Commit Graph

806 Commits

Author SHA1 Message Date
Andreas Steffen 636a7d2bc3 whitelisting can already be enabled in strongswan.conf 2011-05-14 17:11:15 +02:00
Andreas Steffen 8afbc768f3 added ikev2/rw-whitelist scenario 2011-05-12 21:11:01 +02:00
Andreas Steffen 1ef7a2ef94 with the 2.6.38 kernel alice is preferred for handling the IKE connections 2011-04-08 07:50:20 +02:00
Andreas Steffen 7346114e9c added ikev2/rw-eap-peap-mschapv2 scenario 2011-04-06 19:44:58 +02:00
Andreas Steffen 35e2a87e1e added ikev2/rw-eap-peap-md5 scenario 2011-04-06 19:44:30 +02:00
Andreas Steffen 119b0a45a1 added ikev2/rw-eap-peap-radius scenario 2011-04-06 19:42:52 +02:00
Andreas Steffen bf2233b32d updated ikev2/rw-eap-tnc scenarios 2011-04-01 19:44:25 +02:00
Andreas Steffen 3f5647819b redirect debug output of imc/imv pairs to syslog 2011-03-19 23:23:52 +01:00
Andreas Steffen b03dd40fe6 some changes to the ikev2/rw-eap-tnc-11|20 scenarios 2011-03-19 16:48:06 +01:00
Andreas Steffen 357894c692 af-alg plugin does not require hmac and xcbc plugins 2011-03-18 09:55:26 +01:00
Andreas Steffen ae04b73eb4 added af-alg-ikev1/alg-camellia scenario 2011-03-18 07:39:21 +01:00
Andreas Steffen ec160f132c added af-alg-ikev2/alg-camellia scenario 2011-03-18 07:34:48 +01:00
Andreas Steffen efe7e863e7 added the af-alg-ikev1/rw-cert scenario 2011-03-17 23:16:41 +01:00
Andreas Steffen d6946481ae added the af-alg-ikev2/rw-cert scenario 2011-03-17 22:55:26 +01:00
Andreas Steffen 76c8b190f8 removed ipsec up %startall from scenario descriptions 2011-02-10 10:03:59 +01:00
Andreas Steffen f04d1c2dfe replaced ipsec up %startall command by start_action job 2011-02-09 22:27:04 +01:00
Andreas Steffen 2ecafc7316 added openssl-ikev2/critical-extension scenario 2011-02-08 22:58:31 +01:00
Andreas Steffen 2ee4cb6430 added ikev2/critical-extension scenario 2011-02-08 07:05:23 +01:00
Tobias Brunner 84545f6e7c Some typos fixed. 2011-02-07 11:39:41 +01:00
Andreas Steffen 3891b75628 disable INITIAL_CONTACT message by setting unigueids=no 2011-02-02 15:58:40 +01:00
Andreas Steffen f808aa2c44 load constraints plugin in ikev2/multi-level-ca-pathlen scenario 2011-01-31 14:46:16 +01:00
Andreas Steffen ec9f8440f3 adapted some UML timings 2011-01-31 09:38:22 +01:00
Andreas Steffen 3ba7616d8f added ikev2/rw-eap-tnc-dynamic scenario 2011-01-31 07:30:41 +01:00
Andreas Steffen e27554144a increase sleep time in mediation scenarios 2010-12-12 21:54:44 +01:00
Andreas Steffen 458e7779a8 reorganized ikev2/rw-eap-tnc scenarios 2010-12-12 12:51:14 +01:00
Andreas Steffen 146e9123a2 added the ikev2/rw-eap-tnc-20 scenario 2010-12-12 10:47:16 +01:00
Andreas Steffen 2965eb3cc7 added sql/multi-level-ca scenario 2010-12-05 21:53:43 +01:00
Andreas Steffen f143f0f743 use a composite test proposal 2010-12-01 10:05:28 +01:00
Andreas Steffen cbdcca7fd7 renamed algorithm to proposal 2010-11-30 17:38:49 +01:00
Andreas Steffen f4e5acef3a store IKE and ESP proposals in SQL database 2010-11-30 17:03:21 +01:00
Andreas Steffen b62bde3b95 configured various DPD modes in sql scenarios 2010-11-28 17:41:27 +01:00
Andreas Steffen 11c904b373 added sql/net2net-route-pem scenario 2010-11-28 12:00:44 +01:00
