]> git.ipfire.org Git - thirdparty/strongswan.git/log
thirdparty/strongswan.git
15 years agoremove spaces within tabs (\t( )+\t)
Martin Willi [Fri, 4 Sep 2009 12:58:05 +0000 (14:58 +0200)] 
remove spaces within tabs (\t( )+\t)

15 years agoreplaces four spaces by tabs, where appropriate
Martin Willi [Fri, 4 Sep 2009 12:50:23 +0000 (14:50 +0200)] 
replaces four spaces by tabs, where appropriate

15 years agoremoved trailing spaces ([[:space:]]+$)
Martin Willi [Fri, 4 Sep 2009 11:46:09 +0000 (13:46 +0200)] 
removed trailing spaces ([[:space:]]+$)

15 years agofixed open failure debug message in load_secrets
Marius Tomaschewski [Fri, 4 Sep 2009 09:36:36 +0000 (11:36 +0200)] 
fixed open failure debug message in load_secrets

15 years agofixed memleak in rekey collissions
Martin Willi [Thu, 3 Sep 2009 16:09:29 +0000 (18:09 +0200)] 
fixed memleak in rekey collissions

15 years agoConvert empty CREATE_CHILD_SA exchange to an INFORMATIONAL
Martin Willi [Thu, 3 Sep 2009 15:32:41 +0000 (17:32 +0200)] 
Convert empty CREATE_CHILD_SA exchange to an INFORMATIONAL

15 years agoUse get_notify() to look up single notifies
Martin Willi [Thu, 3 Sep 2009 15:32:01 +0000 (17:32 +0200)] 
Use get_notify() to look up single notifies

15 years agoaccept octet strings in is_asn1() check
Martin Willi [Thu, 3 Sep 2009 13:35:05 +0000 (15:35 +0200)] 
accept octet strings in is_asn1() check

15 years agoUse recursive source address lookup if we get a gateway only
Martin Willi [Wed, 2 Sep 2009 09:47:14 +0000 (11:47 +0200)] 
Use recursive source address lookup if we get a gateway only

15 years agoFixed load_secrets to acquire/release lock in level 0 only
Marius Tomaschewski [Wed, 2 Sep 2009 11:49:39 +0000 (13:49 +0200)] 
Fixed load_secrets to acquire/release lock in level 0 only

The write_lock call fails with EDEADLK and unlocks in the
next recursion level.

15 years agoComplain about rw(un)lock errors
Martin Willi [Thu, 3 Sep 2009 12:27:33 +0000 (14:27 +0200)] 
Complain about rw(un)lock errors

15 years agoSimplified the search for ME_CONNECTID notifies.
Tobias Brunner [Wed, 2 Sep 2009 15:29:02 +0000 (17:29 +0200)] 
Simplified the search for ME_CONNECTID notifies.

15 years agoFixed some typos; whitespace cleanup.
Tobias Brunner [Wed, 2 Sep 2009 15:26:36 +0000 (17:26 +0200)] 
Fixed some typos; whitespace cleanup.

15 years agoMissing commas added.
Tobias Brunner [Wed, 2 Sep 2009 14:12:52 +0000 (16:12 +0200)] 
Missing commas added.

15 years agohandle plugin loading failures
Martin Willi [Tue, 1 Sep 2009 14:20:45 +0000 (16:20 +0200)] 
handle plugin loading failures

15 years agoplugins marked with a '!' are handled as critical: cancel if loading fails
Martin Willi [Tue, 1 Sep 2009 14:08:28 +0000 (16:08 +0200)] 
plugins marked with a '!' are handled as critical: cancel if loading fails

15 years agouse subjectPublicKeyInfo hash for CA certificate lookup
Martin Willi [Tue, 1 Sep 2009 12:05:58 +0000 (14:05 +0200)] 
use subjectPublicKeyInfo hash for CA certificate lookup

15 years agoDescription of new lifetime limits added to manpage.
Tobias Brunner [Tue, 1 Sep 2009 10:48:59 +0000 (12:48 +0200)] 
Description of new lifetime limits added to manpage.

15 years agoAdded lifetime/margintime keywords as alias for keylife/rekeymargin.
Tobias Brunner [Fri, 28 Aug 2009 15:10:08 +0000 (17:10 +0200)] 
Added lifetime/margintime keywords as alias for keylife/rekeymargin.

15 years agoRefactored the lifetime_cfg_t struct to be simpler and more expressive. Initializatio...
Tobias Brunner [Fri, 28 Aug 2009 15:04:35 +0000 (17:04 +0200)] 
Refactored the lifetime_cfg_t struct to be simpler and more expressive. Initialization is now static.

