index
:
src
cvs/HEAD
kms/intel
kms/radeon
master
OpenBSD base system
summary
refs
log
tree
commit
diff
log msg
author
committer
range
path:
root
/
sbin
/
iked
/
policy.c
Age
Commit message (
Expand
)
Author
2016-06-01
Implement a second address pool specifically for IPv6, so that
Patrick Wildt
2015-10-20
Fix ocsp by adding a missing TAILQ_INIT().
Reyk Floeter
2015-10-01
Fix interoperability with Apple iOS9: If we don't get a (valid)
Reyk Floeter
2015-08-21
Switch iked to C99-style fixed-width integer types.
Reyk Floeter
2015-08-19
spacing (no binary change, verified with checksums)
Reyk Floeter
2015-07-07
repair policy-ikesa-linking by replacing the broken RB_TREE w/TAILQ
Markus Friedl
2015-01-16
Replace <sys/param.h> with <limits.h> and other less dirty headers where
Theo de Raadt
2014-11-07
Fixup a few problems with EAP state transition
Mike Belopuhov
2014-05-06
initiate ike sa rekeying (ikesalifetime keyword), re-queue pfkey
Markus Friedl
2014-05-06
cleanup IKE-SA tree handling (fixes repeated-insert & double-remove)
Markus Friedl
2014-04-29
make sure the state machine only advances if the AUTH payload has
Markus Friedl
2014-02-21
support rekeying for IPCOMP; ok mikeb@
Markus Friedl
2014-02-17
interpret 'config address net/prefix' as a pool of addresses and
Markus Friedl
2014-01-24
re-lookup the policy as soon as we have the ID of the peer (destid)
Markus Friedl
2014-01-24
make sure sa_lookup() can actually find SAs; ok mikeb
Markus Friedl
2013-12-03
never cast to sockaddr_storage, always cast to the abstract 'class' sockaddr
Markus Friedl
2013-11-28
sa_lookup: don't compare with sh_rspi if rspi is not set
Markus Friedl
2013-11-28
sa_new(): discard & free duplicate IKESAs; ok mibek@
Markus Friedl
2013-10-24
no need for netinet/ip_var.h (and friends)
Theo de Raadt
2013-01-08
Remove private CVS tag from an obsolete repository and bump copyright
Reyk Floeter
2012-12-15
Don't dereference NULL pointers (and some cleanup here).
Reyk Floeter
2012-09-18
update email addresses to match reality.
Reyk Floeter
2012-05-30
when changing peer's address in the SA, remove the old entry from the
Mike Belopuhov
2011-05-02
store the peer address as it was specified in the policy in the
Mike Belopuhov
2011-04-18
Improve the iked acquire mode peer <-> policy matching. This change
Reyk Floeter
2011-04-18
When the kernel wants to acquire an SA for an unknown flow, lookup a
Reyk Floeter
2011-01-26
get rid of acquire flows completely, as they tend to pass traffic
Mike Belopuhov
2011-01-21
Reimplement the iked(8) policy evaluation for incoming connections to
Reyk Floeter
2011-01-18
reyk noticed that my rb-tree-fu is not that great. fixup compare function
Mike Belopuhov
2011-01-17
Add initial acquire mode support and use it whenever Windows peers decide
Mike Belopuhov
2010-12-22
child sa rekeying revamp plus numerous bugfixes;
Mike Belopuhov
2010-07-03
Better non-debug logging messages when a session is established/closed.
Reyk Floeter
2010-06-27
print the required bits as a string
Reyk Floeter
2010-06-15
only compare the SPIi in the SA tree
Reyk Floeter
2010-06-14
Initiator mode with certificates; needs more work but works.
Reyk Floeter
2010-06-14
Initial support for initiator mode which allows to run iked as a
Reyk Floeter
2010-06-14
remove policy lookup debug message
Reyk Floeter
2010-06-14
restructure code a bit to move closer to initiator mode:
Reyk Floeter
2010-06-14
More code for initiator mode (not finished yet)
Reyk Floeter
2010-06-10
Add another tree to lookup policy SAs by peer address.
Reyk Floeter
2010-06-10
only call RB_REMOVE once when removing an SA.
Reyk Floeter
2010-06-03
Import iked, a new implementation of the IKEv2 protocol.
Reyk Floeter