Tobias Brunner
|
4a6474c2c3
|
enabling acquire for mediated connections
|
2008-04-10 12:51:04 +00:00 |
|
Tobias Brunner
|
78abba428f
|
enabling reauthentication on mediation connections
|
2008-04-10 08:42:27 +00:00 |
|
Tobias Brunner
|
4a03518112
|
fixing a problem if the mediation server initiates the rekeying
|
2008-04-10 07:24:30 +00:00 |
|
Tobias Brunner
|
22452f70fc
|
mediation connections should now properly rekey
|
2008-04-09 18:12:22 +00:00 |
|
Martin Willi
|
ad81e51afc
|
implemented a simple attribute provider for stroke
|
2008-04-09 12:56:20 +00:00 |
|
Martin Willi
|
cdcfe777f4
|
implementation of an CFG attribute framework, currently supporting virtual IPs
updated ipsec.conf sourceip parameter to support
CIDR notatation to serve from a pool
%poolname to query a separate (database?) pool
|
2008-04-09 12:54:47 +00:00 |
|
Tobias Brunner
|
4a96521965
|
signature in connectivity checks is now built with the message id in network byte order
|
2008-04-08 13:45:30 +00:00 |
|
Tobias Brunner
|
1d295d1ffa
|
printing the checklist, two bugfixes
|
2008-04-08 12:31:27 +00:00 |
|
Tobias Brunner
|
6f186d7e2e
|
connect manager: restart the sender if it is not running anymore
|
2008-04-08 09:21:27 +00:00 |
|
Tobias Brunner
|
03e5336340
|
better logging for chunks in connect manager
|
2008-04-08 08:41:23 +00:00 |
|
Tobias Brunner
|
028a345c63
|
refactored callback data in connect manager
|
2008-04-08 08:33:15 +00:00 |
|
Tobias Brunner
|
6970925422
|
fast finishing connectivity checks on the initiators side
|
2008-04-07 15:45:37 +00:00 |
|
Tobias Brunner
|
dd563e60df
|
corrected the logging for retransmissions of connectivity checks
|
2008-04-07 14:45:39 +00:00 |
|
Tobias Brunner
|
b03c1d415c
|
changed how retransmissions of connectivity checks are sent
|
2008-04-07 11:26:15 +00:00 |
|
Tobias Brunner
|
70a568b015
|
fixing another memory leak
|
2008-04-07 09:36:52 +00:00 |
|
Martin Willi
|
1749642b15
|
use cert->equals() to filter out equal certificates in seperate instances
|
2008-04-07 08:48:08 +00:00 |
|
Martin Willi
|
da5e7bdb4c
|
try to cache the same instance of equal certificates
|
2008-04-07 08:44:43 +00:00 |
|
Martin Willi
|
9caadea8c8
|
fixed bad cleanup which results in segfault if no issuer cert found, fixes #43
|
2008-04-07 08:06:02 +00:00 |
|
Andreas Steffen
|
480297b883
|
cosmetics
|
2008-04-07 07:02:47 +00:00 |
|
Martin Willi
|
ff867d062e
|
added ./configure option --with-strongswan-conf=
defaults to /etc/strongswan.conf
|
2008-04-07 06:56:33 +00:00 |
|
Andreas Steffen
|
f8ab4a8f76
|
log shared secret with debug level 4
|
2008-04-06 17:51:29 +00:00 |
|
Andreas Steffen
|
1b247314fd
|
default is hostaccess=no
|
2008-04-06 12:15:05 +00:00 |
|
Tobias Brunner
|
4c7e6112c5
|
and another
|
2008-04-03 15:22:06 +00:00 |
|
Tobias Brunner
|
471f923071
|
fixed two other memory leaks
|
2008-04-03 15:13:25 +00:00 |
|
Tobias Brunner
|
84b18d5fc7
|
replaced mutex in leak detective with thread scheduling
