]> git.ipfire.org Git - thirdparty/strongswan.git/log
thirdparty/strongswan.git
12 years agofixed debug output
Andreas Steffen [Mon, 5 Nov 2012 20:56:49 +0000 (21:56 +0100)] 
fixed debug output

12 years agoeliminate deinstalled packages
Andreas Steffen [Mon, 5 Nov 2012 20:40:19 +0000 (21:40 +0100)] 
eliminate deinstalled packages

12 years agocheck installed packages in OS database
Andreas Steffen [Mon, 5 Nov 2012 20:00:56 +0000 (21:00 +0100)] 
check installed packages in OS database

12 years agoDefine and use an OS enumeration type
Andreas Steffen [Mon, 5 Nov 2012 13:48:43 +0000 (14:48 +0100)] 
Define and use an OS enumeration type

12 years agocheck if assessment has already been done
Andreas Steffen [Mon, 5 Nov 2012 13:46:50 +0000 (14:46 +0100)] 
check if assessment has already been done

12 years agocompute the optimum Installed Packages attribute size
Andreas Steffen [Mon, 5 Nov 2012 11:13:13 +0000 (12:13 +0100)] 
compute the optimum Installed Packages attribute size

12 years agoAdded ITA Start/Stop Angel attributes to split bulk data into multiple attributes
Andreas Steffen [Mon, 5 Nov 2012 09:24:12 +0000 (10:24 +0100)] 
Added ITA Start/Stop Angel attributes to split bulk data into multiple attributes

12 years agoenumerate over installed Debian/Ubuntu packages
Andreas Steffen [Sun, 4 Nov 2012 22:54:36 +0000 (23:54 +0100)] 
enumerate over installed Debian/Ubuntu packages

12 years agodebug output in lower case letters
Andreas Steffen [Sun, 4 Nov 2012 22:52:34 +0000 (23:52 +0100)] 
debug output in lower case letters

12 years agoadded second index
Andreas Steffen [Sun, 4 Nov 2012 22:51:04 +0000 (23:51 +0100)] 
added  second index

12 years agoadd generation time to package versions
Andreas Steffen [Sun, 4 Nov 2012 17:55:37 +0000 (18:55 +0100)] 
add generation time to package versions

12 years agoextract generation time of packages file
Andreas Steffen [Sun, 4 Nov 2012 16:27:55 +0000 (17:27 +0100)] 
extract generation time of packages file

12 years agoadded pacman to .gitignore
Andreas Steffen [Sun, 4 Nov 2012 14:57:36 +0000 (15:57 +0100)] 
added pacman to .gitignore

12 years agostore packages with security issues and their optional updates only
Andreas Steffen [Sun, 4 Nov 2012 14:42:31 +0000 (15:42 +0100)] 
store packages with security issues and their optional updates only

12 years agocreated pacman - an Ubuntu/Debian package manager
Andreas Steffen [Sun, 4 Nov 2012 08:25:31 +0000 (09:25 +0100)] 
created pacman - an Ubuntu/Debian package manager

12 years agoadded generation time to package versions
Andreas Steffen [Sun, 4 Nov 2012 16:47:06 +0000 (17:47 +0100)] 
added generation time to package versions

12 years agoadded package management to ipsec attest
Andreas Steffen [Fri, 2 Nov 2012 22:16:54 +0000 (23:16 +0100)] 
added package management to ipsec attest

12 years agoandroid: Use proper intent-filter for our VpnService
Tobias Brunner [Fri, 2 Nov 2012 14:55:08 +0000 (15:55 +0100)] 
android: Use proper intent-filter for our VpnService

12 years agoLog sent vendor IDs for IKEv1
Tobias Brunner [Fri, 2 Nov 2012 14:40:32 +0000 (15:40 +0100)] 
Log sent vendor IDs for IKEv1

12 years agoCompiler warning fixed
Tobias Brunner [Fri, 2 Nov 2012 14:39:51 +0000 (15:39 +0100)] 
Compiler warning fixed

12 years agocheck if setting exists
Andreas Steffen [Thu, 1 Nov 2012 18:26:29 +0000 (19:26 +0100)] 
check if setting exists

12 years agoimplemented ITA Get Settings and ITA Settings attributes
Andreas Steffen [Thu, 1 Nov 2012 17:00:40 +0000 (18:00 +0100)] 
implemented ITA Get Settings and ITA Settings attributes

12 years agosome improvements in tcg_pts_attr_file_meas.c
Andreas Steffen [Thu, 1 Nov 2012 16:59:54 +0000 (17:59 +0100)] 
some improvements in tcg_pts_attr_file_meas.c

