]> git.ipfire.org Git - thirdparty/strongswan.git/log
thirdparty/strongswan.git
15 years agomake error message about missing MD4 hasher more explicit
Andreas Steffen [Wed, 30 Dec 2009 22:32:03 +0000 (23:32 +0100)] 
make error message about missing MD4 hasher more explicit

15 years agodifferentiate EAP method initialization errors
Andreas Steffen [Wed, 30 Dec 2009 20:34:59 +0000 (21:34 +0100)] 
differentiate EAP method initialization errors

15 years agoremoved charon-specific load statement in pluto scenario
Andreas Steffen [Sat, 26 Dec 2009 16:13:53 +0000 (17:13 +0100)] 
removed charon-specific load statement in pluto scenario

15 years agoPluto's fetcher thread is now created via libstrongswan.
Tobias Brunner [Sat, 26 Dec 2009 14:49:15 +0000 (15:49 +0100)] 
Pluto's fetcher thread is now created via libstrongswan.

15 years agoadded RFC 3779 CA
Andreas Steffen [Fri, 25 Dec 2009 10:01:30 +0000 (11:01 +0100)] 
added RFC 3779 CA

15 years agoadded three RFC 3779 scenarios
Andreas Steffen [Fri, 25 Dec 2009 09:58:06 +0000 (10:58 +0100)] 
added three RFC 3779 scenarios

15 years agoAdded RFC 3779 support to NEWS
Andreas Steffen [Fri, 25 Dec 2009 08:10:44 +0000 (09:10 +0100)] 
Added RFC 3779 support to NEWS

15 years agoenforce RFC 3779 address constraints on traffic selectors
Andreas Steffen [Fri, 25 Dec 2009 00:58:20 +0000 (01:58 +0100)] 
enforce RFC 3779 address constraints on traffic selectors

15 years agoAdapted the load_tester kernel-interface to the changes introduced in 6ec949e02.
Tobias Brunner [Wed, 23 Dec 2009 16:15:28 +0000 (17:15 +0100)] 
Adapted the load_tester kernel-interface to the changes introduced in 6ec949e02.

15 years agoAdded some IPv6 tweaks for Android.
Tobias Brunner [Wed, 23 Dec 2009 10:30:41 +0000 (11:30 +0100)] 
Added some IPv6 tweaks for Android.

Android 1.6 does not yet support the Advanced Sockets API for IPv6 as defined in
RFC 3542. Also, in6addr_any is missing.

15 years agoSemicolon removed.
Tobias Brunner [Tue, 22 Dec 2009 12:59:32 +0000 (13:59 +0100)] 
Semicolon removed.

15 years agoAccording to the man page (and the header files in Android) prctl takes a total of...
Tobias Brunner [Tue, 22 Dec 2009 12:36:46 +0000 (13:36 +0100)] 
According to the man page (and the header files in Android) prctl takes a total of 5 arguments.

15 years agoAdded a workaround for the missing pthread_cancel on Android.
Tobias Brunner [Tue, 22 Dec 2009 09:51:11 +0000 (10:51 +0100)] 
Added a workaround for the missing pthread_cancel on Android.

15 years agoUse pthread_cond_timedwait_monotonic on Android.
Tobias Brunner [Mon, 21 Dec 2009 16:03:33 +0000 (17:03 +0100)] 
Use pthread_cond_timedwait_monotonic on Android.

15 years agoCache queue locking in credential manager corrected.
Tobias Brunner [Mon, 21 Dec 2009 13:09:09 +0000 (14:09 +0100)] 
Cache queue locking in credential manager corrected.

15 years agoJoin worker threads when destroying the processor.
Tobias Brunner [Mon, 21 Dec 2009 12:42:48 +0000 (13:42 +0100)] 
Join worker threads when destroying the processor.

15 years agoCallback job refactored and fixed.
Tobias Brunner [Thu, 17 Dec 2009 17:30:15 +0000 (18:30 +0100)] 
Callback job refactored and fixed.

15 years agoWhitespace cleanup.
Tobias Brunner [Thu, 17 Dec 2009 15:00:14 +0000 (16:00 +0100)] 
Whitespace cleanup.

15 years agoReadding changes that got lost during refactoring/rebasing.
Tobias Brunner [Thu, 17 Dec 2009 14:58:46 +0000 (15:58 +0100)] 
Readding changes that got lost during refactoring/rebasing.

15 years agoUsing the thread wrapper in charon, libstrongswan and their plugins.
Tobias Brunner [Thu, 17 Dec 2009 14:58:12 +0000 (15:58 +0100)] 
Using the thread wrapper in charon, libstrongswan and their plugins.

