Andreas Steffen
|
4ab5874ccd
|
adapted gcrypt-ikev2/alg-camellia scenario
|
2009-12-09 15:48:03 +01:00 |
|
Andreas Steffen
|
fcca5b5caf
|
adapted gcrypt-ikev1 alg scenarios
|
2009-12-09 15:45:45 +01:00 |
|
Andreas Steffen
|
8603d1d76c
|
adapted ikev1 alg and esp scenarios
|
2009-12-09 15:41:54 +01:00 |
|
Andreas Steffen
|
4c8f3dff9c
|
adapted pfkey alg and esp scenarios
|
2009-12-09 15:38:17 +01:00 |
|
Andreas Steffen
|
8e7e81451b
|
remove again the ikev2/esp-alg-camellia scenario
|
2009-12-09 15:26:43 +01:00 |
|
Andreas Steffen
|
99133d3086
|
adapted ikev2 alg and esp scenarios
|
2009-12-09 15:19:10 +01:00 |
|
Andreas Steffen
|
344061ebce
|
removed redundant ikev1/ike-alg-sha2 scenarios
|
2009-12-09 10:11:03 +01:00 |
|
Andreas Steffen
|
01a8af1b1b
|
added ikev1/alg-sha512 scenario
|
2009-12-09 09:51:54 +01:00 |
|
Andreas Steffen
|
cb7e304d33
|
added ikev1/alg-sha384 scenario
|
2009-12-09 09:46:40 +01:00 |
|
Andreas Steffen
|
5d9d779808
|
renamed ikev1/alg-sha2_256 scenario to ikev1/alg-sha256
|
2009-12-09 09:36:16 +01:00 |
|
Andreas Steffen
|
05ffbc6e59
|
added ikev1/alg-sha256-96 scenario
|
2009-12-09 09:35:17 +01:00 |
|
Andreas Steffen
|
353b829177
|
fixed IKEv1 support of HMAC_SHA2_256_96
|
2009-12-09 09:33:32 +01:00 |
|
Andreas Steffen
|
0a975307f1
|
added Juniper SRX support to NEWS
|
2009-12-09 08:00:19 +01:00 |
|
Andreas Steffen
|
ee2679ec25
|
if end id is missing assign IP address to raw public key
|
2009-12-09 07:24:43 +01:00 |
|
Andreas Steffen
|
a07531250e
|
IKEv1 support of ESP SHA2_HMAC with correct truncation
|
2009-12-09 00:24:42 +01:00 |
|
Andreas Steffen
|
4b615edab4
|
some code optimizations
|
2009-12-09 00:24:42 +01:00 |
|
Andreas Steffen
|
e1573b3fe8
|
added ipAddrBlocks OID
|
2009-12-09 00:24:41 +01:00 |
|
Andreas Steffen
|
7747210f26
|
removed redundant ikev2/esp-alg-camellia scenario
|
2009-12-09 00:24:41 +01:00 |
|
Martin Willi
|
a6225e4936
|
Improved libfast session management, using a hashtable
|
2009-12-08 19:31:02 +01:00 |
|
Martin Willi
|
4e90d9de9f
|
Removed obsolete curl interface specific destructor
|
2009-12-08 16:21:58 +01:00 |
|
Martin Willi
|
89d236f0da
|
Support "_" and "-" variants of NetworkManager pkg-config packages
|
2009-12-08 14:36:22 +01:00 |
|
Martin Willi
|
f469754f7f
|
Undef PACKAGE_BUG/URL of strongSwan before including ruby variants
|
2009-12-08 14:36:22 +01:00 |
|
Martin Willi
|
88dbccc842
|
Remove generated config.h.in from source tree
|
2009-12-08 14:36:21 +01:00 |
|
Andreas Steffen
|
04933ea74e
|
added ikev2/alg-3des-md5 scenario
|
2009-12-08 12:54:42 +01:00 |
|
Tobias Brunner
|
268911a5cc
|
The attribute manager was moved from daemon_t to libstrongswan.
