Martin Willi
11b18f65b1
vici: Remove support for Python 2
...
Python 2 is dead and unmaintained for a while now. Time to stop carrying
on its support.
2022-12-12 14:38:09 +01:00
Tobias Brunner
a2b1e06f07
vici: Base default soft lifetime on hard lifetime if configured
...
Depending on the configured hard lifetime the default soft lifetime
might not make sense and could even cause rekeying to get disabled.
To avoid that, derive the soft lifetime from the hard lifetime so it's
10% higher than the soft lifetime.
References strongswan/strongswan#1414
2022-12-12 14:24:50 +01:00
Tobias Brunner
9efd7d7e90
eap: Print vendor (PEN) names for vendor-specific EAP methods
2022-09-21 13:53:44 +02:00
Tobias Brunner
f21ef43b0c
vici: Ignore NULL message in raise_event()
...
There are a lot of calls like this:
this->dispatcher->raise_event(this->dispatcher, "...", 0,
b->finalize(b));
However, if finalize() fails, e.g. because a previous call to add()
failed due to the size limit, it returns NULL. This then caused a
segmentation fault in raise_event() when it interacted with that value.
Closes strongswan/strongswan#1278
2022-09-20 10:15:13 +02:00
Tobias Brunner
8a57c2ab52
configure: Add an option to build with AddressSanitizer
2022-09-15 18:23:57 +02:00
Tobias Brunner
3af7c6db87
Rename diffie_hellman_t to key_exchange_t and change the interface etc.
...
This makes it more generic so we can use it for QSKE methods.
2022-06-29 10:28:50 +02:00
Tobias Brunner
df18934d20
Replace or remove wiki.strongswan.org URLs
2022-06-28 13:33:51 +02:00
Tobias Brunner
19ef2aec15
Update copyright headers after acquisition by secunet
2022-06-28 10:22:56 +02:00
Tobias Brunner
c9d471091f
Use mallinfo2() if available
...
mallinfo() is deprecated because it uses `int` for the members of the
returned struct, whereas mallinfo2() uses `size_t`. It's available
since glibc 2.33.
2022-04-25 14:16:20 +02:00
Tobias Brunner
ec17fa2fef
vici: Report registered KDFs
2022-04-14 18:54:24 +02:00
Tobias Brunner
b1c7fac768
vici: Add options to only return specific CHILD_SAs in list-sas()
2022-04-14 18:42:01 +02:00
Tobias Brunner
2994347d18
vici: Report security label on CHILD_SA, policies and configs
2022-04-14 18:42:01 +02:00
Tobias Brunner
7cf6f29ac5
vici: Make security labels and mode configurable
2022-04-14 18:42:01 +02:00
Tobias Brunner
c00c5e5a35
vici: Make combination of 'trap' and 'start' configurable
2022-04-14 18:42:01 +02:00
Tobias Brunner
4f4d4021b4
ike: Treat action_t as flags so 'start' and 'trap' can be combined
...
While combining the actions could cause duplicates (while the SA is
initiated, traffic might trigger the trap and the initiation of another
CHILD_SA), the previous commit should avoid most duplicates. If reuse_ikesa
is disabled, duplicates can't be prevented, though.
2022-04-14 18:42:01 +02:00
Tobias Brunner
e43052893d
vici: Fix check before applying identity to public keys
2021-11-23 16:15:41 +01:00
Tobias Brunner
b9aafa7ebf
vici: Clear all request messages in case they contain secrets
2021-10-04 11:30:03 +02:00
Tobias Brunner
4bea9e8b60
vici: Clear cached strings in case the message contained shared secrets
2021-10-04 11:30:03 +02:00
Tobias Brunner
a415761a8e
vici: Update supported Python versions
2021-09-09 12:30:17 +02:00
Noel Kuntze
fbd4930323
vici: Add DBG4 messages that print loaded shared keys and PINs
...
Closes strongswan/strongswan#217
2021-09-02 10:42:41 +02:00
Tobias Brunner
de5609b297
vici: Use the more generic BUILD_BLOB to parse certificates/public keys
2021-08-23 17:59:39 +02:00
Andreas Steffen
a09a905e1d
vici: Suppress trailing nul character
2021-07-06 12:06:23 +02:00
Tobias Brunner
f6aafb3005
Fixed some typos, courtesy of codespell
...
