Tobias Brunner
fb545dd34d
vici: Also return close action
2018-02-16 09:55:22 +01:00
Andreas Steffen
4eaf08c35b
vici: list-conn reports DPD settings and swanctl displays them
2018-02-15 16:28:06 +01:00
Tobias Brunner
2db6d5b8b3
Fixed some typos, courtesy of codespell
2018-02-13 12:19:54 +01:00
Tobias Brunner
a7f613ca2e
vici: Document NTLM secrets in README.md
...
Fixes #2481 .
2017-12-22 10:09:26 +01:00
Tobias Brunner
859d645c44
vici: Accept XAUTH as shared key type too
...
Fixes #2481 .
2017-12-22 10:09:22 +01:00
Tobias Brunner
fdf33b0f1c
vici: Add 'get|reset-counters' commands
2017-11-08 16:28:28 +01:00
Tobias Brunner
2d244f178f
vici: Make setting mark on inbound SA configurable
2017-11-02 09:59:38 +01:00
Tobias Brunner
ca280574ba
Fixed some typos, courtesy of codespell
2017-08-07 17:22:01 +02:00
Tobias Brunner
525cc46cab
Change interface for enumerator_create_filter() callback
...
This avoids the unportable 5 pointer hack, but requires enumerating in
the callback.
2017-05-26 13:56:44 +02:00
Tobias Brunner
95a63bf281
Migrate all enumerators to venumerate() interface change
2017-05-26 13:56:44 +02:00
Tobias Brunner
0afe0eca67
vici: Make 96-bit truncation for SHA-256 configurable
2017-05-26 11:22:28 +02:00
Tobias Brunner
7c4f88d4be
vici: Make hardware offload configurable
2017-05-23 16:58:00 +02:00
Tobias Brunner
749ac175fa
child-cfg: Use flags for boolean options
...
Makes it potentially easier to add new flags.
2017-05-23 16:51:15 +02:00
Tobias Brunner
46a3f92a76
Add an option to announce support for IKE fragmentation but not sending fragments
2017-05-23 16:41:57 +02:00
Tobias Brunner
605a98c7ce
vici: Return key ID from load-key command
...
We already do this for load-token and this should simplify client
implementations.
2017-05-23 16:41:02 +02:00
odi79
0d66b01a81
vici: Fix type error exception in Python bindings
...
Line 66 yields "TypeError: can't concat bytes to str" using Python 3.4.
"requestdata" was introduced in 22f08609f1 but is not actually used.
Since the original "request" is not used anywhere else this can be changed
to be similar to the other UTF-8 encoding changes in that commit.
Fixes: 22f08609f1 ("vici: Explicitly set the Python encoding type").
Closes strongswan/strongswan#66 .
2017-04-19 10:00:21 +02:00
Tobias Brunner
550bd654a7
vici: Don't fall back to uninstalling traps if a matching shunt was found
...
This is different if `ike` and `child` are provided and uninstall()
fails as we call that without knowing whether a matching shunt exists.
But if `ike` is not provided we explicitly search for a matching shunt
and if found don't need to look for a trap policy.
2017-03-23 18:29:18 +01:00
Tobias Brunner
1003cf2330
Fixed some typos, courtesy of codespell
2017-03-23 18:29:18 +01:00
Martin Willi
46d4d2a71e
vici: Document how we pronounce the vici protocol and plugin
2017-03-20 10:39:10 +01:00
Tobias Brunner
8bd8dcd522
vici: Only log messages if there actually is a listener
2017-02-16 19:24:09 +01:00
Tobias Brunner
fa5f6ba26c
vici: Let has_event_listeners() actually check if clients are registered
...
Fixes: 8d96f90a79 ("vici: Add function to test if an event should be
generated")
2017-02-16 19:24:09 +01:00
Tobias Brunner
f927ba975b
vici: Add support for mediation extension
2017-02-16 19:24:09 +01:00
Tobias Brunner
ec5f127a45
vici: Include uniqueness policy in list-conns
2017-02-16 19:24:09 +01:00
Tobias Brunner
808472c9f9
vici: Add command to initiate SA rekeying
2017-02-16 19:24:08 +01:00
Tobias Brunner
04c0219e55
vici: Use unique names for CHILD_SAs in the list-sas command
...
The original name is returned in the new "name" attribute.
This fixes an issue with bindings that map VICI messages to
dictionaries. For instance, in roadwarrior scenarios where every
CHILD_SA has the same name only the information of the last CHILD_SA
would end up in the dictionary for that name.
2017-02-16 19:24:08 +01:00
Tobias Brunner
bd6ef6be7e
vici: Add support to load CA certificates from tokens and paths in authority sections
2017-02-16 19:24:08 +01:00
Tobias Brunner
2f8354ca6c
vici: Add support to load certificates from file paths
...
