summaryrefslogtreecommitdiff
path: root/sbin/isakmpd
AgeCommit message (Collapse)Author
2001-08-11Allocate slightly larger buffer for cert.Angelos D. Keromytis
2001-08-02Let the example config use suites that actually work together.Hakan Olsson
2001-07-29-Wunused for KAME caseJun-ichiro itojun Hagino
2001-07-25pf_key_v2_flow: sync success and failure messages; ok niklas@Markus Friedl
2001-07-25CFG mode changes: send attributes of size 0 if attribute is not availableMarkus Friedl
fix several if statements, ok ho@
2001-07-25do not setup identity extensions for KAME; ok angelos@Markus Friedl
2001-07-20we don't like:Mike Pechkin
o) .Pp before/after .Sh; o) .Pp before/after .Rs/.Re; o) .Nm without argument in SYNOPSIS;
2001-07-18protect #define MAX(); ok ho@Markus Friedl
2001-07-18minor updates.Markus Friedl
2001-07-18use correct length for SADB_X_EXT_POLICY message on KAMEMarkus Friedl
tested on bsd/os; ok ho@
2001-07-13Be more verbose about why X509_verify_cert() failed. Thanks toHakan Olsson
<sakane@kame.net> for pointing out X509_verify_cert_error_string(). :)
2001-07-13Add lc_X509_verify_cert_error_string().Hakan Olsson
2001-07-11Return 0 on success, convert exit to returnAngelos D. Keromytis
2001-07-10(c)-2001Hakan Olsson
2001-07-10Rewrite packet capture to handle IPv6 addresses.Hakan Olsson
2001-07-10htonl() for null.null_family, ok niels@, ho@Markus Friedl
2001-07-06styleNiklas Hallqvist
2001-07-06Style.Hakan Olsson
2001-07-06Remove support for PF_ENCAP (deprecated since OpenBSD2.5).Hakan Olsson
2001-07-06On second thought, we don't need this at all.Hakan Olsson
2001-07-06Remove the .c and .h files that the build process generates.Hakan Olsson
2001-07-05Use -W{missing,strict}-prototypes.Hakan Olsson
2001-07-05Add prototypes and some other various cleanup.Hakan Olsson
2001-07-05Add d2i_X509_NAMEAngelos D. Keromytis
2001-07-05Document ASN1 DN.Angelos D. Keromytis
2001-07-05DER_ASN1_DN ID handling --- untestedAngelos D. Keromytis
2001-07-05On closer inspection, freeing the X509 names is bad. I should stopAngelos D. Keromytis
coding late while half-asleep.
2001-07-05Free X509 names in case of failure and when done.Angelos D. Keromytis
2001-07-04Merge entries.Angelos D. Keromytis
2001-07-04Better handling of Key IDs.Angelos D. Keromytis
2001-07-04Some text on KEY_ID payloads.Angelos D. Keromytis
2001-07-04Better IPv6/IPv4 integrationNiklas Hallqvist
2001-07-04IPv6Niklas Hallqvist
2001-07-03Fix policy information for IPv6 subnet/range cases. This is ugly, I'llAngelos D. Keromytis
have to find another way of dealing with IPv6 addresses.
2001-07-03sync set_spi with netbsd (fixes typo).Markus Friedl
2001-07-03strlcpy->strncpy for nowMarkus Friedl
2001-07-03Wait with strlcpy a while, change to strncpy.Hakan Olsson
2001-07-03use strlcpy instead of memcpy to copy stringsHakan Olsson
2001-07-03Slightly more verbose error messages.Hakan Olsson
2001-07-02make the alpha happyTheo de Raadt
2001-07-01Remove warnings from non-DDEBUG case; angelos told me.Niklas Hallqvist
2001-07-01ISAKMP configuration, a.k.a IKECFG or "mode-config", protocol implementation.Niklas Hallqvist
Disabled, has no configuration mechanism yet. This will be used for roaming users, who are going to get parameters like IP-address and nameserver from its peer, very much like DHCP, but securily inside an ISAKMP connection and still in time before negotiation of IPsec connections. You may see stylistic fixes in this commit too. Add some not yet used Makefile magic to deal with DNSSEC- enabled OpenSSL too. The IKECFG code work was sponsered by Gatespace Inc. Thank you! Configuration will come very soon, btw.
2001-07-01strtol strictness. Style. Do not use dst end on an unconnected socket.Niklas Hallqvist
This should fix the IPv6 work for this round, There has been code by ho@ too in most my recent commits, we did this on Boston Logan airport, on our way home from !c2k1, the OpenBSD hackathon.
2001-07-01More Style police, but also sane checking of addressNiklas Hallqvist
family vs stated ID-type.
2001-07-01strict strtol checking. text2sockaddr/sockaddr2text implementationsNiklas Hallqvist
for systems without get{addr,name}info calls. Some style police.
2001-07-01StyleNiklas Hallqvist
2001-07-01Style policeNiklas Hallqvist
2001-07-01Regression test for isakmpd utility functions, initially just text2sockaddr.Niklas Hallqvist
2001-07-01Start support for IPv6 addresses in policy.Angelos D. Keromytis
2001-07-01Set size correctly for IPv6 Phase 1 IDs.Angelos D. Keromytis