Tobias Brunner
4e9d313ff8
Explicitly include stdint.h for UINT64_MAX.
...
This is required on FreeBSD 8.
2010-06-15 15:31:46 +02:00
Tobias Brunner
ed76b21652
Check for SADB_X_NAT_T_NEW_MAPPING in PF_KEY kernel interface.
...
FreeBSD 8 does not support SADB_X_NAT_T_NEW_MAPPING whereas Linux and
the previous FreeBSD NAT-T patch both do.
2010-06-15 15:31:10 +02:00
Tobias Brunner
668e84d904
Set the ports of all hosts installed via the PF_KEY kernel interface to zero.
2010-06-15 10:11:57 +02:00
Andreas Steffen
5d4c258de7
refer to correct PLUTO_XAUTH_ID variable
2010-06-09 15:21:26 +02:00
Andreas Steffen
fcfd54acde
rename environment variable to PLUTO_XAUTH_ID
2010-06-08 23:18:51 +02:00
Andreas Steffen
611368339b
do not destroy xauth_id if phase2 equals phase1 connection
2010-06-08 23:18:00 +02:00
Andreas Steffen
964f6372cc
make an optional XAUTH user ID available in the updown script
2010-06-08 17:50:22 +02:00
Heiko Hund
52ee813156
inherit XAUTH identities in Phase 2
2010-06-08 12:15:42 +02:00
Tobias Brunner
2e8a5e12ef
Adding a basic unit test for hashtable_t.
2010-06-07 16:40:32 +02:00
Tobias Brunner
b2ddaf0775
Adding a remove_at method to the hash table.
...
This allows to remove key-value pairs while enumerating them.
2010-06-07 16:36:26 +02:00
Tobias Brunner
88b6f14143
Migrated hashtable_t to INIT/METHOD macros.
2010-06-07 15:53:36 +02:00
Thomas Egerer
03ffa88531
Add extra information in debug output for IKE_SA check{out, in}
...
This output helps tracing checkout and checkin of IKE_SAs when there is
more than one IKE_SAs with the same name. I also added the type of
in-air-exchange to the debug output issued by the task_manager in case
a task initiation is delayed, came in handy for me.
2010-06-07 15:12:13 +02:00
Martin Willi
5493ffde0b
traffic_selector_t is gone into libstrongswan, migrate printf hook registration, too.
2010-06-07 15:06:09 +02:00
Martin Willi
550d9085fa
Flush auth configs, create new keymat during SA reset
2010-06-07 14:59:39 +02:00
Martin Willi
dbdb69f908
Recreate IKE_INIT/IKE_NATD/IKE_VENDOR tasks if we reset SA during IKE_AUTH
2010-06-07 14:58:57 +02:00
Martin Willi
8b56ec20f3
Reacquire keymat from new IKE_SA during task migration
2010-06-07 14:56:24 +02:00
Martin Willi
d5ad6eb1e0
Flush certificate cache on CA delete
2010-06-07 13:51:18 +02:00
Martin Willi
a3ffa9edfd
Log non-empty task queues in statusall
2010-06-07 11:59:37 +02:00
Martin Willi
ea340ee840
Wrap task enumerator in ike_sa
2010-06-07 11:37:55 +02:00
Martin Willi
8bced61b76
Migrated ike_sa_t to INIT/METHOD macros
2010-06-07 09:30:27 +00:00
Martin Willi
665c18bd85
Added support for task enumeration in task_manager_t
2010-06-07 10:45:25 +02:00
Martin Willi
9560a3166f
Migrated task_manager_t to INIT/METHOD macros
2010-06-07 10:37:00 +02:00
Andreas Steffen
39e3b58fe4
use --addattr
2010-06-05 13:49:01 +02:00
Andreas Steffen
88613f159d
use --addattr
2010-06-05 13:47:23 +02:00
Andreas Steffen
4321d19d1e
added ikev2/nat-virtual-ip scenario
2010-06-05 13:42:28 +02:00
Andreas Steffen
b2be7dd621
remove stray carolReq.pem
2010-06-05 13:36:39 +02:00
Andreas Steffen
5a9a255ae5
share pool in ikev1/mode-config-multiple scenario
2010-06-05 13:17:51 +02:00
Andreas Steffen
6d989d356b
use --addattr
2010-06-05 13:15:03 +02:00
Andreas Steffen
bdd28aa9c5
remove stray scenario files
2010-06-05 13:10:39 +02:00
Martin Willi
d43775ae58
Accept ARP requests with an ethernet trailer, but trim it
2010-06-03 08:39:33 +02:00
Martin Willi
d2c358742a
Added a EAP-SIM/AKA backend reading triplets/quintuplets from a SQL database
2010-06-02 15:59:44 +02:00
Andreas Steffen
c77f4b305e
fixed configuration attribute type determination
2010-06-02 11:52:17 +02:00
Martin Willi
2f57e6da0e
Disable close action for a redundant CHILD_SA resulting from a rekey collision
...
If a rekey collision is detected, the winning peer of the nonce compare
will delete the redundant CHILD_SA. The other peer should not enforce the
close action on this CHILD, as it would reestablish the redundat CHILD_SA.
Thanks to Thomas Egerer from secunet for pointing this out and the initial
patchset.
2010-06-02 11:48:52 +02:00
Martin Willi
fe02d99b96
Use wrapped getters for close/dpd action
2010-06-02 11:48:51 +02:00
Martin Willi
4c401ea216
Wrap getters for dpd/close action into CHILD_SA, allows us to override them
2010-06-02 11:48:44 +02:00
Andreas Steffen
616b13c7a5
ipsec pool --statusattr [--hexout] outputs attribute values in correct format if known
2010-06-01 16:47:56 +02:00
Andreas Steffen
185d8b7335
added unity_def_domain keyword tip ipsec pool
2010-05-31 16:47:06 +02:00
Martin Willi
80b5661a9b
Added generated manpages to .gitignore
2010-05-31 13:41:25 +02:00
Martin Willi
a2cf26f1c1
Changed default lifetime of certificates to 3 years
2010-05-31 13:15:19 +02:00
Martin Willi
70ac7c43a5
Support extendedKeyUsage flags in self-signed certificates
2010-05-31 13:15:05 +02:00
Tobias Brunner
3d829c4c0a
IPSEC_CONFDIR in ipsec script fixed.
2010-05-30 13:07:32 +02:00
Tobias Brunner
8f76653a4c
Adding the version number to the most relevant manual pages.
2010-05-30 13:03:04 +02:00
Tobias Brunner
1d3a48b559
Updated and corrected the ipsec.secrets(5) manual page.
2010-05-30 12:29:32 +02:00
Tobias Brunner
f115838bee
Updated and corrected the ipsec.conf(5) manual page.
2010-05-30 12:29:26 +02:00
Tobias Brunner
28550caaa8
Updated and corrected the ipsec(8) manual page.
2010-05-30 12:29:18 +02:00
Andreas Steffen
d9c751daac
added --leases command line option to synopsis
2010-05-29 13:29:23 +02:00
Andreas Steffen
751379e5e8
added --showattr command line option to synopsys
2010-05-29 13:23:20 +02:00
Andreas Steffen
3561cc4b3b
added X.509 support by openssl plugin to NEWS
2010-05-29 11:22:36 +02:00
Andreas Steffen
5b6200888b
remove x509 plugin from openssl-ikev1 scenarios
2010-05-28 23:22:15 +02:00
Tobias Brunner
d070e0a6d1
Do not install trap policy if remote host is %any.
2010-05-28 15:43:12 +02:00