summaryrefslogtreecommitdiff
path: root/security/ipsec-tools
AgeCommit message (Collapse)AuthorFilesLines
2008-08-16Update to ipsec-tools 0.7.1, fixes CVE-2008-3652manu2-8/+7
Changes since the 0.6 branch: 0.7.1 - 23 July 2008 o Fixes a memory leak when invalid proposal received o Some fixes in DPD o do not set default gss id if xauth is used o fixed hybrid enabled builds o fixed compilation on FreeBSD8 o cleanup in network port value manipulation o gets ports from SADB_X_EXT_NAT_T_[SD]PORT if present in purge_ipsec_sp i() o Generates a log if cert validation has been disabled by configuration o better handling for pfkey socket read errors o Fixes in yacc / bison stuff o new plog() macro (reduced CPU usage when logging is disabled) o Try to works better with huge SPD/SAD o Corrected modecfg option syntax o Many other various fixes... 0.7 - 09 August 2007 o Xauth with pre-shared key PSK o Xauth with certificates o SHA2 support o pkcs7 support o system accounting (utmp) o Darwin support o configuration can be reloaded o Support for UNIQUE generated policies o Support for semi anonymous sainfos o Support for ph1id to remoteid matching o Plain RSA authentication o Native LDAP support for Xauth and modecfg o Group membership checks for Xauth and sainfo selection o Camellia cipher support o IKE Fragment force option o Modecfg SplitNet attribute support o Modecfg SplitDNS attribute support ( server side ) o Modecfg Default Domain attribute support o Modecfg DNS/WINS server multiple attribute support
2008-01-18Per the process outlined in revbump(1), perform a recursive revbumptnn1-1/+2
on packages that are affected by the switch from the openssl 0.9.7 branch to the 0.9.8 branch. ok jlam@
2007-04-11Update to ipsec-tools 0.6.7.ghen2-6/+6
o Fixed SHA256 detection on some systems o Fixed a DoS in Informationnal messages processing (CVE-2007-1841).
2007-02-22Whitespace cleanup, courtesy of pkglint.wiz1-2/+2
Patch provided by Sergey Svishchev in private mail.
2006-10-25Update ipsec-tools to 0.6.6.bad2-6/+6
Changes since 0.6.3: 0.6.6 * src/racoon/isakmp_xauth.c: Build fix * src/racoon/pfkey.c: Sets NAT-T ports to 0 if no NAT encapsulation in pk_sendgetspi(). * src/racoon/pfkey.c: Sets NAT-T ports to 0 if no NAT encapsulation in pk_sendupdate(). * src/racoon/isakmp_xauth.c: fix memory leak * src/racoon/{cfparse.y|handler.h}: typos 0.6.5 * src/racoon/isakmp.c: Fixed zombie PH1 handler when isakmp_send() fails in isakmp_ph1resend() * src/racoon/{cfparse.y|ipsec_doi.c}: Temporary fix for /32 subnets parsing. * src/racoon/isakmp_cfg.c: make software behave as the documentation advertise for INTERNAL_NETMASK4. Keep the old INTERNAL_MASK4 to avoid breaking backward compatibility. * src/racoon/session.c: Fixed / cleaned up signal handling. 0.6.4 * configure.ac src/racoon/plog.c: backported Fred's workaround for %zu problems on (at least) FreeBSD4. * src/racoon/session.c: backport: fix possible race conditions in signal handlers (see session.c 1.17). * src/libipsec/pfkey_dump.c: fixed compilation when NAT_T disabled (Fred has still some CVS problems). * src/libipsec/{libpfkey.h|pfkey_dump.c}: add a sadump_withports function to display SAD entries with their associated ports. * src/setkey/{parse.y|setkey.c|setkey.8}: allow to use setkey -p flag in conjunction with -D to show SADs with the port, allow both get and delete commands to use bracketed ports if needed. * src/racoon/racoon.conf.5: Style changes
2005-12-05Ran "pkglint --autofix", which corrected some of the quoting issues inrillig1-3/+3
CONFIGURE_ARGS.
2005-12-05Fixed pkglint warnings. The warnings are mostly quoting issues, forrillig1-2/+2
example MAKE_ENV+=FOO=${BAR} is changed to MAKE_ENV+=FOO=${BAR:Q}. Some other changes are outlined in http://mail-index.netbsd.org/tech-pkg/2005/12/02/0034.html
2005-11-22Update "ipsec-tools" package to version 0.6.3. Changes since 0.6.1:tron2-6/+6
- Various bug fixes - ISAKMP mode config works without Xauth This update fixes the security vulnerability reported in SA17668.
