Commit Graph
19030 Commits
Author SHA1 Message Date
Andreas Steffen 922464d00a mpz_clear_randomized() overwrites private key material before releasing it 2007-09-10 19:34:46 +00:00
Andreas Steffen 7bac086733 overwrite storage used for shared secrets with pseudo-random bytes before releasing it 2007-09-10 19:12:01 +00:00
Andreas Steffen db78593370 ipsec barf is not supported by the strongSwan 4.1 branch 2007-09-10 13:32:15 +00:00
Andreas Steffen bb3d6c3dbe the new function chunk_free_randomized() overwrites the contents of a chunk with pseudo-random bytes before freeing it 2007-09-10 12:16:24 +00:00
Andreas Steffen e7d9fa7f98 added new Windows Vista VID, courtesy of Jacco de Leeuw 2007-09-10 12:11:46 +00:00
Andreas Steffen 054767bfff version bump to 4.1.7 2007-09-03 19:04:38 +00:00
Martin Willi 5474dc6500 implemented routeability checks for mobike (experimental) 2007-09-03 12:37:25 +00:00
Andreas Steffen f5da63e937 correct debug 2007-09-02 15:59:59 +00:00
Andreas Steffen 8c4339bdd2 added mobike option to man page 2007-09-02 11:44:32 +00:00
Andreas Steffen 3eac4dfdda added new features 2007-09-02 11:24:53 +00:00
Andreas Steffen 0e3073608d re-introduced the XAUTH_VID compile option 2007-09-02 11:13:24 +00:00
Martin Willi 354242c55a added RADIUS, RADIUS-EAP and EAP-MD5 (CHAP) RFCs 2007-08-30 12:52:44 +00:00
Martin Willi 857ceac9d9 proper initialization of rsa private key 2007-08-30 12:47:38 +00:00
Andreas Steffen cfee19c26c added bitnames for POLICY_BEET and POLICY_MOBIKE flags 2007-08-29 13:17:30 +00:00
Andreas Steffen cdc70899a8 change ipsec route table in UML scenarios 2007-08-29 13:03:34 +00:00
Andreas Steffen 0886e64022 updated index.txt.old 2007-08-29 12:50:26 +00:00
Martin Willi 9164e49ac0 added mobike=yes|no connection option
yes: include mobike support notifies as initiator
  no: only enable mobike as responder when initiator supports it
  default: yes
2007-08-29 12:11:25 +00:00
Andreas Steffen c5dfb88ab8 _updown removed from distribution 2007-08-29 11:59:52 +00:00
Andreas Steffen bdc0b55b72 included the FIPS integrity test in LICENSE, CREDITS and NEWs 2007-08-29 11:04:55 +00:00
Andreas Steffen 0bc5a23023 renamed integrity check to integrity test 2007-08-29 10:36:08 +00:00
Andreas Steffen d3250f74af cosmetics 2007-08-29 10:31:37 +00:00
Andreas Steffen 32be2ec599 fixed 64 bit issue (size_t is 32 bit) 2007-08-29 10:30:17 +00:00
Andreas Steffen ab13376877 fips_verify_hmac_signature() now returns a boolean status 2007-08-29 09:43:02 +00:00
Andreas Steffen df29e8f745 SHA-1 HMAC signature is now computed over concatenation of TEXT and RODATA segments 2007-08-29 09:13:08 +00:00
Andreas Steffen fa50e4df48 compute SHA-1 HMAC over libstrongswan TEXT segment for the time being 2007-08-29 08:54:53 +00:00
Martin Willi dc5a849bf0 signers implemented with HMAC now support NULL output parameters
to feed signer with more than one block of data.
2007-08-29 07:52:49 +00:00
Andreas Steffen ef5f65626f change self_test to self-test 2007-08-29 07:03:47 +00:00
Andreas Steffen d8b45dcdd2 build fips_signer and fips_signature with USE_INTEGRITY_TEST condition only 2007-08-29 07:02:13 +00:00
Andreas Steffen 2fb15ac606 changed interface of fips_verify_hmac_signature 2007-08-29 05:43:45 +00:00
Andreas Steffen 90bcf8b286 free hmac_signature string after use 2007-08-29 05:43:05 +00:00
Andreas Steffen d64b48a80b beautification 2007-08-29 05:42:22 +00:00
Andreas Steffen 55434a1ba5 started implementation of libstrongswan code integrity check 2007-08-29 00:37:10 +00:00
Andreas Steffen 0e54968584 defined ietfAttr_create_from_string() 2007-08-29 00:35:51 +00:00
Andreas Steffen bf422b1664 fixed typo 2007-08-28 09:59:53 +00:00
Martin Willi 69e56d9dec simple console support through pts devices 2007-08-28 07:53:46 +00:00
Andreas Steffen 12fe0e60df set ignore properties 2007-08-28 07:02:51 +00:00
Andreas Steffen 52d39feb81 set ignore properties 2007-08-28 07:02:23 +00:00
Andreas Steffen 8234dd1216 testing/do-tests is made from do-tests.in by inserting actual routing table 2007-08-28 06:40:39 +00:00
Andreas Steffen 35800a11ee testing/do-tests is made from do-tests.in by inserting actual routing table 2007-08-28 06:38:04 +00:00
Andreas Steffen 9ee1111d8b added --enable-integrity-test and --disable-self-test options 2007-08-28 06:36:31 +00:00
Martin Willi 0739cca9d1 default routing table/prio: 220/220 (as 19530 was invalid)
added configure option --with-routing-table-prio=
2007-08-27 14:53:42 +00:00
Martin Willi ad9613226b using default routing table 19530 for ipsec routes 2007-08-27 11:30:21 +00:00
Martin Willi 4e411c8361 added --with-routing-table= configure option 2007-08-27 11:15:35 +00:00
Martin Willi 98f97433af rerouting CHILD_SA if its IKE_SA gets deleted 2007-08-27 09:10:12 +00:00
Andreas Steffen 9a63ddd84d initiated support of caIssuers accessLocation 2007-08-17 08:01:10 +00:00
Andreas Steffen 2a48f47406 required CA is that.ca not this.ca 2007-08-17 07:22:04 +00:00
Andreas Steffen 2133593696 matching_request instead of matching_trust must go into the metric 2007-08-17 07:21:26 +00:00
Andreas Steffen 0f9f19f54e fixed maximum path length info in match_requested_ca() 2007-08-17 07:20:27 +00:00
Andreas Steffen 6a85215809 sort attributes alphabetically 2007-08-15 22:58:15 +00:00
Andreas Steffen cd15679122 added caIssuers OID 2007-08-15 09:46:40 +00:00