Tobias Brunner
|
84b18d5fc7
|
replaced mutex in leak detective with thread scheduling
|
2008-04-03 09:24:35 +00:00 |
|
Tobias Brunner
|
8e91a36314
|
thread locking for sender and processor optimized
|
2008-04-03 09:19:12 +00:00 |
|
Martin Willi
|
6af29ccf33
|
configure option in strongswan.conf for thread count
|
2008-04-03 08:37:24 +00:00 |
|
Martin Willi
|
6e4e27f8de
|
updated test data to use correct encoding data
|
2008-04-03 06:45:17 +00:00 |
|
Andreas Steffen
|
196b28a470
|
demoted more notify debug messages to level 2
|
2008-04-02 19:15:05 +00:00 |
|
Tobias Brunner
|
c3f803c4c6
|
fixing some memory leaks
|
2008-04-02 18:21:03 +00:00 |
|
Tobias Brunner
|
f049b29491
|
securing total_threads with the mutex while destroying the processor
|
2008-04-02 15:28:08 +00:00 |
|
Andreas Steffen
|
1ee637d8b1
|
generate debug output if ocsp response does not contain status information for a given certificate
|
2008-04-02 14:28:17 +00:00 |
|
Martin Willi
|
513f20156a
|
fixed med_db test
|
2008-04-02 12:27:39 +00:00 |
|
Martin Willi
|
489e3da0ea
|
updated mediation database to public key authentication
added mysql table definition, test data
testcase
|
2008-04-02 12:25:14 +00:00 |
|
Martin Willi
|
e29ebcb1af
|
fixed compile warnings
|
2008-04-02 09:54:20 +00:00 |
|
Andreas Steffen
|
281d04502e
|
additional debug line makes certificate status checking more understandable
|
2008-04-02 06:25:59 +00:00 |
|
Andreas Steffen
|
9372f44c67
|
workaround for parsing IPv6 PSKs requires extract_last_token()
|
2008-04-01 20:40:29 +00:00 |
|
Andreas Steffen
|
080555e76a
|
demoted received notify debug message to level 2
|
2008-04-01 20:22:38 +00:00 |
|
Martin Willi
|
9d1c384b4b
|
loading of subjectPublicKeyInfo wrapped keys using KEY_ANY (openssl format)
testcase
|
2008-04-01 14:51:31 +00:00 |
|
Andreas Steffen
|
392f4e17c2
|
minimal stroke_list_ocsp() implementation
|
2008-04-01 12:11:09 +00:00 |
|
Tobias Brunner
|
9c2a905d63
|
stopping connectivity checks on the responders side after receiving an IKE_SA_INIT request with the proper ME_CONNECTID
|
2008-04-01 11:38:18 +00:00 |
|
Martin Willi
|
45d66f5af6
|
some simplifications to trusted_enumerator_t
|
2008-04-01 10:56:08 +00:00 |
|
Martin Willi
|
1bb85edffe
|
checking pretrusted but bad certificates only once
|
2008-04-01 10:43:44 +00:00 |
|
Andreas Steffen
|
946d1ecd59
|
stroke_list groups certificates by issuer
|
2008-04-01 10:26:27 +00:00 |
|
Andreas Steffen
|
c096472605
|
minor changes in debug output
|
2008-03-31 21:59:32 +00:00 |
|
Andreas Steffen
|
aaa7643b73
|
put DN in double quotes
|
2008-03-31 21:08:56 +00:00 |
|
Andreas Steffen
|
a92ea0ccb3
|
output error message if maximum ca path length is reached
|
2008-03-31 20:42:57 +00:00 |
|
Andreas Steffen
|
eafc0654ca
|
ipsec list suppresses duplicates
|
2008-03-31 20:21:24 +00:00 |
|
Tobias Brunner
|
e5ab32a7ee
|
timing of connectivity checks adjusted
|
2008-03-31 15:04:38 +00:00 |
|
Martin Willi
|
9e72d3bcaf
|
