Tobias Brunner
cb26c5547c
quick-mode: Make sure we have a proposal before determining lifetimes
...
Fixes: e0dd36c9c7 ("ikev1: Get and set the lifetimes of the selected proposal/transform")
2020-03-26 08:41:00 +01:00
Tobias Brunner
6987f6b3eb
unit-tests: Update expired certificates for TLS tests
2020-03-25 15:31:07 +01:00
Tobias Brunner
b2d3726501
nm: Version bump to 1.5.0
2020-03-25 10:14:46 +01:00
Tobias Brunner
393e0167fd
charon-nm: Correctly set remote auth class for PSK authentication
...
Fixes: bc3eda99ba ("charon-nm: Add support for EAP-TLS")
2020-03-20 16:06:12 +01:00
Tobias Brunner
9f91f0b3c8
openssl: Add support for SHAKE128/256
2020-03-10 14:12:34 +01:00
Tobias Brunner
112de13f1f
openssl: Add support for SHA-3
2020-03-10 14:12:34 +01:00
Tobias Brunner
dfd261d2de
kernel-netlink: Extract shared route handling code in net/ipsec
2020-03-10 10:30:39 +01:00
Tobias Brunner
e23708bdf3
kernel-netlink: Don't require an interface name for passthrough policies
2020-03-10 10:26:42 +01:00
Tobias Brunner
b0b6bd2470
kernel-netlink: Allow blank source address in routes for passthrough policies
2020-03-10 10:25:19 +01:00
Noel Kuntze and Tobias Brunner
09f4bccfea
kernel-netlink: Implement passthrough type routes and use them on Linux
...
Enables us to ignore any future kernel features for routes unless
we actually need to consider them for the source IP routes.
Also enables us to actually really skip IPsec processing for those networks
(because even the routes don't touch those packets). It's more what
users expect.
Co-authored-by: Tobias Brunner <[email protected] >
2020-03-10 10:20:58 +01:00
Tobias Brunner
4958acc0c2
kernel-interface: Reallocate previously used reqids
...
This is mainly an issue on FreeBSD where the current kernel still only
allows the daemon to use reqids < IPSEC_MANUAL_REQID_MAX (0x3fff = 16383).
Fixes #2315 .
2020-03-09 15:27:03 +01:00
Thomas Egerer
05e373aeb0
ike: Optionally allow private algorithms for IKE/CHILD_SAs
...
Charon refuses to make use of algorithms IDs from the private space
for unknown peer implementations [1]. If you chose to ignore and violate
that section of the RFC since you *know* your peers *must* support those
private IDs, there's no way to disable that behavior.
With this commit a strongswan.conf option is introduced which allows to
deliberately ignore parts of section 3.12 from the standard.
[1] http://tools.ietf.org/html/rfc7296#section-3.12
Signed-off-by: Thomas Egerer <[email protected] >
2020-03-06 11:15:15 +01:00
Tobias Brunner
61769fd1e3
openssl: Don't check signature if issuer doesn't match always
...
Doing this for the self-signed check also (i.e. if this and issuer are
the same) is particularly useful if the issuer uses a different key type.
Otherwise, we'd try to verify the signature with an incompatible key
that would result in a log message.
Fixes #3357 .
2020-03-06 11:12:07 +01:00
Tobias Brunner
5761077091
nm: Update NEWS for next release
2020-03-06 11:06:11 +01:00
Tobias Brunner
e0dd36c9c7
ikev1: Get and set the lifetimes of the selected proposal/transform
...
Previously, we simply used the lifetimes of the first
proposal/transform, which is not correct if the initiator uses different
lifetimes in its proposals/transforms.
2020-03-06 10:31:30 +01:00
Tobias Brunner
1c6b43b8ea
proposal-substructure: Start numbering IKEv1 proposals with 1
2020-03-06 10:31:30 +01:00
Tobias Brunner
859f9c8c83
proposal-substructure: Encode transform number of selected IKEv1 proposal
2020-03-06 10:31:30 +01:00
Tobias Brunner
7da3143aac
proposal-substructure: Store transform number for IKEv1 proposals
2020-03-06 10:31:30 +01:00
Tobias Brunner
e630f2d373
proposal: Add IKEv1 transform number on which a proposal is based
2020-03-06 10:31:30 +01:00
Tobias Brunner
479c85d569
libtls: Remove unused variable in TLS socket implementation
...