15 years agoHandling of new lifetime limits added to stroke.
Tobias Brunner [Thu, 27 Aug 2009 16:10:39 +0000 (18:10 +0200)] 
Handling of new lifetime limits added to stroke.

15 years agoAdded keywords for the new lifetime limits to starter.
Tobias Brunner [Thu, 27 Aug 2009 16:09:26 +0000 (18:09 +0200)] 
Added keywords for the new lifetime limits to starter.

15 years agoAdded parser for unsigned long long ints to starter.
Tobias Brunner [Thu, 27 Aug 2009 16:03:17 +0000 (18:03 +0200)] 
Added parser for unsigned long long ints to starter.

15 years agoIf no inbound CHILD_SA is found, try to find an outbound SA.
Tobias Brunner [Thu, 27 Aug 2009 14:16:23 +0000 (16:16 +0200)] 
If no inbound CHILD_SA is found, try to find an outbound SA.

Due to the new lifetime limits in- and outbound SAs may expire
individually.

15 years agoSet the packet and byte limits in the netlink and pfkey kernel interfaces.
Tobias Brunner [Thu, 27 Aug 2009 14:07:30 +0000 (16:07 +0200)] 
Set the packet and byte limits in the netlink and pfkey kernel interfaces.

15 years agoTerminology and return value of get_lifetime of child_sa_t corrected.
Tobias Brunner [Thu, 27 Aug 2009 09:46:35 +0000 (11:46 +0200)] 
Terminology and return value of get_lifetime of child_sa_t corrected.

15 years agochild_sa_t adapted to the new lifetime configuration.
Tobias Brunner [Thu, 27 Aug 2009 09:45:36 +0000 (11:45 +0200)] 
child_sa_t adapted to the new lifetime configuration.

15 years agoAdapted the kernel interfaces to the new lifetime configuration.
Tobias Brunner [Thu, 27 Aug 2009 09:41:52 +0000 (11:41 +0200)] 
Adapted the kernel interfaces to the new lifetime configuration.

15 years agoAdapted the config backends to the new lifetime configuration.
Tobias Brunner [Thu, 27 Aug 2009 09:38:13 +0000 (11:38 +0200)] 
Adapted the config backends to the new lifetime configuration.

15 years agochild_cfg_t now takes a lifetime_cfg_t to configure the lifetime limits. Also adjuste...
Tobias Brunner [Thu, 27 Aug 2009 09:27:10 +0000 (11:27 +0200)] 
child_cfg_t now takes a lifetime_cfg_t to configure the lifetime limits. Also adjusted the jitter calculation, so it works for values > RAND_MAX.

15 years agolifetime_cfg_t added to configure lifetime limits of a CHILD_SA.
Tobias Brunner [Thu, 27 Aug 2009 09:22:43 +0000 (11:22 +0200)] 
lifetime_cfg_t added to configure lifetime limits of a CHILD_SA.

15 years agoAdded side effect free min and max macros.
Tobias Brunner [Tue, 25 Aug 2009 11:11:42 +0000 (13:11 +0200)] 
Added side effect free min and max macros.

15 years agosql/rw-rsa and sql/rw-rsa-keyid scenarios require the pubkey plugin
Martin Willi [Tue, 1 Sep 2009 09:34:09 +0000 (11:34 +0200)] 
sql/rw-rsa and sql/rw-rsa-keyid scenarios require the pubkey plugin

15 years agofixed certificate_t enum names
Martin Willi [Tue, 1 Sep 2009 09:28:05 +0000 (11:28 +0200)] 
fixed certificate_t enum names

15 years agochanged prefix of crl_reason_t values from CRL_ to CRL_REASON_
Andreas Steffen [Mon, 31 Aug 2009 21:21:50 +0000 (23:21 +0200)] 
changed prefix of crl_reason_t values from CRL_ to CRL_REASON_

15 years agouse crl_reason_t definition from <credentials/certificates/crl.h>
Andreas Steffen [Mon, 31 Aug 2009 21:05:45 +0000 (23:05 +0200)] 
use crl_reason_t definition from <credentials/certificates/crl.h>

15 years agouse crl_reason_t definition from <credentials/certificates/crl.h>
Andreas Steffen [Mon, 31 Aug 2009 20:58:34 +0000 (22:58 +0200)] 
use crl_reason_t definition from <credentials/certificates/crl.h>