15 years agoAdding an object-oriented wrapper for thread-specific values.
Tobias Brunner [Thu, 17 Dec 2009 14:28:23 +0000 (15:28 +0100)] 
Adding an object-oriented wrapper for thread-specific values.

15 years agoAdding an object-oriented wrapper for threads.
Tobias Brunner [Thu, 17 Dec 2009 14:25:37 +0000 (15:25 +0100)] 
Adding an object-oriented wrapper for threads.

15 years agoCheck if libpthread is required or not.
Tobias Brunner [Thu, 10 Dec 2009 10:08:01 +0000 (11:08 +0100)] 
Check if libpthread is required or not.

15 years agoCheck for pthread_condattr_init added to configure script.
Tobias Brunner [Tue, 8 Dec 2009 17:24:40 +0000 (18:24 +0100)] 
Check for pthread_condattr_init added to configure script.

15 years agoGenerating the apidoc in an out-of-tree build fixed.
Tobias Brunner [Tue, 8 Dec 2009 16:06:04 +0000 (17:06 +0100)] 
Generating the apidoc in an out-of-tree build fixed.

15 years agoMoved implementation of condvar_t to mutex.c because it requires access to private_mu...
Tobias Brunner [Tue, 8 Dec 2009 16:55:37 +0000 (17:55 +0100)] 
Moved implementation of condvar_t to mutex.c because it requires access to private_mutex_t.

15 years agoSeparated the public interfaces of the threading primitives.
Tobias Brunner [Tue, 8 Dec 2009 15:53:01 +0000 (16:53 +0100)] 
Separated the public interfaces of the threading primitives.

15 years agoImplemented a read-write lock using only mutex_t and condvar_t (in case the pthread_r...
Tobias Brunner [Tue, 8 Dec 2009 13:06:11 +0000 (14:06 +0100)] 
Implemented a read-write lock using only mutex_t and condvar_t (in case the pthread_rwlock_* group of functions is not available).

15 years agoThreading primitives separated.
Tobias Brunner [Mon, 7 Dec 2009 16:26:39 +0000 (17:26 +0100)] 
Threading primitives separated.

15 years agoMoved mutex.c to a separate folder in order to cleanly wrap other threading primitive...
Tobias Brunner [Mon, 7 Dec 2009 14:56:04 +0000 (15:56 +0100)] 
Moved mutex.c to a separate folder in order to cleanly wrap other threading primitives (and utils/mutex.h is now threading.h).

15 years agoverify RFC3779 IP address blocks along X.509 certificate trust chain
Andreas Steffen [Wed, 23 Dec 2009 13:17:28 +0000 (14:17 +0100)] 
verify RFC3779 IP address blocks along X.509 certificate trust chain

15 years agoFixed untoh32 function
Martin Willi [Wed, 23 Dec 2009 12:08:42 +0000 (13:08 +0100)] 
Fixed untoh32 function

15 years agodo not recalculate netbits for true subnets
Andreas Steffen [Tue, 22 Dec 2009 16:07:08 +0000 (17:07 +0100)] 
do not recalculate netbits for true subnets

15 years agoX509_IP_ADDR_BLOCKS flag signals the presence of an ipAddrBlock certificate extension
Andreas Steffen [Tue, 22 Dec 2009 12:18:27 +0000 (13:18 +0100)] 
X509_IP_ADDR_BLOCKS flag signals the presence of an ipAddrBlock certificate extension

15 years agoadded create_ipAddrBlock_enumerator() method to x509_t
Andreas Steffen [Tue, 22 Dec 2009 10:58:30 +0000 (11:58 +0100)] 
added create_ipAddrBlock_enumerator() method to x509_t

15 years agocosmetics
Andreas Steffen [Tue, 22 Dec 2009 08:53:53 +0000 (09:53 +0100)] 
cosmetics

15 years agofixed IPv6 bug in calc_range()
Andreas Steffen [Mon, 21 Dec 2009 23:49:23 +0000 (00:49 +0100)] 
fixed IPv6 bug in calc_range()

15 years agofixed initialization of netbits
Andreas Steffen [Mon, 21 Dec 2009 22:03:14 +0000 (23:03 +0100)] 
fixed initialization of netbits

15 years agofixed distribution list
Andreas Steffen [Mon, 21 Dec 2009 21:28:08 +0000 (22:28 +0100)] 
fixed distribution list

15 years agotraffic_selector supports RFC 3779 address range format
Andreas Steffen [Mon, 21 Dec 2009 20:28:45 +0000 (21:28 +0100)] 
traffic_selector supports RFC 3779 address range format