Not used anymore since c43e8fdec4 ("Block TLS read when sending data,
but have to wait for the handshake data first").
2020-03-06 10:30:16 +01:00
Tobias Brunner
96b61792df
ike: Don't reestablish IKE_SAs for which a deletion is queued
...
If an IKE_SA is terminated while a task is active, the delete task is
simply queued (unless the deletion is forced). If the active task times
out before any optional timeout associated with the termination hits, the
IKE_SA previously was reestablished without considering the termination
request.
Fixes #3335 .
2020-02-21 10:38:13 +01:00
Tobias Brunner
cfed3a87ee
charon-nm: Use better default directory for D-Bus policy file
...
Also makes it configurable via configure script. Depending on `$datadir` is
not ideal as package maintainers might set that to a custom value. Depending
on `$datarootdir` might have been better, the default if pkg-config fails is
now based on that.
References #3339 .
2020-02-21 09:46:13 +01:00
Tobias Brunner
7eab520bbf
nm: Ignore generated POT file
2020-02-14 14:53:26 +01:00
Tobias Brunner
ca3ff27101
nm: Only check PSK length if one is actually stored
2020-02-14 14:51:43 +01:00
Tobias Brunner
d57d5f510d
nm: Make local identity configurable
...
For PSK authentication we now use the local identity and not the username
field.
2020-02-14 14:45:32 +01:00
Tobias Brunner
ff8f6b15aa
charon-nm: Add support for custom local IKE identities
2020-02-14 14:35:44 +01:00
Tobias Brunner
5575aaf5c8
charon-nm: Keep listener registered even on failures
...
NM doesn't seem to terminate the daemon on failures, so we might not get
further events for later retries.
2020-02-14 13:55:42 +01:00
Tobias Brunner
3d2f5ae003
charon-nm: Support reauthentication and redirection
2020-02-14 13:55:42 +01:00
Tobias Brunner
661e1044c0
nm: Make EAP-TLS configurable
...
A new combo field allows selecting where the certificate/key is stored.
2020-02-14 13:50:32 +01:00
Tobias Brunner
bc3eda99ba
charon-nm: Add support for EAP-TLS
...
The code is structured similar to that in the Android client, but two-round
authentication (cert+EAP) is not supported as that might require multiple
secrets ("password" is currently the only secret field used for every
method) and other details are currently missing too (like configurable
client identities).
2020-02-14 13:44:39 +01:00
Tobias Brunner
e85a43b7b6
nm: Make server port configurable in GUI
2020-02-14 13:36:16 +01:00
Tobias Brunner
60777574c1
charon-nm: Add support for custom server ports
2020-02-14 13:36:16 +01:00
Tobias Brunner
7c6bb33151
nm: Update German translation
2020-02-14 11:19:49 +01:00
Tobias Brunner
a7bda9a95e
nm: Make remote identity editable in GUI
2020-02-14 11:19:49 +01:00
Tobias Brunner
19e64e101d
charon-nm: Add support for a specific remote identity
2020-02-14 11:19:49 +01:00
Tobias Brunner
f9956ca633
nm: Add hint regarding password storage policy
...
Requires targeting GTK 3.2.
2020-02-14 11:19:49 +01:00
Tobias Brunner
23de1602f9
nm: Replace the term "gateway" with "server"
2020-02-14 11:19:49 +01:00
Tobias Brunner
d46f804b09
nm: Update Glade file for GTK 3.0
...
That's the version we check for in the configure script.
2020-02-14 11:19:49 +01:00
Tobias Brunner
cb25022197
unit-tests: Increase timeout for test vectors suite
...
These occasionally fail due to the current timeout on IBM Power on Travis.
2020-02-13 16:42:13 +01:00
Tobias Brunner
19b2f870e2
enumerator: Fall back to lstat() if stat() fails when enumerating dirs/files
...
This happens e.g. if the path is for an invalid symlink.
