]> git.ipfire.org Git - thirdparty/strongswan.git/log
thirdparty/strongswan.git
14 years agoBe a little more verbose about cert payload injection
Martin Willi [Tue, 9 Nov 2010 11:05:30 +0000 (12:05 +0100)] 
Be a little more verbose about cert payload injection

14 years agoSupport hook suffixes to use the same hook multiple times
Martin Willi [Tue, 9 Nov 2010 10:17:20 +0000 (11:17 +0100)] 
Support hook suffixes to use the same hook multiple times

14 years agoSupport arbitrary suffixes for actions, same action multiple times
Martin Willi [Tue, 9 Nov 2010 10:07:37 +0000 (11:07 +0100)] 
Support arbitrary suffixes for actions, same action multiple times

14 years agoAdded a hook to ignore specific messages
Martin Willi [Tue, 9 Nov 2010 09:19:56 +0000 (10:19 +0100)] 
Added a hook to ignore specific messages

14 years agoIngore messages with exchange type altered to UNDEFINED in message() hook
Martin Willi [Tue, 9 Nov 2010 09:19:09 +0000 (10:19 +0100)] 
Ingore messages with exchange type altered to UNDEFINED in message() hook

14 years agoAdded a hook to send unencrypted notifies in established IKE_SAs
Martin Willi [Tue, 9 Nov 2010 08:59:56 +0000 (09:59 +0100)] 
Added a hook to send unencrypted notifies in established IKE_SAs

14 years agoFail silently without INVALID_SYNTAX if message not verified
Martin Willi [Tue, 9 Nov 2010 08:55:20 +0000 (09:55 +0100)] 
Fail silently without INVALID_SYNTAX if message not verified

14 years agoInclude suiteb test suite config in distribution
Martin Willi [Mon, 8 Nov 2010 15:45:48 +0000 (16:45 +0100)] 
Include suiteb test suite config in distribution

14 years agoFixed loading of credentials using a relative path
Martin Willi [Tue, 2 Nov 2010 15:12:29 +0000 (16:12 +0100)] 
Fixed loading of credentials using a relative path

14 years agoImplemented a add_notify hook to inject arbitrary Notify payloads
Martin Willi [Tue, 2 Nov 2010 14:51:56 +0000 (15:51 +0100)] 
Implemented a add_notify hook to inject arbitrary Notify payloads

14 years agoMoved message()-hook invocation to generate_message(), catch pre-generated IKE_SA_INI...
Martin Willi [Tue, 2 Nov 2010 14:49:09 +0000 (15:49 +0100)] 
Moved message()-hook invocation to generate_message(), catch pre-generated IKE_SA_INITs, too

14 years agoImplemented a hook to unsort payloads in messages
Martin Willi [Tue, 2 Nov 2010 13:55:18 +0000 (14:55 +0100)] 
Implemented a hook to unsort payloads in messages

14 years agoSupport removal of payloads from messages
Martin Willi [Tue, 2 Nov 2010 13:30:45 +0000 (14:30 +0100)] 
Support removal of payloads from messages

14 years agoAdded a message_t option to disable automatic payload sorting
Martin Willi [Tue, 2 Nov 2010 13:21:38 +0000 (14:21 +0100)] 
Added a message_t option to disable automatic payload sorting

14 years agoAdded a fist hook to fill up IKE_AUTH messages with dummy certificates (1.1.1/1.2.1)
Martin Willi [Tue, 2 Nov 2010 11:14:03 +0000 (12:14 +0100)] 
Added a fist hook to fill up IKE_AUTH messages with dummy certificates (1.1.1/1.2.1)

14 years agoImplemented cert payload constructor for custom encoding types
Martin Willi [Tue, 2 Nov 2010 11:13:03 +0000 (12:13 +0100)] 
Implemented cert payload constructor for custom encoding types

14 years agoFix segfault if config not found
Martin Willi [Tue, 2 Nov 2010 11:12:42 +0000 (12:12 +0100)] 
Fix segfault if config not found

14 years agoRead actions from test config, delayed execution
Martin Willi [Fri, 29 Oct 2010 13:45:58 +0000 (15:45 +0200)] 
Read actions from test config, delayed execution

14 years agoSupport manually triggerd DPD check, even if DPD disabled in config
Martin Willi [Fri, 29 Oct 2010 13:36:19 +0000 (15:36 +0200)] 
Support manually triggerd DPD check, even if DPD disabled in config

