OpenBSD CVS

CVS log for src/sbin/isakmpd/isakmpd.conf.5


[BACK] Up to [local] / src / sbin / isakmpd

Request diff between arbitrary revisions


Default branch: MAIN


Revision 1.139 / (download) - annotate - [select for diffs], Tue Aug 8 10:31:03 2023 UTC (9 months, 3 weeks ago) by dlg
Branch: MAIN
CVS Tags: OPENBSD_7_5_BASE, OPENBSD_7_5, OPENBSD_7_4_BASE, OPENBSD_7_4, HEAD
Changes since 1.138: +12 -2 lines
Diff to previous 1.138 (colored)

have a go at documenting the Interface config statement.

im not really happy with this, but it's a start.

Revision 1.138 / (download) - annotate - [select for diffs], Thu Mar 31 17:27:20 2022 UTC (2 years, 2 months ago) by naddy
Branch: MAIN
CVS Tags: OPENBSD_7_3_BASE, OPENBSD_7_3, OPENBSD_7_2_BASE, OPENBSD_7_2, OPENBSD_7_1_BASE, OPENBSD_7_1
Changes since 1.137: +3 -3 lines
Diff to previous 1.137 (colored)

man pages: add missing commas between subordinate and main clauses

jmc@ dislikes a comma before "then" in a conditional, so leave those
untouched.

ok jmc@

Revision 1.137 / (download) - annotate - [select for diffs], Sun Feb 6 00:29:02 2022 UTC (2 years, 3 months ago) by jsg
Branch: MAIN
Changes since 1.136: +3 -3 lines
Diff to previous 1.136 (colored)

remove please from manual pages
ok jmc@ sthen@ millert@

Revision 1.136 / (download) - annotate - [select for diffs], Wed Nov 3 05:59:25 2021 UTC (2 years, 6 months ago) by yasuoka
Branch: MAIN
Changes since 1.135: +5 -4 lines
Diff to previous 1.135 (colored)

Clarify that ANY can be used for several parameters of IPsec transform.

ok jmc sthen

Revision 1.135 / (download) - annotate - [select for diffs], Tue Apr 17 12:13:29 2018 UTC (6 years, 1 month ago) by stsp
Branch: MAIN
CVS Tags: OPENBSD_7_0_BASE, OPENBSD_7_0, OPENBSD_6_9_BASE, OPENBSD_6_9, OPENBSD_6_8_BASE, OPENBSD_6_8, OPENBSD_6_7_BASE, OPENBSD_6_7, OPENBSD_6_6_BASE, OPENBSD_6_6, OPENBSD_6_5_BASE, OPENBSD_6_5, OPENBSD_6_4_BASE, OPENBSD_6_4
Changes since 1.134: +5 -2 lines
Diff to previous 1.134 (colored)

Document how to avoid isakmpd(8) source IP address pitfalls by using
the Listen-on directive in isakmpd.conf(5). This directive can be necessary
in multi-homed situations, and if isakmpd(8) is used with carp(4).
ok sthen@ mpi@

Revision 1.134 / (download) - annotate - [select for diffs], Fri Oct 27 08:29:32 2017 UTC (6 years, 7 months ago) by mpi
Branch: MAIN
CVS Tags: OPENBSD_6_3_BASE, OPENBSD_6_3
Changes since 1.133: +8 -6 lines
Diff to previous 1.133 (colored)

Support DH groups 19 to 21 and 25 to 30, just like iked(8) does.

ok visa@, markus@

Revision 1.133 / (download) - annotate - [select for diffs], Sun Jan 1 01:08:11 2017 UTC (7 years, 5 months ago) by tb
Branch: MAIN
CVS Tags: OPENBSD_6_2_BASE, OPENBSD_6_2, OPENBSD_6_1_BASE, OPENBSD_6_1
Changes since 1.132: +4 -4 lines
Diff to previous 1.132 (colored)

Hyphenate compound adjectives 'up-to-date', 'out-of-date' and 'well-known'
if they precede the noun and omit hyphens otherwise.

ok tj

Revision 1.132 / (download) - annotate - [select for diffs], Wed Dec 9 21:41:50 2015 UTC (8 years, 5 months ago) by naddy
Branch: MAIN
CVS Tags: OPENBSD_6_0_BASE, OPENBSD_6_0, OPENBSD_5_9_BASE, OPENBSD_5_9
Changes since 1.131: +8 -91 lines
Diff to previous 1.131 (colored)

Remove plain DES encryption from IPsec.

