Tobias Brunner
fcc33c0cd4
unit-tests: Print loaded plugins
2013-06-27 11:27:13 +02:00
Tobias Brunner
a6357a62b4
unit-tests: RSA key generation might take longer than 4 seconds
...
Check uses a default timeout of 4 seconds for each test case, generating
keys of 6 different key sizes might take longer than that.
2013-06-27 11:06:47 +02:00
Tobias Brunner
65d23c7c90
tests: Properly load plugins from build directory
...
Calling load() incrementally does not really work as dependencies
wouldn't be resolved properly if a required feature was to be provided
by a plugin that is loaded later with a separate call to load().
2013-06-27 11:06:47 +02:00
Tobias Brunner
f2086e42ff
plugin-loader: Method added to provide additional search paths for plugins
2013-06-27 10:27:24 +02:00
Tobias Brunner
78e6f69e5a
Adding NEWS for 5.1.0
2013-06-25 17:51:42 +02:00
Tobias Brunner
9da5a2ed1e
Merge branch 'check-caps'
...
Plugins may now ensure the process has all the required capabilities.
Some minor changes to UID/GID handling are also included.
2013-06-25 17:17:40 +02:00
Tobias Brunner
ac2ffde4ae
capabilities: Return effective UID/GID if user did not configure anything
2013-06-25 17:16:33 +02:00
Tobias Brunner
68b7448eab
capabilities: Make the user and group charon(-nm) changes to configurable
2013-06-25 17:16:33 +02:00
Tobias Brunner
5e80e387bd
capabilities: Report effective UID/GID after dropping capabilities
2013-06-25 17:16:33 +02:00
Tobias Brunner
1091edede8
capabilities: CAP_CHOWN might be required by many plugins opening UNIX sockets
...
But as the sockets will be created with the user/group of the running
process this might not be required as no change may be needed.
2013-06-25 17:16:33 +02:00
Tobias Brunner
1937538440
capabilities: Handle CAP_CHOWN specially as it might not be required
2013-06-25 17:16:33 +02:00
Tobias Brunner
9c354c659f
capabilities: Check effective UID as fallback if capabilities are not supported
2013-06-25 17:16:33 +02:00
Tobias Brunner
9fd2583e6b
kernel-netlink: Make CAP_NET_ADMIN capability optional
...
It is not required to use the kernel-net part of the plugin.
2013-06-25 17:16:32 +02:00
Tobias Brunner
405f5ab9e9
farp: Require CAP_NET_RAW capability to open AF_PACKET socket
2013-06-25 17:16:32 +02:00
Tobias Brunner
6f15f5e632
dhcp: Require CAP_NET_BIND_SERVICE and CAP_NET_RAW to open/bind sockets
2013-06-25 17:16:32 +02:00
Tobias Brunner
1dd61bf13d
socket-default: Require CAP_NET_BIND_SERVICE for ports < 1024
...
Since we don't know which ports are used with socket-dynamic we can't
demand the capability there, but it might still be required.
2013-06-25 17:16:32 +02:00
Tobias Brunner
41b8546ac0
capabilities: Only plugins that require CAP_NET_ADMIN demand it
...
The daemon as such does not require this capability.
2013-06-25 17:16:32 +02:00
Tobias Brunner
a2eb581781
capabilities: Move global capabilities_t instance to libstrongswan
2013-06-25 17:16:32 +02:00
Tobias Brunner
2e21bac19a
capabilities: Ensure required capabilities are actually held by the process/user
2013-06-25 17:16:32 +02:00
Tobias Brunner
e8db483f41
unit-tester: RSA test was removed
2013-06-24 16:01:23 +02:00
Tobias Brunner
b61c78d3c2
Merge branch 'kernel-libipsec'
...
Adds a new kernel interface plugin that uses TUN devices and libipsec to
provide IPsec process in userland.
It works on Linux, FreeBSD and Mac OS X. In particular the latter two
platforms may gain from this approach as their respective kernels don't
provide support for AES-GCM.
kernel-pfroute has been improved (source address lookup) and a second
plugin (osx-attr) installs configuration attributes (currently DNS
servers only) via SystemConfiguration on Mac OS X.
2013-06-21 17:07:41 +02:00
Tobias Brunner
12488efa78
kernel-pfroute: Simplify route lookup after fixing sockaddr parsing
2013-06-21 17:03:22 +02:00
Tobias Brunner
4b3fea3d54
kernel-pfroute: Alignment of sockaddrs is not always the same
2013-06-21 17:03:22 +02:00
Tobias Brunner
aa33d2e6eb
kernel-pfroute: struct sockaddr arguments are 4 byte aligned
...