14 years agoLoad private keys from suite and test configs
Martin Willi [Fri, 29 Oct 2010 09:55:19 +0000 (11:55 +0200)] 
Load private keys from suite and test configs

14 years agoLoad certificates from both, suite and test config
Martin Willi [Fri, 29 Oct 2010 09:47:25 +0000 (11:47 +0200)] 
Load certificates from both, suite and test config

14 years agoLoad test and suite specific connection configurations
Martin Willi [Fri, 29 Oct 2010 08:34:08 +0000 (10:34 +0200)] 
Load test and suite specific connection configurations

14 years agoLoad hooks based on listener dynamically
Martin Willi [Tue, 26 Oct 2010 08:51:28 +0000 (10:51 +0200)] 
Load hooks based on listener dynamically

14 years agoLoad certificates from global suite configuration file
Martin Willi [Thu, 21 Oct 2010 14:36:40 +0000 (16:36 +0200)] 
Load certificates from global suite configuration file

14 years agoAdded a Suite B conftest utility skeleton using libcharon
Martin Willi [Tue, 19 Oct 2010 12:42:47 +0000 (14:42 +0200)] 
Added a Suite B conftest utility skeleton using libcharon

14 years agoAdded a CIDR notation based host constructor
Martin Willi [Fri, 29 Oct 2010 07:54:15 +0000 (09:54 +0200)] 
Added a CIDR notation based host constructor

14 years agoMoved logger initialization from libcharon to charon
Martin Willi [Fri, 29 Oct 2010 07:39:19 +0000 (09:39 +0200)] 
Moved logger initialization from libcharon to charon

14 years agoremoved superfluous s
Andreas Steffen [Wed, 5 Jan 2011 03:09:19 +0000 (04:09 +0100)] 
removed superfluous s

14 years agoremove private_
Andreas Steffen [Wed, 5 Jan 2011 02:44:57 +0000 (03:44 +0100)] 
remove private_

14 years agoremove private_
Andreas Steffen [Wed, 5 Jan 2011 02:44:28 +0000 (03:44 +0100)] 
remove private_

14 years agocosmetics in debug output
Andreas Steffen [Wed, 5 Jan 2011 01:44:27 +0000 (02:44 +0100)] 
cosmetics in debug output

14 years agodetect fragmentation of PB-TNC batch
Andreas Steffen [Wed, 5 Jan 2011 01:41:36 +0000 (02:41 +0100)] 
detect fragmentation of PB-TNC batch

14 years agofixed typo
Andreas Steffen [Sun, 2 Jan 2011 05:52:32 +0000 (06:52 +0100)] 
fixed typo

14 years agoreplaced spaces by tabs
Andreas Steffen [Thu, 30 Dec 2010 02:45:08 +0000 (03:45 +0100)] 
replaced spaces by tabs

14 years agoversion bump to 4.5.1dr5
Andreas Steffen [Mon, 27 Dec 2010 12:49:32 +0000 (13:49 +0100)] 
version bump to 4.5.1dr5

14 years agocommas are required
Andreas Steffen [Mon, 27 Dec 2010 07:26:29 +0000 (08:26 +0100)] 
commas are required

14 years agoadded Sansar Choinambuu to copryright.c
Andreas Steffen [Mon, 27 Dec 2010 07:24:01 +0000 (08:24 +0100)] 
added Sansar Choinambuu to copryright.c

14 years agounset RADIUSHOSTS after before loading new scenario
Andreas Steffen [Mon, 27 Dec 2010 05:26:17 +0000 (06:26 +0100)] 
unset RADIUSHOSTS after before loading new scenario

14 years agoadded missing tfc argument to kernel_pfkey_ipsec interface
Andreas Steffen [Mon, 27 Dec 2010 04:53:36 +0000 (05:53 +0100)] 
added missing tfc argument to kernel_pfkey_ipsec interface

14 years agoset tfcv3 flag TRUE in ha_dispatcher
Andreas Steffen [Sun, 26 Dec 2010 22:10:57 +0000 (23:10 +0100)] 
set tfcv3 flag TRUE in ha_dispatcher

14 years agoimplemented wrap around of registered IKEv1 algorithm names
Andreas Steffen [Sun, 26 Dec 2010 16:11:02 +0000 (17:11 +0100)] 
implemented wrap around of registered IKEv1 algorithm names

