Commit Graph
100 Commits
Author SHA1 Message Date
Martin Willi 74a5dfe537 Added IKE options to configure source/destination ports 2011-01-05 16:45:48 +01:00
Martin Willi 448db6d9c0 Added IKE config option to fake NAT situations 2011-01-05 16:45:48 +01:00
Martin Willi f2116c6de7 Show SPI in proposal logging hook 2011-01-05 16:45:48 +01:00
Martin Willi 42133e33bd Implemented a hook to inject custom proposals 2011-01-05 16:45:48 +01:00
Martin Willi 47e0b50725 Fixed error reporting 2011-01-05 16:45:48 +01:00
Martin Willi 5d82b2d321 Remove unused variable 2011-01-05 16:45:48 +01:00
Martin Willi 7ab6429b3c Added hook to log ID payload type and data 2011-01-05 16:45:47 +01:00
Martin Willi c6f2bac1b8 Added hook to log received KE group 2011-01-05 16:45:47 +01:00
Martin Willi 6dd6b0ef95 Added a hook to modify proposal numbers 2011-01-05 16:45:47 +01:00
Martin Willi 5dca645d46 Added a hook to print received proposals, including number 2011-01-05 16:45:47 +01:00
Martin Willi b080f393ce Added a hook to alter the payload length field of arbitrary payloads 2011-01-05 16:45:47 +01:00
Martin Willi 2ecbd6186e Do not update payload length during generation, allows hooks override payload length 2011-01-05 16:45:47 +01:00
Martin Willi d58127af84 Do not recalculate payload header length after generation, payloads do length calculation 2011-01-05 16:45:47 +01:00
Martin Willi 90994a8a5c Support loading of certificate revocation lists 2011-01-05 16:45:46 +01:00
Martin Willi 00d8b9a638 Implemented a hook that recreates a valid incoming IKE_AUTH response, even if AUTH_FAILED 2011-01-05 16:45:46 +01:00
Martin Willi 2a19095e4c Apply IKE major/minor version set on message to IKE header 2011-01-05 16:45:46 +01:00
Martin Willi 7e7c7c1d84 Added setters for IKE major/minor version to ike_header 2011-01-05 16:45:46 +01:00
Martin Willi 1c22c529a7 Migrated ike_header_t to INIT/METHOD macros 2011-01-05 16:45:46 +01:00
Martin Willi a0a760795e Added hook to set arbitrary IKE major/minor versions in message headers 2011-01-05 16:45:45 +01:00
Martin Willi 2712b113c7 Prefer test specific over suite specific configuration 2011-01-05 16:45:45 +01:00
Martin Willi e330360f77 Added a force_hookie hook that requests a COOKIE independent of our COOKIE mechanism 2011-01-05 16:45:45 +01:00
Martin Willi 1f42c80942 The add_payload hook supports replacing existing payloads of the same type 2011-01-05 16:45:45 +01:00
Martin Willi 60b14332b3 Fix insertion of non hex encoded payload data 2011-01-05 16:45:44 +01:00
Martin Willi b0f6b31db8 Fixed length calculation of unknown payload 2011-01-05 16:45:44 +01:00
Martin Willi 50b28ad8a4 Added a hook to set the critical bit on arbitrary payloads 2011-01-05 16:45:44 +01:00
Martin Willi c67de660d2 Move critical bit checking to ike_sa, notify payload includes unsupported payload type 2011-01-05 16:45:44 +01:00
Martin Willi e7099aa24e Handle all error notifies in CREATE_CHILD_SA exchanges 2011-01-05 16:45:44 +01:00
Martin Willi 24384f352f Support encoding of UKNOWN_DATA 2011-01-05 16:45:44 +01:00
Martin Willi 958c1d75d7 Moved our substructure identifiers above 255, ignore private payloads properly 2011-01-05 16:45:44 +01:00
Martin Willi fea3aa5d12 Check for exceeded payload count even if we have a found one flagged as sufficient 2011-01-05 16:45:43 +01:00
Martin Willi 9b2ed9501f Added a hook to inject custom payloads with critical bit 2011-01-05 16:45:43 +01:00
Martin Willi ca93b54e65 Added a constructor for custom uknown payloads 2011-01-05 16:45:43 +01:00
Martin Willi b6c796464d Use the payloads actual type in unknown_payload_t 2011-01-05 16:45:43 +01:00
