Andreas Steffen [Tue, 19 Aug 2008 18:51:30 +0000 (18:51 -0000)]
fixed libstrongswan integrity test
Martin Willi [Tue, 19 Aug 2008 15:19:45 +0000 (15:19 -0000)]
certificate based gateway authentication
prototype PSK user authentication with auth-dialog
Martin Willi [Mon, 18 Aug 2008 11:59:19 +0000 (11:59 -0000)]
updated nm plugin to NetworkManager API changes
Martin Willi [Mon, 18 Aug 2008 11:07:26 +0000 (11:07 -0000)]
roam jobs for routing table changes not fired for virtual IP routes
Andreas Steffen [Fri, 15 Aug 2008 19:15:52 +0000 (19:15 -0000)]
do not fire a roam job when virtual IP is deleted
Andreas Steffen [Mon, 11 Aug 2008 19:04:48 +0000 (19:04 -0000)]
temporary workaround to prevent roam jobs due to virtual IP installations
Andreas Steffen [Mon, 11 Aug 2008 18:40:22 +0000 (18:40 -0000)]
corrected typo
Tobias Brunner [Thu, 7 Aug 2008 14:56:54 +0000 (14:56 -0000)]
* ruby extension extracted from irdumm
* guests do not shutdown anymore on SIGINT in irb
Andreas Steffen [Wed, 6 Aug 2008 20:40:14 +0000 (20:40 -0000)]
added ipv6/net2net-ip6-in-ip6-ikev2 scenario
Andreas Steffen [Wed, 6 Aug 2008 20:35:42 +0000 (20:35 -0000)]
add additional scenario diagrams
Tobias Brunner [Wed, 6 Aug 2008 07:31:26 +0000 (07:31 -0000)]
added missing cleanup on failure
Andreas Steffen [Tue, 5 Aug 2008 09:05:57 +0000 (09:05 -0000)]
initiator sends contents of rightca= if present as a certificate request without searching for further CA certificates
Andreas Steffen [Sun, 3 Aug 2008 18:01:21 +0000 (18:01 -0000)]
fixed improper TAILQ fix which caused pluto to segfault
Andreas Steffen [Fri, 1 Aug 2008 12:59:08 +0000 (12:59 -0000)]
corrected caption
Andreas Steffen [Fri, 1 Aug 2008 12:04:35 +0000 (12:04 -0000)]
Redhat/Fedora requires var/lock/subsys/ipsec for runlevel changes
Andreas Steffen [Fri, 1 Aug 2008 10:35:59 +0000 (10:35 -0000)]
ipsec starter gives the charon daemon 8s to terminate gracefully before killing the process brutally
Andreas Steffen [Fri, 1 Aug 2008 10:12:33 +0000 (10:12 -0000)]
fixed the close_peerlog() bug causing ipsec pluto --help to segfault
Martin Willi [Thu, 31 Jul 2008 15:07:52 +0000 (15:07 -0000)]
configuration plugin for NetworkManager
Martin Willi [Thu, 31 Jul 2008 14:32:11 +0000 (14:32 -0000)]
added options for virtual IP, UDP encapsulation, IPComp
proper handling of libstrongswan/glib TRUE/FALSE conflict
Tobias Brunner [Thu, 31 Jul 2008 12:59:59 +0000 (12:59 -0000)]
exec on a guest now returns the return value of the executed process
Martin Willi [Thu, 31 Jul 2008 11:16:14 +0000 (11:16 -0000)]
reimplemented dbus plugin for NetworkManager 0.7, renamed to nm
Martin Willi [Thu, 31 Jul 2008 09:04:54 +0000 (09:04 -0000)]
recreating FIFO if it exists
Martin Willi [Thu, 31 Jul 2008 09:01:56 +0000 (09:01 -0000)]
fixed usage typo
Martin Willi [Wed, 30 Jul 2008 14:17:05 +0000 (14:17 -0000)]
increased stroke socket backlog to 10
Martin Willi [Wed, 30 Jul 2008 14:15:08 +0000 (14:15 -0000)]
using a entry cache for duplicate checks, avoids deadlocks
Martin Willi [Wed, 30 Jul 2008 13:19:12 +0000 (13:19 -0000)]
use condvar broadcasts to signal threads waiting for an IP, there might be more than one
Tobias Brunner [Wed, 30 Jul 2008 13:15:18 +0000 (13:15 -0000)]
the list of addresses on the interface of a guest is not cached anymore, but queried directly from the interface
Tobias Brunner [Wed, 30 Jul 2008 13:01:04 +0000 (13:01 -0000)]
* Guest#exec uses the new exec_str function
* tab completion in irdumm enabled
Tobias Brunner [Wed, 30 Jul 2008 12:58:45 +0000 (12:58 -0000)]
added an extended exec function to guests that allows to get the output of the command as string or by line.