Andreas Steffen d6a13b895f added sql/net2net-start-pem scenario 2010-11-28 12:00:19 +01:00
Andreas Steffen d16ecc1753 fixed iptables script of gateway alice 2010-11-20 21:01:54 +01:00
Andreas Steffen aafe3b090e removed copy of strongswancCert.pem 2010-11-20 20:34:21 +01:00
Andreas Steffen 4a8ebe0b35 added ha/both-active scenario 2010-11-20 20:16:26 +01:00
Andreas Steffen 8d01a80819 do not send certificate requests in EAP-ONLY scenarios 2010-10-14 21:10:03 +02:00
Andreas Steffen ea7c8b3880 added ikev2/rw-eap-tnc-ls scenario 2010-10-14 21:00:41 +02:00
Andreas Steffen cf76984c28 Define explicit IKEv1 keyexchange mode V 2010-10-14 16:13:52 +02:00
Andreas Steffen 6587f1a04d increase eap-tls max_message_count in fragments scenario 2010-10-14 16:09:44 +02:00
Tobias Brunner 972663ccb0 Define explicit IKEv1 keyexchange mode IV. 2010-10-14 13:55:04 +02:00
Andreas Steffen 897a9baaba define explicit IKEv1 keyexchange mode III 2010-10-14 07:34:13 +02:00
Andreas Steffen a885f0737c fixed ikev2/rw-eap-ttls-radius scenario 2010-10-14 07:26:10 +02:00
Andreas Steffen d8a379e1e4 fixed ikev2/rw-eap-tnc-radius-block scenario 2010-10-14 07:22:39 +02:00
Andreas Steffen adf5ebaa28 fixed ikev2/rw-eap-tnc scenario 2010-10-14 07:08:33 +02:00
Andreas Steffen c763ec09db fixed ikev2/rw-eap-sim-radius scenario 2010-10-14 07:01:06 +02:00
Andreas Steffen 15a7b95f86 fixed ikev2/rw-eap-sim-only-radius scenario 2010-10-14 06:55:06 +02:00
Andreas Steffen 907ca3d4df fixed ikev2/mult-auth-rsa-eap-sim-id 2010-10-14 06:41:26 +02:00
Andreas Steffen e6f685b0fa scenarios without RADIUS server can use default iptables script 2010-10-11 17:04:53 +02:00
Andreas Steffen e5f5f612bd fixed some evaltest.dat files 2010-10-11 16:58:12 +02:00
Andreas Steffen 7d8cb1f952 added ikev2/rw-eap-tnc-block scenario 2010-10-11 16:58:12 +02:00
Andreas Steffen 8efd583a64 explicit ikev1 key exchange for ikev1/esp-alg-null scenario 2010-10-09 22:07:51 +02:00
Andreas Steffen 1e6c92789e fixed typo 2010-10-09 22:05:26 +02:00
Andreas Steffen 74e14ed631 define explicit IKEv1 key exchange mode II 2010-10-09 20:04:00 +02:00
Andreas Steffen ed08f7ce83 use DBG_TNC for TNC debugging output 2010-10-09 16:01:19 +02:00
Andreas Steffen db24b600fb changed filter attribute from access to allow 2010-10-09 01:01:19 +02:00
Andreas Steffen a1afa8d810 added ikev2/rw-eap-tnc scenario 2010-10-09 00:59:31 +02:00
Andreas Steffen 8dcc56dcc0 created tnc-imc and tnc-imv plugins 2010-10-07 23:31:23 +02:00
Andreas Steffen 84babfb895 define explicit IKEv1 key exchange mode 2010-10-07 07:31:44 +02:00
Andreas Steffen 9b201cf859 host venus is used in ikev2/rw-eap-tnc-radius scenario 2010-10-06 10:38:18 +02:00
Andreas Steffen 541666b89f added ikev2/rw-eap-tnc-radius-block scenario 2010-10-06 10:32:50 +02:00
Andreas Steffen 48e16e0ae1 final version of ikev2/rw-eap-tnc-radius scenario 2010-10-05 20:38:34 +02:00
Andreas Steffen 9ffa3f71f2 fixed typo in image path 2010-10-05 09:09:58 +02:00
Andreas Steffen e7104a6ec9 updated ikev2/rw-eap-tnc-radius scenario 2010-10-05 07:56:57 +02:00
Andreas Steffen 30f14b7066 added configuration files for dummyimc.so IMC 2010-10-01 00:14:44 +02:00
