Andreas Steffen
57e80492eb
libtpmtss: Implemented TSS2 quote() method
2016-06-26 18:19:05 +02:00
Andreas Steffen
bc67802ac8
libtpmtss: Implemented TSS2 read_pcr() method
2016-06-22 15:33:44 +02:00
Andreas Steffen
30d4989aec
libimcv: migrate pts to tpm_tss
2016-06-22 15:33:44 +02:00
Andreas Steffen
8301dc859c
libtpmtss: Get TPM 2.0 capabilities
2016-06-22 15:33:44 +02:00
Andreas Steffen
fedc6769dc
libtpmtss: Retrieve TPM 1.2 version info
2016-06-22 15:33:43 +02:00
Andreas Steffen
c08753bdf4
Created libtpmtss library handling access to v1.2 and v2.0 TPMs
2016-06-22 15:33:43 +02:00
Andreas Steffen
6337770845
aikpub2: --handle option retrieves public key from TPM 2.0 NVRAM
2016-06-22 15:33:43 +02:00
Andreas Steffen
87d356dc47
aikpub2: Convert TSS 2.0 AIK public key blob into PKCS#1 format
2016-06-22 15:33:43 +02:00
Andreas Steffen
310b583925
Merge branch 'test-timing'
2016-05-15 19:03:49 +02:00
Andreas Steffen
78adb5a7b1
testing: Changed gcrypt-ikev1 scenarios to swanctl
2016-05-15 19:02:57 +02:00
Andreas Steffen
141ac4df8f
testing: wait until connections are loaded
2016-05-15 19:02:57 +02:00
Andreas Steffen
1aeaccad11
Version bump to 5.4.1dr4
2016-05-13 12:49:52 +02:00
Andreas Steffen
26aa9c638d
Version bump to 5.4.1dr3
2016-05-08 09:06:16 +02:00
Andreas Steffen
6a6876390d
swanctl: indicate initiator and responder in --list-sas
2016-05-07 17:54:56 +02:00
Andreas Steffen
ab1cebda3a
Version bump to 5.4.1dr2
2016-05-06 22:29:32 +02:00
Andreas Steffen
7cf3a5ae15
Merge branch 'fwd-policy-prio'
2016-05-06 22:28:44 +02:00
Andreas Steffen
b9522f9d64
swanctl: Do not display rekey times for shunts
2016-05-05 14:53:22 +02:00
Andreas Steffen
d95f2ab0cf
Merge branch 'list-conns-plus'
2016-05-04 18:16:32 +02:00
Andreas Steffen
ff4e01dab5
testing: Use reauthentication and set CHILD_SA rekey time, bytes and packets limits
2016-05-04 18:13:52 +02:00
Andreas Steffen
b1df631212
vici list-conns sends reauthentication and rekeying time information
2016-05-04 18:13:52 +02:00
Andreas Steffen
e88f21cf65
swanctl: --list-conns shows eap_id, xauth_id and aaa_id
2016-05-04 18:13:52 +02:00
Andreas Steffen
87381a55a9
testing: uses xauth_id in swanctl/xauth-rsa scenario
2016-05-04 18:13:52 +02:00
Andreas Steffen
278497f2ba
testing: Use absolute path of imv_policy_manager
2016-04-26 17:15:37 +02:00
Andreas Steffen
ef84ad0e11
Updated products in IMV database
2016-04-26 17:15:37 +02:00
Andreas Steffen
afcd466192
swanctl: list EAP type in --list-conns
2016-04-26 17:15:37 +02:00
Andreas Steffen
b85422b90c
testing: -D and -u options in sfdisk are not supported any more
2016-04-26 17:15:37 +02:00
Andreas Steffen
c87f428836
leak-detective: added _IO_file_doallocate to whitelist
2016-04-24 23:34:44 +02:00
Andreas Steffen
4e3234afb4
swanctl: log errors to stderr
2016-04-24 23:33:23 +02:00
Andreas Steffen
029d3a0ce6
testing: updated testing.conf
2016-04-24 13:36:31 +02:00
Andreas Steffen
0ff486f507
testing: Added swanctl/rw-multi-ciphers-ikev1 scenario
2016-04-12 18:50:58 +02:00
Andreas Steffen
c407f163e6
Version bump to 5.4.1dr1
2016-04-11 10:24:12 +02:00
Andreas Steffen
b1c89bb0f9
Merge branch 'kernel-policies'
2016-04-11 10:19:21 +02:00
Andreas Steffen
d3af3b799f
Extended IPsec kernel policy scheme
...