14 years agodisable AEAD crypto algorithm if no key size is supported
Andreas Steffen [Sat, 25 Dec 2010 15:14:55 +0000 (16:14 +0100)] 
disable AEAD crypto algorithm if no key size is supported

14 years agodisable crypto algorithm if no key size is supported
Andreas Steffen [Sat, 25 Dec 2010 15:11:50 +0000 (16:11 +0100)] 
disable crypto algorithm if no key size is supported

14 years agolog if an AEAD algorithm does not support a given key size
Andreas Steffen [Sat, 25 Dec 2010 14:53:15 +0000 (15:53 +0100)] 
log if an AEAD algorithm does not support a given key size

14 years agolog if a crypto algorithm does not support a given key size
Andreas Steffen [Sat, 25 Dec 2010 14:49:29 +0000 (15:49 +0100)] 
log if a crypto algorithm does not support a given key size

14 years agowrap list of IKEv2 algorithms after 120 characters per line
Andreas Steffen [Fri, 24 Dec 2010 16:29:51 +0000 (17:29 +0100)] 
wrap list of IKEv2 algorithms after 120 characters per line

14 years agoMigrated stroke_list_t to INIT/METHOD macros
Andreas Steffen [Fri, 24 Dec 2010 13:29:09 +0000 (14:29 +0100)] 
Migrated stroke_list_t to INIT/METHOD macros

14 years agoprinted plugin names have a hyphen
Andreas Steffen [Fri, 24 Dec 2010 04:53:27 +0000 (05:53 +0100)] 
printed plugin names have a hyphen

14 years agoFixed public key construction from PKCS#11 private key
Martin Willi [Thu, 23 Dec 2010 09:29:01 +0000 (10:29 +0100)] 
Fixed public key construction from PKCS#11 private key

14 years agoeliminated whitespace
Andreas Steffen [Tue, 21 Dec 2010 16:51:27 +0000 (17:51 +0100)] 
eliminated whitespace

14 years agoMigrated child_create_t to INIT/METHOD macros
Andreas Steffen [Tue, 21 Dec 2010 16:45:10 +0000 (17:45 +0100)] 
Migrated child_create_t to INIT/METHOD macros

14 years agoAdded NEWS for af-alg plugin
Martin Willi [Mon, 20 Dec 2010 09:22:14 +0000 (10:22 +0100)] 
Added NEWS for af-alg plugin

14 years agoProbe for supported AF_ALG algorithms, register dynamically
Martin Willi [Mon, 8 Nov 2010 13:56:23 +0000 (14:56 +0100)] 
Probe for supported AF_ALG algorithms, register dynamically

14 years agoRegister algorithms with dependencies only if dependency available
Martin Willi [Mon, 8 Nov 2010 13:20:15 +0000 (14:20 +0100)] 
Register algorithms with dependencies only if dependency available

14 years agoRegister some less common AF_ALG ciphers (cast5, serpent, twofish, blowfish)
Martin Willi [Mon, 8 Nov 2010 10:58:01 +0000 (11:58 +0100)] 
Register some less common AF_ALG ciphers (cast5, serpent, twofish, blowfish)

14 years agoImplemented PRFs using AF_ALG
Martin Willi [Mon, 8 Nov 2010 10:41:01 +0000 (11:41 +0100)] 
Implemented PRFs using AF_ALG

14 years agoUse the AF_ALG wrapper in hasher, crypter and signer
Martin Willi [Mon, 8 Nov 2010 10:02:35 +0000 (10:02 +0000)] 
Use the AF_ALG wrapper in hasher, crypter and signer

14 years agoUse a generic AF_ALG wrapper for common operations
Martin Willi [Mon, 8 Nov 2010 09:59:54 +0000 (10:59 +0100)] 
Use a generic AF_ALG wrapper for common operations

14 years agoImplemented crypter on top of AF_ALG
Martin Willi [Sat, 6 Nov 2010 10:03:12 +0000 (11:03 +0100)] 
Implemented crypter on top of AF_ALG

14 years agoImplemented signer interface using AF_ALG
Martin Willi [Fri, 5 Nov 2010 20:29:43 +0000 (21:29 +0100)] 
Implemented signer interface using AF_ALG

14 years agoImplemented hasher based on AF_ALG
Martin Willi [Fri, 5 Nov 2010 15:55:53 +0000 (15:55 +0000)] 
Implemented hasher based on AF_ALG

14 years agoAdded Linux AF_ALG header
Martin Willi [Fri, 5 Nov 2010 15:15:51 +0000 (16:15 +0100)] 
Added Linux AF_ALG header

