Commit Graph
100 Commits
Author SHA1 Message Date
Martin Willi 7f3bf2b12f Remove outdated TODO information 2012-10-10 13:10:28 +02:00
Martin Willi 82f3549fe2 Fix leak of PINs from ipsec.secrets 2012-10-09 11:54:00 +02:00
Martin Willi 565bfc08c6 Add a libfast sendfile() method to send files from disk 2012-10-02 15:37:36 +02:00
Martin Willi 9564f9eb6e Include all dev headers, even if they are configuration specific 2012-10-02 11:39:55 +02:00
Martin Willi f0a2fef8a5 In mem_pool, check for an existing ID entry before creating a new one 2012-09-20 11:04:55 +02:00
Martin Willi a69bc12a3a Merge branch 'unity'
Add Cisco Unity extension support implemented in a dedicated plugin.
2012-09-18 17:22:47 +02:00
Martin Willi 995a9c8a0a Add a simple test case for the unity plugin, featuring both includes and excludes 2012-09-18 17:20:47 +02:00
Martin Willi f728ae590b Build unity plugin in strongSwan test suite 2012-09-18 17:17:49 +02:00
Martin Willi cc48f36084 Add unity plugin NEWS 2012-09-18 17:17:49 +02:00
Martin Willi 55f126fd55 Update ipsec.conf.5, leftsubnet can handle multiple subnets in IKEv1 with Unity 2012-09-18 17:17:48 +02:00
Martin Willi 77c37ea5e0 As Unity responder, don't change the proposed TS at all, racoon doesn't like that 2012-09-18 17:17:48 +02:00
Martin Willi 336dd7a9c7 Don't complain about multiple TS in IKEv1, as it supported with Unity 2012-09-18 17:17:48 +02:00
Martin Willi 7a7deec283 As initiator, narrow received Unity attributes to configured TS 2012-09-18 17:17:48 +02:00
Martin Willi b8db3775f3 When using Unity, bump up remote TS as initiator to 0.0.0.0/0, too 2012-09-18 17:17:48 +02:00
Martin Willi 284ed1b352 Enable Cisco Unity only if Unity vendor id received 2012-09-18 17:17:48 +02:00
Martin Willi 6e60807637 Exchange 0.0.0.0/0 traffic selectors with Unity, narrowing after exchange 2012-09-18 17:17:48 +02:00
Martin Willi f2463f1bd6 Add a Unity attribute provider that adds Split-Includes for TS 2012-09-18 17:17:47 +02:00
Martin Willi e39e697429 Check if subset calculation actually yields a TS in Unity narrowing 2012-09-18 17:17:47 +02:00
Martin Willi 92b5066705 Request Unity configuration attributes for IKEv1 only 2012-09-18 17:17:47 +02:00
Martin Willi 5ff012f717 Add Cisco Unity client support for Split-Include and Local-LAN 2012-09-18 17:17:47 +02:00
Martin Willi 56ea95195a Add a road-warrior test case requesting both an IPv4 and an IPv6 virtual address 2012-09-18 17:11:03 +02:00
Martin Willi 7ee37114c9 Derive a dynamic TS to multiple virtual IPs 2012-09-18 17:11:03 +02:00
Martin Willi abdb82fcc5 Use the vararg list constructor in quick mode task 2012-09-18 17:11:03 +02:00
Martin Willi 5f9d62fb91 Add a linked list constructor taking items from a vararg list 2012-09-18 17:11:02 +02:00
Martin Willi ab2c989c32 Don't allow NULL encryption with PEAP 2012-09-12 13:19:52 +02:00
Martin Willi acada66a35 Use memmove on overlapping regions, and operate with correct sizeof() 2012-09-12 13:19:52 +02:00
Martin Willi fb3cf1b708 Whitespace cleanups in tls_eap 2012-09-12 13:19:52 +02:00
Martin Willi 5b96503e13 Use uintptr_t in mem pool to avoid compiler warning if sizeof(void*) != sizeof(int) 2012-09-12 13:19:52 +02:00
Martin Willi d4cca1beea Always send a configuration payload in IKEv1 TRANSACTIONs, even if it is empty 2012-09-11 17:20:17 +02:00
