summaryrefslogtreecommitdiff
path: root/sbin/ipsecctl
AgeCommit message (Expand)Author
2024-02-06Tweak previous. Passing "dns" to pledge(2) is suitable for the purpose.YASUOKA Masahiko
2024-01-29Open /etc/{services,protocols} before pledge(2).YASUOKA Masahiko
2023-10-10Print at most pkgsize - hdrsize bytes for pfkey tag and identity toTobias Heider
2023-10-09Add pledge("stdio") before parsing pfkey messages. This applies toTobias Heider
2023-08-07add support route based ipsec vpn negotiation with sec(4) via isakmpd.David Gwynne
2023-04-19remove duplicate includesJonathan Gray
2023-03-07Delete obsolete /* ARGSUSED1 */ lint comments.Philip Guenther
2022-06-25Use in_addr for AF_INET.mbuhl
2022-02-04Fix another instance of incorrect capitalization of ChaCha20.Theo Buehler
2021-11-04Tweaks (improve previous commit)YASUOKA Masahiko
2021-11-04Clarify "aes" will accept keys which length is in 128:256 bits. AlsoYASUOKA Masahiko
2021-10-22After deleting hifn(4) the only provider for the LZS compressionAlexander Bluhm
2021-10-15Don't declare variables as "unsigned char *" that are passed toChristian Weisgerber
2021-07-14Export SA replay counters via pfkey and print with ipsecctl.tobhe
2021-07-05Print SA MTU if included in pfkey message.tobhe
2020-12-29getifaddrs() can return entries where ifa_addr is NULL. Check for thisSebastian Benoit
2020-11-05Enable support for ASN1_DN ipsec identifiers.Peter Hessler
2020-06-01Fix "comparison of integers of different signs" warning.tobhe
2020-04-23Support SADB_X_EXT_RDOMAIN extension in pfkey dump (-m).tobhe
2020-02-16Quote variables in pf tag stringskn
2020-02-10briefly mention /etc/examples/ in the FILES section of all theIngo Schwarze
2020-02-07Extend the ipsecctl(8) parser to set the udpencap flag and portAlexander Bluhm
2019-11-10Consistently use _rcctl enable foo_ in examples, it's simpler and lessLandry Breuil
2019-08-26Fix file descriptor leak due to popfile() never closing the main config file.tobhe
2019-07-03snprintf/vsnprintf return < 0 on error, rather than -1.Theo de Raadt
2019-06-28When system calls indicate an error they return -1, not some arbitraryTheo de Raadt
2019-02-13(unsigned) means (unsigned int) which on ptrdiff_t or size_t or otherTheo de Raadt
2018-11-07sync cmdline_symset() changes with src/usr.sbin; OK sashan@ claudio@miko
2018-11-01- odd condition/test in PF lexerAlexandr Nedvedicky
2018-09-07Remove unnused af argument from unmask(), sync with pfctlkn
2018-08-28Display per-TDB counters in verbose mode.Martin Pieuchot
2018-07-11Do for most running out of memory err() what was done for most runningKenneth R Westerback
2018-07-10Include <sys/queue.h> instead of relying on kernel headers to includeMartin Pieuchot
2018-07-09No need to mention which memory allocation entry point failed (malloc,Kenneth R Westerback
2018-07-08Be consistent in warn() and log_warn() usage whenKenneth R Westerback
2018-04-26Plug leak in error case of the common 'varset' implementations.Kenneth R Westerback
2018-04-17Document how to avoid isakmpd(8) source IP address pitfalls by usingStefan Sperling
2017-11-23in isakmpd(8), provide a hint: from scott chelohaJason McIntyre
2017-11-20Support collapsing flow outputs.Martin Pieuchot
2017-10-27Support DH groups 19 to 21 and 25 to 30, just like iked(8) does.Martin Pieuchot
2017-04-19Rename all SA groups to bundles consistently. The first kernelAlexander Bluhm
2017-04-18use freezero()Theo de Raadt
2017-04-14Up to now ipsecctl(8) grouped SAs with identical src and dst to theAlexander Bluhm
2017-04-10Found another len += snprintf...Theo de Raadt
2017-03-02Now that the kernel provides information about IPsec SA bundles,Alexander Bluhm
2017-02-28Depending on the addresses, ipsecctl(8) automatically groups saAlexander Bluhm
2017-01-05Replace symset()'s hand-rolled for(;;) traversal of 'symhead' TAILQKenneth R Westerback
2016-06-21do not allow whitespace in macro names, i.e. "this is" = "a variable".Sebastian Benoit
2015-12-10Remove NULL-checks before free(). ok tb@mmcc
2015-12-09Remove plain DES encryption from IPsec.Christian Weisgerber