Andreas Steffen ea893a5de2 The TNC@FHH TNC Serve does not like symbolic links 2010-09-30 23:35:24 +02:00
Andreas Steffen cae4668ffb added tnc_config files to TNC scenario 2010-09-30 12:42:18 +02:00
Andreas Steffen 440231e863 load tnccs-11 plugin in ikev2/rw-eap-tnc-radius scenario 2010-09-28 23:52:59 +02:00
Andreas Steffen 280c8ea2f0 stop gateway after clients in order to check release of virtual IP 2010-09-26 11:31:39 +02:00
Andreas Steffen 1e6cc07ee4 stop gateway after clients in order to check release of virtual IP 2010-09-26 10:58:28 +02:00
Andreas Steffen 234aaf2df2 stop gateway after clients in order to check release of virtual IP 2010-09-26 10:35:12 +02:00
Andreas Steffen 939c4bf2e8 added ikev1/net2net-same-nets scenario 2010-09-09 13:37:30 +02:00
Andreas Steffen 2774826995 added openssl-ikev2/rw-eap-tls-only scenario 2010-09-07 17:14:32 +02:00
Andreas Steffen 6d71f4dcb9 updown script variable is called PLUTO_UDP_ENC 2010-09-03 12:58:10 +02:00
Andreas Steffen 6deeacd965 adapted debug options 2010-09-03 09:29:56 +02:00
Andreas Steffen 4cbe758cd4 adapted debug options 2010-09-03 09:27:16 +02:00
Andreas Steffen 5175adee66 optimized FreeRadius scenarios for debug output 2010-09-02 22:19:37 +02:00
Andreas Steffen 0fb2980281 added ikev2/rw-eap-tnc-radius scenario 2010-09-02 22:19:37 +02:00
Tobias Brunner fe962bc788 testing: Added ikev1 xfrm mark scenarios. 2010-09-02 19:04:25 +02:00
Tobias Brunner f23e7394ae pluto: Added PLUTO_UDP_ENC argument to updown script.
This contains the remote UDP port in case of UDP encapsulated ESP.
2010-09-02 19:04:25 +02:00
Tobias Brunner 91ea48352c testing: Adding kernel-netlink to pluto.load statements. 2010-09-02 19:04:22 +02:00
Tobias Brunner cc9cfc2e11 testing: Added missing host alice to test.conf. 2010-09-02 19:04:22 +02:00
Andreas Steffen 4171cbd60b adapted evaltest.dat to new RULE_OCSP_VALIDATION 2010-09-01 22:22:27 +02:00
Andreas Steffen 873604dd7f defined aaa_identity 2010-09-01 00:16:19 +02:00
Andreas Steffen 1bc8690f54 replaced ikev2/esp-alg-aes-ctr by ikev2/alg-aes-ctr 2010-08-29 21:52:08 +02:00
Andreas Steffen 6297dc390f added ctr ccm and gcm plugins to ikev2/rw-cert scenario 2010-08-29 21:11:00 +02:00
Andreas Steffen 8eb74facfe added ctr ccm and gcm plugins to openssl-ikev2/rw-cert scenario 2010-08-29 21:09:25 +02:00
Andreas Steffen 6aa82ec280 added ctr ccm and gcm plugins to gcrypt-ikev2/rw-cert scenario 2010-08-29 20:50:37 +02:00
Andreas Steffen 4f2a0bd839 replaced ikev2/esp-alg-aes-gcm by ikev2/alg-aes-gcm 2010-08-29 20:39:51 +02:00
Andreas Steffen 8318d88450 replaced ikev2/esp-alg-aes-ccm by ikev2/alg-aes-ccm 2010-08-29 20:24:12 +02:00
Andreas Steffen 421a529f88 added ikev2/rw-eap-tls-fragments scenario 2010-08-24 10:12:15 +02:00
Andreas Steffen 234aa8ee03 use correct network diagram 2010-08-24 10:09:58 +02:00
Andreas Steffen f9a2d4bfcb describe EAP-TTLS phase2 start options using the phase2_piggyback parameter 2010-08-16 19:29:39 +02:00
Andreas Steffen cf95e162f2 added ikev2/rw-eap-ttls-phase2-piggyback scenario 2010-08-16 18:32:00 +02:00
Andreas Steffen f2b9b9725c changed ikev2/rw-eap-ttls-only description 2010-08-16 18:30:41 +02:00
Andreas Steffen d2be215a99 added ikev2/rw-eap-ttls-only scenario 2010-08-16 16:44:13 +02:00