Martin Willi [Wed, 30 Jul 2008 11:38:44 +0000 (11:38 -0000)]
using shared read locks in credential set enumerators to avoid deadlocks
Martin Willi [Wed, 30 Jul 2008 08:27:08 +0000 (08:27 -0000)]
added strongswan.conf option "charon.dos_protection" to disable cookies/aggressiveness check
Andreas Steffen [Tue, 29 Jul 2008 19:46:39 +0000 (19:46 -0000)]
added keyid2sql helper script
Andreas Steffen [Tue, 29 Jul 2008 19:44:54 +0000 (19:44 -0000)]
starter now waits for a maximum of 10s instead of 1s for charon before restarting the daemon
Andreas Steffen [Mon, 28 Jul 2008 14:01:45 +0000 (14:01 -0000)]
demoted IKE state change output to debug level 2
Andreas Steffen [Mon, 28 Jul 2008 13:53:04 +0000 (13:53 -0000)]
ignore AUTH_LIFETIME value if reauthentication has already been scheduled earlier
Martin Willi [Mon, 28 Jul 2008 13:10:34 +0000 (13:10 -0000)]
switched xterm console title
Martin Willi [Mon, 28 Jul 2008 12:37:01 +0000 (12:37 -0000)]
using gnome-terminal in irdumm
Andreas Steffen [Mon, 28 Jul 2008 09:14:07 +0000 (09:14 -0000)]
version bump to 4.2.6
Martin Willi [Mon, 28 Jul 2008 08:29:04 +0000 (08:29 -0000)]
use XFRM_MSG_UPDPOLICY for existing policies only
Andreas Steffen [Fri, 25 Jul 2008 10:30:53 +0000 (10:30 -0000)]
updated UML INSTALL information
Andreas Steffen [Fri, 25 Jul 2008 10:18:23 +0000 (10:18 -0000)]
adapted UML scenarios to improved virtual IP address pool
Andreas Steffen [Fri, 25 Jul 2008 08:02:53 +0000 (08:02 -0000)]
SQLite database template with improved address pool management
Andreas Steffen [Fri, 25 Jul 2008 08:00:04 +0000 (08:00 -0000)]
added changes for the 4.2.5 release
Martin Willi [Thu, 24 Jul 2008 12:48:36 +0000 (12:48 -0000)]
added tests.h to distribution
Martin Willi [Thu, 24 Jul 2008 08:52:12 +0000 (08:52 -0000)]
fixed UCI thread cancellation on ARM
Martin Willi [Thu, 24 Jul 2008 08:28:45 +0000 (08:28 -0000)]
added option charon.plugins.sql.lease_history to disable lease history logging
Martin Willi [Thu, 24 Jul 2008 08:21:55 +0000 (08:21 -0000)]
fixed statistic calcuation for static leases
Andreas Steffen [Wed, 23 Jul 2008 18:46:34 +0000 (18:46 -0000)]
completed IKE_SA logging at the AUDIT level
Martin Willi [Wed, 23 Jul 2008 13:56:07 +0000 (13:56 -0000)]
fixed pool statistics
Andreas Steffen [Wed, 23 Jul 2008 07:44:26 +0000 (07:44 -0000)]
IKE_SA rekeying inherits other_host from old IKE_SA
Andreas Steffen [Wed, 23 Jul 2008 06:38:24 +0000 (06:38 -0000)]
cosmetics
Andreas Steffen [Tue, 22 Jul 2008 17:21:01 +0000 (17:21 -0000)]
start default strongSwan UML topology
Andreas Steffen [Tue, 22 Jul 2008 17:10:10 +0000 (17:10 -0000)]
some more changes to IKE_SA and CHILD_SA logging
Martin Willi [Tue, 22 Jul 2008 14:56:15 +0000 (14:56 -0000)]