This was noticed on Mac OS X where, if the default route is returned,
RTA_NETMASK has sa_len set to 0, but skipping zero bytes to read the
next address makes no sense, of course. Using 0 for sa_len seems
a bit strange, in particular, because struct sockaddr has by definition
a minimum length of 16 bytes. But it seems FreeBSD actually does the
same.
2013-06-21 17:03:22 +02:00
Tobias Brunner
23ea59a95c
kernel-libipsec: Ignore failures when installing routes for multicast or broadcast policies
2013-06-21 17:03:22 +02:00
Tobias Brunner
b0629f7d9b
kernel-pfroute: Improve route lookup depending on information we get back
...
Kernels don't provide the same information for all routes.
2013-06-21 17:03:22 +02:00
Tobias Brunner
1c697ff1c5
kernel-pfroute: Try to ensure we get a source address or interface name
2013-06-21 17:03:22 +02:00
Tobias Brunner
01955eec71
ike: Force NAT-T/UDP encapsulation if kernel interface requires it
2013-06-21 17:03:21 +02:00
Tobias Brunner
35fe41f7d0
kernel-libipsec: Add a feature to request UDP encapsulation of ESP packets
2013-06-21 17:03:21 +02:00
Tobias Brunner
66aaabf342
tun-device: Packets sent over utun devices on Mac OS X have the protocol family prepended
2013-06-21 17:03:21 +02:00
Tobias Brunner
34b0ad0653
kernel-pfroute: Use DST as nexthop for host routes
...
These are created as cache/clone on Mac OS X.
2013-06-21 17:03:21 +02:00
Tobias Brunner
d6c17e96b2
kernel-pfroute: Implement get_source_addr()
2013-06-21 17:03:21 +02:00
Tobias Brunner
f58f8bf409
kernel-pfroute: Properly install routes with interface and gateway
2013-06-21 17:03:21 +02:00
Tobias Brunner
1f31a2bc2e
kernel-libipsec: Install a gateway for routes on platforms other than Linux
...
This seems required e.g. on FreeBSD but doesn't work on Linux.
2013-06-21 17:03:21 +02:00
Tobias Brunner
93e4df3761
kernel-pfroute: Activate TUN device before setting address
...
On FreeBSD, for some reason, we don't learn the interface is up
otherwise. Even though ifconfig lists it as up at the same time.
2013-06-21 17:03:21 +02:00
Tobias Brunner
c8a56512a6
tun-device: Avoid opening /dev/tunX multiple times (e.g. on FreeBSD)
2013-06-21 17:03:21 +02:00
Tobias Brunner
dcaf8d570c
kernel-libipsec: Router reads packets from multiple TUN devices
...
These devices are collected via kernel_listener_t interface.
2013-06-21 17:03:21 +02:00
Tobias Brunner
7045defbff
kernel-libipsec: Use separate class to route packets between charon, libipsec and TUN device
2013-06-21 17:03:21 +02:00
Tobias Brunner
554c4276a5
kernel-pfroute: Raise tun event when creating/destroying TUN devices for virtual IPs
2013-06-21 17:03:21 +02:00
Tobias Brunner
4868d1c3bc
kernel: Add an event kernel interfaces can raise if they create/destroy a TUN device
2013-06-21 17:03:21 +02:00
Tobias Brunner
0d2ad63fe2
printf-hook: Avoid double-free when freeing Vstr config
...
Thread-specific objects get freed when the thread value object is
destroyed (wasn't the case earlier, i.e. before 2b19dd35 ), which
may cause the second call to vstr_free_conf() to fail in an assert
in Vstr (depending on how it was built).
2013-06-21 17:03:20 +02:00
Tobias Brunner
587bdf8768
kernel-libipsec: Track policies and automatically install routes
...
The routes direct traffic matching the remote traffic selector to the
TUN device.
If the remote traffic selector includes the IKE peer a very specific route
is installed to allow IKE traffic.
2013-06-21 17:03:20 +02:00
Tobias Brunner
44a49681fd
kernel-libipsec: Handle packets between charon socket, libipsec and TUN device
2013-06-21 17:03:20 +02:00
Tobias Brunner
59be6ddd08
kernel-libipsec: Create a TUN device and use it to install virtual IPs
2013-06-21 17:03:20 +02:00
Tobias Brunner
279e0d42bd
kernel-libipsec: Add plugin that implements kernel_ipsec_t using libipsec
2013-06-21 17:03:20 +02:00
Tobias Brunner
3cd7ba4960
kernel-netlink: Routes don't require a gateway/nexthop
2013-06-21 17:03:20 +02:00
Tobias Brunner
1b3b7ba54d
charon-cmd: Document auxiliary options
2013-06-21 17:00:49 +02:00
Tobias Brunner
4d62ad7571
charon-cmd: Link strongswan.conf(5) and charon-cmd(8) man pages
2013-06-21 16:35:19 +02:00
Tobias Brunner
5991f09565
charon-cmd: Use fixed number of character to align command descriptions
...