12 years agouse countof()
Andreas Steffen [Thu, 1 Nov 2012 08:02:58 +0000 (09:02 +0100)] 
use countof()

12 years agoscanner imc/imv pair uses IETF VPN PA-TNC message subtype
Andreas Steffen [Wed, 31 Oct 2012 20:58:21 +0000 (21:58 +0100)] 
scanner imc/imv pair uses IETF VPN PA-TNC message subtype

12 years agotransmit Product Vendor ID if known
Andreas Steffen [Wed, 31 Oct 2012 19:29:36 +0000 (20:29 +0100)] 
transmit Product Vendor ID if known

12 years agoadded some Linux OS PENs
Andreas Steffen [Wed, 31 Oct 2012 13:52:46 +0000 (14:52 +0100)] 
added some Linux OS PENs

12 years agoExclude dynamic TS from Unity Split-Include attributes
Martin Willi [Tue, 30 Oct 2012 08:14:44 +0000 (09:14 +0100)] 
Exclude dynamic TS from Unity Split-Include attributes

12 years agoFQDNs are actually not resolved when loading secrets
Tobias Brunner [Mon, 29 Oct 2012 09:06:43 +0000 (10:06 +0100)] 
FQDNs are actually not resolved when loading secrets

12 years agoFixed log message when no shared secret is found during IKEv1 Main Mode
Tobias Brunner [Mon, 29 Oct 2012 09:01:46 +0000 (10:01 +0100)] 
Fixed log message when no shared secret is found during IKEv1 Main Mode

12 years agoversion bump to 5.0.2dr3
Andreas Steffen [Sun, 28 Oct 2012 07:21:02 +0000 (08:21 +0100)] 
version bump to 5.0.2dr3

12 years agoissue warning if sqlite finalize is missing
Andreas Steffen [Fri, 26 Oct 2012 11:22:02 +0000 (13:22 +0200)] 
issue warning if sqlite finalize is missing

12 years agoAdded documentation for NTLM secrets
Tobias Brunner [Thu, 25 Oct 2012 07:51:47 +0000 (09:51 +0200)] 
Added documentation for NTLM secrets

12 years agoFix RSA encryption padding terminator in gmp plugin, broken with 5025135f
Martin Willi [Wed, 24 Oct 2012 18:15:50 +0000 (20:15 +0200)] 
Fix RSA encryption padding terminator in gmp plugin, broken with 5025135f

12 years agoAdded missing noskip_flag setter/getter to some pa_tnc_attr_t constructors
Tobias Brunner [Wed, 24 Oct 2012 15:57:19 +0000 (17:57 +0200)] 
Added missing noskip_flag setter/getter to some pa_tnc_attr_t constructors

12 years agoAdd a scepclient option to specify a CA identifier to fetch certs for
Martin Willi [Wed, 24 Oct 2012 14:28:17 +0000 (16:28 +0200)] 
Add a scepclient option to specify a CA identifier to fetch certs for

12 years agoRemove all ESP proposals with non-matching DH group during Quick Mode
Tobias Brunner [Thu, 18 Oct 2012 16:09:16 +0000 (18:09 +0200)] 
Remove all ESP proposals with non-matching DH group during Quick Mode

According to RFC 2409, section 5.5, if PFS is used all proposals MUST
include the selected DH group, so we remove proposals without the
proposed group and remove other DH groups from the remaining proposals.

12 years agoproposal_t.strip_dh() takes a DH group to keep, using MODP_NONE will remove all
Tobias Brunner [Thu, 18 Oct 2012 15:15:32 +0000 (17:15 +0200)] 
proposal_t.strip_dh() takes a DH group to keep, using MODP_NONE will remove all

12 years agoRemove MODP groups from default ESP proposal
Tobias Brunner [Thu, 18 Oct 2012 14:38:22 +0000 (16:38 +0200)] 
Remove MODP groups from default ESP proposal

This now actually makes pfs=no the default and it equals the default
listed in ipsec.conf.5. efc69e9f preserved the default of pfs=yes.