Martin Willi c4acf37502 Don't use host address for dynamic TS in IKEv1 if a virtual IP was expected 2012-09-11 16:18:29 +02:00
Martin Willi 7d82aaea8d Don't use host address for dynamic TS in IKEv2 if a virtual IP was expected 2012-09-11 16:18:28 +02:00
Martin Willi 4cb0783f3c Don't return a subset for a dynamic TS unless set_address has been called 2012-09-11 16:18:28 +02:00
Martin Willi c7294f7a58 Send FAILED_CP_REQUIRED if a configuration payload was expected, but not received 2012-09-11 16:18:28 +02:00
Martin Willi 1e04488f32 Check for an existing lease in all stroke pools before creating a new one 2012-09-11 16:18:28 +02:00
Martin Willi 28a3d5bfbd Pass full pool list to release_address 2012-09-11 16:18:28 +02:00
Martin Willi 594c58e111 Pass the full list of pools to acquire_address, enumerate in providers
If the provider has access to the full pool list, it can enumerate
them twice, for example to search for existing leases first, and
only search for new leases in a second step.

Fixes lease enumeration in attr-sql using multiple pools.
2012-09-11 16:18:28 +02:00
Martin Willi dc7b79d8a5 Add a linked list constructor initializing from an enumerator 2012-09-11 16:18:28 +02:00
Martin Willi f942588f95 Add a responder narrow() hook to change TS in the kernel, but not on the wire 2012-09-11 16:14:39 +02:00
Martin Willi cf85ebbfec Support RADIUS accounting when using IKEv1 with xauth-eap and eap-radius 2012-09-11 15:22:22 +02:00
Martin Willi 37095ce1c1 Fix leak while enumerating RADIUS Framed-IPs from IKE_SA 2012-09-11 15:22:22 +02:00
Martin Willi c51af950b1 Add random plugin options to strongswan.conf.5 2012-09-10 17:07:51 +02:00
Martin Willi 7b68cd9212 Add strongswan.conf runtime options for /dev/[u]random files
Fixes #221.
2012-09-10 17:07:51 +02:00
Martin Willi 4c892fe533 In mode_config, destroy temporary pool list instead of the virtual IP list twice 2012-09-05 14:18:52 +02:00
Martin Willi 1323dc1138 Merge branch 'multi-vip'
Brings support for multiple virtual IPs and multiple pools in
left/rigthsourceip definitions. Also introduces the new left/rightdns
options to configure requested DNS server address family and respond
with multiple connection specific servers.
2012-08-31 12:55:56 +02:00
Martin Willi 69e056a2c1 Added multiple left/rightsourceip NEWS 2012-08-30 16:43:46 +02:00
Martin Willi e76f3d0df7 Added NEWS for left/rightdns options 2012-08-30 16:43:45 +02:00
Martin Willi 26bc695806 Updated ipsec.conf.5 with multiple left/rightsourceip support 2012-08-30 16:43:45 +02:00
Martin Willi 2df155958c Added a note to _updown for the new PLUTO_MY_SOURCEIP* variables 2012-08-30 16:43:45 +02:00
Martin Willi 7f52f621c2 Be less verbose if IP allocation for a single pool fails 2012-08-30 16:43:44 +02:00
Martin Willi 980c468cdc DHCP plugin returns virtual IPs for IPv4 requests only 2012-08-30 16:43:44 +02:00
Martin Willi 769446a8c7 Check address family in HA virtual IP backend 2012-08-30 16:43:44 +02:00
Martin Willi 40e9089889 Strictly enforce address family match while acquiring mem_pool IPs 2012-08-30 16:43:44 +02:00
Martin Willi 13f11ccf46 Don't parse comma separated pool names in attr-sql
We now handle multiple pools at a deeper level, making that special
handling obsolete. Comma separated pools are parsed in stroke.