The kernel policy now considers src and dst port masks as well as
restictions to a given network interface. The base priority is
100'000 for passthrough shunts, 200'000 for IPsec policies,
300'000 for IPsec policy traps and 400'000 for fallback drop shunts.
The values 1..30'000 can be used for manually set priorities.
2016-04-09 16:51:02 +02:00
Andreas Steffen
d3edc8aa0f
testing: Added swanctl/manual_prio scenario
2016-04-09 16:51:02 +02:00
Andreas Steffen
e9704e90cf
Include manual policy priorities and restriction to interfaces in vici list-conn command
2016-04-09 16:51:02 +02:00
Andreas Steffen
c26e4330e7
Implemented IPsec policies restricted to given network interface
2016-04-09 16:51:02 +02:00
Andreas Steffen
7f57c4f9fb
Support manually-set IPsec policy priorities
2016-04-09 16:51:01 +02:00
Andreas Steffen
aaa4e478b1
Use u_int32_t legacy type in blowfish header file
2016-03-24 20:58:32 +01:00
Andreas Steffen
b12c53ce77
Use standard unsigned integer types
2016-03-24 18:52:48 +01:00
Andreas Steffen
7a117eeaec
Version bump to 5.4.0
2016-03-22 11:20:36 +01:00
Andreas Steffen
bebccf9876
Updated NEWS
2016-03-11 11:31:02 +01:00
Andreas Steffen
35babdf43f
Initialize ts variable
2016-03-11 08:29:23 +01:00
Andreas Steffen
6b8acc49ed
Merge branch 'subnet-identities'
...
Implemented IKEv1 IPv4/IPv6 address subnet and range identities to
be used as owners for shared secrets.
swanctl supports configuration of traffic selectors with IPv4/IPv6
address ranges.
2016-03-10 15:26:03 +01:00
Andreas Steffen
3f1de98678
Support of IP address ranges in traffic selectors
2016-03-10 13:59:37 +01:00
Andreas Steffen
90ef7e8af6
Updated swanctl/rw-psk-ikev1 scenario
2016-03-10 13:59:37 +01:00
Andreas Steffen
1d86d1d65a
Implemented IPv4/IPv6 subnet and range identities
...
The IKEv1 IPV4_ADDR_SUBNET, IPV6_ADDR_SUBNET, IPV4_ADDR_RANGE and
IPV6_ADDR_RANGE identities have been fully implemented and can be
used as owners of shared secrets (PSKs).