2005-09-02Mark this package as only available on NetBSD 3.0 and newer andtron1-1/+3
Linux 2.6.x and newer.
2005-08-21Update "ipsec-tools" package to version 0.6.1. Changes since 0.6.1rc1:tron3-22/+6
- src/racoon/dnssec.c: fix bogus test on function result - src/racoon/isakmp.c: Improved in/out SA addresses check in purge_remote() - src/libipsec/{key_debug.c|pfkey.c|pfkey_dump.c}: de-lint, warnings - src/racoon/privsep.c: Fixed a %d -> %zu in port_check()
2005-08-07Fix build problem under platforms were "size_t" is not an integer.tron2-1/+17
2005-08-05Update "ipsec-tools" package to version 0.6.1rc1.tron3-8/+22
Changes since version 0.6b2: - NAT-T fixes for situations where NAT-T is not used - OpenSSL 0.9.8 support - keys are not restricted to OpenSSL default size anymore - PKCS7 support - SHA2 support
2005-06-01Fix casing of IPsec in COMMENT.wiz1-2/+2
2005-05-31Packages have no business modifying PKG_DEFAULT_OPTIONS -- it's adillo1-3/+3
user settable variable. Set PKG_SUGGESTED_OPTIONS instead. Also, make use of PKG_OPTIONS_LEGACY_VARS. Reviewed by wiz.
2005-05-23Removed trailing white-space.rillig1-1/+1
2005-05-10Updated ipsec-tools to 0.6b2.manu3-11/+8
Multiple bug fixes, the most important being NAT-T now working with multiple endpoints behind the same NAT.
2005-04-11Remove USE_BUILDLINK3 and NO_BUILDLINK; these are no longer used.tv1-2/+1
2005-03-23Missing installed files inPLISTmanu1-1/+18
2005-03-23Upgrade to ipsec-tools 0.6b1.manu2-9/+10
New features: - PAM support - privilege separation
2005-02-24Add RMD160 digests.agc1-1/+2
2005-02-20Fix file installation, add missing samples config filesmanu2-4/+29
2005-02-18Upgraded ipsec-tools to release version 0.5manu11-188/+7
2005-01-12Use PKG_SYSCONFDIRkim1-1/+4
2004-12-12Add (unsigned char) cast to ctype functions; taken from the NetBSD trunk.kleink6-1/+117
2004-11-11add additional libraries required by libradius.grant1-1/+2
2004-11-11include libradius/buildlink3.mk only if we're including radiusgrant1-2/+2
support.
2004-11-11include some additional header files on FreeBSD >= 5.grant2-1/+23
2004-11-11allow radius support to be disabled by moving it to PKG_OPTIONS.grant1-2/+12
no PKGREVISION bump as it is still enabled by default.
2004-11-11Remove lex and yacc generated files before building: they might notmanu1-1/+5
match with the libraries installed on the system.
2004-11-10Add patches checksummanu1-1/+3
2004-11-10Fix minor LP64 problemsmanu2-0/+39
2004-11-10Disable nat-t by default as the kernel does not have support for itmanu1-3/+5
without an unofficial patch yet.
2004-11-10This package needs openssl bl3.mk... and it needs NAT-T kernel optionxtraeme1-1/+2
to build...
2004-11-10No need to set BUILDLINK_DEPMETHOD.libradius-linux?= build here...xtraeme1-3/+1
2004-11-10* Fix HOMEPAGE.xtraeme1-7/+5
* No need to use LIBTOOL_OVERRIDE. * Remove unneeded ${EXAMPLESDIR} (??!!) after bl3.mk includes * Remove unneeded BUILD_DEPEND, because this pkg uses bl3 Still libradius is broken...
2004-11-09racoon speaks IKE (ISAKMP/Oakley) key management protocol, tomanu4-0/+82
establish IPsec security association with other hosts. This is based on KAME racoon, with some enhancements such as NAT-Traversal (needs a kernel patch), hybrid authentication, ISAKMP mode config, RADIUS support, IKE fragmentation and others. Ipsec-tools' racoon is able to act as a VPN server for the Cisco VPN client using hybrid authentication.