]> git.ipfire.org Git - people/ms/strongswan.git/log
people/ms/strongswan.git
14 years agoadapted gcrypt-ikev1 alg scenarios
Andreas Steffen [Wed, 9 Dec 2009 14:45:45 +0000 (15:45 +0100)] 
adapted gcrypt-ikev1 alg scenarios

14 years agoadapted ikev1 alg and esp scenarios
Andreas Steffen [Wed, 9 Dec 2009 14:41:54 +0000 (15:41 +0100)] 
adapted ikev1 alg and esp scenarios

14 years agoadapted pfkey alg and esp scenarios
Andreas Steffen [Wed, 9 Dec 2009 14:38:17 +0000 (15:38 +0100)] 
adapted pfkey alg and esp scenarios

14 years agoremove again the ikev2/esp-alg-camellia scenario
Andreas Steffen [Wed, 9 Dec 2009 14:26:43 +0000 (15:26 +0100)] 
remove again the ikev2/esp-alg-camellia scenario

14 years agoadapted ikev2 alg and esp scenarios
Andreas Steffen [Wed, 9 Dec 2009 14:19:10 +0000 (15:19 +0100)] 
adapted ikev2 alg and esp scenarios

14 years agoremoved redundant ikev1/ike-alg-sha2 scenarios
Andreas Steffen [Wed, 9 Dec 2009 09:11:03 +0000 (10:11 +0100)] 
removed redundant ikev1/ike-alg-sha2 scenarios

14 years agoadded ikev1/alg-sha512 scenario
Andreas Steffen [Wed, 9 Dec 2009 08:51:54 +0000 (09:51 +0100)] 
added ikev1/alg-sha512 scenario

14 years agoadded ikev1/alg-sha384 scenario
Andreas Steffen [Wed, 9 Dec 2009 08:46:40 +0000 (09:46 +0100)] 
added ikev1/alg-sha384 scenario

14 years agorenamed ikev1/alg-sha2_256 scenario to ikev1/alg-sha256
Andreas Steffen [Wed, 9 Dec 2009 08:36:16 +0000 (09:36 +0100)] 
renamed ikev1/alg-sha2_256 scenario to ikev1/alg-sha256

14 years agoadded ikev1/alg-sha256-96 scenario
Andreas Steffen [Wed, 9 Dec 2009 08:35:17 +0000 (09:35 +0100)] 
added ikev1/alg-sha256-96 scenario

14 years agofixed IKEv1 support of HMAC_SHA2_256_96
Andreas Steffen [Wed, 9 Dec 2009 08:33:32 +0000 (09:33 +0100)] 
fixed IKEv1 support of HMAC_SHA2_256_96

14 years agoadded Juniper SRX support to NEWS
Andreas Steffen [Wed, 9 Dec 2009 07:00:19 +0000 (08:00 +0100)] 
added Juniper SRX support to NEWS

14 years agoif end id is missing assign IP address to raw public key
Andreas Steffen [Wed, 9 Dec 2009 06:24:43 +0000 (07:24 +0100)] 
if end id is missing assign IP address to raw public key

14 years agoIKEv1 support of ESP SHA2_HMAC with correct truncation
Andreas Steffen [Tue, 8 Dec 2009 23:24:22 +0000 (00:24 +0100)] 
IKEv1 support of ESP SHA2_HMAC with correct truncation

14 years agosome code optimizations
Andreas Steffen [Tue, 8 Dec 2009 23:19:03 +0000 (00:19 +0100)] 
some code optimizations

14 years agoadded ipAddrBlocks OID
Andreas Steffen [Tue, 8 Dec 2009 22:48:56 +0000 (23:48 +0100)] 
added ipAddrBlocks OID

14 years agoremoved redundant ikev2/esp-alg-camellia scenario
Andreas Steffen [Tue, 8 Dec 2009 20:43:03 +0000 (21:43 +0100)] 
removed redundant ikev2/esp-alg-camellia scenario

