-
53c98f098f
Correctly check buffer length in netlink_add_attribute()
Martin Willi
2013-03-15 14:32:25 +01:00
-
6ac601f543
Avoid unneeded termination of netlink algorithm name arrays with END_OF_LIST
Martin Willi
2013-03-15 14:01:15 +01:00
-
cf729248b2
Add a "resetcounters" command to ipsec, clearing global or connection counters
Martin Willi
2013-03-15 10:55:22 +01:00
-
d022322bed
Add connection name specific stroke counters
Martin Willi
2013-03-15 10:41:04 +01:00
-
a34ffd1c05
Add a chunk_from_str() initializer that does not include 0-terminator
Martin Willi
2013-01-03 14:09:05 +01:00
-
e813d218f1
Don't create interim update entries if RADIUS accounting is disabled
Martin Willi
2013-03-14 16:44:09 +01:00
-
d019764ab6
Add support for RADIUS Interim accounting updates
Martin Willi
2013-03-14 16:35:11 +01:00
-
1ba1cd0c9b
Add an option to delete any established IKE_SA if RADIUS server is not responding
Martin Willi
2013-03-14 14:01:17 +01:00
-
49960f021d
Make check whether to use IKEv1 fragmentation more readable
Martin Willi
2013-03-13 16:08:12 +01:00
-
552b8ad5f5
Send Acct-Terminate-Cause based on some alerts catched on the bus
Martin Willi
2013-03-13 15:53:39 +01:00
-
335982169a
When IKEv1 DPD times out, raise missing SEND_RETRANSMIT_TIMOUT alert
Martin Willi
2013-03-13 16:06:54 +01:00
-
c45cf9048e
Raise an alert if an IKE_SA could not have been reauthenticated and expires
Martin Willi
2013-03-13 15:52:16 +01:00
-
68c12fd9f9
Send NAS-Port, NAS-IP and Calling/Called-Station-ID in Accounting-Requests
Martin Willi
2013-03-13 15:19:07 +01:00
-
b4568ca230
Support RADIUS accounting of sent/received packets
Martin Willi
2013-03-13 11:52:38 +01:00
-
d28391a244
Report the number of processed packets in "ipsec statusall"
Martin Willi
2013-03-13 11:46:32 +01:00
-
d954a2081b
child_sa_t.get_usestats() can additionally return the number of processed packets
Martin Willi
2013-03-13 11:38:02 +01:00
-
6b35ab84da
Pass correclty sized pointer to lookup_algorithm() in PF_KEY
Martin Willi
2013-03-13 11:33:53 +01:00
-
7eeeb1c702
kernel_ipsec_t.query_sa() additionally returns the number of processed packets
Martin Willi
2013-03-13 11:31:36 +01:00
-
003452d18f
Send NAS-Port, NAS-IP and Calling/Called-Station-ID in Access-Request
Martin Willi
2013-03-13 11:11:49 +01:00
-
02bf38890d
Forward Cisco Banner received from RADIUS to Unity capable clients
Martin Willi
2013-03-12 20:33:08 +01:00
-
54b3cbdc78
Add a radius message method to enumerate vendor specific attributes
Martin Willi
2013-03-12 20:32:05 +01:00
-
b4d172aa8e
Add Altiga Private Enterprise Numbers that Cisco uses in VPN 3000
Martin Willi
2013-03-12 20:31:10 +01:00
-
f4c8e6def7
In eap-radius, hand out received Framed-IP-Address attributes as virtual IP
Martin Willi
2013-03-12 17:44:13 +01:00
-
-
-
3a23794fa2
Add missing XAuthRespPSK switch case to IKEv1 key derivation
Martin Willi
2013-03-08 15:21:36 +01:00
-
cf6a4ea005
strdup() iface passed to queue_route_reinstall(), fixing double-free
Martin Willi
2013-03-11 15:17:50 +01:00
-
d6b6d1ecdb
Support mutliple subnets and ranges as external load-tester addresses
Martin Willi
2013-03-11 15:16:13 +01:00
-
0897cda33b
Add a constructor to create in-memory pools from an address range
Martin Willi
2013-03-11 14:49:02 +01:00
-
d3f5a05e29
When adding Netlink attributes, increase header length with potential alignment
Martin Willi
2013-03-11 12:32:21 +01:00
-
-
8f727d8007
Clean up IKE_SA state if IKE_SA_INIT request does not have message ID 0
Martin Willi
2013-03-11 11:30:47 +01:00
-
0235914d2f
Ignore fourth Qick Mode message sent by Windows servers.
