]>
git.ipfire.org Git - thirdparty/strongswan.git/log
Martin Willi [Tue, 13 Dec 2011 15:21:47 +0000 (16:21 +0100)]
Ignore additional TRANSACTION request if we already queued one
Martin Willi [Tue, 13 Dec 2011 15:14:17 +0000 (16:14 +0100)]
Keep a history of received response hashes to detect late retransmissions
If we receive an old response and we already sent out the next request,
we must be able to identify that it is not the response to the new
request.
Martin Willi [Tue, 13 Dec 2011 14:32:53 +0000 (15:32 +0100)]
Narrow down received and configured traffic selector to a common subset
Martin Willi [Tue, 13 Dec 2011 14:10:26 +0000 (15:10 +0100)]
Don't send a retransmit for a request we never have sent a response
Martin Willi [Tue, 13 Dec 2011 13:52:50 +0000 (14:52 +0100)]
Print unsigned IKEv1 message IDs
Tobias Brunner [Tue, 13 Dec 2011 12:09:56 +0000 (13:09 +0100)]
Log selected peer config during Main Mode.
Tobias Brunner [Tue, 13 Dec 2011 12:09:37 +0000 (13:09 +0100)]
Log configured IKE version in stroke plugin.
Tobias Brunner [Tue, 13 Dec 2011 12:08:54 +0000 (13:08 +0100)]
Fixed SIGSEGV when logging peer config matches.
Martin Willi [Tue, 13 Dec 2011 13:39:24 +0000 (14:39 +0100)]
Added a bunch of well known IKEv1 vendor IDs to database
Martin Willi [Tue, 13 Dec 2011 13:26:31 +0000 (14:26 +0100)]
Use a generic IKEv1 vendor ID database to send and receive vendor IDs
Martin Willi [Tue, 13 Dec 2011 12:42:41 +0000 (13:42 +0100)]
Fixed compiler warning (set but unused variable)
Martin Willi [Tue, 13 Dec 2011 11:17:35 +0000 (12:17 +0100)]
Queue a TRANSACTION message for later processing if Main Mode not yet completed
Martin Willi [Tue, 13 Dec 2011 10:39:54 +0000 (11:39 +0100)]
Fixed leak of shared keys in xauth-generic plugin
Martin Willi [Tue, 13 Dec 2011 10:37:02 +0000 (11:37 +0100)]
Free list after removing the last local credential set, fixes a leak report
Martin Willi [Tue, 13 Dec 2011 10:30:35 +0000 (11:30 +0100)]
Fixed SPI size calculation in DELETE payload
Martin Willi [Tue, 13 Dec 2011 10:19:08 +0000 (11:19 +0100)]
Reset task manager state when build() completes an exchange (quick mode)
Martin Willi [Tue, 13 Dec 2011 10:10:48 +0000 (11:10 +0100)]
Include COOKIES in IKEv1 delete payloads
Martin Willi [Tue, 13 Dec 2011 10:08:53 +0000 (11:08 +0100)]
Support IKEv1 SPIs in IKEv1 delete payload
Tobias Brunner [Tue, 13 Dec 2011 09:39:36 +0000 (10:39 +0100)]
Fixed missing shared_key initialization in main_mode task.