DES is insecure since brute force attacks are practical due to its
short key length.

This removes support for DES-CBC encryption in ESP and in IKE main
and quick mode from the kernel, isakmpd(8), ipsecctl(8), and iked(8).

ok mikeb@

Revision 1.131 / (download) - annotate - [select for diffs], Fri Jan 16 15:37:20 2015 UTC (9 years, 4 months ago) by schwarze
Branch: MAIN
CVS Tags: OPENBSD_5_8_BASE, OPENBSD_5_8, OPENBSD_5_7_BASE, OPENBSD_5_7
Changes since 1.130: +20 -39 lines
Diff to previous 1.130 (colored)

Arguments are just ".Ar", not ".Brq Ar" or even ".Ns { Ns Ar ... Ns }".
The .Ar macro already causes distinctive formatting in a standard way,
so there is no need for additional braces.
This also fixes the only mandoc warning in src/sbin.

Revision 1.130 / (download) - annotate - [select for diffs], Sun Aug 12 17:01:35 2012 UTC (11 years, 9 months ago) by schwarze
Branch: MAIN
CVS Tags: OPENBSD_5_6_BASE, OPENBSD_5_6, OPENBSD_5_5_BASE, OPENBSD_5_5, OPENBSD_5_4_BASE, OPENBSD_5_4, OPENBSD_5_3_BASE, OPENBSD_5_3
Changes since 1.129: +3 -3 lines
Diff to previous 1.129 (colored)

Use .Lk for HTTP hyperlinks, not .Pa.
Most of the patch from Arto Jonsson <ajonsson at kapsi dot fi>.
jmc@ agrees in principle that .Lk is the right macro to use.

While here, update a few broken links,
and add missing markup at a few places.

Revision 1.129 / (download) - annotate - [select for diffs], Sat Jun 30 14:51:31 2012 UTC (11 years, 11 months ago) by naddy
Branch: MAIN
CVS Tags: OPENBSD_5_2_BASE, OPENBSD_5_2
Changes since 1.128: +3 -2 lines
Diff to previous 1.128 (colored)

enable use of AES-{192,256}-CTR, and explicitly of AES-128-CTR, for IPsec ESP
ok mikeb@

Revision 1.128 / (download) - annotate - [select for diffs], Thu Jun 23 20:35:22 2011 UTC (12 years, 11 months ago) by sthen
Branch: MAIN
CVS Tags: OPENBSD_5_1_BASE, OPENBSD_5_1, OPENBSD_5_0_BASE, OPENBSD_5_0
Changes since 1.127: +9 -10 lines
Diff to previous 1.127 (colored)

Use a common text explaining how the various configuration parsers using
the standard OpenBSD-style parse.y handle continuing lines with backslashes,
paying particular attention to how comments are handled (which can cause
nasty side-effects if you're not expecting it).

Most wording from jmc@, with suggestions from fgsch@, marc@, Richard Toohey,
patrick keshishian and Florian Obser, ok jmc@.

Revision 1.127 / (download) - annotate - [select for diffs], Wed Sep 22 13:45:16 2010 UTC (13 years, 8 months ago) by mikeb
Branch: MAIN
CVS Tags: OPENBSD_4_9_BASE, OPENBSD_4_9
Changes since 1.126: +5 -3 lines
Diff to previous 1.126 (colored)

Support for use of AES-GCM-16 (as AESGCM) and ENCR_NULL_AUTH_AES_GMAC
(as AESGMAC) ciphers in the ISAKMP Phase 2 (aka Quick Mode).

Thoroughly tested by me and naddy.  Works fine with Linux.

Requires updated pfkeyv2.h include file.

ok naddy

Revision 1.126 / (download) - annotate - [select for diffs], Mon Jun 7 08:38:09 2010 UTC (13 years, 11 months ago) by jmc
Branch: MAIN
CVS Tags: OPENBSD_4_8_BASE, OPENBSD_4_8
Changes since 1.125: +3 -3 lines
Diff to previous 1.125 (colored)

make clearer the relationship between isakmpd and ikev1; and iked and ikev2;
ok reyk

Revision 1.125 / (download) - annotate - [select for diffs], Sun Feb 17 10:36:32 2008 UTC (16 years, 3 months ago) by hshoexer
Branch: MAIN
CVS Tags: OPENBSD_4_7_BASE, OPENBSD_4_7, OPENBSD_4_6_BASE, OPENBSD_4_6, OPENBSD_4_5_BASE, OPENBSD_4_5, OPENBSD_4_4_BASE, OPENBSD_4_4, OPENBSD_4_3_BASE, OPENBSD_4_3
Changes since 1.124: +174 -4 lines
Diff to previous 1.124 (colored)

Define default configurations for AES-192 and AES-256.  From Mitja Muzenic
<mitja at muzenic dot net>, diff provided already quite some time ago,
many many thanks.  This should have gone in months ago but I was slacking,
sorry for that.