14 years agoImproved libfast session management, using a hashtable
Martin Willi [Sat, 5 Dec 2009 16:56:44 +0000 (17:56 +0100)] 
Improved libfast session management, using a hashtable

14 years agoRemoved obsolete curl interface specific destructor
Martin Willi [Tue, 8 Dec 2009 15:21:58 +0000 (16:21 +0100)] 
Removed obsolete curl interface specific destructor

14 years agoSupport "_" and "-" variants of NetworkManager pkg-config packages
Martin Willi [Tue, 8 Dec 2009 13:35:16 +0000 (14:35 +0100)] 
Support "_" and "-" variants of NetworkManager pkg-config packages

14 years agoUndef PACKAGE_BUG/URL of strongSwan before including ruby variants
Martin Willi [Tue, 8 Dec 2009 13:34:14 +0000 (14:34 +0100)] 
Undef PACKAGE_BUG/URL of strongSwan before including ruby variants

14 years agoRemove generated config.h.in from source tree
Martin Willi [Tue, 8 Dec 2009 13:29:48 +0000 (14:29 +0100)] 
Remove generated config.h.in from source tree

14 years agoadded ikev2/alg-3des-md5 scenario
Andreas Steffen [Tue, 8 Dec 2009 11:54:42 +0000 (12:54 +0100)] 
added ikev2/alg-3des-md5 scenario

14 years agoThe attribute manager was moved from daemon_t to libstrongswan.
Tobias Brunner [Mon, 7 Dec 2009 15:00:27 +0000 (16:00 +0100)] 
The attribute manager was moved from daemon_t to libstrongswan.

14 years agoDo not execute the callback job if it has been cancelled since registration
Martin Willi [Thu, 3 Dec 2009 07:00:04 +0000 (08:00 +0100)] 
Do not execute the callback job if it has been cancelled since registration

14 years agoCleanup library if daemon initialization fails
Martin Willi [Thu, 3 Dec 2009 06:56:19 +0000 (07:56 +0100)] 
Cleanup library if daemon initialization fails

14 years agoTo build strongSwan from git sources, gettext is required
Martin Willi [Wed, 2 Dec 2009 10:49:11 +0000 (11:49 +0100)] 
To build strongSwan from git sources, gettext is required

14 years agoDo not install invalid 0.0.0.0 DNS servers
Martin Willi [Tue, 1 Dec 2009 14:46:56 +0000 (15:46 +0100)] 
Do not install invalid 0.0.0.0 DNS servers

14 years agoPrefer EAP-Identity for provider attribute/address lookup
Martin Willi [Tue, 1 Dec 2009 13:01:56 +0000 (13:01 +0000)] 
Prefer EAP-Identity for provider attribute/address lookup

14 years agoSave EAP-Identity on auth config
Martin Willi [Tue, 1 Dec 2009 13:23:37 +0000 (14:23 +0100)] 
Save EAP-Identity on auth config

14 years agoStore completed authentication rounds permanently on IKE_SA, with flush option
Martin Willi [Tue, 1 Dec 2009 10:35:30 +0000 (11:35 +0100)] 
Store completed authentication rounds permanently on IKE_SA, with flush option

14 years agoRemoved obsolete and unused [gs]et_eap_identity() methods
Martin Willi [Mon, 30 Nov 2009 15:59:23 +0000 (16:59 +0100)] 
Removed obsolete and unused [gs]et_eap_identity() methods

14 years agoDo not propose transport mode as initiator if connection is NATed
Martin Willi [Mon, 30 Nov 2009 10:32:26 +0000 (11:32 +0100)] 
Do not propose transport mode as initiator if connection is NATed

14 years agoVerify EAP-SIM/AKA AT_MAC before processing any attributes
Martin Willi [Mon, 30 Nov 2009 08:58:54 +0000 (09:58 +0100)] 
Verify EAP-SIM/AKA AT_MAC before processing any attributes

