Martin Willi
|
ff6b084ac4
|
Confirm message reception time only if DPD sequence number valid
|
2012-03-20 17:31:35 +01:00 |
|
Martin Willi
|
2ddd45c9a7
|
Simplified DPD handling by using a task for a single message only
|
2012-03-20 17:31:35 +01:00 |
|
Martin Willi
|
5ac4c2e1a9
|
Added missing short enum names for DPD notify types
|
2012-03-20 17:31:35 +01:00 |
|
Martin Willi
|
bb2d4e1882
|
Print IKEv1 notify types in message summary
|
2012-03-20 17:31:35 +01:00 |
|
Martin Willi
|
5f2f864efc
|
Support IKEv1 notifies in message_t.get_notify()
|
2012-03-20 17:31:35 +01:00 |
|
Martin Willi
|
3fca5bd123
|
Check if we have an RNG for IKEv1 task manager before using it
|
2012-03-20 17:31:35 +01:00 |
|
Martin Willi
|
31689338d6
|
Remove unused DPD sequence number getter on task manager
|
2012-03-20 17:31:35 +01:00 |
|
Martin Willi
|
1e624ce876
|
Don't retransmit, rekey, reauth or DPD check SAs when in PASSIVE state
|
2012-03-20 17:31:35 +01:00 |
|
Clavister OpenSource
|
c9a160953e
|
Send DPD vendor ID
|
2012-03-20 17:31:35 +01:00 |
|
Clavister OpenSource
|
3e6b740336
|
Isakmp_dpd task added.
|
2012-03-20 17:31:35 +01:00 |
|
Clavister OpenSource
|
36c8169629
|
DPD_R_U_THERE defines added
|
2012-03-20 17:31:35 +01:00 |
|
Martin Willi
|
346dad30d4
|
Request and handle retransmission of a lost third aggressive mode message
|
2012-03-20 17:31:34 +01:00 |
|
Martin Willi
|
37c12bd31e
|
Streamlined debug output when initiating IKEv1 IKE_SAs
|
2012-03-20 17:31:34 +01:00 |
|
Tobias Brunner
|
bd8d1f1d9c
|
Accept unencrypted Aggressive Mode messages.
Racoon does not encrypt the third message during Aggressive Mode.
|
2012-03-20 17:31:34 +01:00 |
|
Martin Willi
|
c40963b457
|
Enforce encapsulation mode of configuration, in case initiator proposes both
|
2012-03-20 17:31:34 +01:00 |
|
Martin Willi
|
e129168ba6
|
Added a "aggressive" ipsec.conf connection option
|
2012-03-20 17:31:34 +01:00 |
|
Martin Willi
|
830ab2ae7f
|
Handle aggressive mode task in IKEv1 task manager
|
2012-03-20 17:31:34 +01:00 |
|
Martin Willi
|
91c212fd6a
|
Select IKEv1 configurations by main/aggressive mode option
|
2012-03-20 17:31:34 +01:00 |
|
Martin Willi
|
5ce59d4c06
|
Added an aggressive mode peer_cfg option
|
2012-03-20 17:31:34 +01:00 |
|
Martin Willi
|
a347c1ac43
|
Fix sending of CERTREQ/CERT payloads in aggressive mode
|
2012-03-20 17:31:34 +01:00 |
|
Martin Willi
|
ebc7bcb550
|
Encrypt payloads of third aggressive mode message
|
2012-03-20 17:31:33 +01:00 |
|
Martin Willi
|
ee325b555f
|
Implemented aggressive mode using Phase 1 helper class
|
2012-03-20 17:31:33 +01:00 |
|
Martin Willi
|
b4bd875612
|
Make use of the new Phase 1 helper class in main mode
|
2012-03-20 17:31:33 +01:00 |
|
Martin Willi
|
c29a89b80d
|
Implemented a common Phase 1 helper class to use by main and aggressive modes
|
2012-03-20 17:31:33 +01:00 |
|
Martin Willi
|
44dcd5944a
|
Fix error handling if no PSK found for main mode
|
2012-03-20 17:31:33 +01:00 |
|
Martin Willi
|
90731f38c9
|