Revision 1.124 / (download) - annotate - [select for diffs], Thu May 31 19:19:45 2007 UTC (17 years ago) by jmc
Branch: MAIN
CVS Tags: OPENBSD_4_2_BASE, OPENBSD_4_2
Changes since 1.123: +2 -2 lines
Diff to previous 1.123 (colored)

convert to new .Dd format;

Revision 1.123 / (download) - annotate - [select for diffs], Wed May 23 07:28:15 2007 UTC (17 years ago) by hshoexer
Branch: MAIN
Changes since 1.122: +1 -5 lines
Diff to previous 1.122 (colored)

Get rid of some obsolete exampels.

ok and prodding @jmc

Revision 1.122 / (download) - annotate - [select for diffs], Sun Mar 18 22:31:40 2007 UTC (17 years, 2 months ago) by hshoexer
Branch: MAIN
Changes since 1.121: +19 -19 lines
Diff to previous 1.121 (colored)

Fix usage of predefined lifetimes.  "Default-phase-[12]-lifetime"
just specifies the values to be used.  However, the specifications
are called "LIFE_MAIN_MODE" and "LIFE_QUICK_MODE".

ok ho@ jmc@

Revision 1.121 / (download) - annotate - [select for diffs], Mon Feb 19 14:17:56 2007 UTC (17 years, 3 months ago) by jmc
Branch: MAIN
CVS Tags: OPENBSD_4_1_BASE, OPENBSD_4_1
Changes since 1.120: +2 -2 lines
Diff to previous 1.120 (colored)

tweak;

Revision 1.120 / (download) - annotate - [select for diffs], Mon Feb 19 10:00:13 2007 UTC (17 years, 3 months ago) by hshoexer
Branch: MAIN
Changes since 1.119: +2 -2 lines
Diff to previous 1.119 (colored)

Document NULL encryption.

Revision 1.119 / (download) - annotate - [select for diffs], Fri Nov 24 13:52:14 2006 UTC (17 years, 6 months ago) by reyk
Branch: MAIN
Changes since 1.118: +36 -1 lines
Diff to previous 1.118 (colored)

add support to tag ipsec traffic belonging to specific IKE-initiated
phase 2 traffic. this allows policy-based filtering of encrypted and
unencrypted ipsec traffic with pf(4). see ipsec.conf(5) and
isakmpd.conf(5) for details and examples.

this is work in progress and still needs some testing and feedback,
but it is safe to put it in now.

ok hshoexer@

Revision 1.118 / (download) - annotate - [select for diffs], Fri Sep 15 09:49:07 2006 UTC (17 years, 8 months ago) by hshoexer
Branch: MAIN
CVS Tags: OPENBSD_4_0_BASE, OPENBSD_4_0
Changes since 1.117: +1 -7 lines
Diff to previous 1.117 (colored)

Remove "Delete-SAs" config option.  This was needed for interaction
with sasyncd(8).  Now sasyncd(8) controls isakmpd(8) regarding SA
deletion so this option is obsolete.

ok mpf jmc

Revision 1.117 / (download) - annotate - [select for diffs], Wed Aug 30 16:56:56 2006 UTC (17 years, 9 months ago) by hshoexer
Branch: MAIN
Changes since 1.116: +2 -2 lines
Diff to previous 1.116 (colored)

Make SA deletion on shutdown the default again.  Use -S for failover
situations where you do not want this.

Discussed and agreed on with ho, mcbride, markus, cloder,...  We
will have to teach sasyncd to deal with this.

