Tobias Brunner
89bd016ef4
Fixed some typos, courtesy of codespell
2018-05-23 16:33:02 +02:00
Tobias Brunner
1b67166921
Unify format of HSR copyright statements
2018-05-23 16:32:53 +02:00
Tobias Brunner
0bcfed1aa2
vici: Optionally terminate IKE_SA immediately
2018-05-22 10:06:07 +02:00
Tobias Brunner
7b72909774
controller: Add option to force destruction of an IKE_SA
...
It's optionally possible to wait for a timeout to destroy the SA.
2018-05-22 10:06:07 +02:00
Tobias Brunner
16898026a5
child-sa: Add new state to track deleted but not yet destroyed CHILD_SAs
...
This allows us to easily identify SAs we keep around after a rekeying to
process delayed packets.
2018-04-09 17:13:41 +02:00
Adi Nissim
8ced1570ab
child-cfg: Make HW offload auto mode configurable
...
Until now the configuration available to user for HW offload were:
hw_offload = no
hw_offload = yes
With this commit users will be able to configure auto mode using:
hw_offload = auto
Signed-off-by: Adi Nissim <adin@mellanox.com >
Reviewed-by: Aviv Heller <avivh@mellanox.com >
2018-03-21 10:32:02 +01:00
Tobias Brunner
70d99d67d6
vici: Make sure to read all requested data from socket in Perl binding
...
Closes strongswan/strongswan#91 .
2018-03-21 10:10:35 +01:00
Tobias Brunner
24fa1bb02a
trap-manager: Remove reqid parameter from install() and change return type
...
Reqids for the same traffic selectors are now stable so we don't have to
pass reqids of previously installed CHILD_SAs. Likewise, we don't need
to know the reqid of the newly installed trap policy as we now uninstall
by name.
2018-02-22 11:31:05 +01:00
Tobias Brunner
ca213e1907
trap-manager: Uninstall trap policies by name and not reqid
...
If a trap policy is concurrently uninstalled and reinstalled under a
different name the reqid will be the same so the wrong trap might be
removed.
2018-02-22 11:31:05 +01:00
Tobias Brunner
6f569263a0
vici: Remove external enumeration to uninstall shunt policies
2018-02-22 11:31:05 +01:00
Tobias Brunner
fb545dd34d
vici: Also return close action
2018-02-16 09:55:22 +01:00
Andreas Steffen
4eaf08c35b
vici: list-conn reports DPD settings and swanctl displays them
2018-02-15 16:28:06 +01:00
Tobias Brunner
2db6d5b8b3
Fixed some typos, courtesy of codespell
2018-02-13 12:19:54 +01:00
Tobias Brunner
a7f613ca2e
vici: Document NTLM secrets in README.md
...
Fixes #2481 .
2017-12-22 10:09:26 +01:00
Tobias Brunner
859d645c44
vici: Accept XAUTH as shared key type too
...
Fixes #2481 .
2017-12-22 10:09:22 +01:00
Tobias Brunner
fdf33b0f1c
vici: Add 'get|reset-counters' commands
2017-11-08 16:28:28 +01:00
Tobias Brunner
2d244f178f
vici: Make setting mark on inbound SA configurable
2017-11-02 09:59:38 +01:00
Tobias Brunner
ca280574ba
Fixed some typos, courtesy of codespell
2017-08-07 17:22:01 +02:00
Tobias Brunner
525cc46cab
Change interface for enumerator_create_filter() callback
...
This avoids the unportable 5 pointer hack, but requires enumerating in
the callback.
2017-05-26 13:56:44 +02:00
Tobias Brunner
95a63bf281
Migrate all enumerators to venumerate() interface change
2017-05-26 13:56:44 +02:00
Tobias Brunner
0afe0eca67
vici: Make 96-bit truncation for SHA-256 configurable
2017-05-26 11:22:28 +02:00
Tobias Brunner
7c4f88d4be
vici: Make hardware offload configurable
2017-05-23 16:58:00 +02:00
Tobias Brunner
749ac175fa
child-cfg: Use flags for boolean options
...
Makes it potentially easier to add new flags.
2017-05-23 16:51:15 +02:00
Tobias Brunner
46a3f92a76
Add an option to announce support for IKE fragmentation but not sending fragments
2017-05-23 16:41:57 +02:00
Tobias Brunner
605a98c7ce
vici: Return key ID from load-key command
...
We already do this for load-token and this should simplify client
implementations.
2017-05-23 16:41:02 +02:00
odi79
0d66b01a81
vici: Fix type error exception in Python bindings
...
Line 66 yields "TypeError: can't concat bytes to str" using Python 3.4.
"requestdata" was introduced in 22f08609f1 but is not actually used.
Since the original "request" is not used anywhere else this can be changed
to be similar to the other UTF-8 encoding changes in that commit.