15 years agouse time_monotonic() instead of time() for statistics and time difference calculations
Martin Willi [Mon, 31 Aug 2009 15:59:00 +0000 (17:59 +0200)] 
use time_monotonic() instead of time() for statistics and time difference calculations

15 years agouse time_monotonic() instead of gettimeofday() for time difference calculations
Martin Willi [Mon, 31 Aug 2009 13:25:03 +0000 (15:25 +0200)] 
use time_monotonic() instead of gettimeofday() for time difference calculations

15 years agouse monotonic time source in convar->timed_wait, and in the scheduler using it
Martin Willi [Mon, 31 Aug 2009 13:13:48 +0000 (15:13 +0200)] 
use monotonic time source in convar->timed_wait, and in the scheduler using it

15 years agoimplemented a monotonic timestamping function, unaffected from system time changes
Martin Willi [Mon, 31 Aug 2009 13:03:35 +0000 (15:03 +0200)] 
implemented a monotonic timestamping function, unaffected from system time changes

15 years agodo not depend on gcrypt autoconf macros
Martin Willi [Mon, 31 Aug 2009 11:14:54 +0000 (13:14 +0200)] 
do not depend on gcrypt autoconf macros

15 years agoadded ECGDSA specific OIDs
Martin Willi [Mon, 31 Aug 2009 08:34:00 +0000 (10:34 +0200)] 
added ECGDSA specific OIDs

15 years agofixed crash in crl listing
Martin Willi [Mon, 31 Aug 2009 08:21:38 +0000 (10:21 +0200)] 
fixed crash in crl listing

15 years agogeneration of keyid requires pkcs1 plugin
Andreas Steffen [Sun, 30 Aug 2009 20:55:40 +0000 (22:55 +0200)] 
generation of keyid requires pkcs1 plugin

15 years agoclear RSA private key chunks after use
Andreas Steffen [Sun, 30 Aug 2009 17:12:29 +0000 (19:12 +0200)] 
clear RSA private key chunks after use

15 years agoASN.1 DER encoding of private key is not needed anymore
Andreas Steffen [Sun, 30 Aug 2009 17:05:43 +0000 (19:05 +0200)] 
ASN.1 DER encoding of private key is not needed anymore

15 years agonew UML scenario certs have SHA256 digest
Andreas Steffen [Sun, 30 Aug 2009 15:58:34 +0000 (17:58 +0200)] 
new UML scenario certs have SHA256 digest

15 years agoremoved position debug output
Andreas Steffen [Sun, 30 Aug 2009 15:37:27 +0000 (17:37 +0200)] 
removed position debug output

15 years agoadded workaround to parse PEM encoded PGP key with KEY_RSA
Martin Willi [Fri, 28 Aug 2009 15:25:07 +0000 (17:25 +0200)] 
added workaround to parse PEM encoded PGP key with KEY_RSA

15 years agoimplemented PGP Secret-Key Packet parsing
Martin Willi [Fri, 28 Aug 2009 15:23:58 +0000 (17:23 +0200)] 
implemented PGP Secret-Key Packet parsing

15 years agofixed memleak
Martin Willi [Fri, 28 Aug 2009 14:16:39 +0000 (16:16 +0200)] 
fixed memleak

15 years ago.., but a comment might be helpful
Andreas Steffen [Fri, 28 Aug 2009 07:28:39 +0000 (09:28 +0200)] 
.., but a comment might be helpful

15 years agoremoved TODO reminder
Andreas Steffen [Fri, 28 Aug 2009 07:26:46 +0000 (09:26 +0200)] 
removed TODO reminder

15 years agoallow choice of digest algorithm in certificate generation
Andreas Steffen [Fri, 28 Aug 2009 07:08:03 +0000 (09:08 +0200)] 
allow choice of digest algorithm in certificate generation

15 years agobuild_curve_signature() processes hash not data
Andreas Steffen [Thu, 27 Aug 2009 18:41:29 +0000 (20:41 +0200)] 
build_curve_signature() processes hash not data

15 years agoNID_hash and NID_ec_curve were interchanged
Andreas Steffen [Thu, 27 Aug 2009 18:28:41 +0000 (20:28 +0200)] 
NID_hash and NID_ec_curve were interchanged

15 years agoverify_signature() now processes hash not data
Andreas Steffen [Thu, 27 Aug 2009 18:18:22 +0000 (20:18 +0200)] 
verify_signature() now processes hash not data

15 years agoNID_hash and NID_ec_curver were interchanged
Andreas Steffen [Thu, 27 Aug 2009 18:11:49 +0000 (20:11 +0200)] 
NID_hash and NID_ec_curver were interchanged