Andreas Steffen 758d7283fb used default ipsec.secrets 2010-08-15 12:49:14 +02:00
Andreas Steffen d662a7ffad included bad case in ikev2/rw-eap-ttls-radius scenario 2010-08-15 11:13:41 +02:00
Andreas Steffen e8f971ee4e added rw-eap-ttls-radius scenario 2010-08-14 20:05:21 +02:00
Andreas Steffen 6ac797ad3a added ikev2/rw-eap-tls-radius 2010-08-05 19:28:06 +02:00
Andreas Steffen 6b717cc28d no need for strongSwan VID since the EAP_ONLY notification has been officially registered with IANA 2010-08-05 12:47:09 +02:00
Andreas Steffen f8bb082f1f added ikev2/rw-eap-tls-only scenario 2010-08-04 08:36:27 +02:00
Andreas Steffen ff7b0dd289 added NETMAP rules for the reverse direction 2010-07-27 21:16:44 +02:00
Andreas Steffen c100dd6b5f fixed description of ikev2/net2net-same-nets scenario 2010-07-27 20:50:28 +02:00
Andreas Steffen c74c4c2a20 added net2net-same-nets 2010-07-25 11:56:33 +02:00
Andreas Steffen e93f452825 remove the private updown scripts after use 2010-07-17 23:25:15 +02:00
Andreas Steffen 15fd135564 minor fixes in the ikev2/rw-mark-in-out scenarios 2010-07-17 17:36:04 +02:00
Andreas Steffen f5baa5c4cf some reformulations 2010-07-17 17:19:26 +02:00
Andreas Steffen d2d7ed9227 the ikev2/nat-two-rw-mark and ikev2/rw-mark-in-out scenarios use the PLUTO_MARK_IN and PLUTO_ESP_ENC variables in the mark_update script 2010-07-17 16:32:47 +02:00
Andreas Steffen 34e93c0280 fix html error in scenario description 2010-07-17 13:09:28 +02:00
Andreas Steffen cde633d632 all x509 based sql scenarios require the revocation plugin 2010-07-15 23:19:52 +02:00
Andreas Steffen c349a68b2e all x509 based pfkey scenarios require the revocation plugin 2010-07-15 23:17:37 +02:00
Andreas Steffen f5731b4579 all x509 based p2pnat scenarios require the revocation plugin 2010-07-15 23:07:12 +02:00
Andreas Steffen 295d9cc313 all x509 based ipv6/*-ikev2 scenarios require the revocation plugin 2010-07-15 23:02:17 +02:00
Andreas Steffen 84fe65bd43 all x509 based ike scenarios require the revocation plugin 2010-07-15 22:40:20 +02:00
Andreas Steffen 001787b3eb all x509 based openssl-ikev2 scenarios require the revocation plugin 2010-07-15 22:33:05 +02:00
Andreas Steffen 6c2bd2a7d8 all x509 based gcrypt-ikev2 scenarios require the revocation plugin 2010-07-15 22:03:16 +02:00
Andreas Steffen 2cf4d34f2f all x509 based ikev2 scenarios require the revocation plugin 2010-07-15 21:39:01 +02:00
Andreas Steffen afe5d482db ikev2/net2net-psk-dscp does not need certificate support 2010-07-15 21:37:45 +02:00
Andreas Steffen a3527c39dd add revocation plugin to ikev2/rw-cert scenario 2010-07-15 20:03:11 +02:00
Martin Willi f90d465ce2 Added addrblock plugin to RFC3779 test cases 2010-07-13 10:26:07 +02:00
Martin Willi 1f457546c1 Added revocation plugin to ikev2 crl/ocsp test cases 2010-07-13 10:26:07 +02:00
Andreas Steffen bb021fbbc9 updated ikev2/ip-two-pools-db scenario to support pool and identity based dns attributes 2010-07-12 20:54:40 +02:00
Andreas Steffen f65e0dc80f added ikev2/net2net-psk-dscp2 DiffServ scenario 2010-07-09 11:55:01 +02:00
Andreas Steffen 9f94906815 added ikev2/nat-two-rw-mark-in-out scenario 2010-07-09 09:36:03 +02:00
