Martin Willi
7455ab063f
Added a function to segmentate a generic integer
2010-07-28 10:06:19 +02:00
Martin Willi
c03b64a4ac
Reserving does not work, as our pools do not support acquiring arbitrary addresses
...
This reverts commit d1384080b3 .
2010-07-27 12:05:39 +02:00
Martin Willi
7eeb687d59
Flush any remaining cache state if an IKE_SA goes down
2010-07-27 09:18:06 +02:00
Martin Willi
fa4f71c819
Synchronize EAP-Identity of remote peer
2010-07-26 15:10:54 +02:00
Martin Willi
d1384080b3
Reserve virtual IP of passive IKE_SAs in the local pool
2010-07-26 15:01:24 +02:00
Martin Willi
65d15aff73
Added strongswan.conf options for HA heartbeat
2010-07-26 14:30:19 +02:00
Martin Willi
08e266a119
Log CHILD_SA segment responsibility
2010-07-26 13:53:54 +02:00
Martin Willi
3e6736f67e
Pass initiator parameter to distinguish between original and exchange initiator
2010-07-26 13:53:53 +02:00
Martin Willi
b2e447e24a
Pass the CREATE_CHILD_SA initiator flag to the child_keys parameter
2010-07-26 13:53:53 +02:00
Martin Willi
aa334daa9b
Use a sync message cache to resynchronize IKE_SAs without rekeying
2010-07-26 13:53:49 +02:00
Martin Willi
2031002d42
Log received HA message types
2010-07-26 11:33:00 +02:00
Martin Willi
f2eebed2a3
Add enum names for HA message types
2010-07-26 11:33:00 +02:00
Martin Willi
51217527e6
Delay resynchronization request until starter has loaded the configurations
2010-07-26 11:33:00 +02:00
Martin Willi
2cbc48ecab
Replaces in_segment() by a more generic get_segment() function
2010-07-26 11:33:00 +02:00
Martin Willi
ad2488fcdf
Use distinct message types for HA message ID updates
2010-07-26 10:15:17 +02:00
Martin Willi
00c1bd0606
Migrated ha plugin to INIT/METHOD macros
2010-07-26 10:15:17 +02:00
Martin Willi
ce7967c50c
Implemented support for multiple RADIUS servers
2010-07-21 17:25:09 +02:00
Martin Willi
58d2ef6e14
Migrated eap-radius plugin to INIT/METHOD macros
2010-07-21 17:09:27 +02:00
Martin Willi
5b6c220d13
Added log statement if peer requests EAP, but current config does not allow it
2010-07-21 17:09:15 +02:00
Andreas Steffen
ae0e3b03b7
in a ESP_IN_UDP situation make UDP port available in the updown script
2010-07-17 13:27:19 +02:00
Andreas Steffen
14665981a5
make xfrm marks available in the updown scripts
2010-07-17 13:08:50 +02:00
Martin Willi
0406eeaacb
Support different encoding types in certificate.get_encoding()
2010-07-13 13:53:20 +02:00
Martin Willi
da9724e6d0
Renamed key_encod{ing,der}_t and constants, prepare for generic credential encoding
2010-07-13 11:29:35 +02:00
Martin Willi
e57a29c731
Moved X509 ipAddrBlock checking to the addrblock plugin
2010-07-13 10:26:07 +02:00
Martin Willi
be715344c2
Added a hook to narrow traffic selectors for CHILD_SAs
2010-07-13 10:26:07 +02:00
Martin Willi
88fa56b1ad
Moved bus_t to METHOD/INIT macros
2010-07-13 10:26:07 +02:00
Martin Willi
1c8c924610
Moved addrblock plugin to libcharon
2010-07-13 10:26:07 +02:00
Martin Willi
2ccc02a4fd
Moved credential manager to libstrongswan
2010-07-13 10:26:07 +02:00
Martin Willi
2ca7db1337
Move pathlen constraint checking to X509 specific checks
2010-07-13 10:26:06 +02:00
Martin Willi
5db798c8e0
Charon uses a generic trunstchain length limit, not only for X509 certificates
2010-07-13 10:26:06 +02:00
Martin Willi
01bb70e4ad
Combined the OCSP/CRL options to a signle Online check option
2010-07-13 10:26:06 +02:00
Andreas Steffen
ab635e029e
updated SQL templates to support attribute pool and identity parameters
2010-07-12 20:28:34 +02:00
Tobias Brunner
af7b34b13b
Added missing pool parameter in DHCP attribute provider.
2010-07-12 12:27:49 +02:00
Martin Willi
52f97c3893
Do not interpret long class attributes (such as from NPS) as group
2010-07-09 13:53:43 +02:00
Martin Willi
cfa1c07604
Group membership constraint is fulfilled if subject is member in one of the groups
2010-07-09 13:51:58 +02:00
Heiko Hund
ec7adea007
Added support for named attribute groups
...
Add the possibility to group attributes by a name and assign these
groups to connections. This allows a more granular configuration of
which client will receive what atrributes.
2010-07-09 13:09:31 +02:00
Andreas Steffen
26c4d0102a
configuration of different marks for inbound and outbound direction
2010-07-09 09:06:07 +02:00
Martin Willi
6f07f5e3d4
The file logger supports a time prefix using a strftime() format specifier
2010-07-08 17:44:19 +02:00
Martin Willi
4cc9afe35f
Print identity to a lease address on the same line for simpler greping
2010-07-08 17:44:19 +02:00
Martin Willi
6c4cd8fa15
Implemented missing bypass_socket() method in load-testers faked kernel interface
2010-07-07 10:01:32 +02:00
Martin Willi
4f99093235
Show mallinfo() data in statusall, if available
2010-07-06 16:28:25 +02:00
Tobias Brunner
f395f28e44
Added missing markt_t in load tester, also migrated to INIT/METHOD macros.
2010-07-06 09:29:18 +02:00
Tobias Brunner
83b23011de
Some Doxygen fixes.
2010-07-05 15:04:30 +02:00
Tobias Brunner
8f7e8e075a
Fixed typo.
2010-07-05 14:53:56 +02:00
Martin Willi
a4c0da1669
Added support for group membership information containted in the RADIUS class attribute
2010-07-05 09:41:04 +02:00
Martin Willi
4172574bfb
Use the group constraint in a more generic fashion, not only for attribute certificates
2010-07-05 09:41:04 +02:00
Martin Willi
53913d764e
Use the responder side configured EAP-Identity directly, if given
2010-07-05 09:41:04 +02:00
Martin Willi
ec6caa1367
Copy EAP specific attributes to auth config only
2010-07-05 09:41:04 +02:00
Andreas Steffen
ee26c537d7
support of xfrm marks for IKEv2
2010-07-02 23:46:09 +02:00
Martin Willi
02571374c4
Recreate IKE_SA_INIT related tasks only if they have completed
2010-06-30 13:48:47 +02:00