Martin Willi
3683c0424f
Fixed compiler warning
2011-02-08 11:03:10 +01:00
Martin Willi
3af88e4657
tnccs_11 does not link to libtnc anymore
2011-02-08 11:03:10 +01:00
Martin Willi
10a6019ec6
Implement correct signature for pb_tnc_msg->process()
2011-02-08 10:57:41 +01:00
Martin Willi
11a6f29944
Fixed doxygen groups in libcharon tnc subtree
2011-02-08 10:57:41 +01:00
Martin Willi
6cc11bccd1
Fixed various doxygen errors in tnc plugins
2011-02-08 10:57:40 +01:00
Martin Willi
0700c153e7
Fixed function parameter description
2011-02-08 10:14:56 +01:00
Martin Willi
94030a670b
Report correct key size if a cipher is not supported
2011-02-07 16:39:33 +01:00
Tobias Brunner
84545f6e7c
Some typos fixed.
2011-02-07 11:39:41 +01:00
Tobias Brunner
56f57e5814
maemo: Listen for IKE_SA state changes insted of CHILD_SA state changes.
...
If the IKE_SA_INIT request fails, there is not yet a CHILD_SA that could
trigger state changes.
2011-02-04 18:02:48 +01:00
Martin Willi
b49d047bfc
Invoke the per-round authorize() hook before purging current auth info on IKE_SA
2011-02-03 17:08:39 +01:00
Martin Willi
4536e669a8
Filter out non-matching ike_cfg in backend manager, so backends don't have to
2011-02-03 10:12:16 +01:00
Martin Willi
2b7686b5d8
Migrated ike_auth to INIT/METHOD macros, fixes missing initial_contact initialization
2011-02-02 15:13:39 +01:00
Martin Willi
fe79cd4257
Accept non-encrypted INFORMATIONALs for ME connectivity checks
2011-02-01 09:47:36 +01:00
Martin Willi
1d34612f07
Do not use destroyed rng/hasher if IKE_SA has been flush()ed
2011-02-01 09:25:55 +01:00
Andreas Steffen
88e15afc8c
added comment to determine_tnccs_protocol() function
2011-01-31 05:31:22 +01:00
Andreas Steffen
f652995b21
implemented dynamic detection of TNCCS protocol
2011-01-31 00:59:17 +01:00
Martin Willi
5c89a00f05
Do not log potentially hundreds of cert requests for unknown CAs at level 1
2011-01-28 08:29:23 +01:00
Martin Willi
60b71def1a
Use wrapped threading functions in ha plugin
2011-01-20 15:52:29 +01:00
Thomas Egerer
f2e2a40550
Fix potential use after free
2011-01-19 09:59:01 +01:00
Martin Willi
ff5538e5c0
Use newer Linux capability native API, if available
2011-01-17 18:18:21 +01:00
Martin Willi
983a5e88d3
Revert "Send INITIAL_CONTACT even if we have a unique policy"
...
It makes sense to omit INITIAL_CONTACT if don't have a unique policy,
as a client might want to connect from different devices to the same
account.
This reverts commit 719c33b41a .
2011-01-13 10:50:46 +01:00
Martin Willi
9bac426bf3
Fixed memory cleanup if no DHCP transaction found for an OFFER
2011-01-13 10:36:16 +01:00
Martin Willi
2082417df3
Force port update as responder when initiator switches to 4500 in IKE_AUTH
2011-01-12 14:37:15 +01:00
Martin Willi
8ba805f4db
Avoid variable name overloading
2011-01-12 14:37:09 +01:00
Andreas Steffen
213281de04
terminate TNCCS 1.1 connection after sending recommendation
2011-01-11 01:17:40 +01:00
Andreas Steffen
4c8e9708ca
fixed XML syntax for TNCCS-Recommendation messages
2011-01-11 01:17:40 +01:00
Andreas Steffen
59d1b15aea
implemented check_and_build_recommendation()
2011-01-11 01:17:40 +01:00
Andreas Steffen
21d96f44f7
correct numbering of batches
2011-01-11 01:17:40 +01:00
Andreas Steffen
8d0d0f0fe9
initialize the reference count correctly
2011-01-11 01:17:40 +01:00
Andreas Steffen
f33966fe8f
handle zero size Base64 conversions
2011-01-11 01:17:40 +01:00
Andreas Steffen
8a284e0454
communicate DELETE state to IMCs and IMVs
2011-01-11 01:17:40 +01:00
Martin Willi
719c33b41a
Send INITIAL_CONTACT even if we have a unique policy
2011-01-10 11:54:10 +01:00
Andreas Steffen
5fee822a93
implemented parsing of TNCCS 1.1 messages
2011-01-09 10:00:54 +01:00
Andreas Steffen
33749b879c
send notifyConnectionChange() to IMCs
2011-01-09 10:00:13 +01:00
Andreas Steffen
8235528840
generate TNCCS-Error messages
2011-01-08 02:17:42 +01:00
Andreas Steffen
1c4b4f76ad
created process() method for TNCCS messages
2011-01-08 02:17:42 +01:00
Martin Willi
44e513a320
Added support for trustchain key strength checking to rightauth option
2011-01-07 15:51:35 +01:00
Martin Willi
6367de28ad
Added a left/rightcertpolicy keyword to specify certificatePolicy requirements
2011-01-07 15:51:35 +01:00
Martin Willi
1ed482d808
Fix nonce comparison in rekey collisions, lowest nonce loses
2011-01-07 15:51:35 +01:00
Andreas Steffen
3a04dfaaf6
corrected naming of tnccs_reason_strings_msg_t object
2011-01-07 07:18:42 +01:00
Andreas Steffen
87fd83a91e
do not forget to advance node
2011-01-07 07:17:52 +01:00
Andreas Steffen
3e348daae5
fixed cert_validator_t:validate interface
2011-01-07 05:41:01 +01:00
Andreas Steffen
d9e21bf180
implemented TNCCS 1.1 without libtnc
2011-01-07 05:29:59 +01:00
Martin Willi
6f5892f5c7
Destroy existing IKE_SAs with same identities when receiving INITIAL_CONTACT
2011-01-05 16:46:08 +01:00
Martin Willi
a4a1e24d37
Send INITIAL_CONTACT for the first IKE_SA if it has a unique policy
2011-01-05 16:46:08 +01:00
Martin Willi
240bd7dbb7
Migrated ike_sa_manager_t to INIT/METHOD macros, some cleanups
2011-01-05 16:46:08 +01:00
Martin Willi
2e90006f96
Show base CRL of delta CRLs in listcrls
2011-01-05 16:46:06 +01:00
Martin Willi
3a89b3c52f
Provide CRLs received in CERT payloads to trustchain verification
2011-01-05 16:46:06 +01:00
Martin Willi
b3d359e58f
Use a generic getter for all numerical X.509 constraints
2011-01-05 16:46:05 +01:00
Martin Willi
5dba5852fc
Slightly renamed X509_NO_PATH_LEN_CONSTRAINT to use it for PolicyConstraints, too
2011-01-05 16:46:02 +01:00