Fixes: 22f08609f1 ("vici: Explicitly set the Python encoding type").
Closes strongswan/strongswan#66 .
2017-04-19 10:00:21 +02:00
Tobias Brunner
550bd654a7
vici: Don't fall back to uninstalling traps if a matching shunt was found
...
This is different if `ike` and `child` are provided and uninstall()
fails as we call that without knowing whether a matching shunt exists.
But if `ike` is not provided we explicitly search for a matching shunt
and if found don't need to look for a trap policy.
2017-03-23 18:29:18 +01:00
Tobias Brunner
1003cf2330
Fixed some typos, courtesy of codespell
2017-03-23 18:29:18 +01:00
Martin Willi
46d4d2a71e
vici: Document how we pronounce the vici protocol and plugin
2017-03-20 10:39:10 +01:00
Tobias Brunner
8bd8dcd522
vici: Only log messages if there actually is a listener
2017-02-16 19:24:09 +01:00
Tobias Brunner
fa5f6ba26c
vici: Let has_event_listeners() actually check if clients are registered
...
Fixes: 8d96f90a79 ("vici: Add function to test if an event should be
generated")
2017-02-16 19:24:09 +01:00
Tobias Brunner
f927ba975b
vici: Add support for mediation extension
2017-02-16 19:24:09 +01:00
Tobias Brunner
ec5f127a45
vici: Include uniqueness policy in list-conns
2017-02-16 19:24:09 +01:00
Tobias Brunner
808472c9f9
vici: Add command to initiate SA rekeying
2017-02-16 19:24:08 +01:00
Tobias Brunner
04c0219e55
vici: Use unique names for CHILD_SAs in the list-sas command
...
The original name is returned in the new "name" attribute.
This fixes an issue with bindings that map VICI messages to
dictionaries. For instance, in roadwarrior scenarios where every
CHILD_SA has the same name only the information of the last CHILD_SA
would end up in the dictionary for that name.
2017-02-16 19:24:08 +01:00
Tobias Brunner
bd6ef6be7e
vici: Add support to load CA certificates from tokens and paths in authority sections
2017-02-16 19:24:08 +01:00
Tobias Brunner
2f8354ca6c
vici: Add support to load certificates from file paths
...
Probably not that useful via swanctl.conf but could be when used via VICI.
2017-02-16 19:24:08 +01:00
Tobias Brunner
00bf6a2a49
vici: Add support to load certificates from tokens
2017-02-16 19:24:08 +01:00
Tobias Brunner
2ceeb96db5
vici: Add command to load a private key from a token
...
PINs are stored in a "hidden" credential set, so that its shared
secrets are not exposed via VICI. Since they are not explicitly loaded as
shared secrets via VICI a client might consider them as removed secrets and
remove them.
2017-02-16 19:24:07 +01:00
Tobias Brunner
b657740e16
vici: List namespace/peer-cfg name with policies and allow filtering
...
The two names are also transmitted in separate keys.
2017-02-16 19:24:07 +01:00
Tobias Brunner
7627f5f9c7
vici: Explicitly use peer name when uninstalling trap and shunt policies
...
Also adds an `ike` parameter to the `uninstall` command.
2017-02-16 19:24:07 +01:00
Tobias Brunner
7a0fdbab42
shunt-manager: Add an optional namespace for each shunt
...
This will allow us to reuse the names of child configs e.g. when they
are defined in different connections.
2017-02-16 19:24:07 +01:00
Tobias Brunner
ed105f45af
vici: Add support for NT Hash secrets
...
Fixes #1002 .
2017-02-16 19:23:51 +01:00
Tobias Brunner
3bedf10b25
vici: Add support for IPv6 Transport Proxy Mode
2017-02-16 19:23:50 +01:00
Tobias Brunner
e00bc9f6b2
vici: Add support for certificate policies
2017-02-16 19:23:50 +01:00
Tobias Brunner
44fcc83310
vici: Add missing dscp setting for IKE_SAs
...
Fixes #2170 .
2017-02-16 19:23:31 +01:00
Tobias Brunner
cf57d9a98f
vici: Add possibility to remove shared keys by a unique identifier
...
This identifier can be set when adding/replacing a secret. The unique
identifiers of all secrets may be enumerated.
2017-02-16 19:21:13 +01:00
Tobias Brunner
2a56acf501
vici: Add commands to enumerate and remove private keys
...
They are identified by their SHA-1 key identifier.
2017-02-16 19:21:12 +01:00
Tobias Brunner
d20bf50e04
vici: Update get_pools() in Python and Ruby bindings
2017-02-16 19:21:12 +01:00
Tobias Brunner
71fa1224ec
vici: Add option to query a specific pool
2017-02-16 19:21:12 +01:00