14 years agoSIM/AKA/Request/Reauthentication AT_MAC does not include NONCE_S, only the response
Martin Willi [Fri, 27 Nov 2009 14:40:40 +0000 (15:40 +0100)] 
SIM/AKA/Request/Reauthentication AT_MAC does not include NONCE_S, only the response

14 years agoInvoke attribute/key hooks from libsimaka
Martin Willi [Fri, 27 Nov 2009 10:16:20 +0000 (11:16 +0100)] 
Invoke attribute/key hooks from libsimaka

14 years agoExtended SIM manager by hooks, currently featuring attribute and key hooks
Martin Willi [Fri, 27 Nov 2009 10:14:40 +0000 (11:14 +0100)] 
Extended SIM manager by hooks, currently featuring attribute and key hooks

14 years agoAdded a get_sa() method to the bus, allowing a thread to lookup its IKE_SA
Martin Willi [Fri, 27 Nov 2009 08:34:38 +0000 (09:34 +0100)] 
Added a get_sa() method to the bus, allowing a thread to lookup its IKE_SA

14 years agoHandle NOT_SUPPORTED or other errors properly in get_quintuplet
Martin Willi [Fri, 27 Nov 2009 13:55:20 +0000 (14:55 +0100)] 
Handle NOT_SUPPORTED or other errors properly in get_quintuplet

14 years agoadded RFC-conforming ikev2/sha2 scenarios
Andreas Steffen [Thu, 26 Nov 2009 22:48:29 +0000 (23:48 +0100)] 
added RFC-conforming ikev2/sha2 scenarios

14 years agoadapted ikev2/alg-aes-xcbc scenario
Andreas Steffen [Thu, 26 Nov 2009 22:46:27 +0000 (23:46 +0100)] 
adapted ikev2/alg-aes-xcbc scenario

14 years agoUse transport mode ESP SA if IPcomp is used, IPcomp already applies outer IP header
Martin Willi [Thu, 26 Nov 2009 14:58:55 +0000 (15:58 +0100)] 
Use transport mode ESP SA if IPcomp is used, IPcomp already applies outer IP header

14 years agoAdded NEWS about SHA2 changes
Martin Willi [Thu, 26 Nov 2009 09:27:35 +0000 (10:27 +0100)] 
Added NEWS about SHA2 changes

14 years agoUse full algorithm name for SHA384/512 HMACs
Martin Willi [Tue, 24 Nov 2009 14:21:16 +0000 (15:21 +0100)] 
Use full algorithm name for SHA384/512 HMACs

14 years agoSupport the Linux specific SHA256 96 bit truncation HMAC via "sha256_96" keyword
Martin Willi [Fri, 20 Nov 2009 09:49:03 +0000 (09:49 +0000)] 
Support the Linux specific SHA256 96 bit truncation HMAC via "sha256_96" keyword

14 years agoInstall SHA256_128 auth algorithm with specified 128 bit truncation
Martin Willi [Fri, 20 Nov 2009 09:42:29 +0000 (09:42 +0000)] 
Install SHA256_128 auth algorithm with specified 128 bit truncation

14 years agoUpdated XFRM linux header, includes specified truncations for auth algos
Martin Willi [Fri, 20 Nov 2009 09:41:46 +0000 (09:41 +0000)] 
Updated XFRM linux header, includes specified truncations for auth algos

14 years agoAdded support for IPv6 source route installation
Martin Willi [Tue, 24 Nov 2009 13:10:18 +0000 (14:10 +0100)] 
Added support for IPv6 source route installation

14 years agoCheck existing path in mobike probing only if we still have a route
Martin Willi [Tue, 24 Nov 2009 13:09:09 +0000 (14:09 +0100)] 
Check existing path in mobike probing only if we still have a route

14 years agoput identities in single quotes
Andreas Steffen [Wed, 25 Nov 2009 08:02:09 +0000 (09:02 +0100)] 
put identities in single quotes

