Commit Graph

779 Commits

Author SHA1 Message Date
manu
bd592e6e99 Really delete phase 1 on Xauth failure 2005-05-20 07:34:47 +00:00
manu
48fade8581 Fix NAT-T plus IPcomp 2005-05-20 01:28:13 +00:00
manu
c6660c31c6 Fix parse bug in IPsec policies 2005-05-20 00:57:33 +00:00
manu
2e090d4afb When altering the lifetime, don't modify to configured proposal, duplicate
it instead.
2005-05-20 00:54:55 +00:00
christos
137ea645ec PR/30198: Lubomir Sedlacik: The forwarding listening host is optional; don't
try to free it.
2005-05-18 16:11:11 +00:00
manu
6add206c2f - Fix a double free
- For acquire messages, when NAT-T is in use, consider null port as a
  wildcard and use IKE port
2005-05-13 14:09:44 +00:00
manu
a5a80e2b4d Update sample config file to higher security settings 2005-05-10 10:22:03 +00:00
manu
aed94b2d22 Add two Cisco extensions for pushing PFS group and save password
setting throug ISAKMP mode config
2005-05-10 09:54:43 +00:00
manu
db7c068992 proposal_check fixes:
- fix claim behavior in phase 1
- also check lifebyte
2005-05-10 09:23:36 +00:00
lukem
56b6919254 Remove a stale #endif, and add one missing at EOF.
Noticed by code inspection and confirming by diffing against the vendor source.
The previous code compiled, but it certainly wouldn't have DTRT ...
2005-05-08 23:30:46 +00:00
christos
0a3fafc305 Update PAM from the "portable openssh" 4.0p1 2005-05-08 21:15:04 +00:00
he
8d29e11e90 Add a prototype for getph2bysaddr(), fixes build problem for isakmp.c. 2005-05-08 14:14:18 +00:00
manu
873e8e21a9 More NAT-T fixes for the situation where racoon acts as a VPN client
Flush SA and generated SP on DPD timeout and deletion payloads
2005-05-08 08:57:26 +00:00
manu
63a609062e From Manisha Malla <mmanisha@novell.com>:
fix unsigned int checked for being negative
2005-05-04 17:23:10 +00:00
manu
8bf053b3f3 on phase 2 acquire, lookup phase 2 by (src, dst, policy id) so that
multiple SA can be used in transport mode

While I'm there, patch ipsec-tools ChangeLog to reflect the changes we
took from ipsec-tools-0_6-branch
2005-05-03 21:08:47 +00:00
uwe
f3b48582e5 return statements in void functions make lint very confused. 2005-04-27 22:38:56 +00:00
manu
10802677c9 Bug fixes from the ipsec-tools 0.6 branch:
- Fix NAT-T problems that prevented multiple peers behind the same NAT
  to talk to the same machine outside the NAT. This also require kernel
  fixes (already committed eralier)
- Fix a LP64 bug
- Fix NAT-T RFC conformance bugs (missing non ESP marker in packets)
- Add a -p option to setkey to display ports that could be used for ESP
  over UDP when printing policies
2005-04-27 05:19:49 +00:00
matt
d627c3edde Don't emit struct units [] anymore. emit a struct units * const foo and
in the C file initialize that to the static list.
2005-04-25 17:20:51 +00:00
matt
5ac7f26c22 Emit headers with #include <parse_units.h> so that struct units is defined
so that extern struct units <foo> will not cause errors with gcc4.x
2005-04-25 01:25:25 +00:00
kleink
14fc3b7ba8 Fix printf format/argument mismatch. 2005-04-24 13:31:01 +00:00
christos
a8090b3963 add back moduli 2005-04-23 21:12:47 +00:00
christos
31ed567522 resolve conflicts. 2005-04-23 19:31:14 +00:00
christos
ed314b4eb0 from www.openssl.org 2005-04-23 19:10:56 +00:00
christos
0df7655544 bring back files that this update removed. 2005-04-23 16:55:03 +00:00
christos
8471a3b7da resolve conflicts. 2005-04-23 16:53:28 +00:00
christos
70917d9a4b Import OpenSSH 4.0 from ftp.openbsd.org 2005-04-23 16:28:01 +00:00
manu
6845962b31 Fix simple DES support (security problems for racoon to racoon setups)
Fix broken generated policies flush
2005-04-19 19:42:08 +00:00
christos
97b2d3b1c8 check for pwd != NULL in getpwnam_r. From John Nemeth. 2005-04-19 12:55:31 +00:00
manu
d3e5d568cd Fix SA lifebyte check 2005-04-18 11:15:01 +00:00
wiz
e35111eeee Some more minor changes, ok manu@. 2005-04-17 01:03:46 +00:00
wiz
1390e25dcf Some more English improvements after feedback from manu@; more formatting. 2005-04-15 13:23:58 +00:00
wiz
6e35cd769e Improve English in comments. 2005-04-15 11:10:32 +00:00
wiz
0f822df19c Improve english, improve formatting, sort options. 2005-04-15 10:58:11 +00:00
wiz
c0259e4629 Grammar fixes & improvements. 2005-04-14 11:47:26 +00:00
wiz
57066c3ab7 Grammar improvements. 2005-04-14 11:41:53 +00:00
wiz
097b641d74 kerberos -> Kerberos. 2005-04-14 11:35:08 +00:00
wiz
1b303684c3 Fix typo. 2005-04-14 11:34:37 +00:00
wiz
6b53ca1794 all SA -> all SAs. 2005-04-14 10:31:35 +00:00
wiz
6e903fbf59 New sentence, new line; some other dot fixes found during line breaking. 2005-04-14 10:30:28 +00:00
wiz
1131da3fb1 Use capitalized spelling of NetBSD. 2005-04-14 10:26:40 +00:00
wiz
6e8a3f159a Add LIBRARY section. 2005-04-14 10:25:58 +00:00
wiz
863b095e57 Punctuation nits. 2005-04-14 10:24:43 +00:00
wiz
0fb9995f39 Use Bq instead of []. 2005-04-14 10:24:18 +00:00
wiz
75b3bff7ae Punctuation nits. 2005-04-14 10:23:38 +00:00
wiz
dd317f6217 Use .In for header files. 2005-04-14 10:22:11 +00:00
wiz
9e8d46e23b No dot at end of SEE ALSO; Xr fixes. 2005-04-14 10:21:22 +00:00
wiz
9582558bf7 Mostly punctuation nits; break line after Xr arguments. 2005-04-14 10:20:01 +00:00
wiz
954b6abb72 Fix Dd and Dt arguments; fix two more typos; add comma in SEE ALSO;
format author with An/Aq.
2005-04-14 10:15:58 +00:00
wiz
2299aab679 We want .Os without argument. 2005-04-14 10:13:10 +00:00
wiz
f6b271af05 Add missing .Os. 2005-04-14 10:13:03 +00:00