If the command and argument is longer than that write the first line of
description to the following line.
2013-06-21 16:04:46 +02:00
Tobias Brunner
5e185047e1
charon-cmd: Shortened and fixed command descriptions
2013-06-21 16:04:45 +02:00
Tobias Brunner
463314b55a
charon-cmd: Simplify usage output for authentication profiles
...
The man page describes the min full.
2013-06-21 16:04:45 +02:00
Tobias Brunner
e8d6b91ebd
charon-cmd: Add Aggressive Mode profiles to man page
2013-06-21 16:04:45 +02:00
Tobias Brunner
0d60489bf8
charon-cmd: Add man page for charon-cmd(8)
2013-06-21 16:04:45 +02:00
Tobias Brunner
295d595b49
charon-cmd: Add --debug argument to set the default log level
2013-06-21 15:55:52 +02:00
Tobias Brunner
4049ec42bf
charon-cmd: Handle simple command line arguments like --help before the others
2013-06-21 15:51:42 +02:00
Tobias Brunner
0d25c4ef87
plugin-loader: Move logging of failed features to status()
...
Still log an error message if critical features fail, as loaded
plugins/features are not logged in that case.
This way loaded plugins are printed before failed features and
the relation is easier to make for users. It also allows programs
to log this message on a different level.
2013-06-21 15:22:46 +02:00
Tobias Brunner
607f8e9906
plugin-loader: Add method to print loaded plugins on a given log level
2013-06-21 15:17:53 +02:00
Tobias Brunner
34ee14dd28
plugin-loader: Collect statistics while loading features, print them in case features failed to load
...
There is no need to explicitly search for failed features in critical
plugins as this is now detected while loading the features.
2013-06-21 15:13:25 +02:00
Tobias Brunner
681e53c70c
plugin-loader: Use different log level if failed feature is in critical plugin
2013-06-21 15:13:25 +02:00
Tobias Brunner
13d2d8f634
plugin-loader: Log message when failing to load plugin
2013-06-21 15:13:25 +02:00
Tobias Brunner
51b9d7513d
plugin-loader: Reduce verbosity while loading plugins
2013-06-21 15:13:25 +02:00
Tobias Brunner
0adf165c7e
Fix crash if the initiator has no suitable proposal available
...
Could be triggered with a typo in the ike or esp options when ! is used.
2013-06-21 11:09:03 +02:00
Tobias Brunner
8c88ca0fcf
stroke: Add statusall-nb as alias for statusallnb
2013-06-21 10:51:41 +02:00
Tobias Brunner
4182c86aed
stroke: Add non-blocking versions of up and down
...
stroke up-nb and stroke down-nb do not block until the command has
finished. Instead, they return right after initiating the respective
operation.
2013-06-21 10:49:39 +02:00
Tobias Brunner
9afc6e6a70
starter: Make ipsec.conf path configurable via command line
2013-06-21 10:08:56 +02:00
Tobias Brunner
c0d0391a51
pubkey: Improve comparison of raw public key certificate objects
2013-06-21 10:02:25 +02:00
Tobias Brunner
4d04e2c63b
utils: Remove volatile qualifier from refcount_t typedef
...
It's not really required anymore (if it ever was) and may cause compiler
warnings when using the non atomic versions of ref_get/ref_put.
2013-06-19 09:28:30 +02:00
Tobias Brunner
c6f1929a45
socket-default: Make sure sockets are open when checking with FD_ISSET
2013-06-14 17:25:16 +02:00
Tobias Brunner
1889837767
socket-default: Properly initialize NAT-T port if opening regular socket failed
2013-06-14 16:42:56 +02:00
Tobias Brunner
92f102c21b
android: Forward initiator flag to libipsec when adding IPsec SA
2013-06-13 13:55:58 +02:00
Tobias Brunner
52d7c530e9
libipsec: Add initiator flag to definition of ipsec_sa_mgr_t.add_sa()
2013-06-13 13:54:05 +02:00
Tobias Brunner
44fb978169
ha: Fix CHILD_SA installation in ha_dispatcher after adding initiator flag
2013-06-13 13:17:55 +02:00
Tobias Brunner
f5f7053bcd
leak-detective: Resolve hooked functions during initialization
...
If uses of dlopen(), e.g. when loading plugins, produce errors an error
string could get allocated dynamically. At this point realloc() might not
yet be resolved and when dlsym() is later called by leak detective to do
so the error string might get freed while leak detective is disabled and
real_free() will be called with a pointer into one of leak detective's
memory blocks instead of a pointer to the block itself, causing a SIGSEGV.