Martin Willi
2013-03-11 10:52:13 +01:00
-
f361a85ebb
added ITA Echo PA-TNC Subtype and ITA Echo Attribute type
Andreas Steffen
2013-03-11 09:30:20 +01:00
-
e99cf029dc
version bump to 5.0.3dr4
Andreas Steffen
2013-03-11 09:29:22 +01:00
-
a498c7a9c3
moved ar_id from imv_agent to imv_state
Andreas Steffen
2013-03-11 08:54:02 +01:00
-
2b1e2434e4
esc() is only used if dladdr(3) is available
Tobias Brunner
2013-03-08 16:43:07 +01:00
-
292ee515db
Fix maximum size of a mem_pool_t
Tobias Brunner
2013-03-07 18:21:02 +01:00
-
d6da0a367a
New Android release after adding translations and Cert/EAP authentication
Tobias Brunner
2013-03-07 13:53:54 +01:00
-
76de964617
android: Add support for combined certificate and EAP authentication
Tobias Brunner
2013-03-07 13:50:29 +01:00
-
7d70a14779
Merge branch 'pt-tls'
Martin Willi
2013-03-07 14:10:50 +01:00
-
-
83e2c81924
If controller operations have a callback, don't succeed before hook gets called
Martin Willi
2013-03-07 12:13:26 +01:00
-
5807f9cfcd
Add a stroke command timeout option, and report status of completed command
Martin Willi
2013-03-07 11:45:33 +01:00
-
-
9d9042d6d9
As Quick Mode initiator, select a subset of the proposed and the returned TS
Martin Willi
2013-03-07 09:50:43 +01:00
-
1db6bf2f3f
If TLS peer authentication not required, the client does nonetheless, allow it to fail
Martin Willi
2013-03-06 14:39:51 +01:00
-
486f4b5838
added some otherNames OIDs
Andreas Steffen
2013-03-06 11:50:32 +01:00
-
ad9af9e2d8
Fix some apidoc in mem_pool.h
Martin Willi
2013-03-05 17:52:07 +01:00
-
d62f043f01
testing: Add screen package to base image
Tobias Brunner
2013-03-04 18:05:49 +01:00
-
eeb029360a
testing: Enable ssh connection to second IP by name (e.g. moon1)
Tobias Brunner
2013-03-04 18:01:10 +01:00
-
45ee7c9429
testing: ssh script accepts IP addresses instead of host names
Tobias Brunner
2013-03-04 11:55:26 +01:00
-
5057455674
testing: ssh script forwards arguments to ssh command
Tobias Brunner
2013-03-04 11:36:47 +01:00
-
d7eec03815
removed unneeded DS files
Andreas Steffen
2013-03-05 09:08:25 +01:00
-
1a9dee5d22
instead of cloning use extract_buf() method
Andreas Steffen
2013-03-04 23:21:21 +01:00
-
b668f1417d
Don't invoke addr2line if dladdr() did not yield a filename
Martin Willi
2013-03-04 15:50:21 +01:00
-
1f69412b4d
When receiving critical signals, additionally log backtraces to syslog/files
Martin Willi
2013-03-04 15:46:34 +01:00
-
fe03f51302
backtrace_t.log() takes a NULL file pointer to log to registered dbg() hook
Martin Willi
2013-03-04 15:45:03 +01:00
-
8b24863b1f
Don't use color escapes when printing backtraces to a non-TTY file
Martin Willi
2013-03-04 15:07:03 +01:00
-
4d17427205
Add a utility function to resolve TTY color escape codes dynamically
Martin Willi
2013-03-04 15:04:56 +01:00
-
c88104aa25
make TNC Access Requestor ID available to IMVs
Andreas Steffen
2013-03-03 17:18:09 +01:00
-
1fc609fed3
updated NEWS
Andreas Steffen
2013-03-03 17:17:08 +01:00
-
7b11a1dcdc
upgraded KVM test suite to Linux 3.8 kernel
Andreas Steffen
2013-03-03 11:59:07 +01:00
-
f7580a5a67
added openssl-ikev2/alg-aes-gcm scenario
Andreas Steffen
2013-03-03 11:43:52 +01:00
-
81419b9748
use DNs in tnc/tnccs-20-tls scenario
Andreas Steffen
2013-03-03 10:47:17 +01:00
-
c9418d4fd3
added getpwuid_r and initgroups to whitelist
Andreas Steffen
2013-03-03 09:04:49 +01:00
-
eeb69761ae
third parameter was not copied
Andreas Steffen
2013-03-02 22:03:07 +01:00
-
11adf114c1
Fixed Doxygen comments after scanning complete src directory
Tobias Brunner
2013-03-02 15:26:45 +01:00
-
b42f2cacac
Include the whole src directory in apidoc and make source files browsable
Tobias Brunner
2013-03-02 14:58:33 +01:00
-
cd612784e4
Prevent Doxygen from processing __attribute__(...)