|
2008-04-03 09:24:35 +00:00 |
|
Tobias Brunner
|
8e91a36314
|
thread locking for sender and processor optimized
|
2008-04-03 09:19:12 +00:00 |
|
Martin Willi
|
6af29ccf33
|
configure option in strongswan.conf for thread count
|
2008-04-03 08:37:24 +00:00 |
|
Martin Willi
|
6e4e27f8de
|
updated test data to use correct encoding data
|
2008-04-03 06:45:17 +00:00 |
|
Andreas Steffen
|
196b28a470
|
demoted more notify debug messages to level 2
|
2008-04-02 19:15:05 +00:00 |
|
Tobias Brunner
|
c3f803c4c6
|
fixing some memory leaks
|
2008-04-02 18:21:03 +00:00 |
|
Tobias Brunner
|
f049b29491
|
securing total_threads with the mutex while destroying the processor
|
2008-04-02 15:28:08 +00:00 |
|
Andreas Steffen
|
1ee637d8b1
|
generate debug output if ocsp response does not contain status information for a given certificate
|
2008-04-02 14:28:17 +00:00 |
|
Martin Willi
|
513f20156a
|
fixed med_db test
|
2008-04-02 12:27:39 +00:00 |
|
Martin Willi
|
489e3da0ea
|
updated mediation database to public key authentication
added mysql table definition, test data
testcase
|
2008-04-02 12:25:14 +00:00 |
|
Martin Willi
|
e29ebcb1af
|
fixed compile warnings
|
2008-04-02 09:54:20 +00:00 |
|
Andreas Steffen
|
281d04502e
|
additional debug line makes certificate status checking more understandable
|
2008-04-02 06:25:59 +00:00 |
|
Andreas Steffen
|
9372f44c67
|
workaround for parsing IPv6 PSKs requires extract_last_token()
|
2008-04-01 20:40:29 +00:00 |
|
Andreas Steffen
|
080555e76a
|
demoted received notify debug message to level 2
|
2008-04-01 20:22:38 +00:00 |
|
Martin Willi
|
9d1c384b4b
|
loading of subjectPublicKeyInfo wrapped keys using KEY_ANY (openssl format)
testcase
|
2008-04-01 14:51:31 +00:00 |
|
Andreas Steffen
|
392f4e17c2
|
minimal stroke_list_ocsp() implementation
|
2008-04-01 12:11:09 +00:00 |
|
Tobias Brunner
|
9c2a905d63
|
stopping connectivity checks on the responders side after receiving an IKE_SA_INIT request with the proper ME_CONNECTID
|
2008-04-01 11:38:18 +00:00 |
|
Martin Willi
|
45d66f5af6
|
some simplifications to trusted_enumerator_t
|
2008-04-01 10:56:08 +00:00 |
|
Martin Willi
|
1bb85edffe
|
checking pretrusted but bad certificates only once
|
2008-04-01 10:43:44 +00:00 |
|
Andreas Steffen
|
946d1ecd59
|
stroke_list groups certificates by issuer
|
2008-04-01 10:26:27 +00:00 |
|
Andreas Steffen
|
c096472605
|
minor changes in debug output
|
2008-03-31 21:59:32 +00:00 |
|
Andreas Steffen
|
aaa7643b73
|
put DN in double quotes
|
2008-03-31 21:08:56 +00:00 |
|
Andreas Steffen
|
a92ea0ccb3
|
output error message if maximum ca path length is reached
|
2008-03-31 20:42:57 +00:00 |
|
Andreas Steffen
|
eafc0654ca
|
ipsec list suppresses duplicates
|
2008-03-31 20:21:24 +00:00 |
|
Tobias Brunner
|
e5ab32a7ee
|
timing of connectivity checks adjusted
|
2008-03-31 15:04:38 +00:00 |
|
Martin Willi
|
9e72d3bcaf
|
defining ME globally, as we need it in plugins
|
2008-03-31 15:01:43 +00:00 |
|