Andreas Steffen bcf608c848 some changes to the ikev2/nat-two-rw-mark scenario 2010-07-09 09:35:02 +02:00
Andreas Steffen 36b3c0a8dd regenerated loop intermediate CA certificates 2010-07-03 18:18:30 +02:00
Andreas Steffen 342fc85e9e added ikev2/nat-two-rw-mark scenario 2010-07-03 13:25:09 +02:00
Andreas Steffen b3f65304ba check for installed aead algorithms in kernel 2010-06-27 22:26:00 +02:00
Andreas Steffen 39e3b58fe4 use --addattr 2010-06-05 13:49:01 +02:00
Andreas Steffen 88613f159d use --addattr 2010-06-05 13:47:23 +02:00
Andreas Steffen 4321d19d1e added ikev2/nat-virtual-ip scenario 2010-06-05 13:42:28 +02:00
Andreas Steffen 5a9a255ae5 share pool in ikev1/mode-config-multiple scenario 2010-06-05 13:17:51 +02:00
Andreas Steffen 6d989d356b use --addattr 2010-06-05 13:15:03 +02:00
Andreas Steffen bdd28aa9c5 remove stray scenario files 2010-06-05 13:10:39 +02:00
Andreas Steffen 5b6200888b remove x509 plugin from openssl-ikev1 scenarios 2010-05-28 23:22:15 +02:00
Andreas Steffen bd371ccac7 remove x509 plugin from remaining openssl-ikev2 scenarios 2010-05-25 15:49:58 +02:00
Andreas Steffen 2996cb3163 openssl-ikev2/rw-cert scenario doesn't need x509 plugin any more 2010-05-25 15:26:46 +02:00
Andreas Steffen b596f4f260 updated ikev1/rw-cert scenario to support xauth integrity test 2010-05-19 08:31:39 +02:00
Andreas Steffen 73434ce9eb updated ikev1/xauth-rsa-mode-config scenario to support xauth plugin 2010-05-18 22:57:12 +02:00
Andreas Steffen 1fe5d973cb updated ikev1/xauth-psk-mode-config scenario to support xauth plugin 2010-05-18 22:56:42 +02:00
Andreas Steffen 17adc8d074 updated ikev1/xauth-psk-mode-config scenario to support xauth plugin 2010-05-18 22:48:37 +02:00
Andreas Steffen efde96b38e updated ikev1/xauth-rsa-nosecret scenario to support xauth plugin 2010-05-18 20:20:55 +02:00
Andreas Steffen 4f1110ab7b created ikev1/xauth-id-psk scenario 2010-05-18 20:04:52 +02:00
Andreas Steffen dc5d63a599 updated ikev1/xauth-psk scenario to support xauth plugin 2010-05-18 20:04:02 +02:00
Andreas Steffen 8ebc3da64c updated ikev1/xauth-rsa-fail scenario to xauth plugin 2010-05-18 16:54:25 +02:00
Andreas Steffen 2549ff7849 created ikev1/xauth-id-rsa scenario using XAUTH identities 2010-05-18 16:54:25 +02:00
Andreas Steffen 0a6085b13e updated ikev1/xauth-rsa scenario to xauth plugin 2010-05-18 16:54:25 +02:00
Andreas Steffen 20ae6eccf5 the keyid is a subjectKeyIdentifier 2010-05-15 17:03:04 +02:00
Andreas Steffen ccfd54e68d fixed keyids in sql/rw-psk-rsa-split scenario 2010-05-15 16:55:08 +02:00
Andreas Steffen 4636f1579c fixed keyids in sql/rw-eap-aka-rsa scenario 2010-05-15 16:44:53 +02:00
Andreas Steffen 88e180489a fixed keyids in sql/rw-cert scenario 2010-05-15 16:34:50 +02:00
Andreas Steffen 829b790e5b fixed keyids in sql/net2net-cert scenario 2010-05-15 16:20:34 +02:00
Andreas Steffen d147de932e inserted newline 2010-05-15 16:13:22 +02:00
Andreas Steffen c572f93ed7 fixed keyids in sql/ip-split-pools-db-restart scenario 2010-05-15 16:11:08 +02:00
Andreas Steffen 2948e3d0c2 fixed keyids in sql/ip-split-pools-db scenario 2010-05-15 13:40:11 +02:00
Andreas Steffen 1ae9353d8a fixed keyids in sql/ip-pool-db-restart scenario 2010-05-15 13:22:49 +02:00