Install quick mode CHILD_SAs with negotiated encapsulation mode
|
2012-03-20 17:31:33 +01:00 |
|
Martin Willi
|
927c1dd9d2
|
Support IKEv1 proposal encodings having both lifebytes and a lifetime
|
2012-03-20 17:31:33 +01:00 |
|
Martin Willi
|
b147679a2c
|
Try to detect reauthentication as responder and adopt children to new SA
|
2012-03-20 17:31:33 +01:00 |
|
Martin Willi
|
3a0b67bce5
|
Destroy IKE_SA after reauthentication initiatend and lifetime limit reached
|
2012-03-20 17:31:33 +01:00 |
|
Martin Willi
|
cb1a145ce2
|
Added an IKE_SA manager method to enumerate IKE_SA IDs filtered by identities
|
2012-03-20 17:31:33 +01:00 |
|
Martin Willi
|
beab4a90ae
|
Query for XAuth identity in get_other_eap_id(), too
|
2012-03-20 17:31:32 +01:00 |
|
Martin Willi
|
1b79299b89
|
Set ISAKMP SA state to rekeying after triggering reauthentication
|
2012-03-20 17:31:32 +01:00 |
|
Martin Willi
|
c9d68d17f0
|
Include peer config overtime in negotiated ISAKMP SA lifetime
|
2012-03-20 17:31:32 +01:00 |
|
Martin Willi
|
4f49b06843
|
Initiate IKEv1 reauthentication, take over all children
|
2012-03-20 17:31:32 +01:00 |
|
Martin Willi
|
17c64d5ff9
|
Establish IKE_SA only once as XAuth responder
|
2012-03-20 17:31:32 +01:00 |
|
Martin Willi
|
9c64f214f1
|
Support initiation of childless IKEv1 ISAKMP SAs
|
2012-03-20 17:31:32 +01:00 |
|
Martin Willi
|
7e9e1f96df
|
Don't trigger reauthentication if initiator authenticated using XAuth
|
2012-03-20 17:31:32 +01:00 |
|
Martin Willi
|
2da3ff7a52
|
Set a condition flag if peer has been authenticated using XAuth
|
2012-03-20 17:31:32 +01:00 |
|
Martin Willi
|
54773729a8
|
Queue Mode Config tasks after main mode as initiator, not as responder
|
2012-03-20 17:31:32 +01:00 |
|
Clavister OpenSource
|
d71092ceed
|
Setting Mode Cfg identifier for CFG_ACK messages.
|
2012-03-20 17:31:32 +01:00 |
|
Clavister OpenSource
|
e32820f593
|
Add functions to set mode cfg identifier
|
2012-03-20 17:31:32 +01:00 |
|
Martin Willi
|
462c9a4f72
|
Try all matching XAuth secrets we find, not only the first one
|
2012-03-20 17:31:32 +01:00 |
|
Martin Willi
|
3d86d76b86
|
Fixed create_shared_enumerator method description
|
2012-03-20 17:31:31 +01:00 |
|
Martin Willi
|
f56c3c53f6
|
As responder, try to reuse the reqid of the CHILD_SA the initiator is rekeying
|
2012-03-20 17:31:31 +01:00 |
|
Martin Willi
|
31bd5c8c0e
|
Reply quick mode with the same SA lifetime that we received
|
2012-03-20 17:31:31 +01:00 |
|
Martin Willi
|
3a925f74ab
|
Do not query CHILD_SA during delete if they already expired
|
2012-03-20 17:31:31 +01:00 |
|
Martin Willi
|
07202a2bf1
|
Be less verbose when deleting SAs triggered by a hard expire
|
2012-03-20 17:31:31 +01:00 |
|
Martin Willi
|
23eb447c9a
|
Implemented CHILD_SA rekeying
|
2012-03-20 17:31:31 +01:00 |
|
Martin Willi
|
634ac410a2
|
Don't return FAILED if a CHILD_SA to delete could not be found
|
2012-03-20 17:31:31 +01:00 |
|
Martin Willi
|
14dc794165
|
Support installing of quick mode SAs with a specific reqid
|
2012-03-20 17:31:31 +01:00 |
|