Commit Graph
12886 Commits
Author SHA1 Message Date
Tobias Brunner 7f2e3091ee Log the proper type for virtual EAP methods 2012-08-31 11:42:03 +02:00
Tobias Brunner 333c3b6228 Added an option to prefer types sent by peer in eap-dynamic plugin 2012-08-31 11:42:03 +02:00
Tobias Brunner 3dde55e67b eap-dynamic plugin handles EAP-Nak messages and selects a method supported by the peer 2012-08-31 11:42:03 +02:00
Tobias Brunner a2f1d75eae Preferred EAP methods for eap-dynamic can be configured 2012-08-31 11:42:03 +02:00
Tobias Brunner a2a61ec2e2 The eap-dynamic plugin uses the first supported method as default 2012-08-31 11:42:03 +02:00
Tobias Brunner 700ff5def9 Added eap-dynamic plugin which can proxy any other EAP method 2012-08-31 11:42:01 +02:00
Tobias Brunner 7240914955 Use eap_vendor_type_from_string() in stroke 2012-08-31 11:40:28 +02:00
Tobias Brunner db409006e4 Function added that parses EAP method strings ([eap-]type[-vendor]) 2012-08-31 11:40:28 +02:00
Tobias Brunner 576490ab09 Added method to enumerate EAP types contained in an EAP-Nak 2012-08-31 11:40:28 +02:00
Tobias Brunner cc4eec56f7 Encode EAP-Naks in expanded format if we got an expanded type request
Since methods defined by the IETF (vendor ID 0) could also be encoded in
expanded type format the previous check was insufficient.
2012-08-31 11:40:27 +02:00
Tobias Brunner 78e8dca94f Allow clients to request a configured EAP method via EAP-Nak 2012-08-31 11:40:27 +02:00
Tobias Brunner 34742f1bf8 Virtual EAP methods handle EAP-Naks themselves 2012-08-31 11:40:27 +02:00
Tobias Brunner af04233e14 Send EAP-Nak with supported types if requested type is unsupported 2012-08-31 11:40:27 +02:00
Tobias Brunner 7cad171da8 Filter invalid EAP authentication types when enumerating them
Valid authentication types defined by the IETF are 4-253 and 255.
2012-08-31 11:37:45 +02:00
Tobias Brunner eae5616ae6 Move our pseudo EAP types out of the range of valid EAP methods 2012-08-31 11:31:48 +02:00
Andreas Steffen 7b1c711ea0 version bump to 5.0.1dr4 2012-08-31 02:47:37 +02:00
Martin Willi 69e056a2c1 Added multiple left/rightsourceip NEWS 2012-08-30 16:43:46 +02:00
Martin Willi e76f3d0df7 Added NEWS for left/rightdns options 2012-08-30 16:43:45 +02:00
Martin Willi 26bc695806 Updated ipsec.conf.5 with multiple left/rightsourceip support 2012-08-30 16:43:45 +02:00
Martin Willi 2df155958c Added a note to _updown for the new PLUTO_MY_SOURCEIP* variables 2012-08-30 16:43:45 +02:00
Martin Willi 7f52f621c2 Be less verbose if IP allocation for a single pool fails 2012-08-30 16:43:44 +02:00
Martin Willi 980c468cdc DHCP plugin returns virtual IPs for IPv4 requests only 2012-08-30 16:43:44 +02:00
Martin Willi 769446a8c7 Check address family in HA virtual IP backend 2012-08-30 16:43:44 +02:00
Martin Willi 40e9089889 Strictly enforce address family match while acquiring mem_pool IPs 2012-08-30 16:43:44 +02:00
Martin Willi 13f11ccf46 Don't parse comma separated pool names in attr-sql
We now handle multiple pools at a deeper level, making that special
handling obsolete. Comma separated pools are parsed in stroke.
2012-08-30 16:43:44 +02:00
Martin Willi 7b83cc62e0 Handle comma separated pools as multiple pool names in SQL plugin 2012-08-30 16:43:43 +02:00
Martin Willi b5d2bf975b Request and acquire multiple virtual IPs in IKEv1 Mode Config 2012-08-30 16:43:43 +02:00
Martin Willi 61d6ccf51c Request and acquire multiple virtual IPs in IKEv2 configuration payload 2012-08-30 16:43:43 +02:00
Martin Willi d55fe264d1 Pass all configured pool names to attribute provider enumerator 2012-08-30 16:43:43 +02:00
Martin Willi feb8550401 Pass a list instead of a single virtual IP to attribute enumerators 2012-08-30 16:43:42 +02:00
Martin Willi 96c2b3cf89 Support multiple addresses/pools in left/rightsourceip 2012-08-30 16:43:42 +02:00
Martin Willi 497ce2cf51 Support multiple address pools configured on a peer_cfg 2012-08-30 16:43:42 +02:00
Martin Willi 101d26babe Support multiple virtual IPs on peer_cfg and ike_sa classes 2012-08-30 16:43:42 +02:00
Tobias Brunner db275b1477 Ported tun_device de-/initialization to FreeBSD 2012-08-29 15:34:17 +02:00
Tobias Brunner 39e9af9666 struct iphdr is Linux specific use struct ip instead 2012-08-29 15:32:26 +02:00
Tobias Brunner 55e05aa226 Include stdint.h for UINT32_MAX on FreeBSD 2012-08-29 15:32:26 +02:00
Martin Willi 584c063e36 Ported tun_device initialization to OS X utun 2012-08-28 11:16:31 +02:00
Tobias Brunner 48f51d9454 android: Field added to store the type of a VPN profile 2012-08-27 15:36:36 +02:00
Tobias Brunner 1f6f501978 android: Enum added for VPN types 2012-08-27 15:33:58 +02:00
Tobias Brunner 8a9956762c android: Simplified handling of error dialog that is displayed if VpnService API is not supported 2012-08-27 10:48:13 +02:00
Tobias Brunner aa55040192 android: LoginDialog refactored so it also works when the device is rotated 2012-08-27 10:48:13 +02:00
Tobias Brunner e09f4120d4 android: Added a field to store selected user certificate 2012-08-27 10:48:13 +02:00
Andreas Steffen 8528f841de Ewa did the new Polish translation 2012-08-24 16:59:47 +02:00
Tobias Brunner a21fac9a85 Log configured IKE_SA proposals as initiator 2012-08-24 13:43:14 +02:00
Tobias Brunner d2b4dff5dd Log configured CHILD_SA proposals as initiator 2012-08-24 13:43:14 +02:00
Tobias Brunner 1184493407 Fall back to local address as IKEv1 identity if nothing else is configured 2012-08-24 12:55:01 +02:00
Tobias Brunner 454fb91367 Removed deprecated options from ipsec.conf template 2012-08-24 11:52:01 +02:00
Tobias Brunner 20915d6fa7 Apply send delay before adding non-ESP marker
Otherwise the packet header could not be parsed correctly when NAT-T is
used.
2012-08-24 11:23:36 +02:00
Martin Willi d8eec395b2 Add a getter for the mem_pool_t base address 2012-08-24 11:19:07 +02:00
Andreas Steffen 014d007000 use pen_type_t for PA Message Subtype 2012-08-23 10:49:00 +02:00