strongswan/src
Tobias Brunner 47701e1178 ike-init: Verify REDIRECT notify before processing IKE_SA_INIT message
An attacker could blindly send a message with invalid nonce data (or none
at all) to DoS an initiator if we just destroy the SA.  To prevent this we
ignore the message and wait for the one by the correct responder.
2016-03-04 16:03:00 +01:00
..
_copyright lib: Add global config namespace 2014-02-12 14:34:31 +01:00
_updown updown: Add rules to allow IP6IP6 traffic used for uncompressed small packets 2015-09-21 10:12:17 +02:00
aikgen aikgen generates AIK private/public key pairs 2014-05-03 15:28:17 +02:00
charon libhydra: Remove empty unused library 2016-03-03 17:36:11 +01:00
charon-cmd libhydra: Remove empty unused library 2016-03-03 17:36:11 +01:00
charon-nm libhydra: Remove empty unused library 2016-03-03 17:36:11 +01:00
charon-svc libhydra: Remove empty unused library 2016-03-03 17:36:11 +01:00
charon-systemd libhydra: Remove empty unused library 2016-03-03 17:36:11 +01:00
charon-tkm libhydra: Remove empty unused library 2016-03-03 17:36:11 +01:00
checksum libhydra: Remove empty unused library 2016-03-03 17:36:11 +01:00
conftest libhydra: Remove empty unused library 2016-03-03 17:36:11 +01:00
dumm dumm: Fix -Wformat warning in ruby extension 2014-12-10 14:29:19 +01:00
frontends libhydra: Remove empty unused library 2016-03-03 17:36:11 +01:00
include include: Add linux/socket.h 2015-09-07 14:07:46 +02:00
ipsec ipsec: Fix stop command on systems where sleep(1) only supports integers 2015-12-10 11:46:21 +01:00
libcharon ike-init: Verify REDIRECT notify before processing IKE_SA_INIT message 2016-03-04 16:03:00 +01:00
libfast sigwaitinfo() may fail with EINTR if interrupted by an unblocked signal not in the set 2015-11-23 11:37:19 +01:00
libimcv Request missing SWID tags in a directed PA-TNC message 2016-03-04 01:04:44 +01:00
libipsec libipsec: Pass the same data to del_policy() as to add_policy() 2016-02-04 11:02:59 +01:00
libpttls Fixed AR identities in mutual TNC measurements case 2015-08-15 22:46:21 +02:00
libradius eap-radius: Add ability to configure RADIUS retransmission behavior 2015-11-17 14:25:08 +01:00
libsimaka libhydra: Remove empty unused library 2016-03-03 17:36:11 +01:00
libstrongswan thread: Allow thread ID to be value returned by gettid() 2016-03-04 09:12:11 +01:00
libtls unit-tests: Forward variable argument list in TEST_SUITE_DEPEND 2015-07-12 13:25:50 +02:00
libtnccs Fix of the mutual TNC measurement use case 2016-02-16 18:00:27 +01:00
libtncif Defined PWG HCD PA-TNC subtypes 2015-08-18 21:25:39 +02:00
manager plugins: Don't link with -rdynamic on Windows 2014-06-04 15:53:02 +02:00
medsrv medsrv: Replace remaining JavaScript code with CSS 2015-11-09 16:36:48 +01:00
pki pki: Increase MAX_LINES 2015-12-16 12:09:18 +01:00
pool libhydra: Remove empty unused library 2016-03-03 17:36:11 +01:00
pt-tls-client Optionally announce PB-TNC mutual protocol capability 2015-03-23 22:25:43 +01:00
scepclient libhydra: Remove empty unused library 2016-03-03 17:36:11 +01:00
starter libhydra: Remove empty unused library 2016-03-03 17:36:11 +01:00
stroke stroke: Fix --utc option for list* commands 2015-12-17 16:56:20 +01:00
swanctl vici: Match subnets and ranges against peer IP in redirect command 2016-03-04 16:03:00 +01:00
Makefile.am libhydra: Remove empty unused library 2016-03-03 17:36:11 +01:00