 +02:00
Martin Willi
294ac097d6
af-alg: Silently skip probing algorithms if AF_ALG is not supported
...
If the af-alg plugin is enabled, but kernel support is missing, we get
an error line during startup for each probed algorithm. This is way too
verbose, so just skip probing if AF_ALG is unsupported.
2016-05-19 11:13:24 +02:00
Martin Willi
989db1bf2f
configure: Check for a potential -lpthread by using -ldl
...
Some pthread library variants depend on libdl, hence we must pass such a
library to successfully build against libpthread.
2016-05-18 14:46:20 +02:00
Martin Willi
bb723f97c7
Merge branch 'vici-undo-on-unload'
...
Undo start actions when unloading connections, and add some misc fixes and
extensions to vici connection handling.
2015-12-07 10:29:57 +01:00
Martin Willi
1a8a420c1c
vici: Fix documentation about the initiate/terminate timeout
2015-12-07 10:28:45 +01:00
Martin Willi
eaca77d03e
vici: Honor an optionally passed IKE configuration name in initiate/install
...
If two IKE configurations have CHILD configurations with the same name,
we have no control about the CHILD_SA that actually gets controlled. The
new "ike" parameter specifies the peer config name to find the "child" config
under.
2015-12-07 10:28:45 +01:00
Martin Willi
5e79ae2d65
vici: Support completely asynchronous initiating and termination
...
In some situations the vici client is not interested in waiting for a
timeout at all, so don't register a logging callback if the timeout argument
is negative.
2015-12-07 10:28:45 +01:00
Martin Willi
1db918c4f8
vici: Use an empty local auth round if none given
...
While it hardly makes sense to use none for negotiated SAs, it actually does
when installing shunt policies.
2015-12-07 10:05:07 +01:00
Martin Willi
b26ba1b4a4
vici: Limit start action undoing to IKE_SAs using the base peer config name
...
If two peer configs use the same child config names, potentailly delete
the wrong CHILD_SA. Check the peer config name as well to avoid that.
2015-12-07 10:05:07 +01:00
Martin Willi
23b1f71372
vici: Close empty IKE_SAs after undoing CHILD_SA start actions
2015-12-07 10:05:07 +01:00
Martin Willi
2facf18833
vici: Use value based array to store CHILD_SA ids during restart
...
The previous approach stored a pointer to a volatile stack variable, which
works for a single ID, but not for multiple.
2015-12-07 10:05:07 +01:00
Martin Willi
01caed533b
array: Add an insert/create function for value based arrays
2015-12-07 10:05:07 +01:00
Martin Willi
f3b2d4a9d8
vici: Undo start actions when unloading configs
2015-12-07 10:05:07 +01:00
Martin Willi
057e6cc524
byteorder: Provide a fallback for le32toh/htole32()
...
Some older toolchains don't provide these macros, so implement them using
the gcc builtins. We also provide 64-bit variants as used by chapoly.
2015-12-04 10:29:09 +01:00
Martin Willi
8fa0c7bc77
byteorder: Add 32-bit unaligned little-endian conversion functions
2015-12-04 10:29:09 +01:00
Martin Willi
9709418871
swanctl: Explicitly link against -lpthread and -ldl if required
...
We already do this for charon, as some toolchains require an explicit
link even if libstrongswan already depends on it.
2015-12-04 08:02:03 +01:00
Martin Willi
41106e7993
pki: Explicitly link against -lpthread and -ldl if required
...
We already do this for charon, as some toolchains require an explicit
link even if libstrongswan already depends on it.
2015-12-04 08:02:03 +01:00
Martin Willi
2b39da2634
configure: Link against potential -ldl when checking for OpenSSL libcrypto
2015-12-04 08:02:03 +01:00
Martin Willi
8b0c9cf155
watcher: Check for cancellation if poll() fails with EINTR
...
With LinuxThreads, poll() is unfortunately no cancellation point. It seems
that poll gets woken up after cancellation, but we actively must check
for cancellation before re-entering poll to properly shut down the watcher
thread.
