-
c9d68d17f0
Include peer config overtime in negotiated ISAKMP SA lifetime
Martin Willi
2012-01-03 13:33:18 +01:00
-
4f49b06843
Initiate IKEv1 reauthentication, take over all children
Martin Willi
2012-01-03 12:00:12 +01:00
-
17c64d5ff9
Establish IKE_SA only once as XAuth responder
Martin Willi
2012-01-03 11:59:21 +01:00
-
9c64f214f1
Support initiation of childless IKEv1 ISAKMP SAs
Martin Willi
2012-01-03 11:58:40 +01:00
-
7e9e1f96df
Don't trigger reauthentication if initiator authenticated using XAuth
Martin Willi
2012-01-03 11:28:45 +01:00
-
2da3ff7a52
Set a condition flag if peer has been authenticated using XAuth
Martin Willi
2012-01-03 11:27:41 +01:00
-
54773729a8
Queue Mode Config tasks after main mode as initiator, not as responder
Martin Willi
2012-01-03 11:57:35 +01:00
-
d71092ceed
Setting Mode Cfg identifier for CFG_ACK messages.
Clavister OpenSource
2011-12-29 00:06:12 +01:00
-
e32820f593
Add functions to set mode cfg identifier
Clavister OpenSource
2011-12-29 00:05:04 +01:00
-
462c9a4f72
Try all matching XAuth secrets we find, not only the first one
Martin Willi
2012-01-02 16:38:47 +01:00
-
3d86d76b86
Fixed create_shared_enumerator method description
Martin Willi
2012-01-02 16:38:30 +01:00
-
f56c3c53f6
As responder, try to reuse the reqid of the CHILD_SA the initiator is rekeying
Martin Willi
2012-01-02 16:36:39 +01:00
-
31bd5c8c0e
Reply quick mode with the same SA lifetime that we received
Martin Willi
2012-01-02 15:49:20 +01:00
-
3a925f74ab
Do not query CHILD_SA during delete if they already expired
Martin Willi
2012-01-02 15:40:31 +01:00
-
07202a2bf1
Be less verbose when deleting SAs triggered by a hard expire
Martin Willi
2012-01-02 15:39:16 +01:00
-
23eb447c9a
Implemented CHILD_SA rekeying
Martin Willi
2012-01-02 14:27:10 +01:00
-
634ac410a2
Don't return FAILED if a CHILD_SA to delete could not be found
Martin Willi
2012-01-02 14:26:32 +01:00
-
14dc794165
Support installing of quick mode SAs with a specific reqid
Martin Willi
2012-01-02 13:36:10 +01:00
-
5f1df0a060
Double check that we could select a TS as quick mode responder
Martin Willi
2011-12-22 13:26:38 +01:00
-
f5a84055fe
Implemented responder retransmission, currently enabled for quick mode only
Martin Willi
2011-12-21 17:08:08 +01:00
-
dc8e964775
Queue IKEv1 INFORMATIONALS with higher priority to process notifies first
Martin Willi
2011-12-21 15:02:02 +01:00
-
96f98a8c11
Accept IKEv1 INVALID_KE_INFORMATION notifies without data
Martin Willi
2011-12-21 15:01:29 +01:00
-
253d7e3eff
Don't process notifies in quick mode task when we get an INFORMATIONAL
Martin Willi
2011-12-21 14:39:05 +01:00
-
9276f7121c
Always queue a new passive task when receiving an IKEv1 INFORMATIONAL
Martin Willi
2011-12-21 14:38:36 +01:00
-
db1dc81329
IKEv1 ATTRIBUTES_NOT_SUPPORTED error notify added.
Tobias Brunner
2011-12-21 13:46:47 +01:00
-
8a395e889c
Fixed leak of a hash when checking out by hash
Martin Willi
2011-12-21 13:55:30 +01:00
-
dd5c3787dc
Give a hint that decryption failed if payload length invalid
Martin Willi
2011-12-21 13:54:40 +01:00
-
07b8ec7c00
Cast keymat safely, not based on external input
Martin Willi
2011-12-21 12:39:21 +01:00
-
3bacc1f429
Added a keymat_t version to cast it safely
Martin Willi
2011-12-21 12:13:43 +01:00
-
3d54ae94d9
Handle initiation of not supported IKE versions properly
Martin Willi
2011-12-21 12:05:34 +01:00
-
daee47ba46
Send a delete for every CHILD_SA before deleting IKE_SA
Martin Willi
2011-12-21 10:53:05 +01:00
-
6379c679ae
Set used auth_class in PSKv1 authenticator to comply to constraints
Martin Willi
2011-12-20 19:20:51 +01:00
-
8573b18d22
Fixed scheduling of IKEv2 init tasks in a second keyingtry
Martin Willi
2011-12-20 19:08:29 +01:00
-
8ed976c061
Don't requeue IKEv1 init tasks if they already exist in a second keyingtry
Martin Willi
2011-12-20 19:03:12 +01:00
-
fd5d6bb08e
Use IPSEC DOI also for ISAKMP SA deletes.
