Andreas Steffen
|
062e8faee1
|
version bump to 4.5dr4
|
2010-09-29 07:14:33 +02:00 |
|
Andreas Steffen
|
440231e863
|
load tnccs-11 plugin in ikev2/rw-eap-tnc-radius scenario
|
2010-09-28 23:52:59 +02:00 |
|
Andreas Steffen
|
4e8e74fcfa
|
moved TNCCS layer out of eap_tnc plugin
|
2010-09-28 23:34:04 +02:00 |
|
Andreas Steffen
|
280c8ea2f0
|
stop gateway after clients in order to check release of virtual IP
|
2010-09-26 11:31:39 +02:00 |
|
Andreas Steffen
|
1e6cc07ee4
|
stop gateway after clients in order to check release of virtual IP
|
2010-09-26 10:58:28 +02:00 |
|
Andreas Steffen
|
234aaf2df2
|
stop gateway after clients in order to check release of virtual IP
|
2010-09-26 10:35:12 +02:00 |
|
Andreas Steffen
|
2b3124c76d
|
fixed release of virtual IP for XAUTH identities
|
2010-09-26 10:17:01 +02:00 |
|
Andreas Steffen
|
f054606586
|
include RFC 5998
|
2010-09-20 20:03:20 +02:00 |
|
Tobias Brunner
|
f22ba072e8
|
draft-ietf-ipsecme-eap-mutual will be released as RFC 5998.
|
2010-09-16 10:27:49 +02:00 |
|
Andreas Steffen
|
824a040284
|
the updated IKEv2 RFC 5996 has been released
|
2010-09-15 12:55:31 +02:00 |
|
Andreas Steffen
|
004de55235
|
added notify messages defined in RFC 5996
|
2010-09-15 12:48:58 +02:00 |
|
Andreas Steffen
|
80f86acccb
|
show validity of OCSP responses
|
2010-09-10 22:26:03 +02:00 |
|
Tobias Brunner
|
41f525becd
|
Added missing options (corrected some default values).
|
2010-09-10 12:01:20 +02:00 |
|
Tobias Brunner
|
3f71c5d95f
|
Moved load-tester configuration to a separate section.
|
2010-09-10 12:01:20 +02:00 |
|
Tobias Brunner
|
b2bcc57737
|
Added information about logger configuration.
|
2010-09-10 12:01:20 +02:00 |
|
Tobias Brunner
|
fa8c06903f
|
More information about IKEv2 retransmissions added.
|
2010-09-10 12:01:20 +02:00 |
|
Tobias Brunner
|
320cecd2dd
|
Adding most of the strongswan.conf options from the wiki.
|
2010-09-10 12:01:20 +02:00 |
|
Tobias Brunner
|
483c1feb7e
|
Added strongswan.conf(5) stub.
|
2010-09-10 12:01:19 +02:00 |
|
Tobias Brunner
|
0a1233e642
|
Moved man pages for config files to a separate directory.
|
2010-09-10 12:01:19 +02:00 |
|
Andreas Steffen
|
3c1debeb59
|
version bump to 4.5.0dr2
|
2010-09-10 07:37:28 +02:00 |
|
Andreas Steffen
|
f3051ebf53
|
fixed memory leak
|
2010-09-09 21:38:41 +02:00 |
|
Martin Willi
|
663e735553
|
Compare subject against all key identifiers in has_subject()
|
2010-09-09 17:46:20 +02:00 |
|
Andreas Steffen
|
f85f0c2795
|
has_subject() now resolves ID_KEY_IDs
|
2010-09-09 17:15:46 +02:00 |
|
Martin Willi
|
89821331e0
|
Do not change cipherspec while we have buffered handshake fragments pending
|
2010-09-09 14:27:41 +02:00 |
|
Andreas Steffen
|
939c4bf2e8
|
added ikev1/net2net-same-nets scenario
|
2010-09-09 13:37:30 +02:00 |
|
Tobias Brunner
|
3f9ba3be66
|
Conditional exclusion of tls_test script completed.
