Clavister OpenSource
|
cc50df9e6c
|
IKEv1 XAuth: XAuthInitPreShared working for XAuth initiator (Main Mode responder). Creates USER/PASS request, retrieves the result and sends status.
|
2012-03-20 17:30:52 +01:00 |
|
Clavister OpenSource
|
2d97ec0d35
|
IKEv1 XAuth: Added ability to initiate the XAuth transactions under a flag, default not to initiate XAuth.
|
2012-03-20 17:30:52 +01:00 |
|
Clavister OpenSource
|
8b30286fcf
|
IKEv1 XAuth: Add XAUTH authentication types to the enum. Added the ability to switch between hardcoded PSK and XAUTH_INIT_PSK authentications using a flag, default to PSK.
|
2012-03-20 17:30:52 +01:00 |
|
Clavister OpenSource
|
ece4ed3fcd
|
IKEv1 ConfigMode: Fix configuration_attribute encoding rules for IKEv1 to use the attribute type instead of the internal only payload type.
|
2012-03-20 17:30:52 +01:00 |
|
Clavister OpenSource
|
0b6811b4a7
|
IKEv1 ConfigMode: Fixed cp_payload to use CONFIGURATION_ATTRIBUTE_V1 in all appropriate places, so the parsing is done correctly.
|
2012-03-20 17:30:51 +01:00 |
|
Clavister OpenSource
|
01685247b0
|
IKEv1 XAuth: Added ike_vendor task to the ID_PROT exchange type processing. We need to process vendor payloads to check to see if our peer understands XAuth before using any of these payload types.
|
2012-03-20 17:30:51 +01:00 |
|
Clavister OpenSource
|
e3bb68841a
|
IKEv1 XAuth: Added temporary "initiate_xauth" public method to ike_sa_t. This allows us to initiate an XAuth password authentication exchange after responding to the final message of Main Mode. This change should be reverted once we have a better method to initiate this exchange.
|
2012-03-20 17:30:51 +01:00 |
|
Clavister OpenSource
|
adf7b76f4c
|
IKEv1 XAuth: Temporarilty add an "initiate_later" flag to the task manager. When set to TRUE it will cause "initiate" to be called when the current process_response call is finished. This change should be reverted once we have a better method in place.
|
2012-03-20 17:30:51 +01:00 |
|
Martin Willi
|
9cc38c8efb
|
Use quick mode task initiator flag instead of passing it as parameter
|
2012-03-20 17:30:51 +01:00 |
|
Martin Willi
|
4e0bc9af22
|
Add quick mode ID payloads only if establishing a non-host2host tunnel
|
2012-03-20 17:30:51 +01:00 |
|
Martin Willi
|
c4b8539f93
|
Refactored traffic selector handling in quick mode
|
2012-03-20 17:30:51 +01:00 |
|
Martin Willi
|
818330aafe
|
Refactored NONCE payload handling in quick mode
|
2012-03-20 17:30:51 +01:00 |
|
Tobias Brunner
|
78f7728c30
|
No need to build a HASH payload in XAUTH task.
It gets added automatically when the message is generated.
|
2012-03-20 17:30:51 +01:00 |
|
Martin Willi
|
c4c5950458
|
Create host-to-host traffic selectors if quick mode identities missing
|
2012-03-20 17:30:51 +01:00 |
|
Tobias Brunner
|
97265a8927
|
Removed redundant '=>' when logging binary data in parser and generator.
|
2012-03-20 17:30:51 +01:00 |
|
Tobias Brunner
|
f4e21faa98
|
Fixed encryption of IKEv2 messages.
|
2012-03-20 17:30:50 +01:00 |
|
Martin Willi
|
d020d4d695
|
Print message payload names after prepending IKEv1 HASH payload
|
2012-03-20 17:30:50 +01:00 |
|
Martin Willi
|
da063ec95e
|
Fixed task_manager_v1 compiler warnings
|
2012-03-20 17:30:50 +01:00 |
|
Martin Willi
|
3e246c4883
|
Generate a new mid only after we start a new task (and exchange)
|
2012-03-20 17:30:50 +01:00 |
|
Martin Willi
|
a7910b1c6e
|
Derive IKEv1 CHILD_SA keymat twice, once for each IPsec SA
|
2012-03-20 17:30:50 +01:00 |
|
Martin Willi
|
85f5c478bf
|
Fix seed construction for IKEv1 key derivation
|
2012-03-20 17:30:50 +01:00 |
|
Martin Willi
|
9cc8bd4fd2
|
Use a dedicated message hash to detect IKEv1 retransmissions
|
2012-03-20 17:30:50 +01:00 |
|
Martin Willi
|
7a7f486df6
|
Include hardcoded tunnel mode attribute in porposal, remove ESN attribute
|
2012-03-20 17:30:50 +01:00 |
|
Tobias Brunner
|
cd200cb821
|
Authenticate and verify Phase 2 IKEv1 messages with appropriate hashes.
