Tobias Brunner
|
d4aad55434
|
IPComp for IKEv2
|
2008-05-08 16:19:11 +00:00 |
|
Martin Willi
|
0f074a4344
|
implemented append mode for xcbc, testcase
|
2008-05-08 14:51:37 +00:00 |
|
Martin Willi
|
affd7a90ba
|
moved RAW public key support to a separate plugin (pubkey)
|
2008-05-08 13:16:42 +00:00 |
|
Martin Willi
|
5b7ec6d4e0
|
renamed med_db plugin to medsrv, as we will introduce an additional medcli client plugin
|
2008-05-08 12:11:30 +00:00 |
|
Martin Willi
|
25b12c696b
|
replaced --with-gid/uid by --with-group/user
using named users, groups
fixed capability dropping in pluto
|
2008-05-08 10:58:04 +00:00 |
|
Martin Willi
|
5302703407
|
prototype of sql pool administration utility
|
2008-05-07 09:37:08 +00:00 |
|
Martin Willi
|
bc1f02a860
|
providing medation configuration through med_db plugin
|
2008-05-06 13:44:14 +00:00 |
|
Martin Willi
|
27d04e055d
|
implemented XCBC algorithms (signer, prf) for IKE on top of a crypter
supporting ike=...-aesxcbc-... in ipsec.conf
added AUTH_AES_XCBC_96 and PRF_AES128_CBC to default IKE proposal
AES XCBC testcase
|
2008-04-30 14:26:24 +00:00 |
|
Martin Willi
|
3444390241
|
supporting multiple comma seperated subnets in left/rightsubnet definition
e.g. leftsubnet=10.2.0.0/16,10.4.0.0/16
|
2008-04-25 12:41:37 +00:00 |
|
Martin Willi
|
5e6bbf4f77
|
added _GNU_SOURCE and limits.h to build against glibc-2.8
|
2008-04-24 13:49:20 +00:00 |
|
Martin Willi
|
c624081a7f
|
added missing base64 chunk test
|
2008-04-24 13:28:18 +00:00 |
|
Martin Willi
|
9213ad27c2
|
replaced freeswan ttodata by own chunk_{to|from}_{hex|base64} functions
|
2008-04-24 13:26:22 +00:00 |
|
Martin Willi
|
8570c648f1
|
fixed AES-128 test
|
2008-04-22 09:00:27 +00:00 |
|
Martin Willi
|
65456bfe33
|
added AES-128 unit test
|
2008-04-22 08:33:55 +00:00 |
|
Andreas Steffen
|
1d5d6f9667
|
Hash and URL cosmetics
|
2008-04-18 21:27:08 +00:00 |
|
Martin Willi
|
fa3fe3c1cf
|
sql pool prototype
|
2008-04-18 11:51:58 +00:00 |
|
Tobias Brunner
|
6439267a8c
|
support for hash and URL encoded certificate payloads in charon
|
2008-04-18 11:24:45 +00:00 |
|
Andreas Steffen
|
8eeb796a51
|
changed logging of crl writing to old style
|
2008-04-17 20:23:31 +00:00 |
|
Martin Willi
|
c4ec8c9d18
|
fixed compiler warning
|
2008-04-17 15:08:48 +00:00 |
|
Martin Willi
|
b360e3933d
|
respecting ipsec.conf cachecrls= option
|
2008-04-17 15:01:57 +00:00 |
|
Martin Willi
|
d33fa48bc7
|
caching of CRLs to /etc/ipsec.d/crls
|
2008-04-17 14:08:38 +00:00 |
|
Martin Willi
|
2270b396b3
|
added missing credential_set method to stroke_ca
|
2008-04-17 13:00:05 +00:00 |
|
Martin Willi
|
233b853dfa
|
extended credential_set_t interface by a cache_cert() method
allows persistent or in-memory caching of fetched certificates
|
2008-04-17 11:22:37 +00:00 |
|
Martin Willi
|
e5617e40d1
|
adding rightsourceip=%poolname properly to peer config
|
2008-04-17 08:55:32 +00:00 |
|
Martin Willi
|
140ed97c0c
|
disable DPD if dpddelay is set but dpdaction=none
|
2008-04-16 05:50:56 +00:00 |
|
Martin Willi
|
02e4180e48
|