15 years agoMigrated identification_t to INIT/METHOD macros
Martin Willi [Mon, 21 Dec 2009 14:23:34 +0000 (15:23 +0100)] 
Migrated identification_t to INIT/METHOD macros

15 years agothis->type is set by traffic_selector_create()
Andreas Steffen [Sun, 20 Dec 2009 19:01:18 +0000 (20:01 +0100)] 
this->type is set by traffic_selector_create()

15 years agoparse RFC 3779 addressFamily
Andreas Steffen [Sun, 20 Dec 2009 18:26:28 +0000 (19:26 +0100)] 
parse RFC 3779 addressFamily

15 years agoplugin name is x509
Andreas Steffen [Sun, 20 Dec 2009 15:01:35 +0000 (16:01 +0100)] 
plugin name is x509

15 years agodiscard certificate with unknown critical extensions
Andreas Steffen [Sun, 20 Dec 2009 14:53:39 +0000 (15:53 +0100)] 
discard certificate with unknown critical extensions

15 years agouse traffic_selector_t object to represent ipAddrBlocks
Andreas Steffen [Sun, 20 Dec 2009 14:15:02 +0000 (15:15 +0100)] 
use traffic_selector_t object to represent ipAddrBlocks

15 years agomoved traffic_selectors from charon to libstrongswan
Andreas Steffen [Sun, 20 Dec 2009 13:57:38 +0000 (14:57 +0100)] 
moved traffic_selectors from charon to libstrongswan

15 years agofirewall-enabled ipv6/net2net-ip6-in-ip4-ikev2 scenario
Andreas Steffen [Thu, 17 Dec 2009 18:43:33 +0000 (19:43 +0100)] 
firewall-enabled ipv6/net2net-ip6-in-ip4-ikev2 scenario

15 years agofirewall-enabled ipv6/net2net-ip4-in-ip6-ikev2 scenario
Andreas Steffen [Thu, 17 Dec 2009 17:50:45 +0000 (18:50 +0100)] 
firewall-enabled ipv6/net2net-ip4-in-ip6-ikev2 scenario

15 years agoparse ipAddrBlocks
Andreas Steffen [Thu, 17 Dec 2009 16:32:26 +0000 (17:32 +0100)] 
parse ipAddrBlocks

15 years agofixed updown plugin for mixed IPv4/IPv6 tunnels
Andreas Steffen [Thu, 17 Dec 2009 16:28:11 +0000 (17:28 +0100)] 
fixed updown plugin for mixed IPv4/IPv6 tunnels

15 years agoMigrated curl_fetcher to INIT/METHOD macros
Martin Willi [Tue, 8 Dec 2009 15:21:08 +0000 (16:21 +0100)] 
Migrated curl_fetcher to INIT/METHOD macros

15 years agoAdded a METHOD() macro to define methods with both public and private signatures
Martin Willi [Tue, 8 Dec 2009 15:12:16 +0000 (16:12 +0100)] 
Added a METHOD() macro to define methods with both public and private signatures

15 years agoAdded a INIT() macro to initialize class instances
Martin Willi [Tue, 8 Dec 2009 15:11:37 +0000 (16:11 +0100)] 
Added a INIT() macro to initialize class instances

15 years agoFixed BEET mode by installing SAs with negotiated address in traffic selector
Martin Willi [Thu, 17 Dec 2009 09:50:37 +0000 (10:50 +0100)] 
Fixed BEET mode by installing SAs with negotiated address in traffic selector

15 years agoadded IKEv1 Camellia support to NEWS
Andreas Steffen [Wed, 16 Dec 2009 20:52:32 +0000 (21:52 +0100)] 
added IKEv1 Camellia support to NEWS

15 years agoikev1/ip-pool-db-push scenario tests DNS and NBNS server support
Andreas Steffen [Wed, 16 Dec 2009 20:50:39 +0000 (21:50 +0100)] 
ikev1/ip-pool-db-push scenario tests DNS and NBNS server support

15 years agoIKEv1 daemon supports DNS and NBNS server assignment from database
Andreas Steffen [Wed, 16 Dec 2009 20:49:51 +0000 (21:49 +0100)] 
IKEv1 daemon supports DNS and NBNS server assignment from database

15 years agoikev1/ip-pool-db scenario tests DNS and NBNS server support
Andreas Steffen [Wed, 16 Dec 2009 20:22:13 +0000 (21:22 +0100)] 
ikev1/ip-pool-db scenario tests DNS and NBNS server support

15 years agosql/ip-pool-db scenario tests DNS and NBNS server support
Andreas Steffen [Wed, 16 Dec 2009 18:02:23 +0000 (19:02 +0100)] 
sql/ip-pool-db scenario tests DNS and NBNS server support

