Commit Graph
8191 Commits
Author SHA1 Message Date
Clavister OpenSource d71092ceed Setting Mode Cfg identifier for CFG_ACK messages. 2012-03-20 17:31:32 +01:00
Clavister OpenSource e32820f593 Add functions to set mode cfg identifier 2012-03-20 17:31:32 +01:00
Martin Willi 462c9a4f72 Try all matching XAuth secrets we find, not only the first one 2012-03-20 17:31:32 +01:00
Martin Willi 3d86d76b86 Fixed create_shared_enumerator method description 2012-03-20 17:31:31 +01:00
Martin Willi f56c3c53f6 As responder, try to reuse the reqid of the CHILD_SA the initiator is rekeying 2012-03-20 17:31:31 +01:00
Martin Willi 31bd5c8c0e Reply quick mode with the same SA lifetime that we received 2012-03-20 17:31:31 +01:00
Martin Willi 3a925f74ab Do not query CHILD_SA during delete if they already expired 2012-03-20 17:31:31 +01:00
Martin Willi 07202a2bf1 Be less verbose when deleting SAs triggered by a hard expire 2012-03-20 17:31:31 +01:00
Martin Willi 23eb447c9a Implemented CHILD_SA rekeying 2012-03-20 17:31:31 +01:00
Martin Willi 634ac410a2 Don't return FAILED if a CHILD_SA to delete could not be found 2012-03-20 17:31:31 +01:00
Martin Willi 14dc794165 Support installing of quick mode SAs with a specific reqid 2012-03-20 17:31:31 +01:00
Martin Willi 5f1df0a060 Double check that we could select a TS as quick mode responder 2012-03-20 17:31:31 +01:00
Martin Willi f5a84055fe Implemented responder retransmission, currently enabled for quick mode only 2012-03-20 17:31:30 +01:00
Martin Willi dc8e964775 Queue IKEv1 INFORMATIONALS with higher priority to process notifies first 2012-03-20 17:31:30 +01:00
Martin Willi 96f98a8c11 Accept IKEv1 INVALID_KE_INFORMATION notifies without data 2012-03-20 17:31:30 +01:00
Martin Willi 253d7e3eff Don't process notifies in quick mode task when we get an INFORMATIONAL 2012-03-20 17:31:30 +01:00
Martin Willi 9276f7121c Always queue a new passive task when receiving an IKEv1 INFORMATIONAL 2012-03-20 17:31:30 +01:00
Tobias Brunner db1dc81329 IKEv1 ATTRIBUTES_NOT_SUPPORTED error notify added. 2012-03-20 17:31:30 +01:00
Martin Willi 8a395e889c Fixed leak of a hash when checking out by hash 2012-03-20 17:31:30 +01:00
Martin Willi dd5c3787dc Give a hint that decryption failed if payload length invalid 2012-03-20 17:31:30 +01:00
Martin Willi 07b8ec7c00 Cast keymat safely, not based on external input 2012-03-20 17:31:30 +01:00
Martin Willi 3bacc1f429 Added a keymat_t version to cast it safely 2012-03-20 17:31:30 +01:00
Martin Willi 3d54ae94d9 Handle initiation of not supported IKE versions properly 2012-03-20 17:31:30 +01:00
Martin Willi daee47ba46 Send a delete for every CHILD_SA before deleting IKE_SA 2012-03-20 17:31:30 +01:00
Martin Willi 6379c679ae Set used auth_class in PSKv1 authenticator to comply to constraints 2012-03-20 17:31:30 +01:00
Martin Willi 8573b18d22 Fixed scheduling of IKEv2 init tasks in a second keyingtry 2012-03-20 17:31:29 +01:00
Martin Willi 8ed976c061 Don't requeue IKEv1 init tasks if they already exist in a second keyingtry 2012-03-20 17:31:29 +01:00
Tobias Brunner fd5d6bb08e Use IPSEC DOI also for ISAKMP SA deletes. 2012-03-20 17:31:29 +01:00
Martin Willi d9c1dae293 Implemented resetting of IKEv1 task manager, enabling additional keyingtries 2012-03-20 17:31:29 +01:00
Martin Willi 94450913ef Fixed migration of NATD task 2012-03-20 17:31:29 +01:00
Martin Willi bce22af29e Implemented migration of quick mode task 2012-03-20 17:31:29 +01:00
Martin Willi ca037076bf Implemented migration of XAuth task 2012-03-20 17:31:29 +01:00
Martin Willi 5903acd0ff Implemented migration of certificate handling tasks 2012-03-20 17:31:29 +01:00
Martin Willi 451ebecc85 Implemented migration of Main Mode task 2012-03-20 17:31:29 +01:00
Martin Willi 448e2e2945 Check message version before processing it on an IKE_SA 2012-03-20 17:31:29 +01:00
Martin Willi 986237603f Fix ike_version_t enum names 2012-03-20 17:31:29 +01:00
Martin Willi 82b1e5e270 Accept NULL as keymat when generating a message 2012-03-20 17:31:29 +01:00
Martin Willi 53300baded Send correct INVALID_MAJOR_VERSION when receiving packet with unsupported protocol 2012-03-20 17:31:28 +01:00
Martin Willi be83ea7ebf Drop IKEv1 main/aggressive modes if peer to aggressive 2012-03-20 17:31:28 +01:00
Martin Willi 87791f7538 Added description for the xauth-eap plugin 2012-03-20 17:31:28 +01:00
Martin Willi 28e3c6595d Check if a config has been selected before narrowing selectors in quick mode 2012-03-20 17:31:28 +01:00
Martin Willi 85fc1eb640 Added an XAuth plugin that forwards authentication to EAP methods 2012-03-20 17:31:28 +01:00
Martin Willi 747f837cce Added a flag to register local credential sets exclusively, disabling all others 2012-03-20 17:31:28 +01:00
Martin Willi 5d1677f52d Added missing XAuth plugin feature enum names 2012-03-20 17:31:28 +01:00
Martin Willi 438a8d785f Added a TODO for creating IKE_SAs with unsupported protocol version 2012-03-20 17:31:28 +01:00
Martin Willi 38bb727c06 Don't accept IKEv2 packets if IKEv2 disabled 2012-03-20 17:31:28 +01:00
Martin Willi 7d788af0a0 Don't include ikev1/ikev2 subfolders in build when using --disable-ikev1/ikev2 2012-03-20 17:31:28 +01:00
Martin Willi 326a94232d Moved eap/xauth classes out of protocol specific subdirectories 2012-03-20 17:31:27 +01:00
Martin Willi 3b08de850a Removed obsolete task header inclusion in IKE_SA 2012-03-20 17:31:27 +01:00
Martin Willi 873df908cc Moved MOBIKE task creation to protocol specific task manager 2012-03-20 17:31:27 +01:00