Testing by msf and hshoexer with help from mtu

ok markus cloder

Revision 1.116 / (download) - annotate - [select for diffs], Sun Jun 11 11:07:41 2006 UTC (17 years, 11 months ago) by hshoexer
Branch: MAIN
Changes since 1.115: +22 -12 lines
Diff to previous 1.115 (colored)

Document AESCTR for quick mode and SHA2-* for main mode.  Help by jmc.

ok jmc@

Revision 1.115 / (download) - annotate - [select for diffs], Sun Jun 11 00:20:36 2006 UTC (17 years, 11 months ago) by jmc
Branch: MAIN
Changes since 1.114: +3 -3 lines
Diff to previous 1.114 (colored)

tweaks;

Revision 1.114 / (download) - annotate - [select for diffs], Sat Jun 10 21:23:50 2006 UTC (17 years, 11 months ago) by hshoexer
Branch: MAIN
Changes since 1.113: +7 -1 lines
Diff to previous 1.113 (colored)

Document -S and the "Delete-SAs" tag.  Those will enable SA deletion
on shutdown.

Revision 1.113 / (download) - annotate - [select for diffs], Sat Jun 10 21:09:45 2006 UTC (17 years, 11 months ago) by msf
Branch: MAIN
Changes since 1.112: +5 -1 lines
Diff to previous 1.112 (colored)

Allow isakmpd to use a different private rsa key per isakmp ID. Hans wrote this a long time ago, I synced it to -current and tested.

ok hshoexer@

Revision 1.112 / (download) - annotate - [select for diffs], Sat May 27 21:09:11 2006 UTC (18 years ago) by hshoexer
Branch: MAIN
Changes since 1.111: +6 -6 lines
Diff to previous 1.111 (colored)

document modp3072.

Revision 1.111 / (download) - annotate - [select for diffs], Fri May 26 09:30:36 2006 UTC (18 years ago) by jmc
Branch: MAIN
Changes since 1.110: +2 -2 lines
Diff to previous 1.110 (colored)

ipsectl -> ipsecctl

Revision 1.110 / (download) - annotate - [select for diffs], Fri May 26 09:26:07 2006 UTC (18 years ago) by jmc
Branch: MAIN
Changes since 1.109: +2 -3 lines
Diff to previous 1.109 (colored)

vpn.8 removal;

Revision 1.109 / (download) - annotate - [select for diffs], Fri May 26 04:02:59 2006 UTC (18 years ago) by deraadt
Branch: MAIN
Changes since 1.108: +3 -3 lines
Diff to previous 1.108 (colored)

let us not talk about ipsecadm and vpn anymore; ok reyk

Revision 1.108 / (download) - annotate - [select for diffs], Thu Oct 6 18:29:18 2005 UTC (18 years, 7 months ago) by hshoexer
Branch: MAIN
CVS Tags: OPENBSD_3_9_BASE, OPENBSD_3_9
Changes since 1.107: +17 -1 lines
Diff to previous 1.107 (colored)

improve examples and show how to use KEY_LENGTH.  Slightly different fix than
proposed by sthen at spacehopper dot org, fixes pr 4522, thanks!

ok and with jmc@

Revision 1.107 / (download) - annotate - [select for diffs], Tue Aug 23 13:19:22 2005 UTC (18 years, 9 months ago) by jmc
Branch: MAIN
CVS Tags: OPENBSD_3_8_BASE, OPENBSD_3_8
Changes since 1.106: +5 -5 lines
Diff to previous 1.106 (colored)

`DSS' is unsupported, so remove references to it;
ok hshoexer@

Revision 1.106 / (download) - annotate - [select for diffs], Sat Jun 11 08:31:40 2005 UTC (18 years, 11 months ago) by jmc
Branch: MAIN
Changes since 1.105: +2 -2 lines
Diff to previous 1.105 (colored)

grammar;

Revision 1.105 / (download) - annotate - [select for diffs], Tue May 31 14:28:39 2005 UTC (19 years ago) by hshoexer
Branch: MAIN
Changes since 1.104: +2 -4 lines
Diff to previous 1.104 (colored)

certpatch is gone, noticed by david@

Revision 1.104 / (download) - annotate - [select for diffs], Mon May 23 23:09:39 2005 UTC (19 years ago) by cloder
Branch: MAIN
Changes since 1.103: +2 -2 lines
Diff to previous 1.103 (colored)

