| | 1 | strongswan-4.1.0 / R:2552 |
|---|
| | 2 | =========================== |
|---|
| | 3 | |
|---|
| | 4 | fixed nat detection bug |
|---|
| | 5 | OCSP support |
|---|
| | 6 | updated NEWS, TODO and man page |
|---|
| | 7 | respecting "keyingtries" parameter on IKE_SA setup |
|---|
| | 8 | cleanups |
|---|
| | 9 | fixed reset() |
|---|
| | 10 | not installing a route when policy gets updated |
|---|
| | 11 | renamed keyingtries attribute |
|---|
| | 12 | adjusted loglevels |
|---|
| | 13 | delay OCSP response by 5 seconds |
|---|
| | 14 | always update reqid on policy install, fixes dpdaction=hold issue |
|---|
| | 15 | EAP-SIM cleanups |
|---|
| | 16 | fixed CHILD_SA rekeying/delete bug on 64bit machines |
|---|
| | 17 | removed obsolete methods in delete_payload |
|---|
| | 18 | Shortened distribution string |
|---|
| | 19 | Shortened distribution string |
|---|
| | 20 | shortened distribution string |
|---|
| | 21 | add daemon.log to web page |
|---|
| | 22 | remove /etc/resolv.conf |
|---|
| | 23 | version bump to 4.1.0 |
|---|
| | 24 | added apache2/ocsp log directory to winnetou |
|---|
| | 25 | removed killall openssl |
|---|
| | 26 | removed killall openssl |
|---|
| | 27 | deleted |
|---|
| | 28 | deleted |
|---|
| | 29 | create apach2/ocsp/ logging directory on winnetou |
|---|
| | 30 | do not check for type of dpd action any more |
|---|
| | 31 | create /var/log/apache2/ocsp on winnetou |
|---|
| | 32 | added |
|---|
| | 33 | added |
|---|
| | 34 | added |
|---|
| | 35 | delete virtual IP addresses after use |
|---|
| | 36 | deleted |
|---|
| | 37 | added |
|---|
| | 38 | fixed case of missing subjectKeyID |
|---|
| | 39 | corrected typo |
|---|
| | 40 | version bump to 4.1.0 |
|---|
| | 41 | added |
|---|
| | 42 | use CURLOPT_NOSIGNAL |
|---|
| | 43 | added --with-sim-reader option to configure script |
|---|
| | 44 | some cleanups in eap_sim |
|---|
| | 45 | removed dublicated code in eap_authenticator |
|---|
| | 46 | log reception of trusted signer certificate |
|---|
| | 47 | version bump to 4.1.0 |
|---|
| | 48 | deleted |
|---|
| | 49 | added |
|---|
| | 50 | changed OCSPSigner to OCSPSigning |
|---|
| | 51 | fixed carry bug in FIPS prf |
|---|
| | 52 | user standard cert |
|---|
| | 53 | deleted |
|---|
| | 54 | deleted |
|---|
| | 55 | added |
|---|
| | 56 | added |
|---|
| | 57 | modified description.txt and evaltest.dat |
|---|
| | 58 | version number selection fix |
|---|
| | 59 | some cleanups |
|---|
| | 60 | cleaned up and fixed DPD handling code |
|---|
| | 61 | removed cfg-payload dns test code |
|---|
| | 62 | added |
|---|
| | 63 | added |
|---|
| | 64 | version bump to strongswan-4.1.0 and linux-2.6.20.3 |
|---|
| | 65 | cosmetics |
|---|
| | 66 | increased control debugging output |
|---|
| | 67 | added EAP-SIM authentication |
|---|
| | 68 | client side only |
|---|
| | 69 | uses an external SIM reader library specified with SIM_READER_LIB |
|---|
| | 70 | untested |
|---|
| | 71 | not detaching from bus when IKE_SA_INIT is retried |
|---|
| | 72 | added AES-192/256 proposals to IKE |
|---|
| | 73 | added generic EAP_IDENTITY client implementation using peers IKEv2 ID |
|---|
| | 74 | fixed compilation warnings and errors when not using curl |
|---|
| | 75 | results from the single responses is stored in the corresponding certinfo_t structs |
|---|
| | 76 | moved credential_store.h from charon/config/credentials to libstrongswan |
|---|
| | 77 | last patch removed, changed CURLOPT_FILE to CURLOPT_WRITEDATA |
|---|
| | 78 | fixed memory leak by calling curl_slist_free_all(headers) |
|---|
| | 79 | fixed memory leak by calling curl_slist_free_all(headers) |
|---|