Martin Willi 9431023ce6 Migrated unknown payload to INIT/METHOD macros 2011-01-05 16:45:43 +01:00
Martin Willi 7814c74970 Added a short README about the conftest utility 2011-01-05 16:45:43 +01:00
Martin Willi a784c9e030 Specify the type of the certificate to load, currently X509 only 2011-01-05 16:45:43 +01:00
Martin Willi 4a2f7f05df Be a little more verbose about cert payload injection 2011-01-05 16:45:43 +01:00
Martin Willi a60b892841 Support hook suffixes to use the same hook multiple times 2011-01-05 16:45:42 +01:00
Martin Willi e5e71e46d9 Support arbitrary suffixes for actions, same action multiple times 2011-01-05 16:45:42 +01:00
Martin Willi cf594ca411 Added a hook to ignore specific messages 2011-01-05 16:45:42 +01:00
Martin Willi c146c3c4e1 Ingore messages with exchange type altered to UNDEFINED in message() hook 2011-01-05 16:45:42 +01:00
Martin Willi 81b213499d Added a hook to send unencrypted notifies in established IKE_SAs 2011-01-05 16:45:42 +01:00
Martin Willi a30dba9282 Fail silently without INVALID_SYNTAX if message not verified 2011-01-05 16:45:42 +01:00
Martin Willi 1009e5c3bc Include suiteb test suite config in distribution 2011-01-05 16:45:42 +01:00
Martin Willi b70abdac2b Fixed loading of credentials using a relative path 2011-01-05 16:45:42 +01:00
Martin Willi 52e6df0cdc Implemented a add_notify hook to inject arbitrary Notify payloads 2011-01-05 16:45:41 +01:00
Martin Willi 89fda1abb5 Moved message()-hook invocation to generate_message(), catch pre-generated IKE_SA_INITs, too 2011-01-05 16:45:41 +01:00
Martin Willi f2986524d9 Implemented a hook to unsort payloads in messages 2011-01-05 16:45:41 +01:00
Martin Willi e6c6a4d304 Support removal of payloads from messages 2011-01-05 16:45:41 +01:00
Martin Willi 363ec8986c Added a message_t option to disable automatic payload sorting 2011-01-05 16:45:41 +01:00
Martin Willi 6260e6fe12 Added a fist hook to fill up IKE_AUTH messages with dummy certificates (1.1.1/1.2.1) 2011-01-05 16:45:41 +01:00
Martin Willi dacf658036 Implemented cert payload constructor for custom encoding types 2011-01-05 16:45:41 +01:00
Martin Willi 3b3e5c0de5 Fix segfault if config not found 2011-01-05 16:45:41 +01:00
Martin Willi 73a3013f7c Read actions from test config, delayed execution 2011-01-05 16:45:41 +01:00
Martin Willi 6c2d466b90 Support manually triggerd DPD check, even if DPD disabled in config 2011-01-05 16:45:40 +01:00
Martin Willi 3f759bb75b Load private keys from suite and test configs 2011-01-05 16:45:40 +01:00
Martin Willi a13c1d649f Load certificates from both, suite and test config 2011-01-05 16:45:40 +01:00
Martin Willi d1041fa463 Load test and suite specific connection configurations 2011-01-05 16:45:40 +01:00
Martin Willi f452a5a1f8 Load hooks based on listener dynamically 2011-01-05 16:45:40 +01:00
Martin Willi b318e0ab57 Load certificates from global suite configuration file 2011-01-05 16:45:40 +01:00
Martin Willi e78ec86d27 Added a Suite B conftest utility skeleton using libcharon 2011-01-05 16:45:40 +01:00
Martin Willi 65697c2734 Added a CIDR notation based host constructor 2011-01-05 16:45:40 +01:00
Martin Willi 84f89634ef Moved logger initialization from libcharon to charon 2011-01-05 16:45:40 +01:00
Martin Willi 33bfdf6f37 Fixed public key construction from PKCS#11 private key 2010-12-23 10:29:01 +01:00
Martin Willi 78a547c999 Added NEWS for af-alg plugin 2010-12-20 10:22:14 +01:00
Martin Willi 23a737eb29 Probe for supported AF_ALG algorithms, register dynamically 2010-12-20 10:09:20 +01:00
Martin Willi 4ee5d97d57 Register algorithms with dependencies only if dependency available 2010-12-20 10:00:39 +01:00