2020-02-13 11:54:19 +01:00
Josh Soref
d30498edf1
ikev2: Fix spelling of routability
...
References strongswan/strongswan#164 .
2020-02-11 18:23:34 +01:00
Josh Soref
b3ab7a48cc
Spelling fixes
...
* accumulating
* acquire
* alignment
* appropriate
* argument
* assign
* attribute
* authenticate
* authentication
* authenticator
* authority
* auxiliary
* brackets
* callback
* camellia
* can't
* cancelability
* certificate
* choinyambuu
* chunk
* collector
* collision
* communicating
* compares
* compatibility
* compressed
* confidentiality
* configuration
* connection
* consistency
* constraint
* construction
* constructor
* database
* decapsulated
* declaration
* decrypt
* derivative
* destination
* destroyed
* details
* devised
* dynamic
* ecapsulation
* encoded
* encoding
* encrypted
* enforcing
* enumerator
* establishment
* excluded
* exclusively
* exited
* expecting
* expire
* extension
* filter
* firewall
* foundation
* fulfillment
* gateways
* hashing
* hashtable
* heartbeats
* identifier
* identifiers
* identities
* identity
* implementers
* indicating
* initialize
* initiate
* initiation
* initiator
* inner
* instantiate
* legitimate
* libraries
* libstrongswan
* logger
* malloc
* manager
* manually
* measurement
* mechanism
* message
* network
* nonexistent
* object
* occurrence
* optional
* outgoing
* packages
* packets
* padding
* particular
* passphrase
* payload
* periodically
* policies
* possible
* previously
* priority
* proposal
* protocol
* provide
* provider
* pseudo
* pseudonym
* public
* qualifier
* quantum
* quintuplets
* reached
* reading
* recommendation to
* recommendation
* recursive
* reestablish
* referencing
* registered
* rekeying
* reliable
* replacing
* representing
* represents
* request
* request
* resolver
* result
* resulting
* resynchronization
* retriable
* revocation
* right
* rollback
* rule
* rules
* runtime
* scenario
* scheduled
* security
* segment
* service
* setting
* signature
* specific
* specified
* speed
* started
* steffen
* strongswan
* subjectaltname
* supported
* threadsafe
* traffic
* tremendously
* treshold
* unique
* uniqueness
* unknown
* until
* upper
* using
* validator
* verification
* version
* version
* warrior
Closes strongswan/strongswan#164 .
2020-02-11 18:23:07 +01:00
Tobias Brunner
baf29263d5
pem: Support parsing PEM-encoded Ed448 keys
2020-02-10 13:37:31 +01:00
Tobias Brunner
878afdf90b
pki: Add support for Ed448 keys/certificates
2020-02-10 13:37:31 +01:00
Tobias Brunner
85a35fc99d
openssl: Support certificates with Ed25519/448 keys
2020-02-10 13:37:31 +01:00
Tobias Brunner
3361f81f1c
pkcs1: Support parsing Ed448 public keys
2020-02-10 13:37:31 +01:00
Tobias Brunner
18bee9306a
nm: Replace deprecated g_type_class_add_private()
...
Fixes #2765 , #3197 .
2020-02-05 10:54:37 +01:00
Tobias Brunner
0f141fb095
soup: Use soup_session_new() to avoid deprecation warning
...
There are a ton of libsoup/GLib-related "leaks" that we can't whitelist
and with leak detective active there is a delay that interestingly doesn't
happen with soup_session_sync_new(), so tests failed with a timeout (actually
they hung due to the lock in the fetcher manager).
On Travis, the curl plugin is used for the tests, so that's not an issue
there (and without LD the tests complete quickly and successfully).
2020-02-05 10:49:35 +01:00
Tobias Brunner
f78dfb7e28
vici: Options are optional in get_pools() of Python bindings
...
Fixes #3319 .
2020-02-03 10:52:31 +01:00
Tobias Brunner
ef4113a49d
libtpmtss: Fix problematic usage of chunk_from_chars() in TSS2 implementations
...
See 8ea13bbc5c for details.
References #3249 .
2020-01-30 18:18:33 +01:00