2012-08-30 16:43:44 +02:00
Martin Willi 7b83cc62e0 Handle comma separated pools as multiple pool names in SQL plugin 2012-08-30 16:43:43 +02:00
Martin Willi b5d2bf975b Request and acquire multiple virtual IPs in IKEv1 Mode Config 2012-08-30 16:43:43 +02:00
Martin Willi 61d6ccf51c Request and acquire multiple virtual IPs in IKEv2 configuration payload 2012-08-30 16:43:43 +02:00
Martin Willi d55fe264d1 Pass all configured pool names to attribute provider enumerator 2012-08-30 16:43:43 +02:00
Martin Willi feb8550401 Pass a list instead of a single virtual IP to attribute enumerators 2012-08-30 16:43:42 +02:00
Martin Willi 96c2b3cf89 Support multiple addresses/pools in left/rightsourceip 2012-08-30 16:43:42 +02:00
Martin Willi 497ce2cf51 Support multiple address pools configured on a peer_cfg 2012-08-30 16:43:42 +02:00
Martin Willi 101d26babe Support multiple virtual IPs on peer_cfg and ike_sa classes 2012-08-30 16:43:42 +02:00
Martin Willi 584c063e36 Ported tun_device initialization to OS X utun 2012-08-28 11:16:31 +02:00
Martin Willi d8eec395b2 Add a getter for the mem_pool_t base address 2012-08-24 11:19:07 +02:00
Martin Willi da646ab94a Remove unused ipsec.conf left/rightnatip keyword 2012-08-21 09:38:01 +02:00
Martin Willi 2b08ae4524 Add description about DNS server variables to _updown 2012-08-21 09:38:01 +02:00
Martin Willi e0d3014a17 Add a DNS attribute handler to updown, passing servers to updown script 2012-08-21 09:38:01 +02:00
Martin Willi c60f1da424 Add a description of the leftdns option to ipsec.conf.5 2012-08-21 09:38:01 +02:00
Martin Willi 63e460542c Add a stroke attribute_handler requesting DNS servers given with leftdns 2012-08-21 09:38:01 +02:00
Martin Willi 9937ca069a Serve ipsec.conf rightdns servers through stroke attribute provider 2012-08-21 09:38:01 +02:00
Martin Willi 17319aa28d Add a left/rightdns keyword to configure connection specific DNS attributes 2012-08-21 09:38:00 +02:00
Martin Willi f26796deb5 Remove unused src/dst variables in send_no_marker() 2012-08-21 09:34:32 +02:00
Martin Willi 88a5abf5e2 Don't use POSIX semaphores if a MONOTONIC clock is available
POSIX semaphores use CLOCK_REALTIME, but our semaphore_t abstraction
expects CLOCK_MONOTONIC based times. Use the mutex/condvar based
fallback if time_monotonic() actuall returns monotonic times.
2012-08-20 18:01:20 +02:00
Martin Willi 10bdc7a968 Remove the unused second IKE_SA entry match function argument
LLVMs clang complains about this parameter, so remove it.
2012-08-20 17:42:14 +02:00
Martin Willi 907d3d0f1d Add a mutex/condvar based semaphore implementation if sem_timedwait is unavailable
Fixes #214.
2012-08-20 17:20:26 +02:00
Martin Willi a63192479d If _POSIX_SPIN_LOCKS is defined as -1, it is not available 2012-08-10 17:02:46 +02:00
Martin Willi 922fb29f89 If vstr printf functions are #defined, undef them before redefinition
At least Mountain Lion seems to have them #defined to secure _chk
variants.