2016-03-10 13:59:37 +01:00
Andreas Steffen
c2523355a4
testing: Added swanctl/mult-auth-rsa-eap-sim-id scenario
2016-03-06 19:09:03 +01:00
Andreas Steffen
70ff382e41
testing: Added swanctl/xauth-rsa scenario
2016-03-06 12:28:55 +01:00
Andreas Steffen
99b794a4cf
Display IKE ports with swanctl --list-sas
2016-03-05 18:19:00 +01:00
Andreas Steffen
724f590711
Version bump to 5.4.0rc1
2016-03-05 18:18:12 +01:00
Andreas Steffen
07b0eac4b1
testing: attr-sql is a charon plugin
2016-03-05 15:53:22 +01:00
Andreas Steffen
26d2011b14
testing: Added swanctl/rw-psk-ikev1 scenario
2016-03-05 13:50:41 +01:00
Andreas Steffen
1989c7a381
testing: Include IKE port information in evaltests
2016-03-05 13:44:06 +01:00
Andreas Steffen
fe1f915b07
Version bump to 5.4.0dr8
2016-03-04 20:55:55 +01:00
Andreas Steffen
ad82c95f0a
Set PLUTO port variables to 0 in the case of no port restrictions
2016-03-04 12:52:35 +01:00
Andreas Steffen
5c25780ce0
Added port range support to NEWS
2016-03-04 10:03:12 +01:00
Andreas Steffen
ba919f393d
testing: Added swanctl/protoport-range scenario
2016-03-04 09:52:34 +01:00
Andreas Steffen
0d7202c7c5
Port range support in updown script
2016-03-04 09:52:34 +01:00
Andreas Steffen
6abae81f86
Implemented port ranges in kernel_netlink interface
2016-03-04 09:52:34 +01:00
Andreas Steffen
f00f679af9
Request missing SWID tags in a directed PA-TNC message
2016-03-04 01:04:44 +01:00
Andreas Steffen
efefa0c6a1
testing: Added swanctl/shunt-policies-nat-rw
2016-02-28 22:25:50 +01:00
Andreas Steffen
13891e2a4f
testing: Some minor fixes in test scenarios
2016-02-28 22:25:21 +01:00
Andreas Steffen
794cfbad71
Version bump to 5.4.0dr7
2016-02-28 15:56:06 +01:00
Andreas Steffen
68c9f0bb80
testing: Added swanctl/protoport-dual scenario
2016-02-28 14:33:48 +01:00
Andreas Steffen
ddf1fc7692
testing: converted af-alg scenarios to swanctl
2016-02-26 13:31:36 +01:00
Andreas Steffen
963b080810
testing: Increased ping interval in ikev2/trap-any scenario
2016-02-16 18:21:19 +01:00
Andreas Steffen
fc0f8466db
Version bump to 5.4.0dr6
2016-02-16 18:17:44 +01:00
Andreas Steffen
726a45b2f2
Corrected the description of the swanctl/dhcp-dynamic scenario
2016-02-16 18:17:17 +01:00
Andreas Steffen
4d83c5b4a6
Fix of the mutual TNC measurement use case
...
If the IKEv2 initiator acting as a TNC server receives invalid TNC measurements
from the IKEv2 responder acting as a TNC clienti, the exchange of PB-TNC batches
is continued until the IKEv2 responder acting as a TNC server has also finished
its TNC measurements.
In the past if these measurements in the other direction were correct
the IKEv2 responder acting as EAP server declared the IKEv2 EAP authentication
successful and the IPsec connection was established even though the TNC
measurement verification on the EAP peer side failed.
The fix adds an "allow" group membership on each endpoint if the corresponding
TNC measurements of the peer are successful. By requiring a "allow" group
membership in the IKEv2 connection definition the IPsec connection succeeds
only if the TNC measurements on both sides are valid.
