Age | Commit message (Collapse) | Author | Files | Lines |
|
- fix sha2 computation (was in patch-ag)
- plug some memory leaks
- more strict isakmp header length check
- correct phase 2 proposal reqid handling
- check for fd_set overrun
|
|
have been converted to USE_BUILDLINK2.
|
|
|
|
unique policy is corrected.
|
|
|
|
file descriptor leak fix.
null encryption algorithm key length fix (should use 0).
couple of null-pointer reference fixes.
set port # to 500 in ID payload (possible interop issue - spec is unclear).
correctly match address pair on informational exchange.
|
|
|
|
- bugfixes in spd handling, scheduler leak.
- make identity check more strict.
- correct phase 2 proposal check.
|
|
bakeoff.
|
|
wrapped by configure.in scripts, however, we don't use them for libipsec part.
|
|
From: Michael Richardson <mcr@sandelman.ottawa.on.ca>
|
|
is not available in *BSD integrated KAME IPsec tree.
|
|
key changes:
-B flag, DH shared secret length handling fix, logging level fix,
gssapi support (not enabled, may not work on plain 1.5 due to issue in
kerberos library)
|
|
sync with kame
|
|
- validate initial contact better.
- more fine-grained control over pre-shared key configuration.
- cert fixes.
|
|
from shigeru@iij.ad.jp. sync with KAME.
|
|
|
|
- disable idea/rc5 in phase 1 by default
- use official DOI # for AES (= rijndael)
- be more careful about parsing variable-length packet content
- have __attribute__((__packed__)), be friendly with align-picky arch
(confirmed to be working on i386, sh3 and alpha)
|
|
|
|
changes: lots of stabilization (made during interop tests with bunch of
other implementations), certificate support improvement, security issue fix
(admin tcp port, without authentication, was open previously)
|
|
certificate improvements. bug fix in policy matching. make pfs/policy
matching strictness configurable. other logs can be found at
http://www.kame.net/dev/cvsweb.cgi/kame/CHANGELOG.
|
|
explicitly specified in a Phase-1 proposal statement.
Patch sent to sakane@kame.net.
|
|
- improvements in multiple address case
- sync with improvements in INET2000 bakeoff
|
|
(does not use anoncvs any more).
changes in racoon itself is way too many to mention. for full changelog refer
http://www.kame.net/dev/cvsweb.cgi/kame/CHANGELOG.
|
|
|