15 years agoikev2/ip-pool-db scenario tests DNS and NBNS server support
Andreas Steffen [Wed, 16 Dec 2009 17:45:29 +0000 (18:45 +0100)] 
ikev2/ip-pool-db scenario tests DNS and NBNS server support

15 years agoadded ipsec pool DNS and NBNS support to NEWS
Andreas Steffen [Wed, 16 Dec 2009 17:20:07 +0000 (18:20 +0100)] 
added ipsec pool DNS and NBNS support to NEWS

15 years agoipsec pool manages dns and nbns servers
Andreas Steffen [Wed, 16 Dec 2009 17:11:57 +0000 (18:11 +0100)] 
ipsec pool manages dns and nbns servers

15 years agocosmetics
Andreas Steffen [Wed, 16 Dec 2009 12:33:09 +0000 (13:33 +0100)] 
cosmetics

15 years agoprovide attributes from SQL database
Andreas Steffen [Wed, 16 Dec 2009 11:31:41 +0000 (12:31 +0100)] 
provide attributes from SQL database

15 years agoadded openssl-ikev1/alg-camellia scenario
Andreas Steffen [Tue, 15 Dec 2009 18:55:58 +0000 (19:55 +0100)] 
added openssl-ikev1/alg-camellia scenario

15 years agoremoved superfluous ikev1/esp-alg-camellia scenario
Andreas Steffen [Tue, 15 Dec 2009 18:16:28 +0000 (19:16 +0100)] 
removed superfluous ikev1/esp-alg-camellia scenario

15 years agoadded gcrypt-ikev1/alg-camellia scenario
Andreas Steffen [Tue, 15 Dec 2009 18:15:44 +0000 (19:15 +0100)] 
added gcrypt-ikev1/alg-camellia scenario

15 years agoadd IKEv1 support for the Camellia cipher
Andreas Steffen [Tue, 15 Dec 2009 18:13:06 +0000 (19:13 +0100)] 
add IKEv1 support for the Camellia cipher

15 years agoAdded htoun16/32 and untoh16/32 to read/write unaligned network order integers
Martin Willi [Tue, 15 Dec 2009 12:39:01 +0000 (13:39 +0100)] 
Added htoun16/32 and untoh16/32 to read/write unaligned network order integers

15 years agoInstall v6 routes via outgoing interface for now
Martin Willi [Mon, 14 Dec 2009 13:44:24 +0000 (14:44 +0100)] 
Install v6 routes via outgoing interface for now

15 years agoactivate tcpdump in ikev1/esp-alg-des scenario
Andreas Steffen [Thu, 10 Dec 2009 21:37:43 +0000 (22:37 +0100)] 
activate tcpdump in ikev1/esp-alg-des scenario

15 years agoshuffled output order to achieve consistence
Andreas Steffen [Wed, 9 Dec 2009 16:26:35 +0000 (17:26 +0100)] 
shuffled output order to achieve consistence

15 years agoadded pfkey/alg-sha384 and pfkey/alg-sha512 scenarios
Andreas Steffen [Wed, 9 Dec 2009 16:25:12 +0000 (17:25 +0100)] 
added pfkey/alg-sha384 and pfkey/alg-sha512 scenarios

15 years agoadapted openssl-ikev2/alg scenarios
Andreas Steffen [Wed, 9 Dec 2009 14:51:43 +0000 (15:51 +0100)] 
adapted openssl-ikev2/alg scenarios

15 years agoadapted gcrypt-ikev2/alg-camellia scenario
Andreas Steffen [Wed, 9 Dec 2009 14:48:03 +0000 (15:48 +0100)] 
adapted gcrypt-ikev2/alg-camellia scenario

15 years agoadapted gcrypt-ikev1 alg scenarios
Andreas Steffen [Wed, 9 Dec 2009 14:45:45 +0000 (15:45 +0100)] 
adapted gcrypt-ikev1 alg scenarios

15 years agoadapted ikev1 alg and esp scenarios
Andreas Steffen [Wed, 9 Dec 2009 14:41:54 +0000 (15:41 +0100)] 
adapted ikev1 alg and esp scenarios

15 years agoadapted pfkey alg and esp scenarios
Andreas Steffen [Wed, 9 Dec 2009 14:38:17 +0000 (15:38 +0100)] 
adapted pfkey alg and esp scenarios

15 years agoremove again the ikev2/esp-alg-camellia scenario
Andreas Steffen [Wed, 9 Dec 2009 14:26:43 +0000 (15:26 +0100)] 
remove again the ikev2/esp-alg-camellia scenario