14 years agoAdded plugin stub for AF_ALG
Martin Willi [Fri, 5 Nov 2010 15:15:13 +0000 (16:15 +0100)] 
Added plugin stub for AF_ALG

14 years agoAdded NEWS about TFC padding
Martin Willi [Mon, 20 Dec 2010 08:51:33 +0000 (09:51 +0100)] 
Added NEWS about TFC padding

14 years agoAdded a tfc ipsec.conf keyword to control Traffic Flow Confidentiality
Martin Willi [Tue, 30 Nov 2010 18:19:56 +0000 (19:19 +0100)] 
Added a tfc ipsec.conf keyword to control Traffic Flow Confidentiality

14 years agoDo not use TFC padding if peer does not support ESPv3
Martin Willi [Wed, 8 Dec 2010 12:41:51 +0000 (12:41 +0000)] 
Do not use TFC padding if peer does not support ESPv3

14 years agoAdded a TFC padding option to child_cfg
Martin Willi [Wed, 8 Dec 2010 12:41:04 +0000 (12:41 +0000)] 
Added a TFC padding option to child_cfg

14 years agoImplemented Traffic Flow Confidentiality padding in kernel_interface
Martin Willi [Tue, 30 Nov 2010 16:17:30 +0000 (16:17 +0000)] 
Implemented Traffic Flow Confidentiality padding in kernel_interface

14 years agoversion bump to 4.5.1dr4
Andreas Steffen [Sun, 19 Dec 2010 08:46:59 +0000 (09:46 +0100)] 
version bump to 4.5.1dr4

14 years agocast enumerated algorithm type as int
Andreas Steffen [Sat, 18 Dec 2010 19:24:53 +0000 (20:24 +0100)] 
cast enumerated algorithm type as int

14 years agoupdated NEWS with new ipsec listalgs feature
Andreas Steffen [Sat, 18 Dec 2010 15:44:29 +0000 (16:44 +0100)] 
updated NEWS with new ipsec listalgs feature

14 years agotrace back crypto algorithms to the plugins that registered them
Andreas Steffen [Sat, 18 Dec 2010 15:31:01 +0000 (16:31 +0100)] 
trace back crypto algorithms to the plugins that registered them

14 years agoAdded news about changes regarding strongswan.conf.
Tobias Brunner [Fri, 17 Dec 2010 16:32:14 +0000 (17:32 +0100)] 
Added news about changes regarding strongswan.conf.

14 years agoMoved "Reading values" section, typo fixed.
Tobias Brunner [Fri, 17 Dec 2010 16:31:42 +0000 (17:31 +0100)] 
Moved "Reading values" section, typo fixed.

14 years agoversion bump to 4.5.1dr3
Andreas Steffen [Wed, 15 Dec 2010 07:56:32 +0000 (08:56 +0100)] 
version bump to 4.5.1dr3

14 years agoInstall selectors on transport mode IPsec SAs.
Jiri Bohac [Mon, 13 Dec 2010 14:28:40 +0000 (15:28 +0100)] 
Install selectors on transport mode IPsec SAs.

This fixes several test cases in IKEv2_Self_Test (part of the IPv6 Ready
Logo Program) which is required for USGv6 certification, namely:

  - IKEv2.EN.I.1.1.7.1, IKEv2.EN.I.1.1.7.1: Narrowing the range of members
    of the set of traffic selectors
  - IKEv2.EN.R.1.1.7.3: Narrowing multiple traffic selector

When traffic selectors of a triggered SA are narrowed by the responder, the
installed policy and the broader trap policy share the same reqid.  Without
selectors on the IPsec SA packets matching the trap policy, but not the
narrowed policy, would incorrectly be handled by that IPsec SA.  Since only
one selector can be specified per IPsec SA, there is currently no solution
for tunnel mode SAs.