2012-08-10 17:02:05 +02:00
Martin Willi cd55a3cb77 Use actual daemon name to enable XAuth/PSK with aggressive mode 2012-08-10 11:53:18 +02:00
Martin Willi 3423b3a88a Add xauth-pam/eap-gtc NEWS 2012-08-10 11:50:44 +02:00
Martin Willi 27128c1e32 EAP-GTC can use any XAuth backend, including xauth-pam
This makes EAP-GTC a generic plain password authentication method,
as it is used with XAuth. Instead of verifying credentials with
PAM, any backend can be configured. The default is xauth-pam,
providing the same functionality as EAP-GTC in strongSwan 4.x.
2012-08-10 10:43:44 +02:00
Martin Willi b9e4916321 Add xauth-pam, an XAuth backend verifying credentials with PAM 2012-08-10 10:43:44 +02:00
Martin Willi 0bac49b0a9 Add getspnam_r() to leak detective whitelist 2012-08-10 10:43:44 +02:00
Martin Willi 02cabd0f26 Check if TLS handshake received Finished before processing application data 2012-08-09 12:10:41 +02:00
Martin Willi 4e98ca1800 Remove queued IKEv1 message before processing it
Avoids destruction or processing of a queued message in
recursive process_message() call.
2012-08-08 14:54:03 +02:00
Martin Willi 7c6d6b0d89 PEM loading soft-depends on MD5 only, as unencrypted files don't need MD5
Fixes #211.
2012-08-03 15:25:17 +02:00
Martin Willi bd28543512 Rebuild charon after running ./configure to reflect plugin changes 2012-08-03 13:11:45 +02:00
Martin Willi 764035d515 Block XAuth transaction on established IKE_SAs, but allow Mode Config 2012-08-03 13:07:57 +02:00
Martin Willi f02a305569 Fix linking of addrblock plugin when building monolithic
Fixes #212.
2012-08-03 10:50:21 +02:00
Martin Willi 394b9f6b65 Reject initial exchange messages early once IKE_SA is established 2012-08-02 13:04:54 +02:00
Martin Willi 804d702b0a Add some more NEWS about 5.0.1 2012-08-02 12:23:59 +02:00
Martin Willi 11d6bc3eb0 Move MODP_CUSTOM va_arg fetching out of loop
It seems problematic at least on PPC with gcc 4.3, fixes #208.
2012-08-02 12:08:27 +02:00
Martin Willi f701ba8389 Lookup IKEv1 PSK even if the peer identity is not known 2012-07-31 15:39:33 +02:00
Martin Willi 777bcdc0d5 Don't include acquiring packet traffic selectors in IKEv1
As we only can negotiate a single TS in IKEv1, don't prepend the
triggering packet TS, as we do in IKEv2. Otherwise we don't establish
the TS of the configuration, but only that of the triggering packet.

Fixes #207.
2012-07-26 15:45:49 +02:00
Martin Willi 8b560a4565 Implement late peer config switching after XAuth authentication
If additional authentication constraints, such as group membership,
is not fulfilled by an XAuth backend, we search for another
peer configuration that fulfills all constraints, including those
from phase1.
2012-07-26 15:17:36 +02:00
Martin Willi 40ca05cff8 Check if XAuth round complies to configured authentication round 2012-07-26 12:40:27 +02:00
Martin Willi 6a8786b55f Show which group would be required when failing in constraint check 2012-07-26 12:39:53 +02:00
Martin Willi 874f7c7e2c Don't add ANY identity constraint to auth config, as XAuth rounds don't use one 2012-07-26 12:38:34 +02:00
Martin Willi 9191946a63 Merge auth config items added from XAuth backends to IKE_SA 2012-07-26 12:07:48 +02:00
Martin Willi 46df61dff7 Add an ipsec.conf leftgroups2 parameter for the second authentication round 2012-07-26 11:51:58 +02:00
Martin Willi 81419807f5 Release leaking child config after uninstalling shunt policy 2012-07-23 17:15:40 +02:00
Martin Willi 3b7468b245 Support Unity split-include/exclude options in attr plugin 2012-07-20 17:36:27 +02:00