Martin Willi
|
269f7f448b
|
leak detective blanks memory on free & alloc, allows further membug detection
|
2006-07-12 11:15:31 +00:00 |
|
Andreas Steffen
|
c361cc8c51
|
identification_t.matches() supports multiple wildcard counts
|
2006-07-11 06:12:45 +00:00 |
|
Martin Willi
|
abba7ecb9d
|
further work done for simultaneous rekeying/delete
still some cases which cause trouble
|
2006-07-10 14:24:04 +00:00 |
|
Martin Willi
|
c5d2d7c023
|
fixed compiler warnings in parser when using -O2
|
2006-07-07 12:48:27 +00:00 |
|
Martin Willi
|
c71d53ba4e
|
updated copyright information
|
2006-07-07 08:49:06 +00:00 |
|
Martin Willi
|
698d774918
|
reimplemented CHILD_SA rekeying & delete
no simultanous transaction with CHILD_SAs yet!
|
2006-07-07 07:04:07 +00:00 |
|
Martin Willi
|
d109b48968
|
added support for leftprotoport and rightprotoport
|
2006-07-05 13:13:07 +00:00 |
|
Martin Willi
|
5f0eb96fc4
|
improved CHILD_SA output for "ipsec statusall"
|
2006-07-05 13:11:55 +00:00 |
|
Martin Willi
|
3dd3c5f39e
|
redesigned IKE_SA using a transaction mechanism:
removed old state machine
reimplemented IKE_SA setup and delete
implemented dead peer detection
implemented keep-alives
a lot of fixes
no rekeying yet
|
2006-07-05 10:53:20 +00:00 |
|
Martin Willi
|
57d02978cf
|
made thread ids unsigned again, to avoid negative thread ids on some systems
|
2006-07-04 13:30:49 +00:00 |
|
Martin Willi
|
1135f79898
|
fixed memleak when initiating a connection already up
|
2006-07-04 13:29:16 +00:00 |
|
Martin Willi
|
f141214e64
|
applied latest NATT patch with some fixes and cleanups
|
2006-07-04 13:25:00 +00:00 |
|
Andreas Steffen
|
a642cbe3ae
|
log entries start with lowcercase character
|
2006-07-04 06:11:35 +00:00 |
|
Andreas Steffen
|
427088f004
|
fixed natd_hash memory leak
|
2006-07-03 08:34:34 +00:00 |
|
Andreas Steffen
|
971218c3ae
|
support of cert payloads
|
2006-07-03 06:27:45 +00:00 |
|
Andreas Steffen
|
1d390631d7
|
lowercase log entries
|
2006-07-03 06:26:06 +00:00 |
|
Andreas Steffen
|
6f74bfd6ac
|
added X.509 trust chain verification
|
2006-06-27 08:48:28 +00:00 |
|
Martin Willi
|
2f89902d07
|
applied new changes from NATT team
DPD only done when no IPsec and IKE traffic processed
minor changes here and there
|
2006-06-23 14:02:30 +00:00 |
|
Martin Willi
|
2891590b05
|
some message code cleanups
|
2006-06-23 14:00:15 +00:00 |
|
Martin Willi
|
4b24dd2d7d
|
cleaner error handling on UDP encapsultion sockopt failure
|
2006-06-22 13:05:15 +00:00 |
|
Martin Willi
|
6f51c9f184
|
added mysterious UDP encapsulation socket option to get encapsulation working
|
2006-06-22 12:57:49 +00:00 |
|
Martin Willi
|
1396815afb
|
first merge of NATT code
|
2006-06-22 06:36:28 +00:00 |
|
Martin Willi
|
6bf1352032
|
fixed testing build
|
2006-06-21 12:58:02 +00:00 |
|
Martin Willi
|
986d23bd6e
|
reworked function ignore mechanism to not-report whitelist
rather than overriding functions
|
2006-06-20 10:05:56 +00:00 |
|
Martin Willi
|
5c6b5bf599
|
fixed bug: usage of already freed mem