12 years agoMoved utils.[ch] to utils folder
Tobias Brunner [Tue, 16 Oct 2012 14:17:57 +0000 (16:17 +0200)] 
Moved utils.[ch] to utils folder

12 years agoMoved settings_t to utils folder
Tobias Brunner [Tue, 16 Oct 2012 14:08:43 +0000 (16:08 +0200)] 
Moved settings_t to utils folder

12 years agoMoved debug.[ch] to utils folder
Tobias Brunner [Tue, 16 Oct 2012 14:03:21 +0000 (16:03 +0200)] 
Moved debug.[ch] to utils folder

12 years agoMoved enum_name_t to utils folder
Tobias Brunner [Tue, 16 Oct 2012 13:58:19 +0000 (15:58 +0200)] 
Moved enum_name_t to utils folder

12 years agoMoved chunk_t to utils folder
Tobias Brunner [Tue, 16 Oct 2012 13:53:49 +0000 (15:53 +0200)] 
Moved chunk_t to utils folder

12 years agoMoved printf hooks to utils folder
Tobias Brunner [Tue, 16 Oct 2012 13:44:58 +0000 (15:44 +0200)] 
Moved printf hooks to utils folder

12 years agoMoved integrity_checker_t to utils folder
Tobias Brunner [Tue, 16 Oct 2012 13:39:26 +0000 (15:39 +0200)] 
Moved integrity_checker_t to utils folder

12 years agoMoved data structures to new collections subfolder
Tobias Brunner [Tue, 16 Oct 2012 12:54:16 +0000 (14:54 +0200)] 
Moved data structures to new collections subfolder

12 years agoMoved packet_t and tun_device_t to networking folder
Tobias Brunner [Tue, 16 Oct 2012 12:33:28 +0000 (14:33 +0200)] 
Moved packet_t and tun_device_t to networking folder

12 years agoMoved host_t and host_resolver_t to a new networking subfolder
Tobias Brunner [Tue, 16 Oct 2012 12:29:18 +0000 (14:29 +0200)] 
Moved host_t and host_resolver_t to a new networking subfolder

12 years agoSend certificate requests in load-tester
Martin Willi [Fri, 19 Oct 2012 13:51:55 +0000 (15:51 +0200)] 
Send certificate requests in load-tester

12 years agoAdd load-tester traffic selector configuration options
Martin Willi [Thu, 18 Oct 2012 09:32:52 +0000 (11:32 +0200)] 
Add load-tester traffic selector configuration options

12 years agoMake use of new CIDR string ts constructor where appropriate
Martin Willi [Thu, 18 Oct 2012 09:23:30 +0000 (11:23 +0200)] 
Make use of new CIDR string ts constructor where appropriate

12 years agoAdd a traffic selector constructor creating a TS directly from a CIDR string
Martin Willi [Thu, 18 Oct 2012 08:52:42 +0000 (10:52 +0200)] 
Add a traffic selector constructor creating a TS directly from a CIDR string

12 years agoAdd NEWS about explicitly loaded pkcs11 certificates from ipsec.conf
Martin Willi [Wed, 24 Oct 2012 11:16:39 +0000 (13:16 +0200)] 
Add NEWS about explicitly loaded pkcs11 certificates from ipsec.conf

12 years agoPKCS#11 library search using keyid uses a fallback to look for certificates
Martin Willi [Wed, 24 Oct 2012 09:13:07 +0000 (11:13 +0200)] 
PKCS#11 library search using keyid uses a fallback to look for certificates

12 years agoIncrease the limit of acceptable IKEv1 CERTREQ payloads to 20
Martin Willi [Wed, 24 Oct 2012 09:01:26 +0000 (11:01 +0200)] 
Increase the limit of acceptable IKEv1 CERTREQ payloads to 20

12 years agoUse explicit, larger buffer sizes for smartcard keyids and modules
Martin Willi [Wed, 24 Oct 2012 08:54:04 +0000 (10:54 +0200)] 
Use explicit, larger buffer sizes for smartcard keyids and modules

12 years agoRemove obsolete pluto smartcard syntax in ipsec.secrets.5
Martin Willi [Wed, 17 Oct 2012 13:53:44 +0000 (15:53 +0200)] 
Remove obsolete pluto smartcard syntax in ipsec.secrets.5

12 years agoUpdated ipsec.conf.5 regarding (CA) certificates loaded from smartcards
Martin Willi [Wed, 17 Oct 2012 13:50:01 +0000 (15:50 +0200)] 
Updated ipsec.conf.5 regarding (CA) certificates loaded from smartcards

12 years agoAdd a strongswan.conf option to disable loading of all certificates from a pkcs11...
Martin Willi [Wed, 17 Oct 2012 13:55:42 +0000 (15:55 +0200)] 
Add a strongswan.conf option to disable loading of all certificates from a pkcs11 module