15 years agoadapted ikev2 alg and esp scenarios
Andreas Steffen [Wed, 9 Dec 2009 14:19:10 +0000 (15:19 +0100)] 
adapted ikev2 alg and esp scenarios

15 years agoremoved redundant ikev1/ike-alg-sha2 scenarios
Andreas Steffen [Wed, 9 Dec 2009 09:11:03 +0000 (10:11 +0100)] 
removed redundant ikev1/ike-alg-sha2 scenarios

15 years agoadded ikev1/alg-sha512 scenario
Andreas Steffen [Wed, 9 Dec 2009 08:51:54 +0000 (09:51 +0100)] 
added ikev1/alg-sha512 scenario

15 years agoadded ikev1/alg-sha384 scenario
Andreas Steffen [Wed, 9 Dec 2009 08:46:40 +0000 (09:46 +0100)] 
added ikev1/alg-sha384 scenario

15 years agorenamed ikev1/alg-sha2_256 scenario to ikev1/alg-sha256
Andreas Steffen [Wed, 9 Dec 2009 08:36:16 +0000 (09:36 +0100)] 
renamed ikev1/alg-sha2_256 scenario to ikev1/alg-sha256

15 years agoadded ikev1/alg-sha256-96 scenario
Andreas Steffen [Wed, 9 Dec 2009 08:35:17 +0000 (09:35 +0100)] 
added ikev1/alg-sha256-96 scenario

15 years agofixed IKEv1 support of HMAC_SHA2_256_96
Andreas Steffen [Wed, 9 Dec 2009 08:33:32 +0000 (09:33 +0100)] 
fixed IKEv1 support of HMAC_SHA2_256_96

15 years agoadded Juniper SRX support to NEWS
Andreas Steffen [Wed, 9 Dec 2009 07:00:19 +0000 (08:00 +0100)] 
added Juniper SRX support to NEWS

15 years agoif end id is missing assign IP address to raw public key
Andreas Steffen [Wed, 9 Dec 2009 06:24:43 +0000 (07:24 +0100)] 
if end id is missing assign IP address to raw public key

15 years agoIKEv1 support of ESP SHA2_HMAC with correct truncation
Andreas Steffen [Tue, 8 Dec 2009 23:24:22 +0000 (00:24 +0100)] 
IKEv1 support of ESP SHA2_HMAC with correct truncation

15 years agosome code optimizations
Andreas Steffen [Tue, 8 Dec 2009 23:19:03 +0000 (00:19 +0100)] 
some code optimizations

15 years agoadded ipAddrBlocks OID
Andreas Steffen [Tue, 8 Dec 2009 22:48:56 +0000 (23:48 +0100)] 
added ipAddrBlocks OID

15 years agoremoved redundant ikev2/esp-alg-camellia scenario
Andreas Steffen [Tue, 8 Dec 2009 20:43:03 +0000 (21:43 +0100)] 
removed redundant ikev2/esp-alg-camellia scenario

15 years agoImproved libfast session management, using a hashtable
Martin Willi [Sat, 5 Dec 2009 16:56:44 +0000 (17:56 +0100)] 
Improved libfast session management, using a hashtable

15 years agoRemoved obsolete curl interface specific destructor
Martin Willi [Tue, 8 Dec 2009 15:21:58 +0000 (16:21 +0100)] 
Removed obsolete curl interface specific destructor

15 years agoSupport "_" and "-" variants of NetworkManager pkg-config packages
Martin Willi [Tue, 8 Dec 2009 13:35:16 +0000 (14:35 +0100)] 
Support "_" and "-" variants of NetworkManager pkg-config packages

15 years agoUndef PACKAGE_BUG/URL of strongSwan before including ruby variants
Martin Willi [Tue, 8 Dec 2009 13:34:14 +0000 (14:34 +0100)] 
Undef PACKAGE_BUG/URL of strongSwan before including ruby variants

15 years agoRemove generated config.h.in from source tree
Martin Willi [Tue, 8 Dec 2009 13:29:48 +0000 (14:29 +0100)] 
Remove generated config.h.in from source tree

15 years agoadded ikev2/alg-3des-md5 scenario
Andreas Steffen [Tue, 8 Dec 2009 11:54:42 +0000 (12:54 +0100)] 
added ikev2/alg-3des-md5 scenario

15 years agoThe attribute manager was moved from daemon_t to libstrongswan.
Tobias Brunner [Mon, 7 Dec 2009 15:00:27 +0000 (16:00 +0100)] 
The attribute manager was moved from daemon_t to libstrongswan.