Tobias Brunner
700ff5def9
Added eap-dynamic plugin which can proxy any other EAP method
2012-08-31 11:42:01 +02:00
Tobias Brunner
09ae3d79ca
Merge branch 'android-app'
...
This branch introduces a userland IPsec implementation (libipsec) and an
Android App which targets the VpnService API that is provided by Android 4+.
The implementation is based on the bachelor thesis 'Userland IPsec for
Android 4' by Giuliano Grassi and Ralf Sager.
2012-08-13 12:07:52 +02:00
Tobias Brunner
e4ef4c9877
Merge branch 'android-ndk'
...
This branch comes with some preliminary changes for the user-land IPsec
implementation and the Android App.
One important change is that the UDP ports used by the socket-default plugin
were made configurable (either via ./configure or strongswan.conf).
Also, the plugin does randomly allocate a port if it is configured to 0,
which is useful for client implementations. A consequence of these
changes is that the local UDP port used when creating ike_cfg_t objects has
to be fetched from the socket.
2012-08-13 10:45:39 +02:00
Martin Willi
b9e4916321
Add xauth-pam, an XAuth backend verifying credentials with PAM
2012-08-10 10:43:44 +02:00
Tobias Brunner
5764a9b355
Moved packet_t to libstrongswan
2012-08-08 15:41:02 +02:00
Tobias Brunner
162621ed57
Moved Android specific logger to separate plugin.
...
This is mainly because the other parts of the existing android plugin
can not be built in the NDK (access to keystore and system properties are
not part of the stable NDK libraries).
2012-08-08 15:07:43 +02:00
Martin Willi
f02a305569
Fix linking of addrblock plugin when building monolithic
...
Fixes #212 .
2012-08-03 10:50:21 +02:00
Martin Willi
0619ddfaa4
Refactored heavily #ifdefd capability code to its own libstrongswan class
2012-07-04 11:01:40 +02:00
Tobias Brunner
eac9d77059
Job added to re-initiate an IKE_SA.
2012-05-30 15:32:52 +02:00
Tobias Brunner
7a56c35fc9
Remove executable flag from source files.
2012-05-18 10:04:08 +02:00
Martin Willi
4b38c22c00
Schedule a DPD timeout job that enforces the IKE message timeout policy
2012-05-15 14:46:02 +02:00
Tobias Brunner
b64f333612
Integrate nm plugin directly in charon-nm.
2012-05-03 13:57:03 +02:00
Tobias Brunner
94b48e071a
Provide plugin list from charon, not internally in libcharon.
2012-05-03 13:14:07 +02:00
Tobias Brunner
0e474f9148
Use a separate interface for loggers.
...
The new interface does not allow loggers to unregister themselves from
the bus. This allows us to use a rwlock_t for them.
The latter also means that loggers can now be called concurrently by
multiple threads.
2012-05-02 14:45:38 +02:00
Martin Willi
b1f2f05c92
Merge branch 'ikev1-clean' into ikev1-master
...
Conflicts:
configure.in
man/ipsec.conf.5.in
src/libcharon/daemon.c
src/libcharon/plugins/eap_ttls/eap_ttls_peer.c
src/libcharon/plugins/eap_radius/eap_radius_accounting.c
src/libcharon/plugins/eap_radius/eap_radius_forward.c
src/libcharon/plugins/farp/farp_listener.c
src/libcharon/sa/ike_sa.c
src/libcharon/sa/keymat.c
src/libcharon/sa/task_manager.c
src/libcharon/sa/trap_manager.c
src/libstrongswan/plugins/x509/x509_cert.c
src/libstrongswan/utils.h
Applied lost changes of moved files keymat.c and task_manager.c.
Updated listener_t.message hook signature in new plugins.
2012-03-20 17:57:53 +01:00
Clavister OpenSource
3e6b740336
Isakmp_dpd task added.