Mention interface names can be used in Listen-on. OK hshoexer

Revision 1.103 / (download) - annotate - [select for diffs], Thu May 12 08:03:11 2005 UTC (19 years ago) by jmc
Branch: MAIN
Changes since 1.102: +19 -6 lines
Diff to previous 1.102 (colored)

add some missing section descriptions to make this page a little
easier to read;

ok hshoexer@

Revision 1.102 / (download) - annotate - [select for diffs], Thu May 5 09:20:27 2005 UTC (19 years, 1 month ago) by jmc
Branch: MAIN
Changes since 1.101: +129 -129 lines
Diff to previous 1.101 (colored)

alphabetically order options within sections;
discussed w/ hshoexer@

Revision 1.101 / (download) - annotate - [select for diffs], Thu May 5 09:00:50 2005 UTC (19 years, 1 month ago) by jmc
Branch: MAIN
Changes since 1.100: +1 -2 lines
Diff to previous 1.100 (colored)

this is not a separate list item;
ok hshoexer@

Revision 1.100 / (download) - annotate - [select for diffs], Thu May 5 08:42:27 2005 UTC (19 years, 1 month ago) by jmc
Branch: MAIN
Changes since 1.99: +247 -168 lines
Diff to previous 1.99 (colored)

first stab at making this page easier to read:
various grammar/mdoc fixes;

Revision 1.99 / (download) - annotate - [select for diffs], Wed Apr 6 00:04:53 2005 UTC (19 years, 2 months ago) by cloder
Branch: MAIN
Changes since 1.98: +4 -3 lines
Diff to previous 1.98 (colored)

Check-interval and DPD-check-interval are specified in seconds.

Revision 1.98 / (download) - annotate - [select for diffs], Tue Feb 22 21:44:55 2005 UTC (19 years, 3 months ago) by moritz
Branch: MAIN
CVS Tags: OPENBSD_3_7_BASE, OPENBSD_3_7
Changes since 1.97: +2 -3 lines
Diff to previous 1.97 (colored)

fix wrong line break in comment.

ok hshoexer@

Revision 1.97 / (download) - annotate - [select for diffs], Wed Jan 5 23:34:37 2005 UTC (19 years, 4 months ago) by jmc
Branch: MAIN
Changes since 1.96: +3 -3 lines
Diff to previous 1.96 (colored)

kill whitespace;

Revision 1.96 / (download) - annotate - [select for diffs], Wed Jan 5 10:23:53 2005 UTC (19 years, 5 months ago) by hshoexer
Branch: MAIN
Changes since 1.95: +11 -1 lines
Diff to previous 1.95 (colored)

Discourage using aggressive mode.

ok and some help ho@

Revision 1.95 / (download) - annotate - [select for diffs], Tue Dec 14 10:17:28 2004 UTC (19 years, 5 months ago) by mcbride
Branch: MAIN
Changes since 1.94: +27 -5 lines
Diff to previous 1.94 (colored)

Allow the Address, Network, or Netmask values of the <IPsec-ID> to be
specified with an interface name (in which case the first address is used)
or the keyword 'default' (in which case the address is selected based on the
default route). eg:

[roadwarrior-ip]
ID-type=                IPV4_ADDR
Address=                default

ok ho@ hshoexer@

Revision 1.94 / (download) - annotate - [select for diffs], Tue Aug 10 15:59:10 2004 UTC (19 years, 9 months ago) by ho
Branch: MAIN
CVS Tags: OPENBSD_3_6_BASE, OPENBSD_3_6
Changes since 1.93: +6 -2 lines
Diff to previous 1.93 (colored)

Better implementation of the Dead Peer Detection protocol, RFC 3706.
hshoexer@ ok.

Revision 1.93 / (download) - annotate - [select for diffs], Thu Jul 8 10:37:12 2004 UTC (19 years, 10 months ago) by jmc
Branch: MAIN
Changes since 1.92: +2 -2 lines
Diff to previous 1.92 (colored)

typo, and line adjustment;

Revision 1.92 / (download) - annotate - [select for diffs], Wed Jul 7 22:25:39 2004 UTC (19 years, 10 months ago) by hshoexer
Branch: MAIN
Changes since 1.91: +25 -1 lines
Diff to previous 1.91 (colored)

document -a/-K and "Acquire-Only"/"Use-Keynote".

ok markus@ henning@ ho@
english polish and mdoc help and ok jmc@

Revision 1.91 / (download) - annotate - [select for diffs], Sat Jun 26 11:32:32 2004 UTC (19 years, 11 months ago) by jmc
Branch: MAIN
Changes since 1.90: +3 -2 lines
Diff to previous 1.90 (colored)

new sentence, new line;

Revision 1.90 / (download) - annotate - [select for diffs], Mon Jun 21 23:42:40 2004 UTC (19 years, 11 months ago) by ho
Branch: MAIN
Changes since 1.89: +4 -1 lines
Diff to previous 1.89 (colored)

Describe the [Default]:NAT-T-Keepalive configuration parameter.