| | 80 | whitelisting static Curl_getaddrinfo() memory leak |
|---|
| | 81 | fixed a certinfo_t memory leak in verify() |
|---|
| | 82 | fixed a memory leak in response_t |
|---|
| | 83 | ocsp signer certificate and ocsp response signature can be verified |
|---|
| | 84 | fixed memleaks when using EAP authentication |
|---|
| | 85 | fixed configuration payloads when using EAP |
|---|
| | 86 | fixed payload order (again) |
|---|
| | 87 | including peers certificate when his certreq is empty |
|---|
| | 88 | implemented cookies as initiator |
|---|
| | 89 | proper logging of notifies in IKE_SA setup |
|---|
| | 90 | disabling routing for IPv6, does not work correctly |
|---|
| | 91 | fixed call of add_auth_certificate() |
|---|
| | 92 | generalized get_ca_certificate() to get_auth_certificate(auth_flags) |
|---|
| | 93 | added fetcher_finalize() to clean up libcurl |
|---|
| | 94 | some cleanups |
|---|
| | 95 | not installing %any DNS servers |
|---|
| | 96 | support of setting and getting authority flags |
|---|
| | 97 | support if ocsp signing certificates |
|---|
| | 98 | support if ocsp signing certificates |
|---|
| | 99 | fixed payload order in IKE_AUTH |
|---|
| | 100 | removed SHA2 kernel proposals from default, the kernel doesn't support them yet |
|---|
| | 101 | allocation fixes, not complete |
|---|
| | 102 | handling "No policy found" properly |
|---|
| | 103 | added more debugging output for policy lookup |
|---|
| | 104 | returning a (dummy) policy even when TS does not match, so we can properly send a TS_UNACCEPTABLE |
|---|
| | 105 | fixed CHILD_SA creation within existing IKE_SA |
|---|
| | 106 | added ocsp_parse_single_response |
|---|
| | 107 | ported changes from EAP branch, renabling EAP framework |
|---|
| | 108 | added (not yet supported) sha2 algorithms to kernel |
|---|
| | 109 | only adding a route if using tunnel mode |
|---|
| | 110 | added SHA2 MAC and PRF to default proposal |
|---|
| | 111 | added more debug output |
|---|
| | 112 | experimental SHA2 HMAC and PRF implementations |
|---|
| | 113 | parsing basic ocsp response |
|---|
| | 114 | forgot to assign public.is_ocsp_signer() method |
|---|
| | 115 | added parsing level to x509_create_from_chunk() |
|---|
| | 116 | added parsing level to x509_create_from_chunk() and added is_ocsp_signer() method |
|---|
| | 117 | http post fetching using libcurl implemented |
|---|
| | 118 | added fetcher.h and fetcher.c |
|---|
| | 119 | added |
|---|
| | 120 | corrected @ingroup to utils |
|---|
| | 121 | corrected comment |
|---|
| | 122 | start ocsp checking only if there are any ocspuris present |
|---|
| | 123 | conntrack -F is used to flush the NAT states |
|---|
| | 124 | the hostaccess=yes parameters are not needed anymore |
|---|
| | 125 | use conntrack -F to flush NAT states |
|---|
| | 126 | replaced actual virtual IP addresses by symbolic ones |
|---|
| | 127 | removed unnecessary double quotes |
|---|
| | 128 | nonce in ocsp_t was not properly initialized |
|---|
| | 129 | ocsp request is now fully built but without requestor signature |
|---|
| | 130 | starting to build ocsp request |
|---|
| | 131 | prevent from initiating multiple exchanges the same time |
|---|
| | 132 | updated apidoc documentation |
|---|
| | 133 | fixed notify handling in IKE_AUTH |
|---|
| | 134 | moved nonce payload before TS in CHILD_SA setup |
|---|
| | 135 | moved REKEY_SA notify to the beginning of the message |
|---|
| | 136 | fixed traffic selector redundancy removal code (not completely tested) |
|---|
| | 137 | add crl and ocsp uris to linked list after partial verification |
|---|
| | 138 | added print hook for certinfo_t printing |
|---|
| | 139 | fixed typo |