Martin Willi d214ebdf82 Register some less common AF_ALG ciphers (cast5, serpent, twofish, blowfish) 2010-12-20 09:52:02 +01:00
Martin Willi 533151692f Implemented PRFs using AF_ALG 2010-12-20 09:52:02 +01:00
Martin Willi 06eb35efb0 Use the AF_ALG wrapper in hasher, crypter and signer 2010-12-20 09:52:02 +01:00
Martin Willi 1b5de7ce3b Use a generic AF_ALG wrapper for common operations 2010-12-20 09:52:02 +01:00
Martin Willi a5c973b955 Implemented crypter on top of AF_ALG 2010-12-20 09:52:02 +01:00
Martin Willi e75e1c9473 Implemented signer interface using AF_ALG 2010-12-20 09:52:02 +01:00
Martin Willi 6f08911321 Implemented hasher based on AF_ALG 2010-12-20 09:52:02 +01:00
Martin Willi fd67d39e93 Added Linux AF_ALG header 2010-12-20 09:52:02 +01:00
Martin Willi 71c87e3483 Added plugin stub for AF_ALG 2010-12-20 09:52:02 +01:00
Martin Willi e44817df6f Added NEWS about TFC padding 2010-12-20 09:51:33 +01:00
Martin Willi 6c302616f1 Added a tfc ipsec.conf keyword to control Traffic Flow Confidentiality 2010-12-20 09:45:39 +01:00
Martin Willi 55df72e6d5 Do not use TFC padding if peer does not support ESPv3 2010-12-20 09:45:39 +01:00
Martin Willi 37788b1d06 Added a TFC padding option to child_cfg 2010-12-20 09:45:39 +01:00
Martin Willi d86bb6ef4d Implemented Traffic Flow Confidentiality padding in kernel_interface 2010-12-20 09:45:39 +01:00
Martin Willi cf5866b9c0 Renamed purgex509/crl to purgecerts/crls to be consistent with list commands 2010-12-10 11:21:55 +01:00
Martin Willi 6aa144ddb7 Added options to flush CRLs/X509 certs from the cert cache 2010-12-10 09:45:22 +01:00
Martin Willi 86993d6b90 Never register IKE_SA during checkout_new, as rekeying keeps it checked out 2010-12-07 16:30:38 +01:00
Martin Willi b78ca4b04c Do not query for CKA_ALWAYS_AUTHENTICATE if PKCS#11 Cryptoki version < 2.20 2010-11-18 08:56:12 +01:00
Martin Willi cfa18d14f1 Use static args for C_Initialize(), OpenSC does not get a copy of the pointers 2010-11-18 08:44:22 +01:00
Martin Willi 93a9926805 Added getter for arbitrary environment variables 2010-11-17 16:46:23 +01:00
Martin Willi d93060759e Remove obsolete pool_size argument in processor_create() 2010-11-16 09:39:06 +01:00
Martin Willi 9cda39923e Added a PKCS#11 module option to enforce OS Locking functions 2010-11-12 16:14:03 +01:00
Martin Willi 213884f947 Print full source route on DBG2 that gets installed 2010-11-11 09:59:02 +01:00
Martin Willi 57398f621a Do not use CKA_TRUSTED attribute for Cryptoki version < 2.20, handling all certs as trusted 2010-11-10 18:36:15 +01:00
Martin Willi 59df2d2a6f Add flags for PKCS#11 libraries with reduced feature set 2010-11-10 18:36:15 +01:00
Martin Willi 851d60484e Added a stroke rekey command to trigger IKE/CHILD_SA rekeying manually 2010-11-03 15:12:05 +01:00
Martin Willi bb16217581 Store proposal number in proposal_t to reuse it in the selected proposal
According to RFC 5996 3.3.1, we MUST reuse the proposal number of
the selected proposal in the SA payload reply.
2010-10-28 15:08:14 +02:00
Martin Willi d454c586ab Migrated proposal_t to INIT/METHOD macros 2010-10-28 13:06:20 +00:00
Martin Willi 806b69a467 Migrated proposal_substructure to INIT/METHOD macros, removed unused methods 2010-10-28 13:06:20 +00:00
Martin Willi 80f93f20a4 Migrated sa_payload to INIT/METHOD macros, removed unused methods 2010-10-28 13:06:19 +00:00
Martin Willi c8f5aaf0a4 Renamed mem_cred_t clear function internally to clear_, fixes potential name conflict 2010-10-28 13:06:19 +00:00
Martin Willi 185c2669d5 Set ownership of all HA ClusterIP control files 2010-10-20 14:55:26 +02:00
Martin Willi 384b69d964 Set ownership/permissions of HA control socket 2010-10-20 14:54:51 +02:00