Andreas Steffen
|
a066f7e6c2
|
corrected captions
|
2008-11-02 22:13:17 +00:00 |
|
Martin Willi
|
5dffdea1d7
|
added hooks for IKE and CHILD keymat
|
2008-10-30 12:58:54 +00:00 |
|
Martin Willi
|
5a76bb7f7a
|
store plain skd, not the prf
|
2008-10-30 09:18:52 +00:00 |
|
Martin Willi
|
80853d8498
|
moved CHILD_SA key derivation to keymat_t
passing key chunks to CHILD_SA, not the PRF
|
2008-10-29 16:06:16 +00:00 |
|
Martin Willi
|
a64cc8f75f
|
do not store DH redundant in keymat
|
2008-10-29 13:35:06 +00:00 |
|
Martin Willi
|
6a4ff35cc4
|
moved key derivation and management into keymat object
allows secured implementation of key management (e.g. in kernel or HW)
only IKE keys for now
|
2008-10-28 16:07:06 +00:00 |
|
Martin Willi
|
3c8234d408
|
store IKE proposal implicitly during derive_keys
|
2008-10-28 10:12:21 +00:00 |
|
Martin Willi
|
85ac2fa547
|
use more generic stats getter, introducing new stats
|
2008-10-27 14:51:00 +00:00 |
|
Martin Willi
|
f2e1ff59ab
|
reset threads IKE_SA after checking other IKE_SAs
invoke updown script only if we have valid IKE_SA
|
2008-10-20 11:38:16 +00:00 |
|
Andreas Steffen
|
7790ab0f37
|
re-established all previous AUD level messages
|
2008-10-17 03:44:06 +00:00 |
|
Martin Willi
|
ad3af574a4
|
moved updown script invocation to an optional plugin
|
2008-10-16 11:48:18 +00:00 |
|
Martin Willi
|
a985db3ff3
|
reintegrated bus-refactoring branch
|
2008-10-14 08:52:13 +00:00 |
|
Martin Willi
|
f0974eb2c2
|
fixed MOBIKE roaming if clients address changes
|
2008-10-09 08:25:11 +00:00 |
|
Martin Willi
|
ce5b17082d
|
mobike: try to keep existing source address before switching to another
|
2008-10-08 08:23:46 +00:00 |
|
Martin Willi
|
9d9a772ee1
|
use MOBIKE enabled DPD if we are NATed
update SAs if we detect changes in NAT mappings
|
2008-10-06 13:37:04 +00:00 |
|
Martin Willi
|
aa1b90a5b2
|
do not run CHILD_SA delete action if rekeying
|
2008-10-03 16:01:14 +00:00 |
|
Martin Willi
|
7827997346
|
also respect the mobike=no setting as responder
|
2008-09-30 12:36:58 +00:00 |
|
Tobias Brunner
|
a341a68fac
|
merging renaming of mode_t to ipsec_mode_t back to trunk
|
2008-09-25 13:56:23 +00:00 |
|
Tobias Brunner
|
507f26f685
|
merging modularized kernel interface back to trunk
|
2008-09-25 07:56:58 +00:00 |
|
Andreas Steffen
|
919019b3cd
|
completed support of AUTHZ_CA_CERT and AUTHZ_CA_CERT_NAME attributes
|
2008-08-26 05:15:34 +00:00 |
|
Martin Willi
|
822901061b
|
ported parts of two-sim branch
eap_identity parameter to exchange in eap_identity
some auth_info/peer_cfg refactorings
fixed some bugs, introduced new ones
|
2008-08-22 10:44:51 +00:00 |
|
Andreas Steffen
|
342c84ddec
|
initiator sends contents of rightca= if present as a certificate request without searching for further CA certificates
|
2008-08-05 09:05:57 +00:00 |
|
Andreas Steffen
|
f6facbe75c
|
completed IKE_SA logging at the AUDIT level
|
2008-07-23 18:46:34 +00:00 |
|
Andreas Steffen
|
6410231335
|
IKE_SA rekeying inherits other_host from old IKE_SA
|
2008-07-23 07:44:26 +00:00 |
|
Andreas Steffen
|
0eede4a31f
|
cosmetics
|
2008-07-23 06:38:24 +00:00 |
|
Andreas Steffen
