Andreas Steffen
88e15afc8c
added comment to determine_tnccs_protocol() function
2011-01-31 05:31:22 +01:00
Andreas Steffen
f652995b21
implemented dynamic detection of TNCCS protocol
2011-01-31 00:59:17 +01:00
Martin Willi
5c89a00f05
Do not log potentially hundreds of cert requests for unknown CAs at level 1
2011-01-28 08:29:23 +01:00
Martin Willi
60b71def1a
Use wrapped threading functions in ha plugin
2011-01-20 15:52:29 +01:00
Thomas Egerer
f2e2a40550
Fix potential use after free
2011-01-19 09:59:01 +01:00
Martin Willi
ff5538e5c0
Use newer Linux capability native API, if available
2011-01-17 18:18:21 +01:00
Martin Willi
983a5e88d3
Revert "Send INITIAL_CONTACT even if we have a unique policy"
...
It makes sense to omit INITIAL_CONTACT if don't have a unique policy,
as a client might want to connect from different devices to the same
account.
This reverts commit 719c33b41a .
2011-01-13 10:50:46 +01:00
Martin Willi
9bac426bf3
Fixed memory cleanup if no DHCP transaction found for an OFFER
2011-01-13 10:36:16 +01:00
Martin Willi
2082417df3
Force port update as responder when initiator switches to 4500 in IKE_AUTH
2011-01-12 14:37:15 +01:00
Martin Willi
8ba805f4db
Avoid variable name overloading
2011-01-12 14:37:09 +01:00
Andreas Steffen
213281de04
terminate TNCCS 1.1 connection after sending recommendation
2011-01-11 01:17:40 +01:00
Andreas Steffen
4c8e9708ca
fixed XML syntax for TNCCS-Recommendation messages
2011-01-11 01:17:40 +01:00
Andreas Steffen
59d1b15aea
implemented check_and_build_recommendation()
2011-01-11 01:17:40 +01:00
Andreas Steffen
21d96f44f7
correct numbering of batches
2011-01-11 01:17:40 +01:00
Andreas Steffen
8d0d0f0fe9
initialize the reference count correctly
2011-01-11 01:17:40 +01:00
Andreas Steffen
f33966fe8f
handle zero size Base64 conversions
2011-01-11 01:17:40 +01:00
Andreas Steffen
8a284e0454
communicate DELETE state to IMCs and IMVs
2011-01-11 01:17:40 +01:00
Martin Willi
719c33b41a
Send INITIAL_CONTACT even if we have a unique policy
2011-01-10 11:54:10 +01:00
Andreas Steffen
5fee822a93
implemented parsing of TNCCS 1.1 messages
2011-01-09 10:00:54 +01:00
Andreas Steffen
33749b879c
send notifyConnectionChange() to IMCs
2011-01-09 10:00:13 +01:00
Andreas Steffen
8235528840
generate TNCCS-Error messages
2011-01-08 02:17:42 +01:00
Andreas Steffen
1c4b4f76ad
created process() method for TNCCS messages
2011-01-08 02:17:42 +01:00
Martin Willi
44e513a320
Added support for trustchain key strength checking to rightauth option
2011-01-07 15:51:35 +01:00
Martin Willi
6367de28ad
Added a left/rightcertpolicy keyword to specify certificatePolicy requirements
2011-01-07 15:51:35 +01:00
Martin Willi
1ed482d808
Fix nonce comparison in rekey collisions, lowest nonce loses
2011-01-07 15:51:35 +01:00
Andreas Steffen
3a04dfaaf6
corrected naming of tnccs_reason_strings_msg_t object
2011-01-07 07:18:42 +01:00
Andreas Steffen
87fd83a91e
do not forget to advance node
2011-01-07 07:17:52 +01:00
Andreas Steffen
3e348daae5
fixed cert_validator_t:validate interface
2011-01-07 05:41:01 +01:00
Andreas Steffen
d9e21bf180
implemented TNCCS 1.1 without libtnc
2011-01-07 05:29:59 +01:00
Martin Willi
6f5892f5c7
Destroy existing IKE_SAs with same identities when receiving INITIAL_CONTACT
2011-01-05 16:46:08 +01:00
Martin Willi
a4a1e24d37
Send INITIAL_CONTACT for the first IKE_SA if it has a unique policy
2011-01-05 16:46:08 +01:00
Martin Willi
240bd7dbb7
Migrated ike_sa_manager_t to INIT/METHOD macros, some cleanups
2011-01-05 16:46:08 +01:00
Martin Willi
2e90006f96
Show base CRL of delta CRLs in listcrls
2011-01-05 16:46:06 +01:00
Martin Willi
3a89b3c52f
Provide CRLs received in CERT payloads to trustchain verification
2011-01-05 16:46:06 +01:00
Martin Willi
b3d359e58f
Use a generic getter for all numerical X.509 constraints
2011-01-05 16:46:05 +01:00
Martin Willi
5dba5852fc
Slightly renamed X509_NO_PATH_LEN_CONSTRAINT to use it for PolicyConstraints, too
2011-01-05 16:46:02 +01:00
Martin Willi
1038d9fee5
Added a null-safe strdup variant
2011-01-05 16:46:02 +01:00
Martin Willi
5f15faebc8
Include the used reserved bytes from ID payloads in AUTH calculation
2011-01-05 16:45:53 +01:00
Martin Willi
502edf425f
Migrated psk/pubkey_authenticators to INIT/METHOD macros
2011-01-05 16:45:53 +01:00
Martin Willi
54f2bdd656
Added substructure enumerators to sa_payload, proposal_substructure
2011-01-05 16:45:52 +01:00
Martin Willi
9ca5d0280e
Moved check if packet already encoded to ike_sa, avoids message() hook invocation twice
2011-01-05 16:45:52 +01:00
Martin Willi
2813be18f5
Added a message method to set the "higher version supported" flag
2011-01-05 16:45:52 +01:00
Martin Willi
166a2a45d9
Added reserved bit mangling wrapper functions to message
2011-01-05 16:45:51 +01:00
Martin Willi
e662d62a76
Implemented a generic payload field lookup function
2011-01-05 16:45:51 +01:00
Martin Willi
bf029696c6
Reserved field get parsed/generated like any other bit/byte field
2011-01-05 16:45:51 +01:00
Martin Willi
c93c7a7560
Added member fields for reserved bits and bytes in all payloads
2011-01-05 16:45:51 +01:00
Martin Willi
1b671248c2
Migrated vendor_id_payload to INIT/METHOD macros
2011-01-05 16:45:51 +01:00
Martin Willi
102adb9bfd
Migrated ts_payload to INIT/METHOD macros
2011-01-05 16:45:51 +01:00
Martin Willi
1f5b2bec4b
Use enumerator instead of deprecated iterator
2011-01-05 16:45:51 +01:00
Martin Willi
9f8ecff2e2
Migrated transform_substructure to INIT/METHOD macros
2011-01-05 16:45:51 +01:00