Clavister OpenSource
|
fbbd439bf9
|
Added possibility to send notification if task_manager->process fails
|
2012-03-20 17:31:14 +01:00 |
|
Clavister OpenSource
|
1390daae15
|
Added status code to status_t
New status_t enum to allow packets to be sent to peer in task_manager->process
|
2012-03-20 17:31:14 +01:00 |
|
Clavister OpenSource
|
9ce5d0c0e8
|
added functions for getting/setting ISAKMP SPI to notify payload
|
2012-03-20 17:31:14 +01:00 |
|
Clavister OpenSource
|
a064eaa8a6
|
Handling of initial contact
|
2012-03-20 17:31:14 +01:00 |
|
Clavister OpenSource
|
751bd02e98
|
Added retransmissions for initiator.
|
2012-03-20 17:31:14 +01:00 |
|
Martin Willi
|
1755ac0617
|
Cleaned up quick mode notify processing
|
2012-03-20 17:31:14 +01:00 |
|
Martin Willi
|
5adf855e3d
|
Add support for KE payloads in IKEv1 quick mode (PFS)
|
2012-03-20 17:31:14 +01:00 |
|
Martin Willi
|
9bb4de1d83
|
En- and decode DH group attribute in quick mode SA payloads
|
2012-03-20 17:31:14 +01:00 |
|
Martin Willi
|
fb8bc6a764
|
Use authenticators in IKEv1 main mode
|
2012-03-20 17:31:14 +01:00 |
|
Martin Willi
|
76fe7de3fd
|
Added a factory function for IKEv1 authenticators
|
2012-03-20 17:31:14 +01:00 |
|
Martin Willi
|
7c27c914d4
|
Implemented IKEv1 pubkey SIG payload processing in an authenticator
|
2012-03-20 17:31:14 +01:00 |
|
Martin Willi
|
2792587875
|
Implemented IKEv1 PSK HASH payload processing in separated authenticator
|
2012-03-20 17:31:14 +01:00 |
|
Clavister OpenSource
|
5d1eeec297
|
Handle incoming delete messages
|
2012-03-20 17:31:13 +01:00 |
|
Andreas Steffen
|
6f6380e670
|
use untoh64 instead of non-portable be64toh
|
2012-03-20 17:31:13 +01:00 |
|
Martin Willi
|
c64a4b4f8e
|
Implemented post-authentication certificate handling for IKEv1
|
2012-03-20 17:31:13 +01:00 |
|
Martin Willi
|
9ad5b8fa95
|
Cleanup CERT payload constructors
|
2012-03-20 17:31:13 +01:00 |
|
Martin Willi
|
0bcdb8e571
|
Implemented pre-authentication certificate handling for IKEv1
|
2012-03-20 17:31:13 +01:00 |
|
Martin Willi
|
8c33850615
|
Added task types for IKEv1 certificate handling
|
2012-03-20 17:31:13 +01:00 |
|
Martin Willi
|
df06ef2098
|
Cleaned up certreq payload for IKEv2/IKEv1 use
|
2012-03-20 17:31:13 +01:00 |
|
Martin Willi
|
6ccabe2561
|
Reverted ike_cert tasks to IKEv2 only, we use dedicated IKEv1 tasks
|
2012-03-20 17:31:13 +01:00 |
|
Tobias Brunner
|
9f80110bc6
|
Install SAs with UDP encapsulation during Quick Mode.
|
2012-03-20 17:31:13 +01:00 |
|
Martin Willi
|
aaa8f88906
|
Fix support for plain RSA authentication in IKEv1, both as initiator and responder
|
2012-03-20 17:31:13 +01:00 |
|
Martin Willi
|
a974700fc0
|
Fix referencing of multiple CERTREQ payload with IKEv1, other cleanups
|
2012-03-20 17:31:12 +01:00 |
|
Martin Willi
|
695aff41f5
|
Encode a single IP traffic selector as ID_IPV?_ADDRESS identity
|
2012-03-20 17:31:12 +01:00 |
|
Martin Willi
|
caa6f772c8
|
Added missing break;s when converting ID_IP_ADDRESS types to ts, extracted function
|
2012-03-20 17:31:12 +01:00 |
|
Martin Willi
|
bd8700f055
|
Don't use unportable htobe64 macro directly
|
2012-03-20 17:31:12 +01:00 |
|
Martin Willi
|
f4e25e602b
|
Implement htoun/untoh64 with potentially faster htobe64/be64toh macros, if available
|
2012-03-20 17:31:12 +01:00 |
|
Andreas Steffen
|
65840cc462
|
fixed copy-and-paste error
|
2012-03-20 17:31:12 +01:00 |
|
Andreas Steffen
|
cd419ae446
|
extended bio_reader and bio_writer to handle u_int64_t
|
2012-03-20 17:31:12 +01:00 |
|
Clavister OpenSource
|
d82a68642d
|
XAUTH additions for certificates.