14 years agoadded more debugging in configuration attribute handling
Andreas Steffen [Tue, 24 Nov 2009 22:17:07 +0000 (23:17 +0100)] 
added more debugging in configuration attribute handling

14 years agochanged error messages in the case of faulty esp and ike strings
Andreas Steffen [Tue, 24 Nov 2009 15:45:52 +0000 (16:45 +0100)] 
changed error messages in the case of faulty esp and ike strings

14 years agodo not send all available kernel algorithms if esp string is faulty
Andreas Steffen [Tue, 24 Nov 2009 15:38:10 +0000 (16:38 +0100)] 
do not send all available kernel algorithms if esp string is faulty

14 years agocheck if alg_info_esp exists
Elmar Vonlanthen [Tue, 24 Nov 2009 15:15:12 +0000 (16:15 +0100)] 
check if alg_info_esp exists

14 years agoadded some parentheses
Andreas Steffen [Tue, 24 Nov 2009 13:36:17 +0000 (14:36 +0100)] 
added some parentheses

14 years agoallow ECP DH groups in pfsgroup definition
Andreas Steffen [Tue, 24 Nov 2009 13:35:25 +0000 (14:35 +0100)] 
allow ECP DH groups in pfsgroup definition

14 years agorenewed OCSP Signing certificate
Andreas Steffen [Tue, 24 Nov 2009 12:55:38 +0000 (13:55 +0100)] 
renewed OCSP Signing certificate

14 years agoissue error message for expired certificates in OCSP trust chain checking
Andreas Steffen [Tue, 24 Nov 2009 11:37:38 +0000 (12:37 +0100)] 
issue error message for expired certificates in OCSP trust chain checking

14 years agoupdated IKEv2 notification messages assigned by IANA
Andreas Steffen [Tue, 24 Nov 2009 08:21:00 +0000 (09:21 +0100)] 
updated IKEv2 notification messages assigned by IANA

14 years agoupdated NEWS for 4.3.6dr2
Andreas Steffen [Tue, 24 Nov 2009 08:18:41 +0000 (09:18 +0100)] 
updated NEWS for 4.3.6dr2

14 years agoDo not recreate existing create_child subtask when retrying with different DH group
Martin Willi [Mon, 23 Nov 2009 12:50:01 +0000 (13:50 +0100)] 
Do not recreate existing create_child subtask when retrying with different DH group

14 years agoAvoid potentially unaligned half-word read
Martin Willi [Mon, 23 Nov 2009 12:49:19 +0000 (13:49 +0100)] 
Avoid potentially unaligned half-word read

14 years agoCorrectly set host number to zero when computing traffic selector range
Eric Mertens [Tue, 17 Nov 2009 18:30:37 +0000 (10:30 -0800)] 
Correctly set host number to zero when computing traffic selector range

14 years agoUse abort() instead of raising SIGKILL, gives us proper core dumps if enabled
Martin Willi [Fri, 20 Nov 2009 13:36:24 +0000 (14:36 +0100)] 
Use abort() instead of raising SIGKILL, gives us proper core dumps if enabled

14 years agoUse status_t return value for get_quintuplet() dummy implementations
Martin Willi [Fri, 20 Nov 2009 10:02:06 +0000 (11:02 +0100)] 
Use status_t return value for get_quintuplet() dummy implementations

14 years agoMove comment out of register_printf_function test
Martin Willi [Thu, 19 Nov 2009 13:37:34 +0000 (14:37 +0100)] 
Move comment out of register_printf_function test

14 years agoMessage stringification supports more detailed EAP payload information
Martin Willi [Wed, 18 Nov 2009 09:37:46 +0000 (10:37 +0100)] 
Message stringification supports more detailed EAP payload information