12 years agoSupport loading cacert certificates in ipsec.conf ca sections from smartcard
Martin Willi [Wed, 17 Oct 2012 13:55:36 +0000 (15:55 +0200)] 
Support loading cacert certificates in ipsec.conf ca sections from smartcard

12 years agoRefactored stroke smartcard token parsing, support module and slot in leftcert option
Martin Willi [Wed, 17 Oct 2012 13:36:45 +0000 (15:36 +0200)] 
Refactored stroke smartcard token parsing, support module and slot in leftcert option

12 years agoExplicit pkcs11 certificate loading can enforce a module and a slot
Martin Willi [Wed, 17 Oct 2012 12:21:06 +0000 (14:21 +0200)] 
Explicit pkcs11 certificate loading can enforce a module and a slot

12 years agoBe less verbose if loading PKCS#11 certificate fails
Martin Willi [Mon, 15 Oct 2012 16:26:26 +0000 (18:26 +0200)] 
Be less verbose if loading PKCS#11 certificate fails

12 years agoAdd leftcert ipsec.conf.5 documentation about smartcard certificates
Martin Willi [Mon, 15 Oct 2012 16:14:03 +0000 (18:14 +0200)] 
Add leftcert ipsec.conf.5 documentation about smartcard certificates

12 years agoLoad ipsec.conf %smartcard leftcerts with pkcs11 builder
Martin Willi [Mon, 15 Oct 2012 15:54:00 +0000 (17:54 +0200)] 
Load ipsec.conf %smartcard leftcerts with pkcs11 builder

12 years agoAdd a builder to load specific pkcs11 certificates by keyid
Martin Willi [Mon, 15 Oct 2012 15:53:21 +0000 (17:53 +0200)] 
Add a builder to load specific pkcs11 certificates by keyid

12 years agoIf no pkcs11 public key for a private key found, search for a certificate
Martin Willi [Mon, 15 Oct 2012 12:05:14 +0000 (14:05 +0200)] 
If no pkcs11 public key for a private key found, search for a certificate

12 years agoMove pkcs11 public key lookup function declaration to header file
Martin Willi [Mon, 15 Oct 2012 12:04:42 +0000 (14:04 +0200)] 
Move pkcs11 public key lookup function declaration to header file

12 years agoAdd NEWS about proposals with PRFs different from integrity protection algorithms
Martin Willi [Wed, 24 Oct 2012 09:52:59 +0000 (11:52 +0200)] 
Add NEWS about proposals with PRFs different from integrity protection algorithms

12 years agoAdd ipsec.conf.5 documentation for explicit PRFs in IKE proposals
Martin Willi [Wed, 10 Oct 2012 12:17:43 +0000 (14:17 +0200)] 
Add ipsec.conf.5 documentation for explicit PRFs in IKE proposals

12 years agoOnly add an implicit PRF based on the MAC alg if no PRF given in proposal
Martin Willi [Wed, 10 Oct 2012 11:36:16 +0000 (13:36 +0200)] 
Only add an implicit PRF based on the MAC alg if no PRF given in proposal

12 years agoAdd proposal keywords to explicitly specify PRF algorithms
Martin Willi [Wed, 10 Oct 2012 11:35:37 +0000 (13:35 +0200)] 
Add proposal keywords to explicitly specify PRF algorithms

12 years agoAdded NEWS about lookip plugin
Martin Willi [Wed, 24 Oct 2012 09:47:18 +0000 (11:47 +0200)] 
Added NEWS about lookip plugin

12 years agoAdd an interactive mode in lookip tool, demonstrate lasting connections
Martin Willi [Tue, 9 Oct 2012 09:36:17 +0000 (11:36 +0200)] 
Add an interactive mode in lookip tool, demonstrate lasting connections

12 years agoSend a lookip NOT_FOUND reply if a lookup yields no results
Martin Willi [Tue, 9 Oct 2012 09:16:07 +0000 (11:16 +0200)] 
Send a lookip NOT_FOUND reply if a lookup yields no results

12 years agolookup function of lookip listener returns the number of matches
Martin Willi [Tue, 9 Oct 2012 09:05:19 +0000 (11:05 +0200)] 
lookup function of lookip listener returns the number of matches

12 years agoHandle multiple lookip connections using a single FDSET
Martin Willi [Tue, 9 Oct 2012 08:03:15 +0000 (10:03 +0200)] 
Handle multiple lookip connections using a single FDSET

12 years agoRenamed list to store listening lookip clients
Martin Willi [Tue, 9 Oct 2012 07:33:15 +0000 (09:33 +0200)] 
Renamed list to store listening lookip clients

