Tobias Brunner
9b0847dd9a
Exposed the mutli-overlay functionality in the ruby bindings.
...
Overlays can be added to individual guests (which overlays exactly the
supplied directory) or to all guests (which overlays a subdirectory
with the guest's name to each guest).
The template functionality is provided as before.
2010-10-12 15:03:37 +02:00
Tobias Brunner
f29396b87e
Added support for multiple overlays to the main library.
...
Also implemented the template functionality using the new overlay functions.
2010-10-12 15:03:27 +02:00
Tobias Brunner
0dbbd47fe7
Added support for multiple overlays to guests (replaces the template functionality).
...
Compared to a template an overlay is an arbitrary directory, not the
parent directory of a directory with the guest's name.
2010-10-12 15:03:26 +02:00
Tobias Brunner
4542920a3e
Added support for multiple overlays to the copy-on-write filesystem.
2010-10-12 15:03:19 +02:00
Tobias Brunner
1dbf0ed982
Do not add additional addresses to MOBIKE path probing messages.
2010-10-12 11:11:06 +02:00
Tobias Brunner
5774408898
Change behavior of responder during roaming.
...
If the current source address is not available anymore, the responder
uses ike_mobike_t.roam, thus, uses multiple address combinations when
trying to notify the initiator.
2010-10-12 11:11:05 +02:00
Tobias Brunner
c5770f864f
Allow responder to use ike_mobike_t.roam.
...
After getting a response the responder updates the IPsec SAs.
2010-10-12 11:11:05 +02:00
Tobias Brunner
261b2572d1
Send list of additional addresses even if current path is still valid.
2010-10-12 11:11:05 +02:00
Tobias Brunner
bab56a4abb
Extracted path checking in ike_sa_t.roam into separate functions.
2010-10-12 11:11:05 +02:00
Tobias Brunner
769c69facc
Added support for responders to change their address via MOBIKE.
...
If the original responder updates its list of additional addresses we
check if the remote endpoint changed and update the IPsec SAs if it did,
as we assume the original address became unavailable and the responder
already updated the SAs on its side.
2010-10-12 11:11:05 +02:00
Tobias Brunner
13876431d6
Explicitly configure MOBIKE tasks to update the list of additional addresses.
2010-10-12 11:11:05 +02:00
Tobias Brunner
31e7dc4dfd
Improved check for first IKE_AUTH message in ike_mobike task.
...
If the original responder initiated a MOBIKE exchange, the previous
check was not always correct.
2010-10-12 11:11:05 +02:00
Tobias Brunner
c817e7bb90
Migrated ike_mobike task to INIT/METHOD macros.
2010-10-12 11:11:05 +02:00
Tobias Brunner
be90134211
Simplified apply_port function in mobike task.
2010-10-12 11:11:04 +02:00
Tobias Brunner
ec0c756d07
Do not fire roam events based on local route changes.
...
These kernel events are triggered on address changes, which is
problematic when deleting virtual IP addresses.
2010-10-12 11:11:04 +02:00
Tobias Brunner
29607690a8
If a changed route has no src, try to find it via interface.
2010-10-12 11:11:04 +02:00
Tobias Brunner
0ac6d2e658
Get source address from interface if the route does not provide one.
2010-10-12 11:11:04 +02:00
Tobias Brunner
cd26eedc5c
Do not update hosts based on retransmitted messages.
2010-10-12 11:11:04 +02:00
Tobias Brunner
d5bd775126
Do not update remote host if we are behind a NAT.
2010-10-12 11:11:04 +02:00
Andreas Steffen
0bc5547d0c
*** HISTORICAL MOMENT: IKEv2 becomes the default! ***
2010-10-09 20:46:55 +02:00
Andreas Steffen
ed08f7ce83
use DBG_TNC for TNC debugging output
2010-10-09 16:01:19 +02:00
Andreas Steffen
3cb3f85dfc
TNCCS debug cosmetics
2010-10-09 00:58:12 +02:00
Andreas Steffen
e9ba435fe3
revert to standard TNCC/TNCS Initialization function
2010-10-09 00:35:45 +02:00
Andreas Steffen
bfba1fdc92
implemented TNC isolation via group memberships
2010-10-09 00:34:53 +02:00
Andreas Steffen
db2f66c2df
implemented a makeshift non-scalable send buffer
2010-10-08 22:24:30 +02:00
Andreas Steffen
55960a170f
imc/imv cosmetics
2010-10-08 06:40:03 +02:00
Andreas Steffen
8dcc56dcc0
created tnc-imc and tnc-imv plugins
2010-10-07 23:31:23 +02:00
Andreas Steffen
04d000210b
deactivate start_phase2_tnc flag after start
2010-10-07 15:42:00 +02:00
Andreas Steffen
888455587b
added server side support for EAP-TNC
2010-10-07 15:02:51 +02:00
Martin Willi
962300b920
Show result of RADIUS authentication along with EAP identity
2010-10-07 11:14:09 +02:00
Andreas Steffen
99dfc3c295
added --debug-tls to charon usage() function
2010-10-07 09:34:56 +02:00
Andreas Steffen
bb43f25ad3
configure tnc_config path and preferred_language via strongswan.conf
2010-10-05 22:09:07 +02:00
Andreas Steffen
6d0e9cf046
created hull for TNCCS 2.0 plugin
2010-10-05 21:15:24 +02:00
Andreas Steffen
a1edf4d33e
use group membership to implement access/isolate redirection in filter-based TNC scenario
2010-10-05 20:40:36 +02:00
Andreas Steffen
b540d19133
moved CHILD_SA selection out of attribute loop
2010-10-05 08:02:07 +02:00
Andreas Steffen
28b23fef11
receive name of preferred CHILD_SA via RADIUS Filter-Id attribute
2010-10-05 07:58:07 +02:00
Andreas Steffen
0cfdbaff2c
set EAP-TTLS/TNC version also in acknowledgement packets
2010-10-04 14:39:49 +02:00
Martin Willi
a8809bb0cb
Fixed status_t enum names definition
2010-10-04 10:48:00 +02:00
Andreas Steffen
a00a43e0f6
print XML as plaintext and process recieved TNCCS Batch
2010-09-30 23:34:00 +02:00
Andreas Steffen
f685b3aca0
started use of libtnc library
2010-09-29 23:24:59 +02:00
Andreas Steffen
3c354b6d11
NOTIFY error message types include 16383
2010-09-29 19:01:36 +02:00
Andreas Steffen
4e8e74fcfa
moved TNCCS layer out of eap_tnc plugin
2010-09-28 23:34:04 +02:00
Andreas Steffen
2b3124c76d
fixed release of virtual IP for XAUTH identities
2010-09-26 10:17:01 +02:00
Tobias Brunner
f22ba072e8
draft-ietf-ipsecme-eap-mutual will be released as RFC 5998.
2010-09-16 10:27:49 +02:00
Andreas Steffen
004de55235
added notify messages defined in RFC 5996
2010-09-15 12:48:58 +02:00
Andreas Steffen
80f86acccb
show validity of OCSP responses
2010-09-10 22:26:03 +02:00
Tobias Brunner
0a1233e642
Moved man pages for config files to a separate directory.
2010-09-10 12:01:19 +02:00
Andreas Steffen
f3051ebf53
fixed memory leak
2010-09-09 21:38:41 +02:00
Martin Willi
663e735553
Compare subject against all key identifiers in has_subject()
2010-09-09 17:46:20 +02:00
Andreas Steffen
f85f0c2795
has_subject() now resolves ID_KEY_IDs
2010-09-09 17:15:46 +02:00