|
2009-12-07 16:00:27 +01:00 |
|
Martin Willi
|
cd51437e43
|
Do not execute the callback job if it has been cancelled since registration
|
2009-12-03 08:00:43 +01:00 |
|
Martin Willi
|
c636bc7e17
|
Cleanup library if daemon initialization fails
|
2009-12-03 08:00:43 +01:00 |
|
Martin Willi
|
65c8bff7a1
|
To build strongSwan from git sources, gettext is required
|
2009-12-02 11:49:11 +01:00 |
|
Martin Willi
|
376a11db3c
|
Do not install invalid 0.0.0.0 DNS servers
|
2009-12-01 15:46:56 +01:00 |
|
Martin Willi
|
5b4d0de7d4
|
Prefer EAP-Identity for provider attribute/address lookup
|
2009-12-01 14:24:07 +01:00 |
|
Martin Willi
|
f6116e61fc
|
Save EAP-Identity on auth config
|
2009-12-01 14:24:06 +01:00 |
|
Martin Willi
|
44ce749360
|
Store completed authentication rounds permanently on IKE_SA, with flush option
|
2009-12-01 11:35:30 +01:00 |
|
Martin Willi
|
5b2b4d190a
|
Removed obsolete and unused [gs]et_eap_identity() methods
|
2009-11-30 16:59:23 +01:00 |
|
Martin Willi
|
5351e51951
|
Do not propose transport mode as initiator if connection is NATed
|
2009-11-30 11:32:26 +01:00 |
|
Martin Willi
|
bff9f824ed
|
Verify EAP-SIM/AKA AT_MAC before processing any attributes
|
2009-11-30 10:00:06 +01:00 |
|
Martin Willi
|
b04e72c21c
|
SIM/AKA/Request/Reauthentication AT_MAC does not include NONCE_S, only the response
|
2009-11-30 09:27:39 +01:00 |
|
Martin Willi
|
5a91fd4536
|
Invoke attribute/key hooks from libsimaka
|
2009-11-30 09:27:34 +01:00 |
|
Martin Willi
|
8434c88b5e
|
Extended SIM manager by hooks, currently featuring attribute and key hooks
|
2009-11-30 09:27:26 +01:00 |
|
Martin Willi
|
fb1ae8da52
|
Added a get_sa() method to the bus, allowing a thread to lookup its IKE_SA
|
2009-11-30 09:27:14 +01:00 |
|
Martin Willi
|
c56d958243
|
Handle NOT_SUPPORTED or other errors properly in get_quintuplet
|
2009-11-30 09:26:35 +01:00 |
|
Andreas Steffen
|
7868162b35
|
added RFC-conforming ikev2/sha2 scenarios
|
2009-11-26 23:48:29 +01:00 |
|
Andreas Steffen
|
68db91ca32
|
adapted ikev2/alg-aes-xcbc scenario
|
2009-11-26 23:46:27 +01:00 |
|
Martin Willi
|
2b2c69e992
|
Use transport mode ESP SA if IPcomp is used, IPcomp already applies outer IP header
|
2009-11-26 16:03:06 +01:00 |
|
Martin Willi
|
52fd0ef9e0
|
Added NEWS about SHA2 changes
|
2009-11-26 10:39:26 +01:00 |
|
Martin Willi
|
6780edc07e
|
Use full algorithm name for SHA384/512 HMACs
|
2009-11-26 10:39:26 +01:00 |
|
Martin Willi
|
6546482a68
|
Support the Linux specific SHA256 96 bit truncation HMAC via "sha256_96" keyword
|
2009-11-26 10:39:25 +01:00 |
|
Martin Willi
|
eebfa73fd5
|
Install SHA256_128 auth algorithm with specified 128 bit truncation
|
2009-11-26 10:39:25 +01:00 |
|
Martin Willi
|
2379fdba1e
|
Updated XFRM linux header, includes specified truncations for auth algos
|
2009-11-26 10:39:25 +01:00 |
|
Martin Willi
|
5be75c2cb1
|
Added support for IPv6 source route installation
|
2009-11-26 10:31:00 +01:00 |
|
Martin Willi
|
387a6e6c32
|
Check existing path in mobike probing only if we still have a route
|
2009-11-26 10:30:59 +01:00 |
|