Revision 1.89 / (download) - annotate - [select for diffs], Fri Feb 27 19:07:16 2004 UTC (20 years, 3 months ago) by hshoexer
Branch: MAIN
CVS Tags: OPENBSD_3_5_BASE, OPENBSD_3_5
Changes since 1.88: +4 -4 lines
Diff to previous 1.88 (colored)

Add group 14 (modp2048) to predefined suites.  Manpage also updated.
ok ho@

Revision 1.88 / (download) - annotate - [select for diffs], Thu Feb 26 05:52:16 2004 UTC (20 years, 3 months ago) by jmc
Branch: MAIN
Changes since 1.87: +4 -4 lines
Diff to previous 1.87 (colored)

tweak;
ok hshoexer@

Revision 1.87 / (download) - annotate - [select for diffs], Wed Feb 25 16:01:28 2004 UTC (20 years, 3 months ago) by hshoexer
Branch: MAIN
Changes since 1.86: +25 -1 lines
Diff to previous 1.86 (colored)

Add and document configuration options Logverbose and Loglevel.  As log.c now
depends on conf.c and some regression tests use log.c, add conf.c to
Makefiles where necessary.

ok ho@

Revision 1.86 / (download) - annotate - [select for diffs], Wed Nov 5 12:55:13 2003 UTC (20 years, 7 months ago) by jmc
Branch: MAIN
Changes since 1.85: +2 -2 lines
Diff to previous 1.85 (colored)

PFS: Perfect Forward Secrecy (RFC 2409);
from misc@ and ok markus@

Revision 1.85 / (download) - annotate - [select for diffs], Thu Aug 28 14:43:35 2003 UTC (20 years, 9 months ago) by markus
Branch: MAIN
CVS Tags: OPENBSD_3_4_BASE, OPENBSD_3_4
Changes since 1.84: +2 -2 lines
Diff to previous 1.84 (colored)

support AES in phase 1, too. switch to OpenSSL EVP interface;
with Hans-Joerg.Hoexer at yerbouti.franken.de; ok ho@

Revision 1.84 / (download) - annotate - [select for diffs], Sat Aug 9 08:45:58 2003 UTC (20 years, 9 months ago) by jmc
Branch: MAIN
Changes since 1.83: +29 -14 lines
Diff to previous 1.83 (colored)

new sentence, new line + small cleanup;
ok ho@

Revision 1.83 / (download) - annotate - [select for diffs], Fri Jul 25 08:31:16 2003 UTC (20 years, 10 months ago) by markus
Branch: MAIN
Changes since 1.82: +2 -2 lines
Diff to previous 1.82 (colored)

add sha2 support; ok ho@

Revision 1.82 / (download) - annotate - [select for diffs], Wed Jul 9 08:16:44 2003 UTC (20 years, 10 months ago) by jmc
Branch: MAIN
Changes since 1.81: +1 -9 lines
Diff to previous 1.81 (colored)

- remove some .Ss's that worked around the old blank line bug
- remove some unnecessary .Pp's
- mdoc a list

ok ho@

Revision 1.81 / (download) - annotate - [select for diffs], Tue Jun 3 14:28:16 2003 UTC (21 years ago) by ho
Branch: MAIN
Changes since 1.80: +1 -6 lines
Diff to previous 1.80 (colored)

Remove clauses 3 and 4. With approval from Niklas Hallqvist and
Niels Provos.

Revision 1.80 / (download) - annotate - [select for diffs], Tue Jun 3 13:16:08 2003 UTC (21 years ago) by jmc
Branch: MAIN
Changes since 1.79: +12 -12 lines
Diff to previous 1.79 (colored)

- section reorder
- some mdoc fixes

Revision 1.79 / (download) - annotate - [select for diffs], Sat May 17 17:26:40 2003 UTC (21 years ago) by jmc
Branch: MAIN
Changes since 1.78: +4 -4 lines
Diff to previous 1.78 (colored)

tweak;
ok ho@

Revision 1.78 / (download) - annotate - [select for diffs], Fri May 16 20:31:16 2003 UTC (21 years ago) by ho
Branch: MAIN
Changes since 1.77: +7 -1 lines
Diff to previous 1.77 (colored)

If the "Renegotiate-on-HUP" tag is defined in the [General] section, a
HUP signal (or "R" to the FIFO) will also renegotiate all Phase 2 SAs,
i.e all connections.
ok niklas@, tested and ok kjell@.