Martin Willi [Tue, 13 Dec 2011 09:36:42 +0000 (10:36 +0100)]
Use version specific DELETE payload identifier in ike_delete task
Martin Willi [Tue, 13 Dec 2011 09:36:02 +0000 (10:36 +0100)]
Activate DELETE tasks when queued
Martin Willi [Tue, 13 Dec 2011 09:35:18 +0000 (10:35 +0100)]
Fix IKEv1 DELETE subtask creation and processing
Martin Willi [Tue, 13 Dec 2011 09:22:49 +0000 (10:22 +0100)]
Handle DELETE as responder as INFORMATIONAL subtask
Martin Willi [Tue, 13 Dec 2011 08:55:37 +0000 (09:55 +0100)]
Close SA immediately after sending an INFORMATIONAL error
Martin Willi [Tue, 13 Dec 2011 08:50:31 +0000 (09:50 +0100)]
Moved responder informational handling to task
Martin Willi [Tue, 13 Dec 2011 08:42:16 +0000 (09:42 +0100)]
Remove unused status type
Martin Willi [Tue, 13 Dec 2011 08:40:26 +0000 (09:40 +0100)]
Check if IKEv1 exchange type matches before handling it as response
Martin Willi [Mon, 12 Dec 2011 17:13:10 +0000 (18:13 +0100)]
Use informational task in quick mode to send notifies
Martin Willi [Mon, 12 Dec 2011 14:45:45 +0000 (15:45 +0100)]
Cleaned up notification sending in IKEv1 task manager
Martin Willi [Mon, 12 Dec 2011 14:44:58 +0000 (15:44 +0100)]
Use informational taks to send notify errors
Martin Willi [Mon, 12 Dec 2011 14:38:20 +0000 (15:38 +0100)]
Added a task stub to create and process IKEv1 informational exchanges
Martin Willi [Mon, 12 Dec 2011 14:16:15 +0000 (15:16 +0100)]
Allow IKEv1 tasks to return ALREADY_DONE to flush all active or passive tasks
Martin Willi [Mon, 12 Dec 2011 17:01:21 +0000 (18:01 +0100)]
Support flushing of single tasks queues in IKEv1 task manager
Martin Willi [Mon, 12 Dec 2011 14:43:12 +0000 (15:43 +0100)]
Double check if we have a packet before retransmitting it
Tobias Brunner [Mon, 12 Dec 2011 17:37:49 +0000 (18:37 +0100)]
Fixed memory leak when handling IKEv1 error notifications.
Tobias Brunner [Mon, 12 Dec 2011 17:38:32 +0000 (18:38 +0100)]
Destroy IKE_SA after failed XAuth authentication.
Tobias Brunner [Mon, 12 Dec 2011 17:26:26 +0000 (18:26 +0100)]
Added generic XAuth backend, using secrets provided by credential sets.
Tobias Brunner [Mon, 12 Dec 2011 13:25:15 +0000 (14:25 +0100)]
Removed xauth-null dummy plugin.
Clavister OpenSource [Mon, 12 Dec 2011 14:54:27 +0000 (15:54 +0100)]
Added possibility to send notifications from the Quick Mode task
Clavister OpenSource [Mon, 12 Dec 2011 13:35:34 +0000 (14:35 +0100)]
Setting Protocol ID of notifys sent from task manager to ISAKMP
Martin Willi [Mon, 12 Dec 2011 11:33:31 +0000 (12:33 +0100)]
If no IKEv1 shared key found for hosts, try to find one based on config identities
Martin Willi [Mon, 12 Dec 2011 11:30:47 +0000 (12:30 +0100)]
Log peer cfg enumeration externally for flexibility
Martin Willi [Mon, 12 Dec 2011 11:17:13 +0000 (12:17 +0100)]
Accept NULL identities passed to peer config enumeration
Martin Willi [Mon, 12 Dec 2011 10:28:24 +0000 (11:28 +0100)]
Fixed authentication method selection for main mode PSK authentication
Martin Willi [Fri, 9 Dec 2011 15:19:54 +0000 (16:19 +0100)]
Use virtual IP to substitute dynamic traffic selectors in quick mode
Martin Willi [Fri, 9 Dec 2011 15:19:37 +0000 (16:19 +0100)]