Tobias Brunner
2011-12-20 18:49:49 +01:00
-
d9c1dae293
Implemented resetting of IKEv1 task manager, enabling additional keyingtries
Martin Willi
2011-12-20 18:02:01 +01:00
-
94450913ef
Fixed migration of NATD task
Martin Willi
2011-12-20 18:01:25 +01:00
-
bce22af29e
Implemented migration of quick mode task
Martin Willi
2011-12-20 18:01:12 +01:00
-
ca037076bf
Implemented migration of XAuth task
Martin Willi
2011-12-20 18:00:57 +01:00
-
5903acd0ff
Implemented migration of certificate handling tasks
Martin Willi
2011-12-20 18:00:03 +01:00
-
451ebecc85
Implemented migration of Main Mode task
Martin Willi
2011-12-20 17:59:45 +01:00
-
448e2e2945
Check message version before processing it on an IKE_SA
Martin Willi
2011-12-20 16:23:12 +01:00
-
986237603f
Fix ike_version_t enum names
Martin Willi
2011-12-20 16:22:56 +01:00
-
82b1e5e270
Accept NULL as keymat when generating a message
Martin Willi
2011-12-20 16:07:00 +01:00
-
53300baded
Send correct INVALID_MAJOR_VERSION when receiving packet with unsupported protocol
Martin Willi
2011-12-20 13:19:52 +01:00
-
be83ea7ebf
Drop IKEv1 main/aggressive modes if peer to aggressive
Martin Willi
2011-12-20 13:24:43 +01:00
-
87791f7538
Added description for the xauth-eap plugin
Martin Willi
2011-12-20 11:25:25 +01:00
-
28e3c6595d
Check if a config has been selected before narrowing selectors in quick mode
Martin Willi
2011-12-20 11:15:15 +01:00
-
85fc1eb640
Added an XAuth plugin that forwards authentication to EAP methods
Martin Willi
2011-12-19 20:21:02 +01:00
-
747f837cce
Added a flag to register local credential sets exclusively, disabling all others
Martin Willi
2011-12-19 20:22:18 +01:00
-
5d1677f52d
Added missing XAuth plugin feature enum names
Martin Willi
2011-12-19 18:55:41 +01:00
-
438a8d785f
Added a TODO for creating IKE_SAs with unsupported protocol version
Martin Willi
2011-12-19 15:50:31 +01:00
-
38bb727c06
Don't accept IKEv2 packets if IKEv2 disabled
Martin Willi
2011-12-19 15:45:03 +01:00
-
7d788af0a0
Don't include ikev1/ikev2 subfolders in build when using --disable-ikev1/ikev2
Martin Willi
2011-12-19 15:28:55 +01:00
-
326a94232d
Moved eap/xauth classes out of protocol specific subdirectories
Martin Willi
2011-12-19 15:22:50 +01:00
-
3b08de850a
Removed obsolete task header inclusion in IKE_SA
Martin Willi
2011-12-19 15:20:36 +01:00
-
873df908cc
Moved MOBIKE task creation to protocol specific task manager
Martin Willi
2011-12-19 15:04:28 +01:00
-
26eee421b4
Check in task manager if we have to requeue IKE tasks in a non-first keyingtry
Martin Willi
2011-12-19 14:46:56 +01:00
-
cedb412e5a
Moved IKE_SA reauth task creation to protocol specific task manager
Martin Willi
2011-12-19 14:39:05 +01:00
-
dab60d6411
Moved IKE_SA rekey task creation to protocol specific task manager
Martin Willi
2011-12-19 14:35:14 +01:00
-
3ed148b37e
Moved IKE_SA delete task creation to protocol specific task manager
Martin Willi
2011-12-19 14:29:57 +01:00
-
83c5fda053
Moved CHILD_SA delete task creation to protocol specific task manager
Martin Willi
2011-12-19 14:25:14 +01:00
-
463a73cc0f
Moved CHILD_SA rekey task creation to protocol specific task manager
Martin Willi
2011-12-19 14:20:33 +01:00
-
fe43d9a237
Moved CHILD_SA initiate task creation to protocol specific task manager
Martin Willi
2011-12-19 14:15:21 +01:00
-
a60daa07f6
Moved IKE_SA initiate task creation to protocol specific task manager
Martin Willi
2011-12-19 14:15:02 +01:00
-
244d715de5
Moved liveness checking task creation to protocol specific task manager
Martin Willi
