Martin Willi
|
3d54ae94d9
|
Handle initiation of not supported IKE versions properly
|
2012-03-20 17:31:30 +01:00 |
|
Martin Willi
|
87791f7538
|
Added description for the xauth-eap plugin
|
2012-03-20 17:31:28 +01:00 |
|
Martin Willi
|
85fc1eb640
|
Added an XAuth plugin that forwards authentication to EAP methods
|
2012-03-20 17:31:28 +01:00 |
|
Martin Willi
|
747f837cce
|
Added a flag to register local credential sets exclusively, disabling all others
|
2012-03-20 17:31:28 +01:00 |
|
Martin Willi
|
326a94232d
|
Moved eap/xauth classes out of protocol specific subdirectories
|
2012-03-20 17:31:27 +01:00 |
|
Martin Willi
|
15a682f4c2
|
Separated libcharon/sa directory with ikev1 and ikev2 subfolders
|
2012-03-20 17:31:26 +01:00 |
|
Martin Willi
|
ac009df132
|
Pass IKE version to peer config enumerator, filter configs
|
2012-03-20 17:31:25 +01:00 |
|
Martin Willi
|
d94c923648
|
Support an "any" IKE version for both IKEv1 or IKEv2
|
2012-03-20 17:31:25 +01:00 |
|
Tobias Brunner
|
f29a4f1c64
|
Added support for iKEIntermediate X.509 extended key usage flag.
Mac OS X requires server certificates to have this flag set.
|
2012-03-20 17:31:24 +01:00 |
|
Martin Willi
|
7a7efbf9d8
|
Added an identity getter to XAuth methods to query the actually used identity
|
2012-03-20 17:31:23 +01:00 |
|
Martin Willi
|
5f6a37eb9b
|
Be a little more verbose about XAuth configs in ipsec statusall
|
2012-03-20 17:31:23 +01:00 |
|
Martin Willi
|
21a4fc832e
|
Pass ipsec.conf xauth_identity option via stroke to charon configurations
|
2012-03-20 17:31:23 +01:00 |
|
Tobias Brunner
|
0a43f4b6c4
|
Log configured IKE version in stroke plugin.
|
2012-03-20 17:31:20 +01:00 |
|
Martin Willi
|
e33510f8a3
|
Fixed leak of shared keys in xauth-generic plugin
|
2012-03-20 17:31:20 +01:00 |
|
Tobias Brunner
|
3d44d735c6
|
Added generic XAuth backend, using secrets provided by credential sets.
|
2012-03-20 17:31:17 +01:00 |
|
Tobias Brunner
|
41e1e435d9
|
Removed xauth-null dummy plugin.
|
2012-03-20 17:31:17 +01:00 |
|
Martin Willi
|
081b6dd3ed
|
Ask for a username/password in xauth-null as XAUTH initiator
|
2012-03-20 17:31:16 +01:00 |
|
Martin Willi
|
cbda13f6fe
|
Accept a xauth backend name appended to left/rightauth
|
2012-03-20 17:31:15 +01:00 |
|
Martin Willi
|
1fe6cdfac2
|
Use a string to identify xauth backends, no need for integer types
|
2012-03-20 17:31:15 +01:00 |
|
Martin Willi
|
96c9159d96
|
Use a second authentication config to configure XAUTH authentication
|
2012-03-20 17:31:15 +01:00 |
|
Clavister OpenSource
|
4394d96844
|
IKEv1 XAuth: Added a "NULL" XAuth plugin which sends a hardcoded user/pass, and blindly accepts whatever user/pass is sent it. Changed the xauth_request task to use this new plugin. Add --enable-xauth-null to your configure line to build with the new plugin.
|
2012-03-20 17:31:11 +01:00 |
|
Martin Willi
|
b4e815354c
|
Map auth_class to auth method and IKEv1 proposal attribute
|
2012-03-20 17:30:53 +01:00 |
|
Clavister OpenSource
|
23f4e4b42d
|
IKEv1 XAUTH: Added ability to configure XAUTH+PSK. Added task to handle XAUTH requests. Modified task_manager_v1 to enable it to initiate new tasks immediately after finishing a response.