14 years agoCorrectly enumerate attributes to request as initiator with the actually requesting...
Martin Willi [Tue, 17 Nov 2009 16:51:30 +0000 (17:51 +0100)] 
Correctly enumerate attributes to request as initiator with the actually requesting handler

14 years agoFixed memleak in attribute handling
Martin Willi [Tue, 17 Nov 2009 15:55:45 +0000 (15:55 +0000)] 
Fixed memleak in attribute handling

14 years agoattr plugin supports any custom attribute type having a v4/v6 IP under the charon...
Martin Willi [Tue, 17 Nov 2009 15:53:57 +0000 (15:53 +0000)] 
attr plugin supports any custom attribute type having a v4/v6 IP under the charon.plugins.attr namespace

14 years agoSupport enumeration of key/value pairs in a section of strongswan.conf
Martin Willi [Tue, 17 Nov 2009 15:52:36 +0000 (15:52 +0000)] 
Support enumeration of key/value pairs in a section of strongswan.conf

14 years agoWhitelist register_printf_specifier in leak detective
Martin Willi [Tue, 17 Nov 2009 15:51:57 +0000 (15:51 +0000)] 
Whitelist register_printf_specifier in leak detective

14 years agoGive plugins more control of which configuration attributes to request, and pass...
Martin Willi [Tue, 17 Nov 2009 13:51:50 +0000 (14:51 +0100)] 
Give plugins more control of which configuration attributes to request, and pass received attributes back to the requesting handler

14 years agoEncrypt payloads with missing rule, fix insertion of non-encrypted payloads
Martin Willi [Thu, 12 Nov 2009 14:52:12 +0000 (14:52 +0000)] 
Encrypt payloads with missing rule, fix insertion of non-encrypted payloads

14 years agoBuild libsimaka with libtool, as we require a PIC-enabled version
Martin Willi [Tue, 10 Nov 2009 13:24:19 +0000 (14:24 +0100)] 
Build libsimaka with libtool, as we require a PIC-enabled version

14 years agoFix word alignement in memxor() on 64-bit architectures
Martin Willi [Tue, 10 Nov 2009 13:12:00 +0000 (14:12 +0100)] 
Fix word alignement in memxor() on 64-bit architectures

14 years agoDo not complain about missing payload order rules for private use payloads
Martin Willi [Tue, 10 Nov 2009 10:11:03 +0000 (11:11 +0100)] 
Do not complain about missing payload order rules for private use payloads

14 years agoProperly initialize attribute encoding/length values
Martin Willi [Tue, 10 Nov 2009 10:07:37 +0000 (11:07 +0100)] 
Properly initialize attribute encoding/length values

14 years agoIdentation/whitespace cleanups
Martin Willi [Tue, 10 Nov 2009 10:07:13 +0000 (11:07 +0100)] 
Identation/whitespace cleanups

14 years agoSimplified vendor ID payload interface
Martin Willi [Mon, 9 Nov 2009 11:38:48 +0000 (12:38 +0100)] 
Simplified vendor ID payload interface

14 years agoInvoke message hook before generation, allowing plugins to mangle it
Martin Willi [Mon, 2 Nov 2009 09:44:11 +0000 (10:44 +0100)] 
Invoke message hook before generation, allowing plugins to mangle it

14 years agoPrefer MODP2048/1536 over ECP Diffie-Hellman groups
Martin Willi [Thu, 12 Nov 2009 13:10:30 +0000 (13:10 +0000)] 
Prefer MODP2048/1536 over ECP Diffie-Hellman groups

14 years agoUse register_printf_specifier instead of deprecated register_printf_function, if...
Martin Willi [Thu, 12 Nov 2009 12:16:46 +0000 (13:16 +0100)] 
Use register_printf_specifier instead of deprecated register_printf_function, if available

14 years agoFixed compiler warning about missing return value
Martin Willi [Thu, 12 Nov 2009 10:17:02 +0000 (11:17 +0100)] 
Fixed compiler warning about missing return value