Queue Mode Config tasks when required
Martin Willi [Fri, 9 Dec 2011 15:18:22 +0000 (16:18 +0100)]
Added IKEv1 Mode Config task based on IKEv2 ike_config
Martin Willi [Fri, 9 Dec 2011 14:22:30 +0000 (15:22 +0100)]
Added missing XAuth auth_class enum name
Martin Willi [Fri, 9 Dec 2011 14:18:23 +0000 (15:18 +0100)]
Reject quick modes if IKE_SA not yet established
Martin Willi [Fri, 9 Dec 2011 14:10:38 +0000 (15:10 +0100)]
Use a common function to set IKE_SA to established
Martin Willi [Wed, 7 Dec 2011 12:40:38 +0000 (13:40 +0100)]
Be less verbose if plugin dependecy not satisfied
Martin Willi [Fri, 9 Dec 2011 13:57:51 +0000 (14:57 +0100)]
Don't complain when receiving XAuth or Unity configuration attributes
Martin Willi [Fri, 9 Dec 2011 13:54:23 +0000 (14:54 +0100)]
Interpret attribute format correctly in IKEv1 configuration format
Martin Willi [Thu, 8 Dec 2011 17:30:47 +0000 (18:30 +0100)]
Implemented responder part of XAUTH task
Martin Willi [Thu, 8 Dec 2011 17:08:54 +0000 (18:08 +0100)]
Implemented initiator part of xauth task
Martin Willi [Thu, 8 Dec 2011 17:08:13 +0000 (18:08 +0100)]
Ask for a username/password in xauth-null as XAUTH initiator
Martin Willi [Thu, 8 Dec 2011 16:19:10 +0000 (17:19 +0100)]
Get first XAuth backend if none configured
Martin Willi [Thu, 8 Dec 2011 15:57:38 +0000 (16:57 +0100)]
Accept a xauth backend name appended to left/rightauth
Martin Willi [Thu, 8 Dec 2011 15:53:27 +0000 (16:53 +0100)]
Added auth_cfg option to select XAUTH backend to use
Martin Willi [Thu, 8 Dec 2011 15:53:01 +0000 (16:53 +0100)]
Remove unused task swap_initiator method
Martin Willi [Thu, 8 Dec 2011 15:42:11 +0000 (16:42 +0100)]
Use a string to identify xauth backends, no need for integer types
Martin Willi [Thu, 8 Dec 2011 15:38:28 +0000 (15:38 +0000)]
Remove xauth_authenticator, we handle it in the task
Martin Willi [Thu, 8 Dec 2011 15:20:46 +0000 (16:20 +0100)]
Use a second authentication config to configure XAUTH authentication
Martin Willi [Thu, 8 Dec 2011 15:19:54 +0000 (16:19 +0100)]
Replace xauth_request task with a new stub where we reimplement it
Martin Willi [Thu, 8 Dec 2011 14:56:01 +0000 (15:56 +0100)]
Added missing auth_method_t enum names
Martin Willi [Thu, 8 Dec 2011 14:55:43 +0000 (15:55 +0100)]
Defined hybrid IKEv1 authentication methods
Clavister OpenSource [Fri, 9 Dec 2011 15:05:17 +0000 (16:05 +0100)]
Some notification errors added to main_mode process_r
Clavister OpenSource [Fri, 9 Dec 2011 15:04:12 +0000 (16:04 +0100)]
Encrypt INFORMATIONAL exchange if needed
Clavister OpenSource [Fri, 9 Dec 2011 15:03:37 +0000 (16:03 +0100)]
Added possibility to send notification if task_manager->process fails
Clavister OpenSource [Fri, 9 Dec 2011 14:49:07 +0000 (15:49 +0100)]
Added status code to status_t
New status_t enum to allow packets to be sent to peer in task_manager->process
Clavister OpenSource [Fri, 9 Dec 2011 14:43:36 +0000 (15:43 +0100)]
added functions for getting/setting ISAKMP SPI to notify payload
Clavister OpenSource [Fri, 9 Dec 2011 10:41:26 +0000 (11:41 +0100)]
Handling of initial contact
Clavister OpenSource [Thu, 8 Dec 2011 12:47:16 +0000 (13:47 +0100)]
Added retransmissions for initiator.