experimental and untested reimplementation of sql based IP pool
uses address preallocation and separate address/lease tables for linear lookup time
Andreas Steffen [Tue, 22 Jul 2008 12:13:48 +0000 (12:13 -0000)]
cosmetics
Andreas Steffen [Tue, 22 Jul 2008 12:03:58 +0000 (12:03 -0000)]
ipsec status lists IPCOMP CPIs
Andreas Steffen [Tue, 22 Jul 2008 10:53:56 +0000 (10:53 -0000)]
own CPI was not deleted due to copy-and-paste error
Andreas Steffen [Tue, 22 Jul 2008 10:16:45 +0000 (10:16 -0000)]
consistent logging of SPIs and CPIs
Andreas Steffen [Tue, 22 Jul 2008 06:24:00 +0000 (06:24 -0000)]
missing FETCH_END caused SEGFAULT in ikev2/rw-hash-and-url scenario
Andreas Steffen [Mon, 21 Jul 2008 19:08:03 +0000 (19:08 -0000)]
display protoport in dynamic/32 traffic selectors
Martin Willi [Mon, 21 Jul 2008 14:23:43 +0000 (14:23 -0000)]
fixed bus args copy on non i386 archs
Andreas Steffen [Mon, 21 Jul 2008 12:47:59 +0000 (12:47 -0000)]
consistent logging of IKE and CHILD SAs
Martin Willi [Mon, 21 Jul 2008 11:17:20 +0000 (11:17 -0000)]
pool performance testing
Martin Willi [Mon, 21 Jul 2008 11:16:07 +0000 (11:16 -0000)]
loading unit-tester plugin as the last one
Martin Willi [Mon, 21 Jul 2008 11:15:16 +0000 (11:15 -0000)]
reverted bus to non-recursive mutex due instability
Martin Willi [Mon, 21 Jul 2008 11:13:06 +0000 (11:13 -0000)]
added a driver type getter for database implementations
Martin Willi [Fri, 18 Jul 2008 15:51:40 +0000 (15:51 -0000)]
introduced an additional bus->signal parameter for signal specific data
added SIG_IKE/SIG_CHD macros for signal emitting
Martin Willi [Fri, 18 Jul 2008 12:14:43 +0000 (12:14 -0000)]
removed testing app, this is scriptable with irdumm now
Martin Willi [Fri, 18 Jul 2008 11:05:01 +0000 (11:05 -0000)]
allow but filter recursive listener invocation
Martin Willi [Fri, 18 Jul 2008 10:54:49 +0000 (10:54 -0000)]
fixed compiler warning
Martin Willi [Fri, 18 Jul 2008 10:34:44 +0000 (10:34 -0000)]
extended UCI plugin by a simple control interface using a fifo
Andreas Steffen [Fri, 18 Jul 2008 10:04:40 +0000 (10:04 -0000)]
eliminated bashisms in _updown scripts
Martin Willi [Thu, 17 Jul 2008 11:45:58 +0000 (11:45 -0000)]
avoid heap allocation in bus->signal for performance reasons
Martin Willi [Thu, 17 Jul 2008 11:06:31 +0000 (11:06 -0000)]
fixed potential segfault in resolve_hosts
Martin Willi [Thu, 17 Jul 2008 08:25:34 +0000 (08:25 -0000)]
ignore IPCOMP acquires, fixes additional CHILD_SA setup with acquired SAs using compression
Martin Willi [Wed, 16 Jul 2008 12:33:19 +0000 (12:33 -0000)]
do not distinguish different policy protocols in userland cache
Martin Willi [Wed, 16 Jul 2008 12:30:47 +0000 (12:30 -0000)]