Andreas Steffen f2c84bd890 fixed keyids in sql/ip-pool-db-expired scenario 2010-05-15 13:07:22 +02:00
Andreas Steffen 0ee2c5e9be fixed keyids in sql/ip-pool-db scenario 2010-05-15 13:06:48 +02:00
Andreas Steffen b8520ad50d adapted evaltest of ikev1/ip-pool-db-push scenario to resolve plugin 2010-05-14 17:26:59 +02:00
Andreas Steffen 9e229e284f adapted evaltest of ikev1/ip-pool-db scenario to resolve plugin 2010-05-14 17:20:28 +02:00
Andreas Steffen a273546854 adapted evaltest of ikev1/mode-config-push scenario to resolve plugin 2010-05-14 15:12:03 +02:00
Andreas Steffen 3cbf6db653 adapted evaltest to resolve plugin 2010-05-14 11:07:26 +02:00
Andreas Steffen cb9c497a86 added ikev1/alg-esp-aes-gmac scenario 2010-04-27 13:48:37 +02:00
Andreas Steffen 6f7dac0d72 added ikev2/alg-esp-aes-gmac scenario 2010-04-27 13:13:10 +02:00
Andreas Steffen 6207b63d76 added ikev1/alg-modp-subgroup scenario 2010-04-23 15:23:54 +02:00
Andreas Steffen 9239fc4a15 added ikev2/alg-modp-subgroup scenario 2010-04-23 15:03:16 +02:00
Andreas Steffen 2dbff1bf53 added ikev2/dhcp-static-client-id scenario 2010-04-23 12:56:59 +02:00
Andreas Steffen 55fe05d489 fixed optional dnsmasq.conf in the ikev2/dhcp-static-mac scenario 2010-04-23 12:38:30 +02:00
Andreas Steffen 837e9fda57 added ikev2/dhcp-static-mac scenario 2010-04-23 12:33:11 +02:00
Andreas Steffen bcd20cc987 added ikev2/dhcp-dynamic scenario 2010-04-23 11:52:37 +02:00
Andreas Steffen 6e939d2f94 added ikev1/ip-two-pools-mixed scenario 2010-04-11 17:05:42 +02:00
Andreas Steffen 2544e08ec7 IKEv1 uses Mode Config payload 2010-04-11 16:09:09 +02:00
Andreas Steffen b87edeaade added ikev1/ip-two-pools scenario 2010-04-11 16:05:54 +02:00
Andreas Steffen a4b2332fd2 remove virtual interfaces after scenario 2010-04-11 16:05:04 +02:00
Andreas Steffen b516382cc9 added ikev1/ip-pool scenario 2010-04-11 14:40:04 +02:00
Andreas Steffen b74cd9573d pluto now requires attr plugin for dns and nbns server loading from strongswan.conf 2010-04-09 21:03:44 +02:00
Andreas Steffen 6c1dc87551 recovered private keys of no CDP certificates 2010-04-07 19:38:10 +02:00
Andreas Steffen 589d175a05 recovered lost Duck CA certificates 2010-04-07 19:38:10 +02:00
Andreas Steffen e6e8eb09dd fixed ikev1/protoport-route timing 2010-04-07 13:24:58 +02:00
Andreas Steffen ef4aa67bf7 generated new research and sales CA certs for carol and dave, respectively 2010-04-07 13:05:17 +02:00
Andreas Steffen 7d00ebfb54 wait one second before running evaluations 2010-04-06 10:55:59 +02:00
Andreas Steffen 5ee07585aa added ikev2/nat-virtual-ip scenario 2010-04-05 14:03:38 +02:00
Andreas Steffen eb11d1c58c added ikev2/farp scenario 2010-04-05 12:50:32 +02:00
Andreas Steffen 5d91d4c6d7 moved attr-sql plugin to libhydra in pool scenarios 2010-03-28 22:33:30 +02:00
Andreas Steffen 44f1024705 mixed IKEv1/IKEv2 scenarios require socket-raw 2010-03-11 21:32:36 +01:00
Tobias Brunner a5166b16a1 Adding socket-default to the plugin list in all test cases. 2010-03-09 17:43:21 +01:00
Andreas Steffen 3cfbc91a98 renewed Authorization Authority certificate 2010-02-27 22:16:36 +01:00