Martin Willi [Wed, 7 Dec 2011 16:51:35 +0000 (17:51 +0100)]
Cleaned up quick mode notify processing
Martin Willi [Wed, 7 Dec 2011 16:43:58 +0000 (17:43 +0100)]
Add support for KE payloads in IKEv1 quick mode (PFS)
Martin Willi [Wed, 7 Dec 2011 16:41:16 +0000 (17:41 +0100)]
En- and decode DH group attribute in quick mode SA payloads
Martin Willi [Wed, 7 Dec 2011 14:10:05 +0000 (14:10 +0000)]
Use authenticators in IKEv1 main mode
Martin Willi [Wed, 7 Dec 2011 14:09:34 +0000 (14:09 +0000)]
Added a factory function for IKEv1 authenticators
Martin Willi [Wed, 7 Dec 2011 14:08:06 +0000 (14:08 +0000)]
Implemented IKEv1 pubkey SIG payload processing in an authenticator
Martin Willi [Wed, 7 Dec 2011 13:52:02 +0000 (14:52 +0100)]
Implemented IKEv1 PSK HASH payload processing in separated authenticator
Clavister OpenSource [Wed, 7 Dec 2011 12:30:53 +0000 (13:30 +0100)]
Handle incoming delete messages
Andreas Steffen [Tue, 6 Dec 2011 14:15:40 +0000 (15:15 +0100)]
use untoh64 instead of non-portable be64toh
Martin Willi [Tue, 6 Dec 2011 12:38:27 +0000 (13:38 +0100)]
Implemented post-authentication certificate handling for IKEv1
Martin Willi [Tue, 6 Dec 2011 12:37:57 +0000 (13:37 +0100)]
Cleanup CERT payload constructors
Martin Willi [Tue, 6 Dec 2011 11:14:48 +0000 (12:14 +0100)]
Implemented pre-authentication certificate handling for IKEv1
Martin Willi [Tue, 6 Dec 2011 10:44:17 +0000 (11:44 +0100)]
Added task types for IKEv1 certificate handling
Martin Willi [Tue, 6 Dec 2011 09:56:39 +0000 (10:56 +0100)]
Cleaned up certreq payload for IKEv2/IKEv1 use
Martin Willi [Tue, 6 Dec 2011 09:55:15 +0000 (10:55 +0100)]
Reverted ike_cert tasks to IKEv2 only, we use dedicated IKEv1 tasks
Tobias Brunner [Tue, 6 Dec 2011 09:33:10 +0000 (10:33 +0100)]
Install SAs with UDP encapsulation during Quick Mode.
Martin Willi [Mon, 5 Dec 2011 16:24:17 +0000 (17:24 +0100)]
Fix support for plain RSA authentication in IKEv1, both as initiator and responder
Martin Willi [Mon, 5 Dec 2011 16:07:48 +0000 (17:07 +0100)]
Fix referencing of multiple CERTREQ payload with IKEv1, other cleanups
Martin Willi [Mon, 5 Dec 2011 15:20:56 +0000 (16:20 +0100)]
Encode a single IP traffic selector as ID_IPV?_ADDRESS identity
Martin Willi [Mon, 5 Dec 2011 15:14:52 +0000 (16:14 +0100)]
Added missing break;s when converting ID_IP_ADDRESS types to ts, extracted function
Martin Willi [Mon, 5 Dec 2011 14:45:01 +0000 (15:45 +0100)]
Don't use unportable htobe64 macro directly
Martin Willi [Mon, 5 Dec 2011 14:44:51 +0000 (15:44 +0100)]
Implement htoun/untoh64 with potentially faster htobe64/be64toh macros, if available
Andreas Steffen [Sun, 4 Dec 2011 11:53:47 +0000 (12:53 +0100)]
fixed copy-and-paste error
Andreas Steffen [Wed, 26 Oct 2011 22:37:24 +0000 (00:37 +0200)]
extended bio_reader and bio_writer to handle u_int64_t
Clavister OpenSource [Mon, 5 Dec 2011 13:27:53 +0000 (14:27 +0100)]
XAUTH additions for certificates.
Clavister OpenSource [Mon, 5 Dec 2011 13:22:11 +0000 (14:22 +0100)]
signature payload handling.
Clavister OpenSource [Mon, 5 Dec 2011 13:17:17 +0000 (14:17 +0100)]
certificate tasks added to passive list for responder