|
2006-06-20 09:53:25 +00:00 |
|
Martin Willi
|
aed58dcc93
|
readded local_credential_store
added sendcert policy to connection
some other cleanups
|
2006-06-20 08:43:57 +00:00 |
|
Andreas Steffen
|
21b433c641
|
implemented rereadcrls rereadcacerts
|
2006-06-20 06:05:01 +00:00 |
|
Andreas Steffen
|
db959e6ea3
|
removed local_credential_store
|
2006-06-20 05:57:52 +00:00 |
|
Martin Willi
|
b965b8456b
|
fixed SPI when acting as initiator of rekeying
|
2006-06-19 09:27:14 +00:00 |
|
Martin Willi
|
c65a4fff3f
|
fixed SPI when rekeying and deleting CHILD_SAs
|
2006-06-19 08:54:19 +00:00 |
|
Martin Willi
|
891dfaf983
|
change key derivation order to fullfill RFC
|
2006-06-19 08:11:42 +00:00 |
|
Martin Willi
|
f7eb60dd5e
|
|
2006-06-16 14:10:49 +00:00 |
|
Andreas Steffen
|
21e7a724d0
|
added crl support
|
2006-06-16 05:55:30 +00:00 |
|
Andreas Steffen
|
d92cca4a72
|
added listcrls
|
2006-06-16 05:55:02 +00:00 |
|
Martin Willi
|
c859ec9592
|
fixed compilation error
|
2006-06-15 13:41:06 +00:00 |
|
Martin Willi
|
147fe5095d
|
fixed aes code, we support now aes128, aes192, aes256 in IKE
|
2006-06-15 13:14:09 +00:00 |
|
Martin Willi
|
c095388f7f
|
added support for "ike" and "esp" keywords
fixed bugs in proposal code
algorithm selection for charon works now with ipsec.conf
a lot of other fixes
|
2006-06-15 11:09:11 +00:00 |
|
Martin Willi
|
3efbf98312
|
implemented clean spi allocation behavior when using multiple proposals
|
2006-06-15 11:06:22 +00:00 |
|
Andreas Steffen
|
b98e0927f4
|
added default CRL directory path
|
2006-06-14 12:44:12 +00:00 |
|
Andreas Steffen
|
03442041a9
|
added option parsing
|
2006-06-14 12:42:36 +00:00 |
|
Martin Willi
|
fa32cd3c47
|
debug and logging improvements
|
2006-06-13 10:01:04 +00:00 |
|
Andreas Steffen
|
5347233204
|
support for stroke listcerts|listcacerts|listall and left|rightca=
|
2006-06-12 08:43:46 +00:00 |
|
Martin Willi
|
50f98119dd
|
using same reqid if a child sa rekeys an existing one
|
2006-06-12 08:36:41 +00:00 |
|
Andreas Steffen
|
bc35460db7
|
add_certificate() now returns pointer to added cert
|
2006-06-12 07:57:14 +00:00 |
|
Andreas Steffen
|
c4a7413e72
|
cosmetics
|
2006-06-12 07:55:37 +00:00 |
|
Martin Willi
|
a2a3fb3e25
|
workaround for peers rekeying at the same time
loading lifetime policies from ipsec.conf
|
2006-06-12 07:33:20 +00:00 |
|
Martin Willi
|
695723d4e8
|
old child_sa gets deleted after rekeying
rekeying almost complete, but:
IKE_SA get in an invalid state when both initiate rekeying at the same time,
|
2006-06-09 15:12:43 +00:00 |
|
Martin Willi
|
b543bef50c
|
improved kernel interface logging
|
2006-06-09 08:41:41 +00:00 |
|
Martin Willi
|
0bb32cb5f3
|
fixed clone/destroy behavior when not using CAs
|
2006-06-09 07:40:40 +00:00 |
|
Martin Willi
|
5c131a016b
|
specifying keysize in bits, as it is required in IKEv2
added generic kernel SA algorithm handling, which brings us:
aes-128, aes-256, blowfish, des, 3des and null encryption for CHILD_SAs
|
2006-06-09 07:31:30 +00:00 |
|