summaryrefslogtreecommitdiff
path: root/regress/sbin/ipsecctl
AgeCommit message (Expand)Author
2016-09-02Adjust for the new default MODP groupMike Belopuhov
2016-09-02Remove obsolete DES-CBC testsMike Belopuhov
2013-08-25transform names cannot have commasMike Belopuhov
2013-08-25transform names cannot have commasMike Belopuhov
2012-09-17sync with transform-name-fixMarkus Friedl
2012-09-15sync with recent ipsecctl changes/fixesMarkus Friedl
2012-07-10Rename "life" to "lifetime" to match iked.Lawrence Teo
2012-07-08AES-CTR, AES-GCM, AES-GMAC are disallowed with manual SAsChristian Weisgerber
2011-07-06update regress for non-crypto flow 'type use' caseTheo de Raadt
2010-10-06Retire SkipjackMike Belopuhov
2010-05-10Various comment typos. 'wether' -> 'whether' (most popular), 'possiblity' ->Kenneth R Westerback
2009-08-04Add regress tests with IPv4 and IPv6 addresses for the srcid and/or dstid.Joel Sing
2009-01-30If the "peer" address is not specified or derived from "to" forAlexander Bluhm
2009-01-29Remove ikefail10 ipsecctl regression test as it always fails. ItAlexander Bluhm
2009-01-28Allow to specify ike and flow explicitly without peer. The anyAlexander Bluhm
2009-01-20Regression tests for source flow NAT support.Marco Pfatschbacher
2009-01-19Do not use "egress" keyword as it expands to an actual interface,Hans-Joerg Hoexer
2008-12-22add regression test for aes-{128,192,256} being used with main and quickHans-Joerg Hoexer
2008-12-22Adopt to recent change: /32 now is treated as a network address.Hans-Joerg Hoexer
2008-07-01Isakmpd acquire mode did not work with a config generated fromAlexander Bluhm
2008-07-01If multiple to addresses but no peer are given in an ike or flowAlexander Bluhm
2008-01-04Add a regression test for handling addresses with trailing '/32' and addressHans-Joerg Hoexer
2007-10-15Add new "reached end of file while parsing quoted string" as expectedHans-Joerg Hoexer
2007-07-03both 'proto 50' and 'proto esp' must work in flow specificationsMarkus Friedl
2007-05-10Do not crash when lists include the "any" keyword. Reported byHans-Joerg Hoexer
2007-03-16move autodetection of the ID type to the parser. this way theMarkus Friedl
2007-03-14We switched to aes cbc quite some time ago, so also use the correctHans-Joerg Hoexer
2007-02-19add a test for null encryptionHans-Joerg Hoexer
2007-02-19we have to use '-k' now to show keys.Hans-Joerg Hoexer
2007-02-19previous commit to parse.y was undone. adopt these two regression tests.Hans-Joerg Hoexer
2007-02-16Adopt to recent change in parse.y (do not accept '\n' in quotedHans-Joerg Hoexer
2007-01-10allow rule if there is at least _one_ matching address family combination.Markus Friedl
2007-01-04don't pass -1 as a netmask; report vicviq at gmail.comMarkus Friedl
2006-11-30wrong rid for protocolMarkus Friedl
2006-11-30sync: rmv to unregister ipsec connectionsMarkus Friedl
2006-11-30sync: proto/port in lid/rid/connectionMarkus Friedl
2006-11-24fix typo for remote port; from Brian CandlerMarkus Friedl
2006-11-21syncMarkus Friedl
2006-11-16add comment on how to update the *.ok files; ok hshoexer@Markus Friedl
2006-11-13Update to match improved address family check.Ryan Thomas McBride
2006-11-01Adjust existing ikedel tests for aggressive mode support (we nowRyan Thomas McBride
2006-10-31Remove bogus input line.Hans-Joerg Hoexer
2006-10-31Add some regression tests for odd ipsecctl behaviour noticed byHans-Joerg Hoexer
2006-08-29Test for an as yet unresolved problem:Christian Weisgerber
2006-08-29Add support for IKE AH rules to ipsecctl. Man page input by jmc@.Christian Weisgerber
2006-07-21tests similar to ike49 and ike50, but with ipv6 addresses.Hans-Joerg Hoexer
2006-07-21yet another test.Hans-Joerg Hoexer
2006-07-21new tests for default peer usageHans-Joerg Hoexer
2006-07-21update and enable that testHans-Joerg Hoexer
2006-06-20The ike/ikedel tests 48 to 50 do net exist yet. They will be neededHans-Joerg Hoexer