Andreas Steffen
d93e2e5409
created an eap-tnc method hull
2010-08-30 15:36:34 +02:00
Andreas Steffen
577893612f
for the time being assume a single request/response exchange for a given EAP method
2010-08-30 15:36:34 +02:00
Tobias Brunner
2402dee177
Port floating patch partially reversed.
...
If MOBIKE is enabled, we do have to switch to port 4500 with the
IKE_AUTH request, that is, before we know whether the other peer
actually supports MOBIKE or not.
2010-08-30 14:54:31 +02:00
Tobias Brunner
277f02ce9e
Slightly refactored port floating.
...
In case of MOBIKE, only float to port 4500 if the other peer actually supports MOBIKE.
2010-08-30 13:42:58 +02:00
Tobias Brunner
fde2d34d0f
Fixed ME after introduction of AEAD wrapper.
2010-08-30 10:48:09 +02:00
Andreas Steffen
897c7a72cf
Win7 might send up to 7k of certificate requests
2010-08-27 16:30:05 +02:00
Martin Willi
dfde6570c7
Update delete_payload length when adding SPIs
2010-08-25 17:04:25 +02:00
Martin Willi
5299719569
Migrated delete_payload to INIT/METHOD macros, replaced iterator
2010-08-25 17:03:00 +02:00
Martin Willi
e5c6ebb697
Use different return values in payload decryption to distinguish between integrity and syntax errors
2010-08-25 15:29:53 +02:00
Thomas Egerer
e54e86cb49
Check if colliding rekey actually created an IKE_INIT
...
In some cases (especially if a child is half-open) the colliding
rekey-job might not have created the ike_init member. If so, the
nonce check fails with SIGSEGV.
2010-08-25 10:16:42 +02:00
Martin Willi
8427c78611
Added a ike_name logger option to prefix the IKE_SA name on each line
2010-08-25 09:55:37 +02:00
Andreas Steffen
d9b85e28b9
removed tls_record_t definition
2010-08-24 19:19:13 +02:00
Martin Willi
69e8bb2e8d
Pass NULL peer identity to omit TLS peer authentication, added eap-ttls.request_peer_auth option
2010-08-24 11:34:43 +02:00
Andreas Steffen
79a5e391f8
support fragmentation in AVPs
2010-08-24 09:02:51 +02:00
Martin Willi
f55f9c4e1e
Client sends empty EAP-TTLS packet on fatal alerts to properly shut down TLS
2010-08-24 08:45:49 +02:00
Martin Willi
1475800080
Moved TLS record parsing/generation to tls.c
2010-08-24 08:45:49 +02:00
Martin Willi
5ff8c62707
EAP-TLS clients send an empty packet on failure to properly shut down a TLS session
2010-08-23 15:13:41 +02:00
Martin Willi
c49475dae1
Accept encryption payloads with no wrapped payloads
2010-08-23 11:30:36 +02:00
Martin Willi
835ec23aff
Use enum mappings to resolve debug group
2010-08-23 09:47:04 +02:00
Martin Willi
96b2fbcc2c
Introducing simple purposes for the TLS stack, switches various options
2010-08-20 15:09:08 +02:00
Martin Willi
6291fbedcb
Fixed compiler warning
2010-08-20 15:09:08 +02:00
Martin Willi
2e64455ee1
Fixed crypter keymat derivation bug
2010-08-19 19:28:08 +02:00
Martin Willi
08a5a708fc
Include CCM/GCM algorithms in IKEv2 proposals, if supported
2010-08-19 19:05:05 +02:00
Martin Willi
84eb3aa456
Implemented IKEv2 keymat derivation for AEAD algorithms
2010-08-19 19:02:34 +02:00
Martin Willi
9d49f79f55
List registered AEAD algorithms in listalgs
2010-08-19 19:02:34 +02:00
Martin Willi
b519071299
Use AEAD wrapper for encryption payload encryption/decryption
2010-08-19 19:02:33 +02:00
Martin Willi
7fc4b0814f
Make function to test if an encryption algorithm is an AEAD alg public
2010-08-19 19:02:16 +02:00
Martin Willi
92a4540aca
Migrated generator_t to INIT/METHOD macros
2010-08-19 12:35:53 +02:00
Martin Willi
0cca7427c7
Migrated encryption_payload to INIT/METHOD macros
2010-08-19 12:35:53 +02:00
Martin Willi
7c9d8e1476
Migrated message_t to INIT/METHOD macros
2010-08-19 12:35:53 +02:00
Martin Willi
5555b900b2
Migrated keymat to INIT/METHOD macros
2010-08-19 12:35:53 +02:00
Andreas Steffen
1894622df2
added EAP-TTLS debug output
2010-08-18 23:21:00 +02:00
Andreas Steffen
5ae4292cb9
added TLS record debug output
2010-08-18 22:52:42 +02:00
Martin Willi
ba31fe1fd6
Use a seperate section for each nested struct member in INIT macro
2010-08-18 12:15:03 +02:00
Andreas Steffen
53115857ae
some simplifications using the INIT macro
2010-08-17 20:09:32 +02:00
Andreas Steffen
9ba53310ee
implemented server-initiated phase2 of EAP-TTLS authentication
2010-08-16 18:30:41 +02:00
Andreas Steffen
79f2102cb4
implemented server side support for EAP-TTLS
2010-08-16 16:44:13 +02:00
Andreas Steffen
06a207480e
fixed typo in eap-mschapv2 plugin
2010-08-16 16:44:13 +02:00
Andreas Steffen
b51ac45c48
optional certificate-based peer authentication on TLS server side
2010-08-15 13:02:57 +02:00
Andreas Steffen
16d8b4b6c1
removed some raw EAP debug output
2010-08-14 12:01:45 +02:00
Andreas Steffen
004b226bb8
use EAP plugin for tunneled client authentication
2010-08-14 01:14:28 +02:00
Andreas Steffen
6659c61335
send tunneled EAP Identity response using eap-identity plugin
2010-08-13 22:45:22 +02:00
Andreas Steffen
486893ee52
allow to send an EAP Identity response without matching request
2010-08-13 22:41:00 +02:00
Andreas Steffen
683a912eab
implement AVP EAP message building and processing
2010-08-13 21:21:49 +02:00
Martin Willi
c03b0d7e6b
Added support for Camellia cipher to xcbc
2010-08-13 17:11:54 +02:00
Martin Willi
c7776e0aa8
Support Camellia XCBC algorithms in proposal
2010-08-13 17:11:54 +02:00
Martin Willi
3b77c27a5b
Added Camellia, AES-CTR to default IKE proposal, if supported
2010-08-13 17:11:53 +02:00
Martin Willi
3102d8669d
Use IV length of a crypter instead of block size for IV calculations
2010-08-13 17:11:53 +02:00
Andreas Steffen
71efe40077
Migrated eap_identity plugin to INIT/METHOD macros
2010-08-13 16:57:01 +02:00
Andreas Steffen
a568897011
Migrated eap_md5 plugin to INIT/METHOD macros
2010-08-13 16:33:26 +02:00