2015-12-04 08:01:15 +01:00
Martin Willi
0020b25a45
ikev2: Enforce remote authentication config before proceeding with own authentication
...
Previously the constraints in the authentication configuration of an
initiator were enforced only after all authentication rounds were
complete. This posed a problem if an initiator used EAP or PSK
authentication while the responder was authenticated with a certificate
and if a rogue server was able to authenticate itself with a valid
certificate issued by any CA the initiator trusted.
Because any constraints for the responder's identity (rightid) or other
aspects of the authentication (e.g. rightca) the initiator had were not
enforced until the initiator itself finished its authentication such a rogue
responder was able to acquire usernames and password hashes from the client.
And if a client supported EAP-GTC it was even possible to trick it into
sending plaintext passwords.
This patch enforces the configured constraints right after the responder's
authentication successfully finished for each round and before the initiator
starts with its own authentication.
Fixes CVE-2015-4171.
2015-06-05 13:44:42 +02:00
Martin Willi
e6ba688a35
During libstrongswan initialization, check if memwipe() works as expected
2013-04-18 13:05:37 +02:00
Martin Willi
3e8caf6af6
Make resync/monitoring functionality optional
2010-04-07 13:55:16 +02:00
Martin Willi
f24ca1dd55
Listen to ike_updown/rekey hook instead of ike_state_change
2010-04-07 13:55:16 +02:00
Martin Willi
c866a42737
Request a complete resync after daemon startup
2010-04-07 13:55:16 +02:00
Martin Willi
1466af8556
Do not automatically take over segments, as we need to resync first
2010-04-07 13:55:16 +02:00
Martin Willi
ea249cc6f0
Drop overlapping segments only if we have no active SAs on it
2010-04-07 13:55:16 +02:00
Martin Willi
a05e388540
Do not install iptables rules, they should stay active after shutdown
2010-04-07 13:55:16 +02:00
Martin Willi
e262f4e543
Take over all segments if heartbeat becomes silent
2010-04-07 13:55:15 +02:00
Martin Willi
d87489661c
Renamed ha-sync plugin to ha
2010-04-07 13:55:15 +02:00
Martin Willi
3c82381296
Try to send HA sync messages synchronously
2010-04-07 13:55:15 +02:00
Martin Willi
f4f394e67c
Do not sync a delete for a child in a destroying IKE_SA
2010-04-07 13:55:15 +02:00
Martin Willi
5a0a359b88
Include ICMP traffic in sync tunnel
2010-04-07 13:55:15 +02:00
Martin Willi
874c0bd8b8
Refactored segment enabling/disabling
2010-04-07 13:55:15 +02:00
Martin Willi
5d67259042
Use a connected UDP socket
2010-04-07 13:55:15 +02:00
Martin Willi
06308d9ede
Removed obsolete socket subclasses
2010-04-07 13:55:15 +02:00
Martin Willi
3912fdb1ec
Automatically segment cluster using periodically sent status messages
2010-04-07 13:55:14 +02:00
Martin Willi
b7f15be136
Do not enable/disable our own sync tunnel
2010-04-07 13:55:14 +02:00
Martin Willi
9fdf5f712e
Enable/disable inactive/active segments only
2010-04-07 13:55:14 +02:00
