Martin Willi
8eefe4617f
use only KEY_ID_PUBKEY_SHA1 fingerprint charon internally
2009-08-26 11:23:53 +02:00
Martin Willi
87d2026341
updated nm plugin to new fingerprinting API
2009-08-26 11:23:53 +02:00
Martin Willi
c5cd195c6c
updated stroke plugin to fingerprinting API
2009-08-26 11:23:53 +02:00
Martin Willi
64fdbce4da
updated charon to new fingerprinting API
2009-08-26 11:23:53 +02:00
Martin Willi
750bbcf9a8
added support for %prompt-ing private key passhprases in strokes "ipsec secrets"
2009-08-26 11:23:50 +02:00
Martin Willi
280469923d
make use of the pem helper plugin to load credentials
2009-08-26 11:23:49 +02:00
Martin Willi
469083cc7d
disable lifetimes of allocated SPIs
...
The default lifetime of 30 seconds is too short, as a tunnel
setup may need several minutes if we have high packet loss. Instead
of increasing the value, we disable lifetimes completely, as we handle
the removal of such SAs from userland just fine.
2009-08-25 18:15:25 +02:00
Martin Willi
1bc0b4f795
remove incomplete SAs with PROTO_ESP
2009-08-25 18:12:55 +02:00
Andreas Steffen
8a17c1f907
check integrity of pool code file
2009-08-17 15:46:56 +02:00
Andreas Steffen
2f5b1e0eb7
check success of library_init()
2009-08-14 22:13:51 +02:00
Tobias Brunner
26965b4ef3
OpenSolaris needs libsocket and libnsl for socket().
2009-08-14 14:50:53 +02:00
Tobias Brunner
932fdc38de
Enable CMSG headers and macros on OpenSolaris.
2009-08-14 14:50:52 +02:00
Tobias Brunner
8c3627c5ae
Added define to get sigwait with two parameters on OpenSolaris.
2009-08-14 14:50:51 +02:00
Tobias Brunner
a3ccf95f3f
LOG_AUTHPRIV is not defined on OpenSolaris.
2009-08-14 13:37:07 +02:00
Tobias Brunner
3901937d14
OpenSolaris defines MUTEX_DEFAULT therefore we rename the members of the enums mutex/condvar/rwlock_type_t.
2009-08-14 13:30:59 +02:00
Andreas Steffen
8ddcac4c48
prepare CAMELLIA_CCM ESP encryption
2009-08-10 16:30:42 +02:00
Martin Willi
dd4c14f37c
set protocol to ESP for policies installed as a trap
2009-08-07 16:05:32 +02:00
Andreas Steffen
4b5b92bfee
%llu correctly prints u_int64_t
2009-08-07 09:50:36 +02:00
Andreas Steffen
4a02deb088
printing u_int64_t caused segfault on 32-bit platforms
2009-08-07 08:47:29 +02:00
Andreas Steffen
99dd42918e
do not set usetime if query_policy() fails
2009-08-07 05:59:09 +02:00
Tobias Brunner
79ff614144
Use LONG_MAX instead of a hard-coded value.
2009-08-06 18:22:01 +02:00
Tobias Brunner
bfca7aa5ed
FreeBSD returns the current policy use time only after specifying a hard lifetime when installing the policy.
2009-08-06 18:14:44 +02:00
Tobias Brunner
c3a78360a8
Fixed a race condition when querying stats of a child_sa in different order.
2009-08-06 16:47:32 +02:00
Andreas Steffen
3646c8a159
abort pluto or charon if initialization fails
2009-08-06 16:32:52 +02:00
Tobias Brunner
dd83c6d490
Don't query the policy usetime if there was no traffic on the SA.
...
This helps in cases where a policy is assigned to more than one SA. That
is, SAs now should have different usetimes even if they use the same policy.
2009-08-06 15:14:54 +02:00
Tobias Brunner
b3f8ea8346
Reverted the interface changes introduced in 3f720dc7.
2009-08-06 13:31:54 +02:00
Martin Willi
51c037cc71
added support for ipsec.secrets "include" directive
2009-08-06 11:48:19 +02:00
Tobias Brunner
1e7b4b0028
Reversed the check for udp.h, fixes compilation on Linux.
2009-08-06 10:01:59 +02:00
Tobias Brunner
7da1f4a0ff
Enabling UDP encapsulation via setsockopt fails on Mac OS X (it is also not required as this is done using sysctl).
2009-08-05 12:31:10 +02:00
Andreas Steffen
fcdf491a21
output number of transmitted bytes in closing CHILD_SA statement
2009-08-04 23:08:42 +02:00
Tobias Brunner
524f9ac470
FreeBSD only reports a policy's usetime if a lifetime has been specified when the policy was added (we only specify a lifetime on the SA, not on the policy).
2009-08-04 11:08:58 +02:00
Tobias Brunner
56ee8fcc96
FreeBSD and Mac OS X both set the sequence number of an SADB_X_SPDGET response to zero, we accept that for now.
2009-08-04 11:08:58 +02:00
Martin Willi
5cb300e795
compare IKE config when reusing an existing IKE_SA to initiate a CHILD_SA
2009-08-03 14:37:24 +02:00
Andreas Steffen
f35f229fd6
implemented query_sa() for PFKEYv2
2009-08-02 11:46:33 +02:00
Andreas Steffen
47eb87d437
corrected interface definition
2009-07-31 08:57:55 +02:00
Andreas Steffen
3f720dc7c3
update usetime only if usebytes increase
2009-07-30 23:19:42 +02:00
Andreas Steffen
2ad51539f6
display transmitted bytes per SA
2009-07-30 21:33:19 +02:00
Tobias Brunner
eab05274f4
Handling of unsupported policy directions (FWD) fixed.
2009-07-30 14:06:26 +02:00
Tobias Brunner
e20bd8b6ea
Enabling NAT-T on Mac OS X using the private SADB_X_EXT_NATT flag and sadb_sa_2 struct.
2009-07-30 14:06:26 +02:00
Tobias Brunner
789ba17024
Configure the NAT-T port via sysctl on Mac OS X to enable handling of incoming UDP encapsulated ESP packets in the kernel.
2009-07-30 14:06:26 +02:00
Tobias Brunner
b2117eee20
Make accept(2) and recvfrom(2) cancellation points on Mac OS X.
2009-07-30 14:06:26 +02:00
Andreas Steffen
def1777eca
streamlined integrity test output some more
2009-07-18 11:23:27 +02:00
Andreas Steffen
eab241fb56
stop strongswan if integrity check of libstrongswan or daemon fails
2009-07-17 20:33:19 +02:00
Andreas Steffen
6b04ba288d
streamlined debug output of integrity tests
2009-07-17 17:00:17 +02:00
Andreas Steffen
848133ff1c
accelerate lookup in non-concatenated pools
2009-07-17 13:58:29 +02:00
Andreas Steffen
7f522b5fd8
check for an existing lease over all assigned pools first
2009-07-17 11:48:35 +02:00
Andreas Steffen
07be083b7f
fixed problem with static leases over multiple pools
2009-07-16 21:53:46 +02:00
Martin Willi
e0964e2e26
fixed memleak in SQL config lookup
2009-07-16 15:59:56 +02:00
Martin Willi
88957f54f2
raise an alert() if the RADIUS server is not responding
2009-07-16 15:15:39 +02:00
Martin Willi
e85b83c737
added an alert() bus hook to raise critical system errors and notifications
2009-07-16 15:15:39 +02:00