|
2012-03-20 17:30:49 +01:00 |
|
Martin Willi
|
17ec1c74de
|
Don't compare initiator flag in IKE_SA manager, pass initiator parameter to IKE_SA constructor
|
2012-03-20 17:30:47 +01:00 |
|
Martin Willi
|
cf1772f685
|
Do not ignore configs for IKEv1 in charon anymore
|
2012-03-20 17:30:43 +01:00 |
|
Tobias Brunner
|
0b611540ef
|
Store IKE version of an SA on ike_sa_t.
|
2012-03-20 17:30:43 +01:00 |
|
Martin Willi
|
4ac22be0ec
|
Fix unaligned aliasing warning in raw socket
|
2012-03-20 17:30:41 +01:00 |
|
Tobias Brunner
|
f7a8fcedc0
|
Use enum to define IKE version on peer_cfg_t.
Replaced all those magic numbers.
|
2012-03-20 17:30:41 +01:00 |
|
Andreas Steffen
|
f673958e59
|
added the strongswan.conf options of the tnc-pdp plugin
|
2012-03-16 11:14:40 +01:00 |
|
Andreas Steffen
|
68c2c7ece4
|
eliminate unneeded private variable
|
2012-03-14 21:38:30 +01:00 |
|
Andreas Steffen
|
fb5450a435
|
use MAX_RADIUS_ATTRIBUTE_SIZE constant from radius_message header file
|
2012-03-14 07:51:56 +01:00 |
|
Andreas Steffen
|
dae4ada4cd
|
make the mppe salt unique
|
2012-03-14 07:31:19 +01:00 |
|
Andreas Steffen
|
6fd612913e
|
implemented MS_MPPE encryption
|
2012-03-13 23:26:15 +01:00 |
|
Andreas Steffen
|
ff4e447954
|
use RADIUS_TUNNEL_TYPE_ESP defined in header file
|
2012-03-13 17:00:37 +01:00 |
|
Andreas Steffen
|
d90ade8f79
|
implemented RADIUS Filter-ID attribute
|
2012-03-13 16:27:18 +01:00 |
|
Andreas Steffen
|
dfa3084223
|
removed double library entry
|
2012-03-13 16:27:17 +01:00 |
|
Andreas Steffen
|
27a91de071
|
adapted debug output
|
2012-03-13 16:27:17 +01:00 |
|
Andreas Steffen
|
70b2bfa5cb
|
keep a list of RADIUS connections with EAP method states
|
2012-03-13 16:27:17 +01:00 |
|
Andreas Steffen
|
595f44e9a3
|
apply maximum RADIUS attribute size to outbound EAP messages
|
2012-03-13 16:27:17 +01:00 |
|
Andreas Steffen
|
d1a311f631
|
read PDP server name from strongswan.conf
|
2012-03-13 16:27:17 +01:00 |
|
Andreas Steffen
|
4853efe891
|
define MAX_RADIUS_ATTRIBUTE_SIZE
|
2012-03-13 16:27:17 +01:00 |
|
Andreas Steffen
|
135822e11b
|
define peer and server identities
|
2012-03-13 16:27:17 +01:00 |
|
Andreas Steffen
|
cd9bde335c
|
added EAP_SUCCESS/FAILURE message to RADIUS Accept/Reject
|
2012-03-13 16:27:17 +01:00 |
|
Andreas Steffen
|
b3ec652192
|
added msg_auth flag in radius_message_t sign() method
|
2012-03-13 16:27:17 +01:00 |
|
Andreas Steffen
|
d4db9f44c2
|
simple RADIUS server example works
|
2012-03-13 16:27:17 +01:00 |
|
Andreas Steffen
|
e9f32b010a
|
first use of libradius
|
2012-03-13 16:27:17 +01:00 |
|
Andreas Steffen
|
21b0f216b9
|
created libradius shared by eap-radius and tnc-pdp plugins
|
2012-03-13 16:27:17 +01:00 |
|
Andreas Steffen
|
70fd2d1af7
|
created tnc-pdp policy decision point plugin
|
2012-03-13 16:27:16 +01:00 |
|
Martin Willi
|
bc403eb1e5
|
Fixed crash and locking issues while unrouting connections via stroke
|
2012-03-13 10:56:22 +01:00 |
|
Tobias Brunner
|
cd6b5bf8e9
|
Clear peer addresses during HA update.
|
2012-03-09 10:30:37 +01:00 |
|