updated sql plugin to respect config changes
|
2008-04-15 15:13:53 +00:00 |
|
Martin Willi
|
1822ca740b
|
disabled SQL logging by default, as tests scenarios do not have a logging table
|
2008-04-15 15:13:08 +00:00 |
|
Martin Willi
|
0dab0f1d5d
|
fixed build of smp plugin
|
2008-04-15 11:51:46 +00:00 |
|
Martin Willi
|
6a365f0740
|
added API for random number generators, served through credential factory
ported randomizer_t to a rng_t on top of /dev/(u)random (plugin random)
|
2008-04-15 05:56:35 +00:00 |
|
Martin Willi
|
0644ebd3de
|
implemented IKE_SA uniqueness using ipsec.conf uniqueids paramater
additionally supports a "keep" value to keep the old IKE_SA
|
2008-04-14 13:23:24 +00:00 |
|
Martin Willi
|
a593db5d35
|
ike_sa_manager enumerable, not iterable
|
2008-04-14 11:37:46 +00:00 |
|
Martin Willi
|
348af092ac
|
added close_action as a seperate config option to dpd_action
|
2008-04-14 08:17:18 +00:00 |
|
Martin Willi
|
45819d7d49
|
fixed rightsourceip=%config scenarios
|
2008-04-14 07:18:16 +00:00 |
|
Martin Willi
|
96926b006d
|
using dpd actions to enforce connection state
dpd actions a per child-, not peer ike-sa
|
2008-04-11 08:14:48 +00:00 |
|
Martin Willi
|
ad81e51afc
|
implemented a simple attribute provider for stroke
|
2008-04-09 12:56:20 +00:00 |
|
Martin Willi
|
cdcfe777f4
|
implementation of an CFG attribute framework, currently supporting virtual IPs
updated ipsec.conf sourceip parameter to support
CIDR notatation to serve from a pool
%poolname to query a separate (database?) pool
|
2008-04-09 12:54:47 +00:00 |
|
Martin Willi
|
1749642b15
|
use cert->equals() to filter out equal certificates in seperate instances
|
2008-04-07 08:48:08 +00:00 |
|
Andreas Steffen
|
480297b883
|
cosmetics
|
2008-04-07 07:02:47 +00:00 |
|
Andreas Steffen
|
f8ab4a8f76
|
log shared secret with debug level 4
|
2008-04-06 17:51:29 +00:00 |
|
Andreas Steffen
|
1b247314fd
|
default is hostaccess=no
|
2008-04-06 12:15:05 +00:00 |
|
Martin Willi
|
6e4e27f8de
|
updated test data to use correct encoding data
|
2008-04-03 06:45:17 +00:00 |
|
Martin Willi
|
513f20156a
|
fixed med_db test
|
2008-04-02 12:27:39 +00:00 |
|
Martin Willi
|
489e3da0ea
|
updated mediation database to public key authentication
added mysql table definition, test data
testcase
|
2008-04-02 12:25:14 +00:00 |
|
Martin Willi
|
e29ebcb1af
|
fixed compile warnings
|
2008-04-02 09:54:20 +00:00 |
|
Andreas Steffen
|
9372f44c67
|
workaround for parsing IPv6 PSKs requires extract_last_token()
|
2008-04-01 20:40:29 +00:00 |
|
Martin Willi
|
9d1c384b4b
|
loading of subjectPublicKeyInfo wrapped keys using KEY_ANY (openssl format)
testcase
|
2008-04-01 14:51:31 +00:00 |
|
Andreas Steffen
|
392f4e17c2
|
minimal stroke_list_ocsp() implementation
|
2008-04-01 12:11:09 +00:00 |
|
Andreas Steffen
|
946d1ecd59
|
stroke_list groups certificates by issuer
|
2008-04-01 10:26:27 +00:00 |
|
Andreas Steffen
|
aaa7643b73
|
put DN in double quotes
|
2008-03-31 21:08:56 +00:00 |
|
Andreas Steffen
|
eafc0654ca
|
ipsec list suppresses duplicates
|
2008-03-31 20:21:24 +00:00 |
|