Andreas Steffen 2d07095e01 hash-and-url avoids IP fragementation, cert and crl fetch based on IPv6 2010-02-06 12:34:41 +01:00
Andreas Steffen 76fe5500c4 hash-and-url avoids IP fragementation, cert and crl fetch based on IPv6 2010-02-06 11:39:33 +01:00
Andreas Steffen 5094bfd85f hash-and-url avoids IP fragmentation, cert and crl fetch based on IPv6 2010-02-05 20:39:13 +01:00
Andreas Steffen 61d7ff0c19 IPv6 fragment and http access are not needed in PSK scenario 2010-02-05 20:27:03 +01:00
Andreas Steffen 699c47a9be hash-and-url avoids IP fragmentation, cert and crl fetch based on IPv6 2010-02-05 20:16:26 +01:00
Andreas Steffen 1f2da75069 IPv6 frag netfilter rule not needed anymore 2010-02-05 20:04:01 +01:00
Andreas Steffen 563a177830 hash-and-url avoids IP fragmentation, cert and crl fetch based on IPv6 2010-02-05 19:58:42 +01:00
Andreas Steffen 52719d719c use static IPsec policy netfilter rules in MOBIKE scenarios 2010-02-04 10:05:44 +01:00
Andreas Steffen 0d8bdf24ff added ikev2/inactivity-timeout scenario 2010-02-03 10:28:30 +01:00
Andreas Steffen 8fb389b299 added ikev2/rw-eap-sim-only-radius scenario 2010-01-11 11:20:45 +01:00
Andreas Steffen 87eb27681a send strongSwan Vendor ID in ikev2/alg-sha256-96 scenario 2010-01-11 00:54:33 +01:00
Andreas Steffen a2847740d2 removed charon-specific load statement in pluto scenario 2009-12-26 17:13:53 +01:00
Andreas Steffen 7c697964d3 added three RFC 3779 scenarios 2009-12-25 11:20:59 +01:00
Andreas Steffen 92f0aa9736 firewall-enabled ipv6/net2net-ip6-in-ip4-ikev2 scenario 2009-12-17 19:43:33 +01:00
Andreas Steffen 02ee613325 firewall-enabled ipv6/net2net-ip4-in-ip6-ikev2 scenario 2009-12-17 18:50:45 +01:00
Andreas Steffen 98b0657c0a ikev1/ip-pool-db-push scenario tests DNS and NBNS server support 2009-12-16 21:50:39 +01:00
Andreas Steffen 4d64cbbc4e ikev1/ip-pool-db scenario tests DNS and NBNS server support 2009-12-16 21:22:13 +01:00
Andreas Steffen c236049850 sql/ip-pool-db scenario tests DNS and NBNS server support 2009-12-16 19:02:23 +01:00
Andreas Steffen 42eb4951f9 ikev2/ip-pool-db scenario tests DNS and NBNS server support 2009-12-16 18:45:29 +01:00
Andreas Steffen b75002bc95 added openssl-ikev1/alg-camellia scenario 2009-12-15 19:55:58 +01:00
Andreas Steffen 1191779744 removed superfluous ikev1/esp-alg-camellia scenario 2009-12-15 19:16:28 +01:00
Andreas Steffen cbcd91314b added gcrypt-ikev1/alg-camellia scenario 2009-12-15 19:15:44 +01:00
Andreas Steffen 25df6196df activate tcpdump in ikev1/esp-alg-des scenario 2009-12-10 22:37:43 +01:00
Andreas Steffen 982596e427 shuffled output order to achieve consistence 2009-12-09 17:26:35 +01:00
Andreas Steffen 4d025314c8 added pfkey/alg-sha384 and pfkey/alg-sha512 scenarios 2009-12-09 17:25:12 +01:00
Andreas Steffen 3e4b1010b0 adapted openssl-ikev2/alg scenarios 2009-12-09 15:51:43 +01:00
Andreas Steffen 4ab5874ccd adapted gcrypt-ikev2/alg-camellia scenario 2009-12-09 15:48:03 +01:00
Andreas Steffen fcca5b5caf adapted gcrypt-ikev1 alg scenarios 2009-12-09 15:45:45 +01:00
Andreas Steffen 8603d1d76c adapted ikev1 alg and esp scenarios 2009-12-09 15:41:54 +01:00
Andreas Steffen 4c8f3dff9c adapted pfkey alg and esp scenarios 2009-12-09 15:38:17 +01:00