do not complain about existing routes
Andreas Steffen [Wed, 16 Jul 2008 12:28:29 +0000 (12:28 -0000)]
included Thomas in copyright statement
Martin Willi [Wed, 16 Jul 2008 11:54:44 +0000 (11:54 -0000)]
build dumm with leak ./configure
Martin Willi [Wed, 16 Jul 2008 11:51:37 +0000 (11:51 -0000)]
fixed acquire-delay bug by:
installing policies before states
updating policies if protocol has changed
Andreas Steffen [Wed, 16 Jul 2008 10:17:04 +0000 (10:17 -0000)]
updated copyright statement
Andreas Steffen [Wed, 16 Jul 2008 06:59:08 +0000 (06:59 -0000)]
fixed bashism in ipsec.in
Andreas Steffen [Tue, 15 Jul 2008 21:35:55 +0000 (21:35 -0000)]
set XFRM_STATE_AF_UNSPEC flag only in IPsec tunnel mode
Andreas Steffen [Tue, 15 Jul 2008 15:31:34 +0000 (15:31 -0000)]
typo
Andreas Steffen [Tue, 15 Jul 2008 15:28:00 +0000 (15:28 -0000)]
The XFRM_STATE_AF_UNSPEC flag added to xfrm.h allows IPv4-over-IPv6 and IPv6-over-IPv6 tunnels with the 2.6.26 and later Linux kernels
Martin Willi [Tue, 15 Jul 2008 14:41:12 +0000 (14:41 -0000)]
ported patch to final 2.6.26 release, including UML Makefile fixes
Andreas Steffen [Tue, 15 Jul 2008 13:09:09 +0000 (13:09 -0000)]
cosmetics
Andreas Steffen [Tue, 15 Jul 2008 13:07:27 +0000 (13:07 -0000)]
added pfsgroup to ipsec.conf.5 man page
Andreas Steffen [Fri, 11 Jul 2008 17:09:48 +0000 (17:09 -0000)]
edited description
Andreas Steffen [Fri, 11 Jul 2008 17:08:25 +0000 (17:08 -0000)]
added the ikev2/any-interface scenario
Andreas Steffen [Fri, 11 Jul 2008 15:24:02 +0000 (15:24 -0000)]
expanded ikev2/ip-two-pools-db to a spoke-to-hub network using virtual IP addresses
Martin Willi [Fri, 11 Jul 2008 08:54:56 +0000 (08:54 -0000)]
reverted [4125],[4166], reimplemented the proper way
Martin Willi [Fri, 11 Jul 2008 08:47:18 +0000 (08:47 -0000)]
setting ike_sa on bus in checkout_new
Andreas Steffen [Wed, 9 Jul 2008 22:13:39 +0000 (22:13 -0000)]
update_peerid() does not accept %any as a certificate's subjectAltName
Martin Willi [Wed, 9 Jul 2008 14:16:19 +0000 (14:16 -0000)]
do a route lookup to allow routing of left=%any connections
Martin Willi [Wed, 9 Jul 2008 12:39:11 +0000 (12:39 -0000)]
added /usr/local/[s]bin to uml exec path
Martin Willi [Wed, 9 Jul 2008 12:18:06 +0000 (12:18 -0000)]
loading ruby scripts specified at command line
Martin Willi [Wed, 9 Jul 2008 11:43:48 +0000 (11:43 -0000)]
ruby bindings/fixes for template loading
Martin Willi [Wed, 9 Jul 2008 10:51:10 +0000 (10:51 -0000)]
passing a block to guest.exec() processes output lines
Martin Willi [Tue, 8 Jul 2008 14:58:20 +0000 (14:58 -0000)]
uml "exec" writes stdout/stderr back to mconsole
guest->exec() accepts a callback for output
sligtly refactored mconsole.c