Age | Commit message (Collapse) | Author |
|
hshoexer@
|
|
ok ho@ markus@
|
|
ok ho@
|
|
|
|
Require DELETE payloads to be accompanied by HASHes, and add validation
for HASH payloads without active exchanges.
From Hans-Joerg Hoexer with various modifications and suggestions from me
and markus@. Ok markus@.
|
|
|
|
foo = realloc(foo...) and avoid possible memory leaks. Avoid
leaving things pointing to freed memory on failure.
|
|
Jean-Francois Dive, although I opted for a slightly different patch.
|
|
data during rekeying. From Jean-Francois Dive.
|
|
|
|
D. Keromytis and Niels Provos.
|
|
|
|
|
|
|
|
ok ho@
|
|
never be used.
|
|
Walpuski.
|
|
|
|
pointed out by Aref Taidi. Replace this with a "Default-Phase-1-Configuration"
that will be used if this tag is missing from the peer. Update manpage
accordingly. niklas@ ok.
|
|
|
|
|
|
|
|
make certificate auth work better with some clients, such as SSH Sentinel.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
thus, failed exchanges/negotiations don't leak SAs and transports. ok niklas@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
along with the ADD message.
|
|
|
|
|
|
conf space on failure to establish dynamic SA. ok niklas@
|
|
exchange, and generalize certificate copying by taking advantage of
the new routines in the cert handler.
|
|
|
|
discovered to have rebooted, and old now invalid SAs had to be garbage-
collected.
|
|
|
|
|
|
SAs match.
|