|
51c8f8261f
|
some more changes to IKE_SA and CHILD_SA logging
|
2008-07-22 17:10:10 +00:00 |
|
Andreas Steffen
|
66da78b4bb
|
ipsec status lists IPCOMP CPIs
|
2008-07-22 12:03:58 +00:00 |
|
Andreas Steffen
|
eba7470b76
|
consistent logging of SPIs and CPIs
|
2008-07-22 10:16:45 +00:00 |
|
Andreas Steffen
|
fb34475b5c
|
consistent logging of IKE and CHILD SAs
|
2008-07-21 12:47:59 +00:00 |
|
Martin Willi
|
a4a3e0c7dc
|
introduced an additional bus->signal parameter for signal specific data
added SIG_IKE/SIG_CHD macros for signal emitting
|
2008-07-18 15:51:40 +00:00 |
|
Martin Willi
|
7beea2e99f
|
fixed acquire-delay bug by:
installing policies before states
updating policies if protocol has changed
|
2008-07-16 11:51:37 +00:00 |
|
Martin Willi
|
62bd123952
|
peer_cfg lookup takes peer addresses into account
|
2008-07-01 09:05:20 +00:00 |
|
Martin Willi
|
866ba8e0b6
|
strongswan.conf's charon.close_ike_on_child_failure closes IKE_SA if CHILD_SA setup in IKE_AUTH fails
|
2008-07-01 07:54:09 +00:00 |
|
Martin Willi
|
d510eaea47
|
sending INTERNAL_ADDRESS_FAILURE if virtual IP requested but none found
|
2008-07-01 06:36:52 +00:00 |
|
Andreas Steffen
|
125aaf1ab1
|
log received vendor id as a hex value
|
2008-06-27 17:11:54 +00:00 |
|
Andreas Steffen
|
bc997f6583
|
display selected IKE proposal in ipsec statusall
|
2008-06-22 11:24:33 +00:00 |
|
Tobias Brunner
|
ea0823dffd
|
ECDSA with OpenSSL
|
2008-06-10 09:08:27 +00:00 |
|
Martin Willi
|
5a22a02156
|
DNS resolving of ike_cfg hosts dynamically on demand
|
2008-06-06 15:05:54 +00:00 |
|
Martin Willi
|
de3d65a132
|
filtering out non matching path probing pairs explicitly
|
2008-05-23 15:43:42 +00:00 |
|
Martin Willi
|
85a119bc0b
|
replying to COOKIE2 mobike notify properly
including COOKIE2 ourself after path probing
|
2008-05-21 17:56:21 +00:00 |
|
Tobias Brunner
|
d4aad55434
|
IPComp for IKEv2
|
2008-05-08 16:19:11 +00:00 |
|
Andreas Steffen
|
1d5d6f9667
|
Hash and URL cosmetics
|
2008-04-18 21:27:08 +00:00 |
|
Tobias Brunner
|
6439267a8c
|
support for hash and URL encoded certificate payloads in charon
|
2008-04-18 11:24:45 +00:00 |
|
Martin Willi
|
6a365f0740
|
added API for random number generators, served through credential factory
ported randomizer_t to a rng_t on top of /dev/(u)random (plugin random)
|
2008-04-15 05:56:35 +00:00 |
|
Martin Willi
|
0644ebd3de
|
implemented IKE_SA uniqueness using ipsec.conf uniqueids paramater
additionally supports a "keep" value to keep the old IKE_SA
|
2008-04-14 13:23:24 +00:00 |
|
Martin Willi
|
348af092ac
|
added close_action as a seperate config option to dpd_action
|
2008-04-14 08:17:18 +00:00 |
|
Martin Willi
|
45819d7d49
|
fixed rightsourceip=%config scenarios
|
2008-04-14 07:18:16 +00:00 |
|
Andreas Steffen
|
b1bdfa4890
|
fixed disabling the sending of cert requests
|
2008-04-13 17:31:07 +00:00 |
|
Martin Willi
|
96926b006d
|
using dpd actions to enforce connection state
dpd actions a per child-, not peer ike-sa
|
2008-04-11 08:14:48 +00:00 |
|
Tobias Brunner
|
78abba428f
|
enabling reauthentication on mediation connections
|
2008-04-10 08:42:27 +00:00 |
|