Andreas Steffen 8e7e81451b remove again the ikev2/esp-alg-camellia scenario 2009-12-09 15:26:43 +01:00
Andreas Steffen 99133d3086 adapted ikev2 alg and esp scenarios 2009-12-09 15:19:10 +01:00
Andreas Steffen 344061ebce removed redundant ikev1/ike-alg-sha2 scenarios 2009-12-09 10:11:03 +01:00
Andreas Steffen 01a8af1b1b added ikev1/alg-sha512 scenario 2009-12-09 09:51:54 +01:00
Andreas Steffen cb7e304d33 added ikev1/alg-sha384 scenario 2009-12-09 09:46:40 +01:00
Andreas Steffen 5d9d779808 renamed ikev1/alg-sha2_256 scenario to ikev1/alg-sha256 2009-12-09 09:36:16 +01:00
Andreas Steffen 05ffbc6e59 added ikev1/alg-sha256-96 scenario 2009-12-09 09:35:17 +01:00
Andreas Steffen 7747210f26 removed redundant ikev2/esp-alg-camellia scenario 2009-12-09 00:24:41 +01:00
Andreas Steffen 04933ea74e added ikev2/alg-3des-md5 scenario 2009-12-08 12:54:42 +01:00
Andreas Steffen 7868162b35 added RFC-conforming ikev2/sha2 scenarios 2009-11-26 23:48:29 +01:00
Andreas Steffen 68db91ca32 adapted ikev2/alg-aes-xcbc scenario 2009-11-26 23:46:27 +01:00
Andreas Steffen 6ae43b9333 mixed fingerprint / userid 2009-11-11 11:17:59 +01:00
Andreas Steffen 262af16179 accept PGP v3 or v4 fingerprint as alternative to PGP user_id 2009-11-09 23:15:17 +01:00
Andreas Steffen b25311fbe2 added ikev2/net2net-pgp-v3 scenario 2009-11-08 23:49:04 +01:00
Andreas Steffen bc662125c2 removed nocrsend=yes statement 2009-11-08 23:48:26 +01:00
Andreas Steffen 2846e51a5b added ikev2/net2net-pgp-v4 scenario 2009-11-08 23:23:45 +01:00
Andreas Steffen 16dca5c2f2 moved multi-level-ca-pathlen scenario 2009-11-04 23:43:43 +01:00
Andreas Steffen 4c68a85a75 implemented path length constraint checkinf for IKEv2 2009-11-04 23:37:15 +01:00
Andreas Steffen 32c8b1847b renamed multi-level-pathlen scenario to multi-level-ca-pathlen 2009-11-04 18:18:43 +01:00
Andreas Steffen cd36095e38 added ikev1/multi-level-pathlen scenario 2009-11-04 18:15:26 +01:00
Andreas Steffen c95671cec2 implemented path length constraint checking for IKEv1 2009-11-04 18:10:31 +01:00
Andreas Steffen c51b78eb2a hyphenate eap-radius 2009-10-17 09:23:09 +02:00
Andreas Steffen 601e2a6986 added ipv6/net2net-ip4-in-ip6-ikev1 and ipv6/net2net-ip4-in-ip6-ikev1 scenarios 2009-10-16 15:04:17 +02:00
Andreas Steffen 50a82b419e corrected description of ikev1/ip-pool-db scenario 2009-10-15 15:25:36 +02:00
Martin Willi f48ceeb1d1 Renamed plugin configuration sections to the actual plugin name 2009-10-15 10:36:17 +02:00
Martin Willi c4d53fe06b Streamlined EAP plugins to use a dash between eap-method, as used in all other places 2009-10-15 10:36:17 +02:00
Andreas Steffen ffe6f83272 added ikev1/ip-pool-db-push scenario 2009-10-14 21:35:43 +02:00
Andreas Steffen f4c4e78296 added ikev1/ip-pool-db scenario 2009-10-14 14:51:12 +02:00
Andreas Steffen 32bc430591 fixed inconsistent triplets.dat files 2009-10-14 11:08:01 +02:00
Andreas Steffen 247794827e move SQL-based pool functionality to new attr-sql libstrongswan plugin 2009-10-13 17:02:29 +02:00
Andreas Steffen 4c8bb47abd check provenance of nameserver entry 2009-10-13 13:58:43 +02:00
Andreas Steffen cb7817a64b scepclient now requires x509 plugin 2009-10-12 19:56:21 +02:00