15 years agoverify that the ECDSA auth signature was done with the correct curve
Martin Willi [Thu, 27 Aug 2009 15:58:02 +0000 (17:58 +0200)] 
verify that the ECDSA auth signature was done with the correct curve

15 years agodistinguish between RFC 4754 (concatenated) and RFC 3279 (DER encoded) ECDSA signatures
Martin Willi [Thu, 27 Aug 2009 15:36:17 +0000 (17:36 +0200)] 
distinguish between RFC 4754 (concatenated) and RFC 3279 (DER encoded) ECDSA signatures

15 years agoOID_EC_PUBLICKEY has a parameters field, defining the elliptic curve
Andreas Steffen [Thu, 27 Aug 2009 14:34:16 +0000 (16:34 +0200)] 
OID_EC_PUBLICKEY has a parameters field, defining the elliptic curve

15 years agoadded OID_EC_PUBLIC_KEY algorithmIdentifier
Andreas Steffen [Thu, 27 Aug 2009 14:07:59 +0000 (16:07 +0200)] 
added OID_EC_PUBLIC_KEY algorithmIdentifier

15 years agocosmetics
Andreas Steffen [Thu, 27 Aug 2009 13:33:22 +0000 (15:33 +0200)] 
cosmetics

15 years agofixed return value
Martin Willi [Thu, 27 Aug 2009 13:28:45 +0000 (15:28 +0200)] 
fixed return value

15 years agodo not append a NULL paramter to ECDSA algorithmIdentifiers
Martin Willi [Thu, 27 Aug 2009 13:28:21 +0000 (15:28 +0200)] 
do not append a NULL paramter to ECDSA algorithmIdentifiers

15 years agoPKI tool supports certificate verification
Martin Willi [Thu, 27 Aug 2009 12:43:40 +0000 (14:43 +0200)] 
PKI tool supports certificate verification

15 years agodo not flush cached encodings, keys are responsible for it
Martin Willi [Thu, 27 Aug 2009 11:58:48 +0000 (13:58 +0200)] 
do not flush cached encodings, keys are responsible for it

15 years agowhitelist openssl ecdsa_check function
Martin Willi [Thu, 27 Aug 2009 11:40:48 +0000 (13:40 +0200)] 
whitelist openssl ecdsa_check function

15 years agoPKI tool supports generation of self-signed certificates
Martin Willi [Thu, 27 Aug 2009 11:34:57 +0000 (13:34 +0200)] 
PKI tool supports generation of self-signed certificates

15 years agosupport generation of EC certificates
Martin Willi [Thu, 27 Aug 2009 11:34:06 +0000 (13:34 +0200)] 
support generation of EC certificates

15 years agoadded support for SIGN_ECDSA_WITH_SHA1 signature scheme in openssl
Martin Willi [Thu, 27 Aug 2009 11:22:01 +0000 (13:22 +0200)] 
added support for SIGN_ECDSA_WITH_SHA1 signature scheme in openssl

15 years agocreate algorithmIdentifier dynamically from OID database
Martin Willi [Thu, 27 Aug 2009 11:14:01 +0000 (13:14 +0200)] 
create algorithmIdentifier dynamically from OID database

15 years agouse subjectPublicKeyInfo encoding type directly
Martin Willi [Thu, 27 Aug 2009 11:09:31 +0000 (13:09 +0200)] 
use subjectPublicKeyInfo encoding type directly

15 years agopkcs1 encoder supports subjectPublicKeyInfo encoding
Martin Willi [Thu, 27 Aug 2009 11:07:34 +0000 (13:07 +0200)] 
pkcs1 encoder supports subjectPublicKeyInfo encoding

15 years agorevoked soon-to-expire carol certificate
Andreas Steffen [Thu, 27 Aug 2009 11:36:02 +0000 (13:36 +0200)] 
revoked soon-to-expire carol certificate

15 years agorenewed expiring strongSwan certicates for UML scenarios
Andreas Steffen [Thu, 27 Aug 2009 11:20:48 +0000 (13:20 +0200)] 
renewed expiring strongSwan certicates for UML scenarios

15 years agoimplemented fingerprinting support for PKI tool
Martin Willi [Thu, 27 Aug 2009 08:41:07 +0000 (10:41 +0200)] 
implemented fingerprinting support for PKI tool

15 years agofixed memleak in openssl fingerprinting
Martin Willi [Thu, 27 Aug 2009 08:40:49 +0000 (10:40 +0200)] 
fixed memleak in openssl fingerprinting

