Age | Commit message (Collapse) | Author | |
---|---|---|---|
2006-12-18 | call ike_setup_ids from a more appropriate location. | Mathieu Sauve-Frankel | |
ok hshoexer@ | |||
2006-11-30 | typo: wrong rid for protocol | Markus Friedl | |
2006-11-30 | use rmv to unregister ipsec connections; ok hshoexer, ho | Markus Friedl | |
2006-11-30 | handle multiple SAs with different same src/dst but different port; | Markus Friedl | |
store IKE connection string and phase2 IDs in the ipsec rule; cleanup internal API: pass rules around instead of rule members; report Brian Candler; fix with hshoexer, msf; ok hshoexer | |||
2006-11-24 | add support to tag ipsec traffic belonging to specific IKE-initiated | Reyk Floeter | |
phase 2 traffic. this allows policy-based filtering of encrypted and unencrypted ipsec traffic with pf(4). see ipsec.conf(5) and isakmpd.conf(5) for details and examples. this is work in progress and still needs some testing and feedback, but it is safe to put it in now. ok hshoexer@ | |||
2006-11-24 | fix typo for remote port; from Brian Candler | Markus Friedl | |
2006-11-21 | do not delete sections that might be shared with other connections | Markus Friedl | |
however, this workaround might leak config entries in isakmpd; ok (for now) hshoexer | |||
2006-11-01 | KNF unrelated to previous commit. | Ryan Thomas McBride | |
2006-11-01 | Add support for aggressive mode (from the k2k6 IPsec hackathon). | Ryan Thomas McBride | |
ok hshoexer | |||
2006-09-18 | KNF and clean some trailing white spaces, no binary change. | Hans-Joerg Hoexer | |
2006-08-30 | actually use the right value for USER_FQDN | Mathieu Sauve-Frankel | |
ok hshoexer@ | |||
2006-08-29 | add support for ufqdn ids in ike rules | Mathieu Sauve-Frankel | |
ok hshoexer@ | |||
2006-08-29 | Add support for IKE AH rules to ipsecctl. Man page input by jmc@. | Christian Weisgerber | |
ok hshoexer@ | |||
2006-07-21 | When no peer is specified, no peer address is defined, thus do not use it. | Hans-Joerg Hoexer | |
Noticed by Alexey E. Suslikov <cruel@texnika.com.ua>, thanks! | |||
2006-06-18 | add group "none"; when choosen, pfs will be disabled. | Hans-Joerg Hoexer | |
ok david msf | |||
2006-06-16 | add a missing "force" | Hans-Joerg Hoexer | |
2006-06-15 | be careful when touch the peer component of a rule. It is not | Hans-Joerg Hoexer | |
necessarily set anymore, as now the peer can be left out. | |||
2006-06-13 | For IKE, allow main mode SHA2 and quick mode AESCTR transforms, | Christian Weisgerber | |
which were recently added to isakmpd. ok hshoexer@, markus@ | |||
2006-06-10 | switch back to original defaults regarding DH groups. modp3072 is to | Hans-Joerg Hoexer | |
heavyweight. Testing by Jason George, thanks! | |||
2006-06-08 | fix some indentation, noticed by david@ | Hans-Joerg Hoexer | |
2006-06-08 | Add a transport mode specifier to ike rules. Tunnel mode remains the default. | Christian Weisgerber | |
"looks right" hshoexer@ | |||
2006-06-08 | allocate enough storage via sockaddr_storage for sockaddr_in6, | Todd T. Fries | |
fixes ike29.in in regress looks right hshoexer@, ok naddy@ | |||
2006-06-08 | Fix a typo: When testing for quick mode lifetimes, make sure to | Hans-Joerg Hoexer | |
reference quick mode lifetimes, too, not main mode lifetimes. Otherwise we might dereference a NULL pointer... | |||
2006-06-02 | support tcp/udp port modifiers in ike rules | Christian Weisgerber | |
"put it in if it doesn't break regress" hshoexer@ | |||
2006-06-02 | allow to specify phase 1 and 2 lifetimes. Right now, these values | Hans-Joerg Hoexer | |
can only be set globally (ie. Default-phase-[12]-lifetime). | |||
2006-06-02 | Simplify main/quick mode parsing and generation of the actual ike config. | Hans-Joerg Hoexer | |
2006-06-01 | change the local-ID section name to always be unique as we may want to use ↵ | Mathieu Sauve-Frankel | |
more than one ISAKMP ID on the local peer. ok hshoexer@ | |||
2006-06-01 | knf | Hans-Joerg Hoexer | |
2006-06-01 | permit feeding isakmpd.fifo IPv6 addresses | Todd T. Fries | |
ok hshoexer@ | |||
2006-06-01 | Generate correct configuration for default peers. | Hans-Joerg Hoexer | |
2006-05-31 | Small function header knf. | Hans-Joerg Hoexer | |
2006-05-31 | Prepare for handling unnamed remote peers. | Hans-Joerg Hoexer | |
2006-05-28 | matching brackets are useful | Todd T. Fries | |
ok dlg@ | |||
2006-05-27 | allow to specify groups to be used IKE | Hans-Joerg Hoexer | |
2006-05-15 | delete weird C | Theo de Raadt | |
2006-04-13 | Add support for "local" to ike rules. Allows to specify the local IP to be | Hans-Joerg Hoexer | |
used on a multi-homed machine. Also, relax order of peer/local keywords. ok markus@ | |||
2006-03-31 | allow do delete dynamic rules | Hans-Joerg Hoexer | |
ok reyk@ | |||
2006-03-31 | allow specification of encapsulated protocol for ike; ok hshoexer | Markus Friedl | |
2006-03-31 | allow specification of encapsulated protocol for flows; ok hshoexer | Markus Friedl | |
2006-03-20 | When being verbose while deleting ike rules (-dv), print deletions instead of | Hans-Joerg Hoexer | |
additions. Suggested by david@ | |||
2006-03-20 | When adding a connection, do not explicitly start that connection | Hans-Joerg Hoexer | |
using "t" and "c" fifo commands. This is prone to a race when adding several tunnels between the same peers. Just let isakmpd start that connection on its own (using the connection checker). | |||
2006-03-07 | add an ike option for road warrior setups (hosts with dynamic ip | Reyk Floeter | |
addresses). "ike dynamic esp" will use the system's hostname as the fqdn source id (instead of the ip address) by default and enable dpd (dead peer detection) to allow smooth reconnects after an ip address change (i.e. forced reconnect with consumer adsl lines). ok hshoexer@, looks fine markus@, jmc@ | |||
2006-02-03 | override authentication tag as well; ok hshoexer@ | Christian Weisgerber | |
2006-02-02 | Two fixes: generate default main mode config when using PSK, added missing | Hans-Joerg Hoexer | |
force (with naddy@) ok reyk@ naddy@ | |||
2006-01-17 | spacing | Theo de Raadt | |
2006-01-16 | add support for pre-shared keys with "ike esp" using the new keyword | Reyk Floeter | |
"psk". rsa-sig is recommended and will still be used by default. ok hshoexer@, manpage ok jmc@ | |||
2005-12-28 | no close() after fdopen(); ok hshoexer@ | Christian Weisgerber | |
2005-12-28 | make sure isakmpd fifo is actually a fifo. | Hans-Joerg Hoexer | |
2005-12-12 | use err() instead of errx() | Hans-Joerg Hoexer | |
2005-11-24 | Remove old-style keyed sha1/md5. We only support hmac-sha1/md5. | Hans-Joerg Hoexer | |
Noticed the hard way by <raff at brodewicz dot pl> |