|
2012-03-20 17:30:50 +01:00 |
|
Tobias Brunner
|
1e5dd62bb2
|
Fixed verification of DELETE_V1 payloads.
|
2012-03-20 17:30:50 +01:00 |
|
Tobias Brunner
|
f3cc8589b1
|
Fixed header length calculation of DELETE payload.
|
2012-03-20 17:30:50 +01:00 |
|
Tobias Brunner
|
d6cec44b24
|
Fixed conftests after extending CERT payload.
|
2012-03-20 17:30:50 +01:00 |
|
Martin Willi
|
b6016fcab3
|
Fixed a config reference leak in IKEv2 initiate
|
2012-03-20 17:30:49 +01:00 |
|
Martin Willi
|
384c1a32a2
|
XAUTH is initiated based on configuration, no need to call externally
|
2012-03-20 17:30:49 +01:00 |
|
Martin Willi
|
017d98bf39
|
Merged IKEv1 attribute payload/data into configuration payload/attribute
|
2012-03-20 17:30:49 +01:00 |
|
Clavister OpenSource
|
df99e976be
|
Temp fix for compile error with XAUTH code.
|
2012-03-20 17:30:49 +01:00 |
|
Clavister OpenSource
|
23f4e4b42d
|
IKEv1 XAUTH: Added ability to configure XAUTH+PSK. Added task to handle XAUTH requests. Modified task_manager_v1 to enable it to initiate new tasks immediately after finishing a response.
|
2012-03-20 17:30:49 +01:00 |
|
Clavister OpenSource
|
79e9f776dc
|
Updates ike_cert_post task with modifications needed for dealing with updated cert_payload class.
|
2012-03-20 17:30:49 +01:00 |
|
Clavister OpenSource
|
c71760570e
|
IKEv1 ConfigMode: Added the payload handlers for attribute_payload and data_attribute payload types.
|
2012-03-20 17:30:49 +01:00 |
|
Clavister OpenSource
|
54a8a94fa9
|
IKEv1 ConfigMode: Added TRANSACTION exchange type. Added attribute_payload (IKEv2 equiv cp_payload) and data_attribute (IKEv2 equiv configuration_attribute) payload types. Did not combine with IKEv2 because it wasn't trivial to do so. This might be a task worth investigating in the future, because there is a decent amount of shared code here.
|
2012-03-20 17:30:49 +01:00 |
|
Clavister OpenSource
|
9769b76cab
|
Updated the CERT payload to work for both IKEv1 and IKEv2.
|
2012-03-20 17:30:49 +01:00 |
|
Martin Willi
|
d50152a70b
|
Parse proposal substructure with multiple IKEv1 transforms to multiple proposals
|
2012-03-20 17:30:49 +01:00 |
|
Martin Willi
|
62a27ba347
|
Encode multiple IKEv1 proposals in a single transform substructure
|
2012-03-20 17:30:48 +01:00 |
|
Martin Willi
|
f9450fc9f7
|
Remove public sa_payload.add_proposal() method
|
2012-03-20 17:30:48 +01:00 |
|
Martin Willi
|
cd89f1a074
|
Only add the first algorithm of a kind to IKEv1 transforms
|
2012-03-20 17:30:48 +01:00 |
|
Martin Willi
|
5351d63c79
|
Install negotiated IKEv1 CHILD_SA negotiated in quick mode
|
2012-03-20 17:30:48 +01:00 |
|
Martin Willi
|
ff2a2ad33a
|
Implemented IKEv1 keymat CHILD_SA key derivation function
|
2012-03-20 17:30:48 +01:00 |
|
Martin Willi
|
6cd72730bf
|
Moved keymat key length lookup functions to keymat.c
|
2012-03-20 17:30:48 +01:00 |
|
Martin Willi
|
d4f6686c69
|
Extended PRF+ by a non-counting variant as used by IKEv1
|
2012-03-20 17:30:48 +01:00 |
|
Martin Willi
|
f5c0096086
|
Hardcode some SA lifetimes until we can configure them dynamically
|
2012-03-20 17:30:48 +01:00 |
|
Tobias Brunner
|
4c6dfbb26b
|
Added missing comma after ME_CONNECT declaration.
|
2012-03-20 17:30:48 +01:00 |
|
Tobias Brunner
|
8c5e78ae4f
|
Fixed creation of endpoint notifies.
|
2012-03-20 17:30:48 +01:00 |
|
Tobias Brunner
|
21da1087a5
|
Fixed diagram of IKEv1 encrypted "payload".
|
2012-03-20 17:30:47 +01:00 |
|
Martin Willi
|
a0b52db079
|
Refactored main mode NONCE/KE payload processing
|
2012-03-20 17:30:47 +01:00 |
|
Martin Willi
|
a0f851cfe0
|
Refactored main mode HASH payload processing
|
2012-03-20 17:30:47 +01:00 |
|