|---|
| | 140 | sending an SPI of 0 as responder when IKE_SA_INIT fails |
|---|
| | 141 | iterate certinfos linked list for matching serialNumber |
|---|
| | 142 | some cleanups |
|---|
| | 143 | not assigning %any virtual IPs to peer anymore |
|---|
| | 144 | fixed double free bug |
|---|
| | 145 | added |
|---|
| | 146 | fixed ID selection bug when peer doesn't include IDr payload |
|---|
| | 147 | allowing vendor ID in any messag |
|---|
| | 148 | moved listing of crls to local_credential_store and ca |
|---|
| | 149 | refactored ca_info_t |
|---|
| | 150 | refactored ca_info_t |
|---|
| | 151 | fixed netlink socket receiver code |
|---|
| | 152 | implemented interface enumeration code with netlink: no getifaddrs reqired anymore |
|---|
| | 153 | refactored kernel interface, works reliable again |
|---|
| | 154 | implemented get_iface() using RTM_GETADDR |
|---|
| | 155 | added support for multi-header netlink messages |
|---|
| | 156 | really ugly now, need a lot of refactoring |
|---|
| | 157 | added debuggin for interface lookup |
|---|
| | 158 | fixed address lookup when !using getifaddrs() |
|---|
| | 159 | added firewalling support when using virtual IPs |
|---|
| | 160 | added support for 0.0.0.0/0 traffic selectors |
|---|
| | 161 | fixed routing to make correct 0.0.0.0/0 routes |
|---|
| | 162 | config-payload scenario fixes |
|---|
| | 163 | preparations for PLUTO_MY_SOURCEIP |
|---|
| | 164 | corrected typo |
|---|
| | 165 | added cert with OCSP access info |
|---|
| | 166 | dpd now takes 180 s and 5 retransmits |
|---|
| | 167 | changed grep to creating aquire job for CHILD SA |
|---|
| | 168 | replaced actual virtual IPs by place holders |
|---|
| | 169 | virtual-ip scenario has been replaces by config-payload scenario |
|---|
| | 170 | added |
|---|
| | 171 | added |
|---|
| | 172 | added ocsp.h and ocsp.c |
|---|
| | 173 | added |
|---|
| | 174 | r2398 | tobias | 2007-02-28 16:20:10 +0100 (Wed, 28 Feb 2007) | 2 lines |
|---|
| | 175 | virtual ip uml test |
|---|
| | 176 | fixed reauthentication when connections other is %any |
|---|
| | 177 | merged tasking branch into trunk |
|---|
| | 178 | fixed big endian bug in md5 hasher |
|---|
| | 179 | cosmetics |
|---|
| | 180 | added once flag to certinfo_t |
|---|
| | 181 | cosmetics |
|---|
| | 182 | added certinfos linked list |
|---|
| | 183 | changed ca info to ca |
|---|
| | 184 | support of ca info sections |
|---|
| | 185 | added support of OCSP accessLocations |
|---|
| | 186 | correct interface definition |
|---|
| | 187 | added support of OCSP accessLocations |
|---|
| | 188 | full support of ca info records |
|---|
| | 189 | added the create_crluri_iterator method |
|---|
| | 190 | replace ca is realized as del_ca followed by add_ca |
|---|
| | 191 | last CA keyword is KW_OCSPURI2 |
|---|
| | 192 | full support of ca info records |
|---|
| | 193 | full support of ca info records |
|---|
| | 194 | alphabetically sorting print commands |
|---|
| | 195 | listing ca_info items |
|---|
| | 196 | replace printf.h by stdio.h |
|---|
| | 197 | addin get_keyid() method |
|---|
| | 198 | support of ca info records |
|---|
| | 199 | support of ca info records |
|---|
| | 200 | version bump to 4.0.8 |
|---|
| | 201 | support of ca info records |
|---|
| | 202 | support of ca info records |
|---|
| | 203 | typo |
|---|
| | 204 | SHA512-HMAC bug fix and hash function self-test support |
|---|
| | 205 | SHA512-HMAC bug fix and hash function self-test support |
|---|
| | 206 | handle strong SHA-2 signatures in X.509 certificates |
|---|
| | 207 | SHA-2 fixes and add-ons |
|---|
| | 208 | version bumps |
|---|
| | 209 | remove strong certs and keys after test |