Revision 1.77 / (download) - annotate - [select for diffs], Sat May 10 21:13:41 2003 UTC (21 years ago) by jmc
Branch: MAIN
Changes since 1.76: +4 -4 lines
Diff to previous 1.76 (colored)

typos;

Revision 1.76 / (download) - annotate - [select for diffs], Fri Mar 21 15:13:26 2003 UTC (21 years, 2 months ago) by markus
Branch: MAIN
CVS Tags: OPENBSD_3_3_BASE, OPENBSD_3_3
Changes since 1.75: +33 -1 lines
Diff to previous 1.75 (colored)

document [initiator-id] section; richb@timestone.com.au; ok ho@, jmc@

Revision 1.75 / (download) - annotate - [select for diffs], Thu Mar 6 20:29:24 2003 UTC (21 years, 3 months ago) by jmc
Branch: MAIN
Changes since 1.74: +3 -3 lines
Diff to previous 1.74 (colored)

.Xr typos;

ok deraadt@

Revision 1.74 / (download) - annotate - [select for diffs], Mon Mar 3 16:51:38 2003 UTC (21 years, 3 months ago) by ho
Branch: MAIN
Changes since 1.73: +6 -1 lines
Diff to previous 1.73 (colored)

Re-add the BUGS section; the RFCs still do not permit differing DH groups
in the same proposal. This time, mention that this also applies to mixing
PFS and non-PFS suites.

Revision 1.73 / (download) - annotate - [select for diffs], Sat Feb 22 06:56:20 2003 UTC (21 years, 3 months ago) by kjell
Branch: MAIN
Changes since 1.72: +13 -13 lines
Diff to previous 1.72 (colored)

Clarify some language, grammar. ho@ okayed this many moons ago,
and I forgot all about it.

Revision 1.72 / (download) - annotate - [select for diffs], Sun Jan 19 21:02:15 2003 UTC (21 years, 4 months ago) by deraadt
Branch: MAIN
Changes since 1.71: +5 -5 lines
Diff to previous 1.71 (colored)

typos; jmc@prioris.mini.pw.edu.pl

Revision 1.71 / (download) - annotate - [select for diffs], Thu Jan 9 13:12:42 2003 UTC (21 years, 4 months ago) by ho
Branch: MAIN
Changes since 1.70: +44 -38 lines
Diff to previous 1.70 (colored)

Document the various "default" settings. Some style and alphabetical
reordering.

Revision 1.70 / (download) - annotate - [select for diffs], Wed Nov 27 14:36:20 2002 UTC (21 years, 6 months ago) by ho
Branch: MAIN
Changes since 1.69: +2 -2 lines
Diff to previous 1.69 (colored)

Update document date.

Revision 1.69 / (download) - annotate - [select for diffs], Fri Nov 15 14:58:38 2002 UTC (21 years, 6 months ago) by ho
Branch: MAIN
Changes since 1.68: +12 -10 lines
Diff to previous 1.68 (colored)

Missing "Configuration" tag in a Phase-1 peer was not handled correctly,
pointed out by Aref Taidi. Replace this with a "Default-Phase-1-Configuration"
that will be used if this tag is missing from the peer. Update manpage
accordingly. niklas@ ok.

Revision 1.68 / (download) - annotate - [select for diffs], Sat Nov 9 00:57:20 2002 UTC (21 years, 6 months ago) by fgsch
Branch: MAIN
Changes since 1.67: +1 -1 lines
Diff to previous 1.67 (colored)

SEE ALSO reordering and corrections.

Revision 1.67 / (download) - annotate - [select for diffs], Wed Aug 7 13:19:20 2002 UTC (21 years, 10 months ago) by ho
Branch: MAIN
CVS Tags: OPENBSD_3_2_BASE, OPENBSD_3_2
Changes since 1.66: +2 -2 lines
Diff to previous 1.66 (colored)

A rewrite of the CRL support code, also from <Thomas.Walpuski@gmx.net>.
Some style mods, and checks added for OpenSSL version 0.9.7 or later.
Currently CRLs are not supported for earlier versions.
Manual pages updated.