Tobias Brunner
2013-03-02 13:33:25 +01:00
-
b6a387f7b0
Updated Doxyfile.in with a recent version of Doxygen
Tobias Brunner
2013-03-02 13:08:52 +01:00
-
9804fccea3
Removed backend for old Android frontend patch
Tobias Brunner
2013-03-02 15:57:00 +01:00
-
b038c62e4a
added ERX_SUPPORTED IKEv2 Notify
Andreas Steffen
2013-03-02 17:18:37 +01:00
-
de218eb09c
added some new TCG IF-M message subtypes and attributes
Andreas Steffen
2013-03-02 17:03:37 +01:00
-
9e9e12bbf8
version bump to 5.0.3dr3
Andreas Steffen
2013-03-02 16:19:57 +01:00
-
e88b529a30
android: Mitigate race condition on reauthentication
Tobias Brunner
2013-03-01 17:01:21 +01:00
-
4c969f7906
openssl: The EVP GCM interface requires at least OpenSSL 1.0.1
Tobias Brunner
2013-03-01 16:56:37 +01:00
-
4dd8d5430d
Merge branch 'multi-eap'
Martin Willi
2013-03-01 11:36:41 +01:00
-
-
e82deaf6ce
Merge branch 'multi-cert'
Martin Willi
2013-03-01 11:35:32 +01:00
-
-
adf239abca
Merge branch 'systime'
Martin Willi
2013-03-01 11:33:47 +01:00
-
-
b611d8ba48
Merge branch 'ikev1-rekeying'
Martin Willi
2013-03-01 11:32:02 +01:00
-
-
ec1b4e6638
Merge branch 'vip-shunts'
Martin Willi
2013-03-01 11:30:13 +01:00
-
-
a36b49f3cb
Merge branch 'opaque-ports'
Martin Willi
2013-03-01 11:27:12 +01:00
-
-
53fcc70acc
When running with an unprivileged user, initialize supplementary groups
Martin Willi
2013-02-20 10:38:45 +01:00
-
21dd4c4bea
Without MOBIKE, update remote host only if it is behind NAT
Martin Willi
2013-02-22 14:55:03 +01:00
-
00683b6864
Merge branch 'ikev1-mm-retransmits'
Martin Willi
2013-03-01 11:24:42 +01:00
-
-
d634109f1d
Merge branch 'tfc-notify'
Martin Willi
2013-03-01 11:16:58 +01:00
-
-
5c55be4915
Send ESP_TFC_PADDING_NOT_SUPPORTED if the used kernel doesn't support it
Martin Willi
2013-02-21 10:09:39 +01:00
-
53e62f5d0c
Indicate support for processing ESPv3 TFC padding in Netlink IPsec backend
Martin Willi
2013-02-21 09:45:46 +01:00
-
76f7d80e80
Introduce "features" for the kernel backends returning kernel capabilities
Martin Willi
2013-02-21 09:39:23 +01:00
-
-
-
9a70fe8412
testing: Add a script to easily connect to a host via SSH
Tobias Brunner
2013-02-19 14:17:26 +01:00
-
81f9cd39fd
openssl: Provide AES-GCM implementation
Tobias Brunner
2013-02-12 16:46:56 +01:00
-
a89ebab62e
Fix cleanup in crypto_tester if AEAD implementation fails
Tobias Brunner
2013-02-12 16:42:45 +01:00
-
5f7f4fa398
Order of arguments in Doxygen comment fixed
Tobias Brunner
2013-02-12 16:40:54 +01:00
-
8656f35ae1
Fix auth_cfg_t.clone() for single-valued auth rules
Tobias Brunner
2013-02-18 17:23:04 +01:00
-
6e935c6fe0
Trigger an updown event when destroying an IKE_SA based on INITIAL_CONTACT
Tobias Brunner
2013-02-18 12:05:58 +01:00
-
61f1693df1
Support different authentication schemes for PT-TLS
Martin Willi
2013-02-28 12:03:40 +01:00
-
807f2facd0
Request a TLS client certificate even if no peer identity is given
Martin Willi
2013-02-28 12:34:53 +01:00
-
257c80cb5b
Wrap tls_t.get_{server,peer}_id methods in tls_socket_t
Martin Willi
2013-02-28 11:44:33 +01:00
-
2de481e32b
Delegate tls_t.get_{peer,server}_id to handshake layer
Martin Willi
2013-02-28 11:39:55 +01:00
-
2ae0c9e618
Implement a SASL PLAIN mechanism using shared secrets
Martin Willi
2013-02-27 16:27:59 +01:00
-
66d8fd690c
Implement SASL authentication in PT-TLS client
Martin Willi
2013-02-27 13:47:08 +01:00
-
3542c4f18a
Implement SASL authentication in PT-TLS server
Martin Willi
2013-02-27 11:43:29 +01:00
-
5b1a10836c
Define PT-TLS SASL result codes
Martin Willi
2013-02-27 11:40:48 +01:00
-
4a801beb3e
Define an interface for SASL mechanisms and provide a static factory
Martin Willi
2013-02-26 14:54:36 +01:00