|
2010-09-09 13:21:38 +02:00 |
|
Tobias Brunner
|
6d4ae46768
|
Fixed typo.
|
2010-09-09 13:21:38 +02:00 |
|
Andreas Steffen
|
3f58022679
|
debug output of inbound and outbound TNCCS batches
|
2010-09-09 11:15:08 +02:00 |
|
Andreas Steffen
|
20ad62026e
|
support non EAP-TTLS conformant RADIUS-type attribute segmentation
|
2010-09-09 11:15:08 +02:00 |
|
Tobias Brunner
|
b1baa90846
|
Fixed copy/paste error.
|
2010-09-09 10:10:43 +02:00 |
|
Andreas Steffen
|
3b7eb3a9f4
|
added explanatory comments
|
2010-09-09 08:57:13 +02:00 |
|
Andreas Steffen
|
48b8cbb206
|
send well-formed TNCCS-Batch
|
2010-09-08 13:44:34 +02:00 |
|
Andreas Steffen
|
de29e3a683
|
max max_message_count configurable and move it into tls_eap_t
|
2010-09-08 12:58:45 +02:00 |
|
Andreas Steffen
|
99b0f633c2
|
handle TLS_PURPOSE_EAP_TNC
|
2010-09-08 12:58:45 +02:00 |
|
Martin Willi
|
30cd31fb69
|
Added a simple led plugin to control Linux LEDs based on IKE activity
|
2010-09-08 12:00:57 +02:00 |
|
Andreas Steffen
|
51b385d44d
|
moved tls_t existance test into tls_eap_create() again
|
2010-09-08 11:09:11 +02:00 |
|
Andreas Steffen
|
d2b1d4378e
|
generalized tls_eap_t to support EAP_TNC wrapping the TNC_IF_TNCCS protocol
|
2010-09-08 11:01:53 +02:00 |
|
Martin Willi
|
7b3c01845f
|
Read the compression type byte for EC groups, only
|
2010-09-08 10:35:29 +02:00 |
|
Andreas Steffen
|
91a0825c39
|
added non-standard SERPENT and TWOFISH support to kernel_netlink plugin
|
2010-09-08 07:22:31 +02:00 |
|
Andreas Steffen
|
2774826995
|
added openssl-ikev2/rw-eap-tls-only scenario
|
2010-09-07 17:14:32 +02:00 |
|
Andreas Steffen
|
52d4dc7fe2
|
added qcStatements OID
|
2010-09-07 11:17:51 +02:00 |
|
Martin Willi
|
61df42ccf3
|
Fixed typos
|
2010-09-07 10:24:40 +02:00 |
|
Martin Willi
|
00755453e3
|
Build tls_test script only if TLS stack is enabled
|
2010-09-07 10:21:44 +02:00 |
|
Martin Willi
|
84c9bc4254
|
Added PKCS#11 NEWS
|
2010-09-07 10:21:25 +02:00 |
|
Martin Willi
|
a782b52f6a
|
Added (EAP-)TLS NEWS
|
2010-09-07 10:10:36 +02:00 |
|
Martin Willi
|
31c65eb362
|
Include ec_point_format extension in ClientHello
|
2010-09-06 18:51:38 +02:00 |
|
Martin Willi
|
02281c87a4
|
Added TLS specific EC point formats
|
2010-09-06 18:42:43 +02:00 |
|
Martin Willi
|
ec7d4e70d3
|
Renamed ecp_format to ansi_format, as point formats in TLS use different identifiers
|
2010-09-06 18:37:24 +02:00 |
|
Martin Willi
|
3f5de7b65f
|
Enable the random plugin for scripts
|
2010-09-06 18:11:05 +02:00 |
|
Martin Willi
|
fe559b5156
|
Accept TLS records with zero-length plaintext
|
2010-09-06 17:04:59 +02:00 |
|