Martin Willi
e13389a7f7
got rid of deprecated create_iterator_locked()
2008-11-05 08:32:38 +00:00
Martin Willi
5dffdea1d7
added hooks for IKE and CHILD keymat
2008-10-30 12:58:54 +00:00
Martin Willi
80853d8498
moved CHILD_SA key derivation to keymat_t
...
passing key chunks to CHILD_SA, not the PRF
2008-10-29 16:06:16 +00:00
Martin Willi
6a4ff35cc4
moved key derivation and management into keymat object
...
allows secured implementation of key management (e.g. in kernel or HW)
only IKE keys for now
2008-10-28 16:07:06 +00:00
Martin Willi
3c8234d408
store IKE proposal implicitly during derive_keys
2008-10-28 10:12:21 +00:00
Martin Willi
20fb671904
fixed reauthentication time in statusall
2008-10-28 09:41:33 +00:00
Martin Willi
85ac2fa547
use more generic stats getter, introducing new stats
2008-10-27 14:51:00 +00:00
Martin Willi
a1db79b31a
fixed some compiler warnings
2008-10-27 11:13:33 +00:00
Martin Willi
82d20c0588
additional getters for ipcomp and UDP encap
2008-10-24 09:51:48 +00:00
Martin Willi
6e10aeadab
more CHILD_SA refactorings
2008-10-24 08:02:35 +00:00
Martin Willi
1df106bf39
cache keys for in and outbound ESP SAs
...
removed redundant storing of traffic selectors in CHILD_SA (sa_policy_t)
creating TS pairs dynamically using create_policy_enumerator()
2008-10-15 12:24:44 +00:00
Martin Willi
9f4e5f8c47
store ESP keys in CHILD_SA
2008-10-15 08:37:56 +00:00
Martin Willi
a985db3ff3
reintegrated bus-refactoring branch
2008-10-14 08:52:13 +00:00
Andreas Steffen
d1cbe55127
implemented ipsec listalgs as a stroke command
2008-10-08 07:00:13 +00:00
Martin Willi
9c0aa46b64
use dpd_action also for remotely closed tunnels
2008-10-02 13:47:19 +00:00
Tobias Brunner
a341a68fac
merging renaming of mode_t to ipsec_mode_t back to trunk
2008-09-25 13:56:23 +00:00
Tobias Brunner
507f26f685
merging modularized kernel interface back to trunk
2008-09-25 07:56:58 +00:00
Andreas Steffen
b33c11b6c7
stroke parses and lists AC groups
2008-09-17 02:17:01 +00:00
Martin Willi
f7c17aa15c
refactored credential builder
...
allow enumeration of matching builders
try a second builder if the first one fails
builder clones resources internally on demand
caller frees added resources on failure and success
stricter handling of non-supported build parts
2008-09-02 11:00:13 +00:00
Andreas Steffen
8fa6f2dc66
streamlined ipsec listalgs output
2008-08-29 05:35:09 +00:00
Martin Willi
9482208633
crypto_factory algorithm enumeration API
...
implementation of "ipsec listalgs"
2008-08-28 09:24:42 +00:00
Andreas Steffen
41dc6b56b0
ipsec statusall lists eap_type and eap_identity
2008-08-26 19:45:44 +00:00
Andreas Steffen
919019b3cd
completed support of AUTHZ_CA_CERT and AUTHZ_CA_CERT_NAME attributes
2008-08-26 05:15:34 +00:00
Andreas Steffen
3c87e92695
list CA restrictions in ipsec statusall
2008-08-25 12:35:18 +00:00
Martin Willi
822901061b
ported parts of two-sim branch
...
eap_identity parameter to exchange in eap_identity
some auth_info/peer_cfg refactorings
fixed some bugs, introduced new ones
2008-08-22 10:44:51 +00:00
Martin Willi
19ad10b5d3
increased stroke socket backlog to 10
2008-07-30 14:17:05 +00:00
Martin Willi
38a8e39739
using shared read locks in credential set enumerators to avoid deadlocks
2008-07-30 11:38:44 +00:00
Andreas Steffen
32f5ee159e
cosmetics
2008-07-22 12:13:48 +00:00
Andreas Steffen
66da78b4bb
ipsec status lists IPCOMP CPIs
2008-07-22 12:03:58 +00:00
Andreas Steffen
eba7470b76
consistent logging of SPIs and CPIs
2008-07-22 10:16:45 +00:00
Martin Willi
a4a3e0c7dc
introduced an additional bus->signal parameter for signal specific data
...
added SIG_IKE/SIG_CHD macros for signal emitting
2008-07-18 15:51:40 +00:00
Andreas Steffen
858a9fd584
update_peerid() does not accept %any as a certificate's subjectAltName
2008-07-09 22:13:39 +00:00
Andreas Steffen
2c258d7373
ipsec statusall displays dpd options
2008-07-02 10:48:57 +00:00
Martin Willi
131064995a
added a "ipsec down-srcip <start> [<end>]" command to terminate IKE_SAs by remote virtual ip
2008-07-01 12:48:56 +00:00
Andreas Steffen
5397a7f91d
show authentication method in ipsec statusall
2008-06-30 17:08:47 +00:00
Martin Willi
eec675bf8c
enumerating loaded plugins in "ipsec statusall"
2008-06-24 12:49:04 +00:00
Tobias Brunner
ad4d3f81c1
changed ipsec.secrets keyword EC to ECDSA
2008-06-24 06:57:47 +00:00
Andreas Steffen
7c8eff1eaa
cosmetics
2008-06-23 09:08:49 +00:00
Martin Willi
857ba3574b
fixed "double-close" of stroke fd resulting in "bad fd" errors if multiple threads are active
2008-06-23 08:53:37 +00:00
Andreas Steffen
bc997f6583
display selected IKE proposal in ipsec statusall
2008-06-22 11:24:33 +00:00
Tobias Brunner
ea0823dffd
ECDSA with OpenSSL
2008-06-10 09:08:27 +00:00
Martin Willi
5a22a02156
DNS resolving of ike_cfg hosts dynamically on demand
2008-06-06 15:05:54 +00:00
Andreas Steffen
f9b1bcad24
do not list empty certuribase strings
2008-05-24 05:47:37 +00:00
Andreas Steffen
0672aa7b0e
added display of holderIssuer, holderSerial, and authorityKeyIdentifier
2008-05-23 14:24:24 +00:00
Andreas Steffen
7199d22e77
implement basic listing of attribute certificates
2008-05-22 21:58:22 +00:00
Andreas Steffen
a327ee9589
suppress listing of integrity algorithm if it is undefined
2008-05-17 21:52:58 +00:00
Martin Willi
a3d92a3745
plugin load configuration in strongswan.conf
...
some components accept a "component.load" option with a space separated list of plugins to load
libcharon- plugins are now handled the same way as libstrongswan- plugins
2008-05-15 14:01:26 +00:00
Martin Willi
0fd4caea66
handle ID_KEY_ID as a ID_PUBKEY_SHA1 for authentication
2008-05-14 06:49:31 +00:00
Andreas Steffen
f85d02a419
fixed typos
2008-05-11 20:36:14 +00:00
Tobias Brunner
d4aad55434
IPComp for IKEv2
2008-05-08 16:19:11 +00:00