15 years agodo openssl fingerprinting/encoding directly, openssl provides all functions
Martin Willi [Thu, 27 Aug 2009 07:58:38 +0000 (09:58 +0200)] 
do openssl fingerprinting/encoding directly, openssl provides all functions

15 years agokey encoding gained a cache() method, allows caching of externally created encodings
Martin Willi [Thu, 27 Aug 2009 07:57:49 +0000 (09:57 +0200)] 
key encoding gained a cache() method, allows caching of externally created encodings

15 years agopgp plugin required in ikev1/net2net-pgp-v3|v4 scenarios
Andreas Steffen [Wed, 26 Aug 2009 21:42:05 +0000 (23:42 +0200)] 
pgp plugin required in ikev1/net2net-pgp-v3|v4 scenarios

15 years agodnskey plugin required in ikev1/net2net-rsa scenario
Andreas Steffen [Wed, 26 Aug 2009 21:11:06 +0000 (23:11 +0200)] 
dnskey plugin required in ikev1/net2net-rsa scenario

15 years agoikev1 psk scenarios don't need pkcs1 and pem plugins
Andreas Steffen [Wed, 26 Aug 2009 20:46:39 +0000 (22:46 +0200)] 
ikev1 psk scenarios don't need pkcs1 and pem plugins

15 years agofixed typo
Andreas Steffen [Wed, 26 Aug 2009 20:25:24 +0000 (22:25 +0200)] 
fixed typo

15 years agostreamlined file loading labels
Andreas Steffen [Wed, 26 Aug 2009 20:02:00 +0000 (22:02 +0200)] 
streamlined file loading labels

15 years agouse --outform consistantly
Andreas Steffen [Wed, 26 Aug 2009 16:55:18 +0000 (18:55 +0200)] 
use --outform consistantly

15 years agothe option has been changed to --outform
Andreas Steffen [Wed, 26 Aug 2009 16:41:19 +0000 (18:41 +0200)] 
the option has been changed to --outform

15 years agoadded pki/.libs/pki to the libs
Andreas Steffen [Wed, 26 Aug 2009 16:27:04 +0000 (18:27 +0200)] 
added pki/.libs/pki to the libs

15 years agofixed two typos
Andreas Steffen [Wed, 26 Aug 2009 15:29:57 +0000 (17:29 +0200)] 
fixed two typos

15 years agoencoding public EC keys is not really possible without subjectPublicKeyInfo
Martin Willi [Wed, 26 Aug 2009 14:15:38 +0000 (16:15 +0200)] 
encoding public EC keys is not really possible without subjectPublicKeyInfo

15 years agocomplain about build errors in non-recursive cases only
Martin Willi [Wed, 26 Aug 2009 12:44:05 +0000 (14:44 +0200)] 
complain about build errors in non-recursive cases only

15 years agoopenac (and tools) do not depend on gmp anymore
Martin Willi [Wed, 26 Aug 2009 12:08:20 +0000 (14:08 +0200)] 
openac (and tools) do not depend on gmp anymore

15 years agomoved chunk_increment() function to libstrongswan
Martin Willi [Wed, 26 Aug 2009 12:07:26 +0000 (14:07 +0200)] 
moved chunk_increment() function to libstrongswan

15 years agopki tool supports public key extraction from private key, certificates
Martin Willi [Wed, 26 Aug 2009 11:05:17 +0000 (13:05 +0200)] 
pki tool supports public key extraction from private key, certificates

15 years agoadded a BUILD_FROM_FD option, supporting credential parsing from stdin
Martin Willi [Wed, 26 Aug 2009 11:03:23 +0000 (13:03 +0200)] 
added a BUILD_FROM_FD option, supporting credential parsing from stdin

15 years agostarted implementation of a PKI tool, currently supporting RSA|ECDSA key generation
Martin Willi [Wed, 26 Aug 2009 09:22:09 +0000 (11:22 +0200)] 
started implementation of a PKI tool, currently supporting RSA|ECDSA key generation

15 years agoimplemented openssl EC key generation
Martin Willi [Wed, 26 Aug 2009 09:20:13 +0000 (11:20 +0200)] 
implemented openssl EC key generation

15 years agofixed openssl RSA private key encoding
Martin Willi [Wed, 26 Aug 2009 09:19:06 +0000 (11:19 +0200)] 
fixed openssl RSA private key encoding

15 years agokeyids in SQL use ID_KEY_ID type with subjectPublicKey SHA1 hash
Martin Willi [Tue, 25 Aug 2009 12:29:48 +0000 (14:29 +0200)] 
keyids in SQL use ID_KEY_ID type with subjectPublicKey SHA1 hash