Martin Willi
|
3dd3c5f39e
|
redesigned IKE_SA using a transaction mechanism:
removed old state machine
reimplemented IKE_SA setup and delete
implemented dead peer detection
implemented keep-alives
a lot of fixes
no rekeying yet
|
2006-07-05 10:53:20 +00:00 |
|
Andreas Steffen
|
971218c3ae
|
support of cert payloads
|
2006-07-03 06:27:45 +00:00 |
|
Martin Willi
|
1396815afb
|
first merge of NATT code
|
2006-06-22 06:36:28 +00:00 |
|
Martin Willi
|
c095388f7f
|
added support for "ike" and "esp" keywords
fixed bugs in proposal code
algorithm selection for charon works now with ipsec.conf
a lot of other fixes
|
2006-06-15 11:09:11 +00:00 |
|
Andreas Steffen
|
c4a7413e72
|
cosmetics
|
2006-06-12 07:55:37 +00:00 |
|
Martin Willi
|
695723d4e8
|
old child_sa gets deleted after rekeying
rekeying almost complete, but:
IKE_SA get in an invalid state when both initiate rekeying at the same time,
|
2006-06-09 15:12:43 +00:00 |
|
Martin Willi
|
5c131a016b
|
specifying keysize in bits, as it is required in IKEv2
added generic kernel SA algorithm handling, which brings us:
aes-128, aes-256, blowfish, des, 3des and null encryption for CHILD_SAs
|
2006-06-09 07:31:30 +00:00 |
|
Martin Willi
|
8d77eddec2
|
further work for rekeying:
get liftimes from policy
added new state
initiation of rekeying done
proposal redone:
removed support for AH+ESP proposals
|
2006-06-07 13:26:23 +00:00 |
|
Martin Willi
|
3a13a78084
|
- handle IKE_SA setup without a piggy-packed CHILD_SA
more IKEv2 conform
|
2006-05-24 09:05:21 +00:00 |
|
Martin Willi
|
4a5bba25e2
|
- reimplemented proper IKE SA deletion using a seperate state,
should conform now to IKEv2
|
2006-05-23 08:01:49 +00:00 |
|
Martin Willi
|
f2c2d395ff
|
- introduced autotools
- first working version
- make dist should work
- things to do:
- UML testing!
- more cleanups
|
2006-05-16 14:24:03 +00:00 |
|
Martin Willi
|
b8577029d1
|
|
2006-05-10 08:02:49 +00:00 |
|