14 years agoincrease sleep time in mediation scenarios
Andreas Steffen [Sun, 12 Dec 2010 20:54:44 +0000 (21:54 +0100)] 
increase sleep time in mediation scenarios

14 years agofixed bug in mem_cred.c:add_crl()
Andreas Steffen [Sun, 12 Dec 2010 20:34:27 +0000 (21:34 +0100)] 
fixed bug in mem_cred.c:add_crl()

14 years agoreverted Connection ID to capital letters
Andreas Steffen [Sun, 12 Dec 2010 11:55:14 +0000 (12:55 +0100)] 
reverted Connection ID to capital letters

14 years agofixed a bug in enum_from_name() function
Andreas Steffen [Sun, 12 Dec 2010 11:54:36 +0000 (12:54 +0100)] 
fixed a bug in enum_from_name() function

14 years agoreorganized ikev2/rw-eap-tnc scenarios
Andreas Steffen [Sun, 12 Dec 2010 11:51:14 +0000 (12:51 +0100)] 
reorganized ikev2/rw-eap-tnc scenarios

14 years agoadded the ikev2/rw-eap-tnc-20 scenario
Andreas Steffen [Sun, 12 Dec 2010 09:47:16 +0000 (10:47 +0100)] 
added the ikev2/rw-eap-tnc-20 scenario

14 years agoNEWS for the 4.5.1dr2 release
Andreas Steffen [Sun, 12 Dec 2010 09:46:43 +0000 (10:46 +0100)] 
NEWS for the 4.5.1dr2 release

14 years agosome more cosmetics
Andreas Steffen [Sun, 12 Dec 2010 09:19:54 +0000 (10:19 +0100)] 
some more cosmetics

14 years agofinal cosmetics in PB-TNC debug output
Andreas Steffen [Sun, 12 Dec 2010 09:17:43 +0000 (10:17 +0100)] 
final cosmetics in PB-TNC debug output

14 years agoimplemented PB-TNC message parsing checks
Andreas Steffen [Sat, 11 Dec 2010 23:42:31 +0000 (00:42 +0100)] 
implemented PB-TNC message parsing checks

14 years agosome code optimizations
Andreas Steffen [Fri, 10 Dec 2010 23:52:53 +0000 (00:52 +0100)] 
some code optimizations

14 years agosupport handshake retry requests
Andreas Steffen [Fri, 10 Dec 2010 22:41:12 +0000 (23:41 +0100)] 
support handshake retry requests

14 years agothe PB-TNC protocol is working
Andreas Steffen [Fri, 10 Dec 2010 22:21:13 +0000 (23:21 +0100)] 
the PB-TNC protocol is working

14 years agorefactored message handling
Andreas Steffen [Fri, 10 Dec 2010 16:09:21 +0000 (17:09 +0100)] 
refactored message handling

14 years agodo not accept results and recommendation messages from clients
Andreas Steffen [Fri, 10 Dec 2010 16:04:11 +0000 (17:04 +0100)] 
do not accept results and recommendation messages from clients

14 years agodefined some additional Private Enterprise Numbers
Andreas Steffen [Fri, 10 Dec 2010 13:58:33 +0000 (14:58 +0100)] 
defined some additional Private Enterprise Numbers

14 years agodefine pb_tnc_state_machine_t object
Andreas Steffen [Fri, 10 Dec 2010 13:56:40 +0000 (14:56 +0100)] 
define pb_tnc_state_machine_t object

14 years agodebug cosmetics
Andreas Steffen [Fri, 10 Dec 2010 10:54:51 +0000 (11:54 +0100)] 
debug cosmetics

14 years agoRenamed purgex509/crl to purgecerts/crls to be consistent with list commands
Martin Willi [Fri, 10 Dec 2010 10:16:39 +0000 (11:16 +0100)] 
Renamed purgex509/crl to purgecerts/crls to be consistent with list commands

14 years agoimplemented handling of received PB-TNC messages
Andreas Steffen [Fri, 10 Dec 2010 10:16:08 +0000 (11:16 +0100)] 
implemented handling of received PB-TNC messages

14 years agoAdded options to flush CRLs/X509 certs from the cert cache
Martin Willi [Thu, 9 Dec 2010 09:06:25 +0000 (10:06 +0100)] 
Added options to flush CRLs/X509 certs from the cert cache

14 years agorefactored PB-TNC state machine in receive direction
Andreas Steffen [Thu, 9 Dec 2010 22:38:38 +0000 (23:38 +0100)] 
refactored PB-TNC state machine in receive direction

14 years agorefactored PB-TNC state machine in send direction
Andreas Steffen [Thu, 9 Dec 2010 22:18:55 +0000 (23:18 +0100)] 
refactored PB-TNC state machine in send direction

14 years agopb_tnc_batch_t class implements parsing and building of PB-TNC batches
Andreas Steffen [Thu, 9 Dec 2010 20:33:12 +0000 (21:33 +0100)] 
pb_tnc_batch_t class implements parsing and building of PB-TNC batches