2013-06-11 15:48:26 +02:00
Tobias Brunner
3873526f3e
Properly compare CHILD_SAs during rekey collision
...
The previous code did not properly check for the situation when the
DELETE for a redundant CHILD_SA created by a responder during a
CHILD_SA rekey collision arrives before the responder's answer to the
initiator's winning CREATE_CHILD_SA request.
2013-06-11 14:00:02 +02:00
Tobias Brunner
5744226e92
Merge branch 'plugin-loader'
...
Improves how plugin loader resolves dependencies between plugins. The
old loader had problems if plugins had dependencies on features provided
by plugins listed later in the plugin list. For instance, it was not
possible to use the X.509 implementation provided by the x509 plugin
while using all the crypto primitives provided by the openssl plugin.
Because the x509 plugin has a dependency on SHA1, the old loader skipped
that plugin until it loaded a SHA1 implementation. Because the loader
also loaded all features with resolved dependencies provided by a specific
plugin it would, while loading the openssl plugin's SHA1 implementation,
also load its X.509 implementation. So to use the x509 plugin it was
necessary to load the sha1 plugin before it so that its dependencies
could be properly resolved.
With the new implementation the plugins don't have to be in a specific
order to resolve dependencies. But the order still matters if two
plugins provide the same feature.
Also, support for the get_features() interface was added to all plugins.
2013-06-11 11:36:40 +02:00
Tobias Brunner
31a416a5b2
Removed stray *_plugin_create() declarations from header files
2013-06-11 11:18:19 +02:00
Tobias Brunner
460488b180
eap-radius: Do initialization in a plugin feature callback
2013-06-11 11:18:19 +02:00
Tobias Brunner
49d7a98f47
Refactored plugin-loader with improved dependency resolution
...
With the new implementation the plugins don't have to be listed in any
special order, dependencies are properly resolved. The order only
matters if two plugins provide the same feature.
2013-06-11 11:18:19 +02:00
Tobias Brunner
facc781500
android-log: Use plugin features
2013-06-11 11:18:19 +02:00
Tobias Brunner
df60999b5f
android-dns: Use plugin features to register attribute handler
2013-06-11 11:18:19 +02:00
Tobias Brunner
e183a6c36d
maemo: Use plugin features
2013-06-11 11:18:19 +02:00
Tobias Brunner
6d766925b2
medsrv: Use plugin features with dependency on database implementation
2013-06-11 11:18:19 +02:00
Tobias Brunner
da7c3f8900
medcli: Use plugin features with dependency on database implementation
2013-06-11 11:18:19 +02:00
Tobias Brunner
d0ccae4dd2
whitelist: Use plugin features to register listener
2013-06-11 11:18:19 +02:00
Tobias Brunner
49d333ac67
updown: Use plugin features to register listener and attribute handler
2013-06-11 11:18:19 +02:00
Tobias Brunner
819cb66298
unity: Use plugin features to register listener and attribute handler/provider
2013-06-11 11:18:19 +02:00
Tobias Brunner
b033d59d1e
unit-tester: Use plugin features
2013-06-11 11:18:19 +02:00
Tobias Brunner
e1360331e9
uci: Use plugin features to register backend and credential set
2013-06-11 11:18:19 +02:00
Tobias Brunner
36f27c1506
systime-fix: Use plugin features to register validator
2013-06-11 11:18:19 +02:00
Tobias Brunner
c1f5841bb2
smp: Use plugin features
2013-06-11 11:18:19 +02:00
Tobias Brunner
64b0c2575f
radattr: Use plugin features to register listener
2013-06-11 11:18:18 +02:00
Tobias Brunner
d94c0913b1
lookip: Use plugin features to register listener
2013-06-11 11:18:18 +02:00
Tobias Brunner
dfe97d63d8
led: Use plugin features to register listener
2013-06-11 11:18:18 +02:00
Tobias Brunner
da04914933
test-vectors: Use plugin features
2013-06-11 11:18:18 +02:00
Tobias Brunner
17f00db6d6
revocation: Use plugin features with soft dependencies on fetcher and en-/decoding
2013-06-11 11:18:18 +02:00
Tobias Brunner
25da1943b3
padlock: Use plugin features to properly register algorithms
2013-06-11 11:18:18 +02:00
Tobias Brunner
7756c0383e
pkcs11: Use plugin_features_add() in get_features()
2013-06-11 11:18:18 +02:00
Tobias Brunner
886a40d75e
plugin-feature: Added helper function to extend arrays of plugin features
2013-06-11 11:18:18 +02:00
Tobias Brunner
c172a92bfb
constraints: Use plugin features with soft dependency on X.509 decoding
2013-06-11 11:18:18 +02:00
Tobias Brunner
e3bdf03af4
blowfish: Use plugin features to properly register crypter
2013-06-11 11:18:18 +02:00