|
2012-03-20 17:31:12 +01:00 |
|
Clavister OpenSource
|
a874a1f50b
|
signature payload handling.
|
2012-03-20 17:31:12 +01:00 |
|
Clavister OpenSource
|
8ad5cd1f6c
|
certificate tasks added to passive list for responder
|
2012-03-20 17:31:12 +01:00 |
|
Clavister OpenSource
|
7d9269bfce
|
certificate handling for XAuth responder.
|
2012-03-20 17:31:11 +01:00 |
|
Clavister OpenSource
|
a846be3116
|
keymat: derive_ike_keys updated with XAUTH RSA:s
|
2012-03-20 17:31:11 +01:00 |
|
Clavister OpenSource
|
e102f86e88
|
Setting transform number in esp proposal.
iPhone (racoon) fails quick mode when transform number is 0
|
2012-03-20 17:31:11 +01:00 |
|
Clavister OpenSource
|
8a9ab2035f
|
ID_IPV4_ADDR and ID_IPV6_ADDR cases added to get_ts
|
2012-03-20 17:31:11 +01:00 |
|
Andreas Steffen
|
8c583c110e
|
version bump to 5.0.0dr1
|
2012-03-20 17:31:11 +01:00 |
|
Clavister OpenSource
|
07abb470c6
|
IKEv1: Added basic support for INFORMATIONAL exchange types, and for NOTIFY_V1 messages in the 3rd message in quick_mode.
|
2012-03-20 17:31:11 +01:00 |
|
Clavister OpenSource
|
f00ffe4dd2
|
IKEv1 XAuth: Added changes to Makefile.am to compile the xauth_null plugin.
|
2012-03-20 17:31:11 +01:00 |
|
Tobias Brunner
|
8cb6f4f979
|
Don't stop processing tasks if one returns SUCCESS.
Only send a response if at least one of the tasks requires it.
|
2012-03-20 17:31:11 +01:00 |
|
Clavister OpenSource
|
4394d96844
|
IKEv1 XAuth: Added a "NULL" XAuth plugin which sends a hardcoded user/pass, and blindly accepts whatever user/pass is sent it. Changed the xauth_request task to use this new plugin. Add --enable-xauth-null to your configure line to build with the new plugin.
|
2012-03-20 17:31:11 +01:00 |
|
Clavister OpenSource
|
9c5366446a
|
IKEv1 XAuth: Added plugin support for XAuth, which allows us to have plugins to talk to servers with different quirks for XAuth authentication.
|
2012-03-20 17:31:11 +01:00 |
|
Clavister OpenSource
|
781f4c8898
|
IKEv1 XAuth: Add XAuth defines for plugin types.
|
2012-03-20 17:31:11 +01:00 |
|
Tobias Brunner
|
3bf0be6b08
|
Add NAT-OA payloads during Quick Mode if transport mode is used.
We don't parse them currently, as the Linux kernel does not need them to fix
the IP header checksum.
|
2012-03-20 17:31:11 +01:00 |
|
Tobias Brunner
|
29b0cb328a
|
Negotiate UDP encapsulation during Quick Mode if NAT is detected.
|
2012-03-20 17:31:10 +01:00 |
|
Tobias Brunner
|
1cc4ec46cf
|
Task added for IKEv1 NAT detection.
There is already support for both Main and Aggressive Mode.
|
2012-03-20 17:31:10 +01:00 |
|
Tobias Brunner
|
61e2a1ad8a
|
Create negotiated hasher earlier during Main Mode so it is available for building NAT-D payloads.
|
2012-03-20 17:31:10 +01:00 |
|
Tobias Brunner
|
4ace4daf0c
|
Added a function to keymat_v1 to create the hasher earlier than during key derivation.
The negotiated hasher is also used to generate NAT-D payloads.
|
2012-03-20 17:31:10 +01:00 |
|
Tobias Brunner
|
a0bea44a97
|
Message rules for IKEv1 NAT-T payloads added.
|
2012-03-20 17:31:10 +01:00 |
|
Clavister OpenSource
|
c5dc9d3383
|
IKEv1 XAuth: Moving the state change to IKE_CONNECTED until after XAuth exchanges are complete.
|
2012-03-20 17:31:10 +01:00 |
|