Main change is the conversion from the British cancelling/-ed to the
American canceling/-ed.
2021-06-25 11:32:29 +02:00
Tobias Brunner
eec3bdb04a
vici: Signal waiting threads when skipping disconnected connections
...
If two threads are waiting in find_entry() and remove_entry(),
respectively, and the former is woken first, the latter remains stuck
as it won't get signaled.
2021-06-21 09:59:15 +02:00
Tobias Brunner
b0e2187b6b
vici: Signal waiting threads when removing a connection entry
...
If there are threads waiting in find_entry() and one in remove_entry()
and the latter is woken first by a thread calling put_entry(), the
former threads would remain stuck as they get never signaled.
2021-06-21 09:59:15 +02:00
Tobias Brunner
4525233b1e
vici: Fix refcount for CA certificates when reloading authority sections
...
Fixes: 3c5e7eaa88 ("vici: Keep track of all CA certificates in vici_authority_t")
2021-01-27 16:50:17 +01:00
Tobias Brunner
2610cd7928
vici: Decode error messages in Python bindings
...
Otherwise we might end up with b'<errmsg>' in the output.
2021-01-18 17:39:15 +01:00
Tobias Brunner
d79cefc3fc
vici: Expose ike-update event
2021-01-18 11:34:40 +01:00
Tobias Brunner
a6f0e19bf5
Fixed some typos, courtesy of codespell
2020-11-04 10:06:46 +01:00
Tobias Brunner
ef636316d2
vici: Send all queued messages during shutdown
...
This ensures that e.g. ike/child-updown messages are sent that were
queued but couldn't be sent (even the job to enable to on_write() callback
requires a worker thread that's not around anymore during shutdown).
References #3602 .
2020-10-30 09:58:42 +01:00
Tobias Brunner
6839256773
vici: Support all defined key types
...
References #3586 .
2020-10-27 11:17:21 +01:00
Tobias Brunner
0ce2e00d94
vici: Don't use pytest-pycodestyle with Python 3.5
...
This causes problems due to a deprecation error during the Ubuntu Xenial
build on Travis.
2020-08-17 15:22:34 +02:00
Tobias Brunner
61af9a3478
vici: Fix typos in comments
2020-07-23 14:50:17 +02:00
Tobias Brunner
3c5e7eaa88
vici: Keep track of all CA certificates in vici_authority_t
...
This way we only have one reference for each CA certificate, whether it
is loaded in an authority section, a connection or via load-certs() command.
It also avoids enumerating CA certificates multiple times if they are
loaded in different ways.
2020-07-20 14:05:39 +02:00
Tobias Brunner
d8a2c58229
vici: Make attribute certificates untrusted again
...
Fixes: 334119b843 ("Share vici_cert_info.c with vici_cred.c")
2020-07-20 14:05:39 +02:00
Tobias Brunner
6fc1b2c3d3
vici: Clear credential cache when unloading an authority section
2020-07-20 14:05:38 +02:00
Tobias Brunner
46ff268885
vici: Directly provide CA certificates in authority sections
...
With the previous approach, CA certificates that were not re-loaded via
load-cert() (e.g. from tokens or via absolute paths) would not be available
anymore after the clear-creds() command was used. This avoids this
issue, but can cause duplicate CA certificates to get stored and enumerated,
so there might be a scaling factor.
2020-07-20 14:05:38 +02:00
Tobias Brunner
736fae4e6c
vici: Store configs in a hashtable
...
This makes updates more efficient if many configs are loaded. Configs
still have to be enumerated to select them.
2020-07-20 13:50:11 +02:00
Tobias Brunner
feda4a3d37
vici: With start_action=start, terminate IKE_SA without children on unload
...
This includes IKE_SAs in CONNECTING state, which not yet have any
CHILD_SAs.
Closes strongswan/strongswan#175 .
2020-07-01 15:59:41 +02:00
Tobias Brunner
33412158f5
ike: Send AEAD ESP default proposal first
...