Martin Willi
310498f3de
Deactivate all active segments before shutting down
2010-04-07 13:55:14 +02:00
Martin Willi
4e248733a8
HA kernel interface can mangle netfilter rules, currently with iptables invocation
2010-04-07 13:55:14 +02:00
Martin Willi
dbc91f7c84
Added support for kernel segment manipulation
2010-04-07 13:55:14 +02:00
Martin Willi
6921e8d5a9
Moved segment configuration parsing to ha_sync_plugin
2010-04-07 13:55:14 +02:00
Martin Willi
37459ea928
Propagate segment manipulation to cluster node
2010-04-07 13:55:14 +02:00
Martin Willi
3d672d4b0a
Segment manipulation in HA sync is thread save
2010-04-07 13:55:14 +02:00
Martin Willi
c573b11c55
Passing 0 to segments->(de-)activate enables/disables all segments
2010-04-07 13:55:14 +02:00
Martin Willi
7ceaf50b05
separated auto-tunnel functionality from socket
2010-04-07 13:55:13 +02:00
Martin Willi
f5632db953
create external fifo socket only if "fifo_interface" option is set
2010-04-07 13:55:13 +02:00
Martin Willi
47d365deef
updated linuxdir include variable
2010-04-07 13:55:13 +02:00
Martin Willi
724736ff1c
updated HA sync plugin to new lifetime config
2010-04-07 13:55:13 +02:00
Martin Willi
f825238594
print "none" if not serving any segments
2010-04-07 13:55:13 +02:00
Martin Willi
a33eb8631c
automatically establish a PSK authenticated SA between cluster nodes
2010-04-07 13:55:13 +02:00
Martin Willi
80624c79d5
fixed memleak when installing synced virtual IPs
2010-04-07 13:55:13 +02:00
Martin Willi
b1d495f469
do not sync CHILD_SAs without an IKE_SA
2010-04-07 13:55:13 +02:00
Martin Willi
5b7c0f4409
removed $Id$ from ha plugin
2010-04-07 13:55:13 +02:00
Martin Willi
26d08a241a
fixed ike_sa condition/extension parsing
2010-04-07 13:55:12 +02:00
Martin Willi
1f32f61c87
added a copy of the linux jenkins hash to dist
2010-04-07 13:55:12 +02:00
Martin Willi
1e977438af
fixed sync of CHILD_SA delete
2010-04-07 13:55:12 +02:00
Martin Willi
9ffcbea6f1
added HA resync option to (re-)integrate nodes to a cluster
2010-04-07 13:55:12 +02:00
Martin Willi
c81f4fa29d
apply peer config during rekeying
2010-04-07 13:55:12 +02:00
Martin Willi
34d240a6e3
manage synced SAs in IKE_SA Manager, tag them with IKE_PASSIVE state
2010-04-07 13:55:12 +02:00
Martin Willi
d4113a42e9
support for IKE_SA rekeying sync
2010-04-07 13:55:12 +02:00
Martin Willi
aa98188af5
IKE_SA activation/deactivation magic using a fifo socket
2010-04-07 13:55:12 +02:00
Martin Willi
c94fe198e9
syncing of complete IKE/CHILD_SAs works
2010-04-07 13:55:11 +02:00
Martin Willi
7999be5b0e
pushing basic CHILD_SA sync data to backup node
2010-04-07 13:55:11 +02:00
Martin Willi
765935c8f6
basic syncing of IKE_SAs
...
recreating SAs with keymat derivation
2010-04-07 13:55:11 +02:00
Martin Willi
190edaf527
added a dispatcher class to receive HA sync messages
...
simple attribute parser enumerator (probably needs a cleaner implementation)
2010-04-07 13:55:11 +02:00
Martin Willi
12ec91ba3a
generating basic IKE_SA sync messages
...