14 years agoSupport variable RES length in AKA quintuplets
Martin Willi [Thu, 12 Nov 2009 09:27:50 +0000 (10:27 +0100)] 
Support variable RES length in AKA quintuplets

14 years agoPorted pseudonym/reauth functionality to EAP-AKA
Martin Willi [Thu, 29 Oct 2009 16:38:45 +0000 (17:38 +0100)] 
Ported pseudonym/reauth functionality to EAP-AKA

14 years agoPassing other as NULL should not always result in a match if me matches
Martin Willi [Thu, 29 Oct 2009 16:37:36 +0000 (17:37 +0100)] 
Passing other as NULL should not always result in a match if me matches

14 years agoUse new identity constructor in EAP-SIM
Martin Willi [Thu, 29 Oct 2009 14:58:43 +0000 (15:58 +0100)] 
Use new identity constructor in EAP-SIM

14 years agoAdded identification constructor using a chunk of data, guessing id type
Martin Willi [Thu, 29 Oct 2009 14:52:00 +0000 (15:52 +0100)] 
Added identification constructor using a chunk of data, guessing id type

14 years agoMoved card/provider enumeration to SIM manager, providing wrapped functions for both...
Martin Willi [Thu, 29 Oct 2009 13:56:45 +0000 (14:56 +0100)] 
Moved card/provider enumeration to SIM manager, providing wrapped functions for both SIM and AKA plugins

14 years agoAdded option to disable identity requests completely (old behavior)
Martin Willi [Thu, 29 Oct 2009 09:19:43 +0000 (10:19 +0100)] 
Added option to disable identity requests completely (old behavior)

14 years agoFixed replacing existing reauthentication data
Martin Willi [Thu, 29 Oct 2009 08:49:55 +0000 (09:49 +0100)] 
Fixed replacing existing reauthentication data

14 years agoInitiate full authentication if reauthentication identity is unknown
Martin Willi [Wed, 28 Oct 2009 15:04:45 +0000 (16:04 +0100)] 
Initiate full authentication if reauthentication identity is unknown

14 years agoMoved reauth/pseudonym functionality from eap-sim-file to separate plugins, usable...
Martin Willi [Wed, 28 Oct 2009 14:34:05 +0000 (15:34 +0100)] 
Moved reauth/pseudonym functionality from eap-sim-file to separate plugins, usable by any SIM/AKA backend

14 years agoeap-sim-file plugin supports volatile in-memory storage of fast reauthentication...
Martin Willi [Wed, 28 Oct 2009 13:18:33 +0000 (14:18 +0100)] 
eap-sim-file plugin supports volatile in-memory storage of fast reauthentication data

14 years agoInitial support for fast reauthentication in EAP-SIM
Martin Willi [Wed, 28 Oct 2009 13:16:54 +0000 (14:16 +0100)] 
Initial support for fast reauthentication in EAP-SIM

14 years agoEAP-SIM/AKA crypto helper supports key derivation for fast reauthentication
Martin Willi [Wed, 28 Oct 2009 13:15:24 +0000 (14:15 +0100)] 
EAP-SIM/AKA crypto helper supports key derivation for fast reauthentication

14 years agoFallback to permanent identity request if pseudonym mapping failed
Martin Willi [Tue, 27 Oct 2009 10:12:36 +0000 (11:12 +0100)] 
Fallback to permanent identity request if pseudonym mapping failed

14 years agoQuery triplet/quintuplet functions with permanent identity only,
Martin Willi [Tue, 27 Oct 2009 10:10:44 +0000 (11:10 +0100)] 
Query triplet/quintuplet functions with permanent identity only,
extended sim_provider with a is_pseudonym() function.

14 years agoeap-sim-file plugin can store pseudonym information volatile in memory
Martin Willi [Mon, 26 Oct 2009 15:11:40 +0000 (16:11 +0100)] 
eap-sim-file plugin can store pseudonym information volatile in memory