summaryrefslogtreecommitdiff
path: root/sbin/ipsec
AgeCommit message (Collapse)Author
1998-09-14remove -DDEBUG from CFLAGSNiels Provos
1998-08-17fix reallocNiels Provos
1998-08-01Clarification.Angelos D. Keromytis
1998-08-01close socket. Not really necessary, but good form.Angelos D. Keromytis
1998-08-01Document accepted values for -proto/-proto2.Angelos D. Keromytis
1998-08-01Sanity check numerical values for -proto/-proto2 flags (4, 50, and 51Angelos D. Keromytis
accepted only).
1998-08-01Forgot this already-documented addition: -proto/-proto2 can also takeAngelos D. Keromytis
"esp", "ah", and "ip4" as arguments (in addition to protocol numbers).
1998-08-01Add symbolic names for the -transport and -sport/-dport flags (fromAngelos D. Keromytis
/etc/protocols and /etc/services respectively). Document changes, document option "ip4".
1998-07-29Do IP-in-IP encapsulation properly.Angelos D. Keromytis
1998-07-27Library dependenciesNiklas Hallqvist
1998-07-24fix spelling of separateTheo de Raadt
1998-07-17Add a notice that DES shouldn't be used.Angelos D. Keromytis
1998-07-10fix va_arg handling when not __STDC__Niels Provos
1998-06-30- support HMAC flag which if present in the attribute list toggles toNiels Provos
HMAC authentication transforms and otherwise to simple keyed authentication. Note, HMAC is necessary if new esp is to use integrity checking, i.e. authentication of the payload. - Also fix bug, where SPIs were reserved for more than one protocol when only one protocol, e.g. ESP or AH, could be agreed upon. - Also make kernel.c a bit less complex, I hope. - return notifies to kernel on failure only when kernel started the keying.
1998-06-24disable startup file in vpn modeNiels Provos
1998-06-18fix spelling mistake, better grammarNiels Provos
1998-06-08exit correctlyNiels Provos
1998-06-03use sigsetopsTheo de Raadt
1998-06-01set correct source address for owner SPIsNiels Provos
1998-06-01correct netmask for flow in local caseNiels Provos
1998-06-01.Dt PHOTURISD 8Niels Provos
1998-05-26grammarTheo de Raadt
1998-05-24update to reflect iv changeNiels Provos
1998-05-24Explain some more about the src field.Angelos D. Keromytis
1998-05-24forgot to apply masks to subnet addressesNiels Provos
1998-05-24add VPN mode.Niels Provos
1998-05-24remote rt and rtdeleteNiels Provos
1998-05-24incorporate functionality of rt and rtdelete commands into ipsecadm,Niels Provos
some improvements to manpage, stricter option checking, -Wall.
1998-05-19fix bug in configuring exchange timeoutNiels Provos
1998-05-19carify iv usage with new esp modeNiels Provos
1998-05-18support kernel notifies for setsockopt/getsockopt interface and fix variousNiels Provos
small bugs.
1998-05-14Explain exchange_lifetime a bit moreNiklas Hallqvist
1998-05-13Clarify tunnel optionsNiklas Hallqvist
1998-05-13Clarify tunnel optionsNiklas Hallqvist
1998-05-13typoNiklas Hallqvist
1998-04-25typosNiklas Hallqvist
1998-04-04use the right key material for authentication, bug report byNiels Provos
Richard Guy Briggs <rgb@conscoop.ottawa.on.ca>
1998-03-16set socket options, so that photuris bypasses kernel ipsec policy,Niels Provos
not yet supported by the kernel actually.
1998-03-07.Bx Open -> .Ox 2.xTodd C. Miller
1998-03-07remove debugging left overs.Niels Provos
1998-03-05correct reference to photurisd.Niels Provos
1998-03-04move man page to right section.Niels Provos
1998-03-04compliance with draft-simpson-photuris-18.txt, better packet structureNiels Provos
checking, better support for new esp and ah, documentation ...
1997-12-02Use the proper .Bd -literal .Ed sequence for quoting examples.Niels Provos
1997-11-24add support for ripemd-160, mention it in man page.Niels Provos
1997-11-18make old style padding default again, use -netpadding for new styleNiels Provos
padding. allow ip4 encapsulation/tunnels with no encryption/authentication.
1997-11-04support for blowfish and cast. add -authkey to seperate key materialNiels Provos
for encryption and authentication which is needed for variable key length ciphers.
1997-09-24Duh!Angelos D. Keromytis
1997-09-24Support for new style padding.Angelos D. Keromytis
1997-09-23Addition for tunnel mode. I'm in Canada, i can write crypto code!Angelos D. Keromytis