We generally prefer AEAD nowadays.
References #3461 .
2020-06-12 13:47:13 +02:00
Thomas Egerer
d2c15b7bf9
vici: Allow maximum vici message size configuration via compile option
...
Signed-off-by: Thomas Egerer <thomas.egerer@secunet.com >
2020-04-14 16:55:49 +02:00
Josh Soref
b3ab7a48cc
Spelling fixes
...
* accumulating
* acquire
* alignment
* appropriate
* argument
* assign
* attribute
* authenticate
* authentication
* authenticator
* authority
* auxiliary
* brackets
* callback
* camellia
* can't
* cancelability
* certificate
* choinyambuu
* chunk
* collector
* collision
* communicating
* compares
* compatibility
* compressed
* confidentiality
* configuration
* connection
* consistency
* constraint
* construction
* constructor
* database
* decapsulated
* declaration
* decrypt
* derivative
* destination
* destroyed
* details
* devised
* dynamic
* ecapsulation
* encoded
* encoding
* encrypted
* enforcing
* enumerator
* establishment
* excluded
* exclusively
* exited
* expecting
* expire
* extension
* filter
* firewall
* foundation
* fulfillment
* gateways
* hashing
* hashtable
* heartbeats
* identifier
* identifiers
* identities
* identity
* implementers
* indicating
* initialize
* initiate
* initiation
* initiator
* inner
* instantiate
* legitimate
* libraries
* libstrongswan
* logger
* malloc
* manager
* manually
* measurement
* mechanism
* message
* network
* nonexistent
* object
* occurrence
* optional
* outgoing
* packages
* packets
* padding
* particular
* passphrase
* payload
* periodically
* policies
* possible
* previously
* priority
* proposal
* protocol
* provide
* provider
* pseudo
* pseudonym
* public
* qualifier
* quantum
* quintuplets
* reached
* reading
* recommendation to
* recommendation
* recursive
* reestablish
* referencing
* registered
* rekeying
* reliable
* replacing
* representing
* represents
* request
* request
* resolver
* result
* resulting
* resynchronization
* retriable
* revocation
* right
* rollback
* rule
* rules
* runtime
* scenario
* scheduled
* security
* segment
* service
* setting
* signature
* specific
* specified
* speed
* started
* steffen
* strongswan
* subjectaltname
* supported
* threadsafe
* traffic
* tremendously
* treshold
* unique
* uniqueness
* unknown
* until
* upper
* using
* validator
* verification
* version
* version
* warrior
Closes strongswan/strongswan#164 .
2020-02-11 18:23:07 +01:00
Tobias Brunner
f78dfb7e28
vici: Options are optional in get_pools() of Python bindings
...
Fixes #3319 .
2020-02-03 10:52:31 +01:00
Tobias Brunner
c584a6b2dc
vici: Remove unused import in Python bindings
2020-01-28 15:29:40 +01:00
Tobias Brunner
df4274171e
vici: Remove unnecessary pass statement
2020-01-28 15:29:40 +01:00
Tobias Brunner
ecf161e517
vici: Move Python test dir and include it in sdist
...
This is the recommended location and import config as it allows running the
tests against installed versions of the package. And while the test file
itself is automatically included in the source distribution this way, the
__init__.py file is not, so we still have to update MANIFEST.in.
2020-01-14 16:53:19 +01:00
Tobias Brunner
b723431540
vici: Run Python tests via tox if available
...
Since we use the serial test harness we can't use AM_TESTS_ENVIRONMENT.
The script is necessary for out-of-tree builds.
2020-01-14 15:26:52 +01:00
Tobias Brunner
574621d80a
vici: Fix several PEP8 issues
2020-01-14 15:26:32 +01:00
Tobias Brunner
d5153c5897
vici: Add tox.ini to run tests with tox
...
Some of the interpreters might not be available on the host system, use
--skip-missing-interpreters to not fail in that case.
2020-01-14 15:26:29 +01:00
Tobias Brunner
c170bb593b
vici: List newer Python versions in setup.py
2020-01-14 10:48:53 +01:00