2011-12-19 13:49:09 +01:00
-
7d0a3a427d
Factories honor charon IKEv1/IKEv2 protocol support flags
Martin Willi
2011-12-19 13:32:41 +01:00
-
e51a28fda8
Added a --disable-ikev2 option to disable IKEv2 support in charon
Martin Willi
2011-12-19 13:13:45 +01:00
-
15a682f4c2
Separated libcharon/sa directory with ikev1 and ikev2 subfolders
Martin Willi
2011-12-19 13:10:29 +01:00
-
2e3c9f8799
Renamed ike_vendor_v1 to isakmp_vendor
Martin Willi
2011-12-19 11:28:54 +01:00
-
79d6fc7f72
Renamed ike_natd_v1 to isakmp_natd
Martin Willi
2011-12-19 11:24:03 +01:00
-
824dc0adad
Renamed ike_cert_pre_v1 to isakmp_cert_pre
Martin Willi
2011-12-19 11:17:31 +01:00
-
0aa2af5efc
Renamed ike_cert_post_v1 to isakmp_cert_post
Martin Willi
2011-12-19 11:12:27 +01:00
-
26a758ffcb
Fixed fix for XAuth plugin feature matching
Martin Willi
2011-12-19 11:33:06 +01:00
-
8833068877
Doxygen fixes
Martin Willi
2011-12-19 10:27:40 +01:00
-
ef32c6866e
Removed obsolete XAuth job
Martin Willi
2011-12-19 10:22:47 +01:00
-
26b02f50f4
Always use a transform number of 1 when encoding a single transform
Martin Willi
2011-12-19 10:12:52 +01:00
-
5d0458af0a
Another set of cleanups in message.c
Martin Willi
2011-12-19 10:12:33 +01:00
-
2ee83c2778
Fix XAuth plugin feature matching
Martin Willi
2011-12-19 10:10:57 +01:00
-
ef175c92d9
Initiate IKE_ANY configurations with IKEv2
Martin Willi
2011-12-17 14:26:04 +01:00
-
ac009df132
Pass IKE version to peer config enumerator, filter configs
Martin Willi
2011-12-17 13:31:27 +01:00
-
d94c923648
Support an "any" IKE version for both IKEv1 or IKEv2
Martin Willi
2011-12-17 12:48:14 +01:00
-
b9a707e696
Some coding style cleanups
Martin Willi
2011-12-17 12:47:44 +01:00
-
2f58f6cba1
Fixed notify enum names
Martin Willi
2011-12-17 12:19:30 +01:00
-
4bc4e8e17b
Added support for iKEIntermediate flag to ipsec pki.
Tobias Brunner
2011-12-15 16:56:07 +01:00
-
f29a4f1c64
Added support for iKEIntermediate X.509 extended key usage flag.
Tobias Brunner
2011-12-15 16:54:49 +01:00
-
00cc2188d4
Some whitespace fixes.
Tobias Brunner
2011-12-15 16:51:19 +01:00
-
b46b56fac1
Log parsed unsigned ints with proper format strings.
Tobias Brunner
2011-12-15 11:22:31 +01:00
-
bf5b1d9e73
Send different notifies if quick mode fails
Martin Willi
2011-12-15 18:35:55 +01:00
-
b64d6423b1
Support flushing of task queue after building message in task fails
Martin Willi
2011-12-15 18:23:28 +01:00
-
fceb20f390
Consider notify errors fatal only during main mode
Martin Willi
2011-12-15 18:11:00 +01:00
-
767966e70b
Delete CHILD_SA if installing SA in third message fails
Martin Willi
2011-12-15 18:04:39 +01:00
-
53816600ff
Added a quick_delete task flag to enforce delete, even if CHILD_SA not found
Martin Willi
2011-12-15 18:03:14 +01:00
-
429d95fef2
Send delete if Main Mode authentication fails as initiator
Martin Willi
2011-12-15 17:28:58 +01:00
-
5762c0efeb
Send notifies in all error cases of Main Mode
Martin Willi
2011-12-15 17:04:45 +01:00
-
ca26065745
Add some additional IKEv1 notify types
Martin Willi
2011-12-15 17:04:29 +01:00
-
a4cc071364
Do not trust unprotected INFORMATIONALS, just print that we got one
Martin Willi
2011-12-15 16:23:47 +01:00
-
daf7e6bc36
Use (as client) and verify (as server) configured XAuth identities
Martin Willi
2011-12-15 13:15:34 +01:00
-
7a7efbf9d8
Added an identity getter to XAuth methods to query the actually used identity
Martin Willi
2011-12-15 13:14:33 +01:00
-
5f6a37eb9b
Be a little more verbose about XAuth configs in ipsec statusall
Martin Willi
2011-12-15 13:13:30 +01:00