pushing to statically configured failover node
2010-04-07 13:55:11 +02:00
Martin Willi
e5e91eec29
set up basic infrastructure ha_sync plugin
2010-04-07 13:55:11 +02:00
Martin Willi
e16d76f9a4
added child_sa serialization to ha_sync plugin
2010-04-07 13:55:11 +02:00
Martin Willi
e67f5136c0
HA sync plugin stub
2010-04-07 13:55:11 +02:00
Martin Willi
ed5fc4cafe
Use message instead of attributes in hook
2010-02-26 11:44:34 +01:00
Martin Willi
3e35a6e7a1
Use side-channel secured mpz_powm_sec of libgmp 5, if available
2010-02-18 17:38:59 +01:00
Martin Willi
7d3a830a71
Updated debian package for NetworkManager-strongswan-1.1.2
2010-02-18 09:51:45 +01:00
Martin Willi
e159cd1d1a
Version bump and NEWS for NetworkManager-strongswan-1.1.2 release
2010-02-18 09:51:44 +01:00
Martin Willi
0209179a30
Updated german translation
2010-02-18 09:51:40 +01:00
Martin Willi
7613a68f33
Tooltips are translatable
2010-02-18 09:20:13 +01:00
Martin Willi
d178eee895
Newer glade requires explicit vertical vboxes
2010-02-18 09:03:17 +01:00
Martin Willi
71070c88b7
Fixed lost renaimings in android plugin
2010-02-18 08:31:10 +01:00
Martin Willi
55699f037f
Added Android plugin, currently provides DNS handling on Android
2010-02-17 18:24:11 +01:00
Martin Willi
63b0bc9c2d
Invoke missing message() hook for incoming responses
2010-02-17 18:23:14 +01:00
Martin Willi
2aa553d773
Do not build own authentication data before we've verified others, we need the other identity in EAP
2010-02-09 16:11:07 +01:00
Martin Willi
313a53d4fc
Use destination address of ppp interfaces as nexthop in starters default route lookup
2010-02-05 09:28:31 +01:00
Martin Willi
7481f964ae
Use child_updown hook in updown plugin, fixes doubled invocation of down script
2010-02-03 11:07:53 +01:00
Martin Willi
909c0c3d63
Updated NEWS about per-connection inactivity timeout
2010-01-27 16:08:06 +01:00
Martin Willi
8015c91cb9
Added a ipsec.conf "inactivity" option to configure inactivity timeout for CHILD_SAs
2010-01-27 16:05:11 +01:00
Martin Willi
71da001753
Made inactivity_timeout a per CHILD_SA config option
2010-01-27 15:47:08 +01:00
Martin Willi
db05341916
Refactored EAP payload, avoid unaligned word access
2010-01-21 14:43:07 +01:00
Martin Willi
23d2bf84a3
Added a METHOD2() macro that implements a method for two different interfaces
2010-01-21 14:42:08 +01:00
Martin Willi
47498044c3
Support RADIUS messages up to 4096 bytes, RADIUS EAP-Message fragmentation
2010-01-19 16:47:21 +01:00
Martin Willi
7eab4a1be6
Support TLS client authentication Extended Key Usage in x509 generation
2010-01-14 12:00:43 +01:00
Martin Willi
aa9eeb5deb
Support for closing CHILD/IKE_SA if a CHILD_SA is inactive.
2010-01-12 10:23:42 +01:00
Martin Willi
bc6ff2fc99
Added strongswan.conf options to configure retransmission timeouts
2010-01-11 16:42:12 +01:00
Martin Willi
527f7f9b1c
Added a "double" getter to libstrongswan settings
2010-01-11 16:39:28 +01:00
Martin Willi
dbee988e28
Cast unaligned memcpy() args to char*, avoids over-optimization on ARM
...
See http://infocenter.arm.com/help/index.jsp?topic=/com.arm.doc.faqs/ka3934.html
2010-01-11 15:35:41 +01:00
Martin Willi
aca9f9ab5a
Added NEWS about mutual EAP-only authentication
2010-01-07 16:16:22 +01:00
Martin Willi
34948b9971
EAP-MSCHAPv2 is indeed mutual, but is prone to MITM dictionary attacks
2010-01-07 15:56:11 +01:00
Martin Willi
f34702ff3f
Support EAP-only authentication for mutual and key deriving EAP methods
2010-01-07 15:51:30 +01:00
Martin Willi
12fca6cc9f
Indicate and dected support for EAP-only authentication
2010-01-07 14:30:28 +01:00
Martin Willi
cdad91de49
Added NEWS for the new Vendor ID requirement for private use allocations
2010-01-07 11:14:33 +01:00