Probably not that useful via swanctl.conf but could be when used via VICI.
2017-02-16 19:24:08 +01:00
Tobias Brunner
00bf6a2a49
vici: Add support to load certificates from tokens
2017-02-16 19:24:08 +01:00
Tobias Brunner
2ceeb96db5
vici: Add command to load a private key from a token
...
PINs are stored in a "hidden" credential set, so that its shared
secrets are not exposed via VICI. Since they are not explicitly loaded as
shared secrets via VICI a client might consider them as removed secrets and
remove them.
2017-02-16 19:24:07 +01:00
Tobias Brunner
b657740e16
vici: List namespace/peer-cfg name with policies and allow filtering
...
The two names are also transmitted in separate keys.
2017-02-16 19:24:07 +01:00
Tobias Brunner
7627f5f9c7
vici: Explicitly use peer name when uninstalling trap and shunt policies
...
Also adds an `ike` parameter to the `uninstall` command.
2017-02-16 19:24:07 +01:00
Tobias Brunner
7a0fdbab42
shunt-manager: Add an optional namespace for each shunt
...
This will allow us to reuse the names of child configs e.g. when they
are defined in different connections.
2017-02-16 19:24:07 +01:00
Tobias Brunner
ed105f45af
vici: Add support for NT Hash secrets
...
Fixes #1002 .
2017-02-16 19:23:51 +01:00
Tobias Brunner
3bedf10b25
vici: Add support for IPv6 Transport Proxy Mode
2017-02-16 19:23:50 +01:00
Tobias Brunner
e00bc9f6b2
vici: Add support for certificate policies
2017-02-16 19:23:50 +01:00
Tobias Brunner
44fcc83310
vici: Add missing dscp setting for IKE_SAs
...
Fixes #2170 .
2017-02-16 19:23:31 +01:00
Tobias Brunner
cf57d9a98f
vici: Add possibility to remove shared keys by a unique identifier
...
This identifier can be set when adding/replacing a secret. The unique
identifiers of all secrets may be enumerated.
2017-02-16 19:21:13 +01:00
Tobias Brunner
2a56acf501
vici: Add commands to enumerate and remove private keys
...
They are identified by their SHA-1 key identifier.
2017-02-16 19:21:12 +01:00
Tobias Brunner
d20bf50e04
vici: Update get_pools() in Python and Ruby bindings
2017-02-16 19:21:12 +01:00
Tobias Brunner
71fa1224ec
vici: Add option to query a specific pool
2017-02-16 19:21:12 +01:00
Martin Willi
0b4e539cb3
vici: Include the Netfilter marks in listed CHILD_SAs
2017-02-13 15:11:20 +01:00
Martin Willi
22f08609f1
vici: Explicitly set the Python encoding type
...
When using vici over RPyC and its (awesome) splitbrain, encoding and decoding
strings fails in vici, most likely because of the Monkey-Patch magic splitbrain
uses.
When specifying the implicit UTF-8 as encoding scheme explicitly, Python uses
the correct method to encode/decode the string, making vici useable in
splitbrain contexts.
2017-02-13 15:04:44 +01:00
Tobias Brunner
83bf6db303
vici: Reload loggers after reloading strongswan.conf via reload-setting command
2017-01-25 14:58:12 +01:00
Weilu Jia
351179d4dc
vici: Check for closed connection in Python bindings
...
The Python VICI library does not check if the socket is closed.
If the daemon closes the connection, _recvall() spins forever.
Closes strongswan/strongswan#56 .
2016-12-14 11:35:31 +01:00
Andreas Steffen
85b5a6ace2
Save both base and delta CRLs to disk
2016-10-11 17:18:22 +02:00
Andreas Steffen
2a2669ee3e
vici: strongswan.conf cache_crls = yes saves fetched CRLs to disk
2016-10-11 17:18:22 +02:00
Tobias Brunner
d5c6a0bac4
vici: Enable IKE fragmentation by default
2016-10-04 10:08:21 +02:00
Tobias Brunner
50721a61d8
vici: Make installation of outbound FWD policies configurable
2016-09-28 17:56:43 +02:00
Tobias Brunner
d344474b3d
vici: Fix indention of flush_certs() method in Python bindings
2016-09-20 15:33:18 +02:00
Andreas Steffen
2c7cfe7630
vici: flush-certs command flushes certificate cache
...
When fresh CRLs are released with a high update frequency (e.g.
every 24 hours) or OCSP is used then the certificate cache gets
quickly filled with stale CRLs or OCSP responses. The new VICI
flush-certs command allows to flush e.g. cached CRLs or OCSP
responses only. Without the type argument all kind of certificates
(e.g. also received end entity and intermediate CA certificates)
are purged.
2016-09-13 17:02:59 +02:00