Commit Graph
196 Commits
Author SHA1 Message Date
Tobias Brunner 6a6e000134 Log selected peer config during Main Mode. 2012-03-20 17:31:20 +01:00
Martin Willi 9f10b95a3b Added a bunch of well known IKEv1 vendor IDs to database 2012-03-20 17:31:20 +01:00
Martin Willi 156cd8827f Use a generic IKEv1 vendor ID database to send and receive vendor IDs 2012-03-20 17:31:20 +01:00
Martin Willi 92aa6e0255 Include COOKIES in IKEv1 delete payloads 2012-03-20 17:31:19 +01:00
Tobias Brunner 5383b50d88 Fixed missing shared_key initialization in main_mode task. 2012-03-20 17:31:19 +01:00
Martin Willi c9fc577a8a Use version specific DELETE payload identifier in ike_delete task 2012-03-20 17:31:19 +01:00
Martin Willi 5dec456b69 Fix IKEv1 DELETE subtask creation and processing 2012-03-20 17:31:19 +01:00
Martin Willi 10e18713f1 Handle DELETE as responder as INFORMATIONAL subtask 2012-03-20 17:31:19 +01:00
Martin Willi 97933967a0 Moved responder informational handling to task 2012-03-20 17:31:18 +01:00
Martin Willi e7ae90c194 Use informational task in quick mode to send notifies 2012-03-20 17:31:18 +01:00
Martin Willi accf46129a Use informational taks to send notify errors 2012-03-20 17:31:18 +01:00
Martin Willi f492907667 Added a task stub to create and process IKEv1 informational exchanges 2012-03-20 17:31:18 +01:00
Martin Willi 590ca1d482 Allow IKEv1 tasks to return ALREADY_DONE to flush all active or passive tasks 2012-03-20 17:31:18 +01:00
Tobias Brunner 4dbd81c669 Destroy IKE_SA after failed XAuth authentication. 2012-03-20 17:31:17 +01:00
Clavister OpenSource 5c6abd2865 Added possibility to send notifications from the Quick Mode task 2012-03-20 17:31:17 +01:00
Martin Willi cc6b03bb5a If no IKEv1 shared key found for hosts, try to find one based on config identities 2012-03-20 17:31:17 +01:00
Martin Willi 033dfba01f Log peer cfg enumeration externally for flexibility 2012-03-20 17:31:17 +01:00
Martin Willi d7376e2ab4 Accept NULL identities passed to peer config enumeration 2012-03-20 17:31:17 +01:00
Martin Willi 0e2cc3fed9 Fixed authentication method selection for main mode PSK authentication 2012-03-20 17:31:17 +01:00
Martin Willi ea9e047bc5 Use virtual IP to substitute dynamic traffic selectors in quick mode 2012-03-20 17:31:17 +01:00
Martin Willi 156b8662a6 Queue Mode Config tasks when required 2012-03-20 17:31:16 +01:00
Martin Willi b155084c42 Added IKEv1 Mode Config task based on IKEv2 ike_config 2012-03-20 17:31:16 +01:00
Martin Willi 67a753b95c Use a common function to set IKE_SA to established 2012-03-20 17:31:16 +01:00
Martin Willi 9f43868a01 Implemented responder part of XAUTH task 2012-03-20 17:31:16 +01:00
Martin Willi d192cc9dc8 Implemented initiator part of xauth task 2012-03-20 17:31:16 +01:00
Martin Willi 89afbe58bb Remove unused task swap_initiator method 2012-03-20 17:31:15 +01:00
Martin Willi 96c9159d96 Use a second authentication config to configure XAUTH authentication 2012-03-20 17:31:15 +01:00
Martin Willi 69adeb5bf2 Replace xauth_request task with a new stub where we reimplement it 2012-03-20 17:31:15 +01:00
Clavister OpenSource c29fba51aa Some notification errors added to main_mode process_r 2012-03-20 17:31:15 +01:00
Clavister OpenSource a064eaa8a6 Handling of initial contact 2012-03-20 17:31:14 +01:00
Martin Willi 1755ac0617 Cleaned up quick mode notify processing 2012-03-20 17:31:14 +01:00
Martin Willi 5adf855e3d Add support for KE payloads in IKEv1 quick mode (PFS) 2012-03-20 17:31:14 +01:00
Martin Willi fb8bc6a764 Use authenticators in IKEv1 main mode 2012-03-20 17:31:14 +01:00
Clavister OpenSource 5d1eeec297 Handle incoming delete messages 2012-03-20 17:31:13 +01:00
Martin Willi c64a4b4f8e Implemented post-authentication certificate handling for IKEv1 2012-03-20 17:31:13 +01:00
Martin Willi 9ad5b8fa95 Cleanup CERT payload constructors 2012-03-20 17:31:13 +01:00
Martin Willi 0bcdb8e571 Implemented pre-authentication certificate handling for IKEv1 2012-03-20 17:31:13 +01:00
Martin Willi 8c33850615 Added task types for IKEv1 certificate handling 2012-03-20 17:31:13 +01:00
Martin Willi 6ccabe2561 Reverted ike_cert tasks to IKEv2 only, we use dedicated IKEv1 tasks 2012-03-20 17:31:13 +01:00
Tobias Brunner 9f80110bc6 Install SAs with UDP encapsulation during Quick Mode. 2012-03-20 17:31:13 +01:00
Martin Willi aaa8f88906 Fix support for plain RSA authentication in IKEv1, both as initiator and responder 2012-03-20 17:31:13 +01:00
Martin Willi a974700fc0 Fix referencing of multiple CERTREQ payload with IKEv1, other cleanups 2012-03-20 17:31:12 +01:00
Clavister OpenSource d82a68642d XAUTH additions for certificates. 2012-03-20 17:31:12 +01:00
Clavister OpenSource a874a1f50b signature payload handling. 2012-03-20 17:31:12 +01:00
Clavister OpenSource 7d9269bfce certificate handling for XAuth responder. 2012-03-20 17:31:11 +01:00
Clavister OpenSource 07abb470c6 IKEv1: Added basic support for INFORMATIONAL exchange types, and for NOTIFY_V1 messages in the 3rd message in quick_mode. 2012-03-20 17:31:11 +01:00
Clavister OpenSource 4394d96844 IKEv1 XAuth: Added a "NULL" XAuth plugin which sends a hardcoded user/pass, and blindly accepts whatever user/pass is sent it. Changed the xauth_request task to use this new plugin. Add --enable-xauth-null to your configure line to build with the new plugin. 2012-03-20 17:31:11 +01:00
Tobias Brunner 3bf0be6b08 Add NAT-OA payloads during Quick Mode if transport mode is used.
We don't parse them currently, as the Linux kernel does not need them to fix
the IP header checksum.
2012-03-20 17:31:11 +01:00
Tobias Brunner 29b0cb328a Negotiate UDP encapsulation during Quick Mode if NAT is detected. 2012-03-20 17:31:10 +01:00
Tobias Brunner 1cc4ec46cf Task added for IKEv1 NAT detection.
There is already support for both Main and Aggressive Mode.
2012-03-20 17:31:10 +01:00