12 years agoHandle client subscriptions in lookip plugin
Martin Willi [Thu, 4 Oct 2012 14:14:10 +0000 (16:14 +0200)] 
Handle client subscriptions in lookip plugin

12 years agoAdd a lookip server side UNIX socket processing LOOKUP and DUMP requests
Martin Willi [Thu, 4 Oct 2012 13:39:26 +0000 (15:39 +0200)] 
Add a lookip server side UNIX socket processing LOOKUP and DUMP requests

12 years agoAdd a simple command line utility to query the lookip plugin
Martin Willi [Thu, 4 Oct 2012 12:49:10 +0000 (14:49 +0200)] 
Add a simple command line utility to query the lookip plugin

12 years agoDefined on-the-wire format used on lookip socket
Martin Willi [Wed, 3 Oct 2012 16:08:38 +0000 (18:08 +0200)] 
Defined on-the-wire format used on lookip socket

12 years agoAdd a lookip function to register virtual IP notification listeners
Martin Willi [Wed, 3 Oct 2012 15:42:19 +0000 (17:42 +0200)] 
Add a lookip function to register virtual IP notification listeners

12 years agoAdd a lookup method to lookip plugin, using a callback to invoke
Martin Willi [Wed, 3 Oct 2012 15:13:37 +0000 (17:13 +0200)] 
Add a lookup method to lookip plugin, using a callback to invoke

12 years agoAdd a lookip listener that collects the information we are interested in
Martin Willi [Wed, 3 Oct 2012 14:58:37 +0000 (16:58 +0200)] 
Add a lookip listener that collects the information we are interested in

12 years agoAdd a lookip plugin stub to lookup connections by virtual IP
Martin Willi [Wed, 3 Oct 2012 14:25:36 +0000 (16:25 +0200)] 
Add a lookip plugin stub to lookup connections by virtual IP

12 years agoAdd NEWS about stroke counters
Martin Willi [Wed, 24 Oct 2012 09:38:24 +0000 (11:38 +0200)] 
Add NEWS about stroke counters

12 years agoAdd "listcounters" command to ipsec.8 manpage
Martin Willi [Mon, 8 Oct 2012 13:38:02 +0000 (15:38 +0200)] 
Add "listcounters" command to ipsec.8 manpage

12 years agoAdd a "ipsec listcounters" command to stroke
Martin Willi [Mon, 8 Oct 2012 10:36:08 +0000 (12:36 +0200)] 
Add a "ipsec listcounters" command to stroke

12 years agoAdd a print method for stroke counters
Martin Willi [Mon, 8 Oct 2012 09:59:20 +0000 (11:59 +0200)] 
Add a print method for stroke counters

12 years agoSupport field with specifiers in %N printf hook
Martin Willi [Mon, 8 Oct 2012 10:35:44 +0000 (12:35 +0200)] 
Support field with specifiers in %N printf hook

12 years agoAdd stroke message type counters
Martin Willi [Mon, 8 Oct 2012 09:49:12 +0000 (11:49 +0200)] 
Add stroke message type counters

12 years agoAdd stroke counters for invalid IKE messages
Martin Willi [Mon, 8 Oct 2012 09:36:07 +0000 (11:36 +0200)] 
Add stroke counters for invalid IKE messages

12 years agoAdd stroke CHILD_SA rekeying counter
Martin Willi [Mon, 8 Oct 2012 09:32:44 +0000 (11:32 +0200)] 
Add stroke CHILD_SA rekeying counter

12 years agoAdd stroke IKE rekey counters
Martin Willi [Mon, 8 Oct 2012 09:31:18 +0000 (11:31 +0200)] 
Add stroke IKE rekey counters

12 years agoRaise a bus alert when IKE message body parsing fails
Martin Willi [Mon, 8 Oct 2012 09:19:54 +0000 (11:19 +0200)] 
Raise a bus alert when IKE message body parsing fails

12 years agoRaise a bus alert when IKE message header parsing fails
Martin Willi [Mon, 8 Oct 2012 09:15:09 +0000 (11:15 +0200)] 
Raise a bus alert when IKE message header parsing fails

12 years agoRaise a bus alert when a received message contains unknown SPIs
Martin Willi [Mon, 8 Oct 2012 09:09:31 +0000 (11:09 +0200)] 
Raise a bus alert when a received message contains unknown SPIs

12 years agoDefine stroke counter types to implement
Martin Willi [Mon, 8 Oct 2012 09:03:08 +0000 (11:03 +0200)] 
Define stroke counter types to implement