2012-03-20 17:31:35 +01:00
Martin Willi
ee325b555f
Implemented aggressive mode using Phase 1 helper class
2012-03-20 17:31:33 +01:00
Martin Willi
c29a89b80d
Implemented a common Phase 1 helper class to use by main and aggressive modes
2012-03-20 17:31:33 +01:00
Martin Willi
b147679a2c
Try to detect reauthentication as responder and adopt children to new SA
2012-03-20 17:31:33 +01:00
Martin Willi
85fc1eb640
Added an XAuth plugin that forwards authentication to EAP methods
2012-03-20 17:31:28 +01:00
Martin Willi
7d788af0a0
Don't include ikev1/ikev2 subfolders in build when using --disable-ikev1/ikev2
2012-03-20 17:31:28 +01:00
Martin Willi
326a94232d
Moved eap/xauth classes out of protocol specific subdirectories
2012-03-20 17:31:27 +01:00
Martin Willi
15a682f4c2
Separated libcharon/sa directory with ikev1 and ikev2 subfolders
2012-03-20 17:31:26 +01:00
Martin Willi
2e3c9f8799
Renamed ike_vendor_v1 to isakmp_vendor
2012-03-20 17:31:26 +01:00
Martin Willi
79d6fc7f72
Renamed ike_natd_v1 to isakmp_natd
2012-03-20 17:31:26 +01:00
Martin Willi
824dc0adad
Renamed ike_cert_pre_v1 to isakmp_cert_pre
2012-03-20 17:31:26 +01:00
Martin Willi
0aa2af5efc
Renamed ike_cert_post_v1 to isakmp_cert_post
2012-03-20 17:31:26 +01:00
Martin Willi
5f10938592
Added a dedicated IKEv1 task to delete CHILD_SAs
2012-03-20 17:31:22 +01:00
Martin Willi
8db202f1b0
Added a dedicated delete task for IKEv1 IKE_SAs
2012-03-20 17:31:21 +01:00
Martin Willi
29101ce978
Added a IKEv1 hybrid authenticator based on Pubkey/PSK authenticators
2012-03-20 17:31:21 +01:00
Martin Willi
f492907667
Added a task stub to create and process IKEv1 informational exchanges
2012-03-20 17:31:18 +01:00
Tobias Brunner
3d44d735c6
Added generic XAuth backend, using secrets provided by credential sets.
2012-03-20 17:31:17 +01:00
Tobias Brunner
41e1e435d9
Removed xauth-null dummy plugin.
2012-03-20 17:31:17 +01:00
Martin Willi
b155084c42
Added IKEv1 Mode Config task based on IKEv2 ike_config
2012-03-20 17:31:16 +01:00
Martin Willi
4e73f85b81
Remove xauth_authenticator, we handle it in the task
2012-03-20 17:31:15 +01:00
Martin Willi
69adeb5bf2
Replace xauth_request task with a new stub where we reimplement it
2012-03-20 17:31:15 +01:00
Martin Willi
7c27c914d4
Implemented IKEv1 pubkey SIG payload processing in an authenticator
2012-03-20 17:31:14 +01:00
Martin Willi
2792587875
Implemented IKEv1 PSK HASH payload processing in separated authenticator
2012-03-20 17:31:14 +01:00
Martin Willi
c64a4b4f8e
Implemented post-authentication certificate handling for IKEv1
2012-03-20 17:31:13 +01:00
Martin Willi
0bcdb8e571
Implemented pre-authentication certificate handling for IKEv1
2012-03-20 17:31:13 +01:00
Clavister OpenSource
f00ffe4dd2
IKEv1 XAuth: Added changes to Makefile.am to compile the xauth_null plugin.
2012-03-20 17:31:11 +01:00
Clavister OpenSource
9c5366446a
IKEv1 XAuth: Added plugin support for XAuth, which allows us to have plugins to talk to servers with different quirks for XAuth authentication.
2012-03-20 17:31:11 +01:00
Tobias Brunner
1cc4ec46cf
Task added for IKEv1 NAT detection.
...
There is already support for both Main and Aggressive Mode.
2012-03-20 17:31:10 +01:00
Clavister OpenSource
2e210e3ef5
IKEv1 XAuth: Added a job to call the initiate_xauth method of ike_sa after the completion of the current set of tasks is complete.
2012-03-20 17:31:09 +01:00
Martin Willi
a2f8fc9711
Use a dedicated IKEv1 vendor ID task to fix using IKEv2 payloads in IKEv1
2012-03-20 17:31:07 +01:00
Martin Willi
017d98bf39
Merged IKEv1 attribute payload/data into configuration payload/attribute
2012-03-20 17:30:49 +01:00
Clavister OpenSource
23f4e4b42d
IKEv1 XAUTH: Added ability to configure XAUTH+PSK. Added task to handle XAUTH requests. Modified task_manager_v1 to enable it to initiate new tasks immediately after finishing a response.
2012-03-20 17:30:49 +01:00
Clavister OpenSource
54a8a94fa9
IKEv1 ConfigMode: Added TRANSACTION exchange type. Added attribute_payload (IKEv2 equiv cp_payload) and data_attribute (IKEv2 equiv configuration_attribute) payload types. Did not combine with IKEv2 because it wasn't trivial to do so. This might be a task worth investigating in the future, because there is a decent amount of shared code here.
2012-03-20 17:30:49 +01:00
Martin Willi
2b04aa46ea
Added a quick mode task stub
2012-03-20 17:30:44 +01:00
Tobias Brunner
273f2f8054
Added factory function to create task_manager_t implementations.
2012-03-20 17:30:43 +01:00