2016-02-16 18:00:27 +01:00
Andreas Steffen
ac134b470a
testing: Added swanctl/dhcp-dynamic scenario
2016-02-03 12:10:59 +01:00
Andreas Steffen
927f733159
Version bump to 5.4.0dr5
2016-01-28 09:41:05 +01:00
Andreas Steffen
7c81942357
Support pseudonym RDN
2016-01-27 11:38:18 +01:00
Andreas Steffen
67a38ac6f1
testing: Added swanctl/config-payload scenario
2016-01-14 06:31:28 +01:00
Andreas Steffen
e7b5171e43
testing: Use include statement in swanctl/rw-pubkey-keyid scenario
2016-01-14 01:44:17 +01:00
Andreas Steffen
9492e12e61
Version bump to 5.4.0dr4
2016-01-10 01:39:08 +01:00
Andreas Steffen
ffd29ab30a
vici: Support multiple named raw ublic keys
2016-01-10 00:12:57 +01:00
Andreas Steffen
2aa2b17d41
testing: swanctl/rw-pubkey-anon uses anonymous public keys in remote access scenario
2016-01-09 07:23:30 +01:00
Andreas Steffen
abe6d07463
swanctl: Load pubkeys with load-creds
2016-01-09 07:23:30 +01:00
Andreas Steffen
b83cef2412
testing: added swanctl scenarios net2net-pubkey, rw-pubkey-keyid and rw-dnssec
2016-01-09 07:23:30 +01:00
Andreas Steffen
4c38c79452
vici: list-cert sends subject, not-before and not-after attributes for pubkeys
2016-01-09 07:23:30 +01:00
Andreas Steffen
87371460f6
vici: Support of raw public keys
2016-01-09 07:23:29 +01:00
Andreas Steffen
bffbf2f5fd
testing: Fixed description of swanctl/frags-iv4 scenario
2016-01-09 00:17:31 +01:00
Andreas Steffen
e333d4c0f1
swanctl.conf: IKEv2 fragmentation supported
2016-01-09 00:06:12 +01:00
Andreas Steffen
1990eeebfe
Version bump to 5.4.0dr3
2016-01-03 06:28:49 +01:00
Andreas Steffen
9121f6cce1
vici: Enable transport encoding of CERT_TRUSTED_PUBKEY objects
2016-01-03 06:28:49 +01:00
Andreas Steffen
9db530493f
testing: Change sql scenarios to swanctl
2016-01-03 06:28:48 +01:00
Andreas Steffen
92b051bd4a
vici: allow legacy shortcuts in cert queries
2015-12-19 10:30:17 +01:00
Andreas Steffen
6943db5679
Version bump to 5.4.0dr2
2015-12-18 15:25:50 +01:00
Andreas Steffen
490ba67682
testing: Fixed description in swanctl/rw-ntru-bliss scenario
2015-12-18 15:24:59 +01:00
Andreas Steffen
9463350943
testing: swanctl is enabled by default
2015-12-18 15:22:29 +01:00
Andreas Steffen
f553aea2c2
Use 128 bit security in README.pod examples
2015-12-18 15:08:33 +01:00
Andreas Steffen
2d9c68b8a8
configure: Enable vici plugin and swanctl by default
2015-12-17 17:49:48 +01:00
Andreas Steffen
76cbf1df34
testing: Added swanctl/rw-ntru-bliss scenario
2015-12-17 17:49:48 +01:00
Andreas Steffen
cc874350b8
Apply pubkey and signature constraints in vici plugin
2015-12-17 17:49:48 +01:00
Andreas Steffen
a78e1c3b11
128 bit default security strength for IKE and ESP algorithms
...
The default ESP cipher suite is now
AES_CBC-128/HMAC_SHA2_256_128
and requires SHA-2 HMAC support in the Linux kernel (correctly implemented
since 2.6.33).
The default IKE cipher suite is now
AES_CBC-128/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/ECP_256
if the openssl plugin is loaded or
AES_CBC-128/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_3072
if ECC is not available.
The use of the SHA-1 hash algorithm and the MODP_2048 DH group has been
deprecated and ENCR_CHACHA20_POLY1305 has been added to the default
IKE AEAD algorithms.
2015-12-17 17:49:48 +01:00
Andreas Steffen
5e2b740a00
128 bit default security strength requires 3072 bit prime DH group
2015-12-14 10:39:40 +01:00
Andreas Steffen
47e5640378
swanctl --stats lists loaded plugins
2015-12-13 17:07:28 +01:00
Andreas Steffen
36b6d400d2
testing: swanctl/rw-cert scenario tests password-protected RSA key
2015-12-12 17:12:44 +01:00
Andreas Steffen
4f7f2538c4
Upgraded IKE and ESP proposals in swanctl scenarios to consistent 128 bit security
2015-12-12 15:54:48 +01:00
Andreas Steffen
02d431022c
Refactored certificate management for the vici and stroke interfaces
2015-12-12 00:19:24 +01:00