defining ME globally, as we need it in plugins
|
2008-03-31 15:01:43 +00:00 |
|
Andreas Steffen
|
58a05045cc
|
utc argument in %#T was missing
|
2008-03-31 14:36:00 +00:00 |
|
Tobias Brunner
|
9e183cd5b8
|
signal fixed
|
2008-03-31 14:27:16 +00:00 |
|
Tobias Brunner
|
f98736aee6
|
changed order of server and peer reflexive endpoints (and also the priorities)
|
2008-03-31 10:56:49 +00:00 |
|
Martin Willi
|
0f7ef3d2a0
|
received certificates have least priority
fixed manager unlocking
|
2008-03-31 08:43:18 +00:00 |
|
Martin Willi
|
d69b267d58
|
fixed refcounting in certificate trustchain validation
|
2008-03-31 07:16:12 +00:00 |
|
Andreas Steffen
|
dcc777652e
|
changed error message
|
2008-03-29 13:26:53 +00:00 |
|
Andreas Steffen
|
40f9006845
|
output uptime in status in local time
|
2008-03-29 08:55:09 +00:00 |
|
Martin Willi
|
6b9290ff12
|
renamed xml plugin to smp to avoid confusion
added some dependency checks to configure
configure checks ClearSilver and fastcgi
cleanups in the build system here and there
|
2008-03-28 12:44:01 +00:00 |
|
Martin Willi
|
35b6e2301f
|
fixed crash if crl fetching fails
|
2008-03-28 12:00:51 +00:00 |
|
Martin Willi
|
d55fa9aff7
|
reentrant save cert_cache
|
2008-03-28 08:38:51 +00:00 |
|
Martin Willi
|
ac1fefc2de
|
caching of CRLs
|
2008-03-28 08:14:47 +00:00 |
|
Martin Willi
|
d20e5c6ab5
|
replaced get_public() by create_public_enumerator() to try multiple public keys for signature verification
|
2008-03-27 19:07:23 +00:00 |
|
Martin Willi
|
0d30ba3343
|
use trusted self-signed root CA certificates as trust anchor only
|
2008-03-27 13:38:02 +00:00 |
|
Tobias Brunner
|
e74bc8e51d
|
changed external interface to the mediation extension.
|
2008-03-27 12:31:35 +00:00 |
|
Tobias Brunner
|
b42421a04c
|
corrected ME_ENDPOINT length check
|
2008-03-27 12:29:51 +00:00 |
|
Martin Willi
|
52a61742e7
|
reusing generic shared_key_t implementation in med_db
|
2008-03-27 11:45:49 +00:00 |
|
Tobias Brunner
|
54150b3f13
|
checking the size of ME_* notify payloads
|
2008-03-27 10:17:29 +00:00 |
|
Tobias Brunner
|
b0dee635d2
|
replaced the COOKIE notify payload in connectivity checks with a ME_CONNECTAUTH notify payload
|
2008-03-27 09:54:09 +00:00 |
|
Martin Willi
|
f957f7dfb3
|
implemented cert cache flushing, ipsec purgeocsp
|
2008-03-27 06:37:29 +00:00 |
|
Andreas Steffen
|
d61bd27a9a
|
fixed plugin/stroke Makefile
|
2008-03-26 20:24:55 +00:00 |
|
Tobias Brunner
|
dc04b7c743
|
mediation extension adapted to the naming convention of the current version of the draft. note: the external interface (config, autotools) has not yet been changed
|
2008-03-26 18:40:19 +00:00 |
|
Martin Willi
|
685232670a
|
added uptime statistics to statusall
|
2008-03-26 16:13:14 +00:00 |
|
Martin Willi
|
7b88a983d8
|
caching of ocsp responses (experimental), no crl caching yet
|
2008-03-26 15:21:50 +00:00 |
|
Martin Willi
|
391abda082
|
fixed compile error if --enable-p2p is set
|
2008-03-26 14:45:24 +00:00 |
|