|---|
| | 210 | added |
|---|
| | 211 | using "left" as my host per default, swapping to "right" when needed |
|---|
| | 212 | respecting source address when sending packets |
|---|
| | 213 | added PRINT_CAINFO hook |
|---|
| | 214 | stroke now recognizes the keywords listocspcerts|cainfos|ocsp, rereadocspcerts and purgeocsp |
|---|
| | 215 | enable IP forwarding |
|---|
| | 216 | prepared support of ca information records and ocsp functionality |
|---|
| | 217 | added support of ca information records and ocsp keywords |
|---|
| | 218 | enabled adding and deleting ca information records |
|---|
| | 219 | fixed starter crash due to freeing default IPSEC_EAPDIR string |
|---|
| | 220 | add --eapdir option only if defined in ipsec.conf |
|---|
| | 221 | removed eap aka module due nda |
|---|
| | 222 | merged EAP framework from branch into trunk |
|---|
| | 223 | includes a lot of other modifications |
|---|
| | 224 | %T requires time_t ptr |
|---|
| | 225 | removed my time_t printf handler patch, applied the one of andreas (64bit save) |
|---|
| | 226 | fixed printf() hooks for time |
|---|
| | 227 | added support for NULL encryption in ESP |
|---|
| | 228 | be more liberal in accepting notifies with a protocol id |
|---|
| | 229 | include NO_EXT_SEQUENCE_NUMBER in default proposal |
|---|
| | 230 | output peer id if RSA public key is not found |
|---|
| | 231 | fixed typo |
|---|
| | 232 | version bump to 4.0.8 |
|---|
| | 233 | added address listing without getifaddrs for uclibc (only IPv4 yet) |
|---|
| | 234 | added threads to support multiple simultaneous stroke requests |
|---|
| | 235 | renamed all static clone() functions to avoid naming conflicts with uclibc |
|---|
| | 236 | sending proper signal to the bus when detecting a dead peer |
|---|
| | 237 | added configuration of XAUTH and ModeConfig push mode |
|---|
| | 238 | version bump |
|---|
| | 239 | version bump |
|---|
| | 240 | Cisco XAUTH interoperability |
|---|
| | 241 | XAUTH interoperability with Cisco |
|---|
| | 242 | removed IPSECPOLICY compile option |
|---|
| | 243 | unload xauth_module only if XAUTH_DEFAULT_LIB is defined |
|---|
| | 244 | loading the XAUTH module requires libdl |
|---|
| | 245 | added some more attributes, inst XAUTH_TYPE in reply |
|---|
| | 246 | Mode Config refactoring |
|---|
| | 247 | XAUTH fixes and Cisco Unity support |
|---|
| | 248 | log APPLICATION_VERSION and UNITY_DDNS_HOSTNAME strings |
|---|
| | 249 | added Cisco Unity ModeCfg attributes |
|---|
| | 250 | version bump to 4.0.7 |
|---|
| | 251 | fixed 64 bit issue with print time |
|---|
| | 252 | fixed XAUTHResp bug |
|---|
| | 253 | included xauth.h |
|---|
| | 254 | use uml_mconsole to check end of booting process |
|---|
| | 255 | name the created CHILD_SA |
|---|
| | 256 | doubled PAYLIMIT to 40 payloads |
|---|
| | 257 | version bump |
|---|
| | 258 | show rekeying|reauthentication time |
|---|
| | 259 | show name of created CHILD_SA |
|---|
| | 260 | combined use_in and use_fwd |
|---|
| | 261 | corrected typo |
|---|
| | 262 | cosmetics |
|---|
| | 263 | cosmetics |
|---|
| | 264 | fixed an enumeration error, added CISCO_IOS VID |
|---|
| | 265 | fixed mismatch in interface definition of get_secret() |
|---|
| | 266 | forward declaration of struct state not needed |
|---|
| | 267 | cosmetics |
|---|
| | 268 | added firewall support to scenario |
|---|
| | 269 | updated changelog for 4.0.6 |
|---|
| | 270 | fixed crash when CA for certrequest not found |
|---|
| | 271 | fixed build when !using smartcard |
|---|
| | 272 | removed unused debugging code |
|---|
| | 273 | updated NEWS for 4.0.6 |
|---|
| | 274 | |
|---|
| | 275 | |
|---|