Revision 1.66 / (download) - annotate - [select for diffs], Fri Aug 2 13:27:22 2002 UTC (21 years, 10 months ago) by ho
Branch: MAIN
Changes since 1.65: +2 -1 lines
Diff to previous 1.65 (colored)

Mention CRL support, tag and default value.

Revision 1.65 / (download) - annotate - [select for diffs], Sun Jun 9 08:13:06 2002 UTC (21 years, 11 months ago) by todd
Branch: MAIN
Changes since 1.64: +5 -5 lines
Diff to previous 1.64 (colored)

rm trailing whitespace

Revision 1.64 / (download) - annotate - [select for diffs], Wed Apr 10 20:56:57 2002 UTC (22 years, 1 month ago) by ho
Branch: MAIN
CVS Tags: OPENBSD_3_1_BASE, OPENBSD_3_1
Changes since 1.63: +43 -2 lines
Diff to previous 1.63 (colored)

Document IKE mode-cfg config. deraadt@ ok.

Revision 1.63 / (download) - annotate - [select for diffs], Fri Mar 1 15:25:17 2002 UTC (22 years, 3 months ago) by ho
Branch: MAIN
Changes since 1.62: +25 -32 lines
Diff to previous 1.62 (colored)

Update to reflect recent changes in DH group handling. Remove BUGS
section.

Revision 1.62 / (download) - annotate - [select for diffs], Fri Dec 21 11:41:50 2001 UTC (22 years, 5 months ago) by mpech
Branch: MAIN
Changes since 1.61: +17 -17 lines
Diff to previous 1.61 (colored)

Initial patch for a new mdoc issue.
Powered by @mantoya:
o) kill extra line in the end of file;
o) kill extra space in the end of line;
o) replace blank lines with .Pp;

millert@ ok

Revision 1.61 / (download) - annotate - [select for diffs], Thu Dec 13 20:16:48 2001 UTC (22 years, 5 months ago) by mpech
Branch: MAIN
Changes since 1.60: +35 -32 lines
Diff to previous 1.60 (colored)

o) start new sentence on a new line;
o) wrap long lines;
o) fix bogus .Xr usage;
o) we don't like blank lines;
o) always close .Bl tags;
o) OpenBSD -> .Ox;
o) don't like .Pp before .Ss;

millert@ ok;

Revision 1.60 / (download) - annotate - [select for diffs], Mon Dec 10 03:45:03 2001 UTC (22 years, 5 months ago) by ho
Branch: MAIN
Changes since 1.59: +7 -1 lines
Diff to previous 1.59 (colored)

Mention that SIGHUP will cause isakmpd to reread isakmpd.conf

Revision 1.59 / (download) - annotate - [select for diffs], Thu Oct 11 13:24:31 2001 UTC (22 years, 7 months ago) by ho
Branch: MAIN
CVS Tags: OPENBSD_3_0_BASE, OPENBSD_3_0
Changes since 1.58: +25 -59 lines
Diff to previous 1.58 (colored)

Fix various bugs in the example configuration. Most entries are
"pregenerated", so indicate which aren't. 'Default-phase-N-lifetime'
replaces LIFE_nnn_SECS.

Revision 1.58 / (download) - annotate - [select for diffs], Thu Oct 4 23:31:27 2001 UTC (22 years, 8 months ago) by ho
Branch: MAIN
Changes since 1.57: +40 -12 lines
Diff to previous 1.57 (colored)

IPv6 type addresses and nets are supported now. Some style fixes.
Also add a BUGS section describing why combining predefined MD5 and
SHA suites in the same quick-mode proposal will currently not work.

Revision 1.57 / (download) - annotate - [select for diffs], Wed Aug 15 09:16:30 2001 UTC (22 years, 9 months ago) by ho
Branch: MAIN
Changes since 1.56: +8 -1 lines
Diff to previous 1.56 (colored)

Support trusted public (RSA) keys as files too. niklas@ ok.

Revision 1.56 / (download) - annotate - [select for diffs], Thu Aug 2 09:55:38 2001 UTC (22 years, 10 months ago) by ho
Branch: MAIN
Changes since 1.55: +2 -2 lines
Diff to previous 1.55 (colored)

Let the example config use suites that actually work together.

Revision 1.55 / (download) - annotate - [select for diffs], Wed Jul 4 22:01:13 2001 UTC (22 years, 11 months ago) by angelos
Branch: MAIN
Changes since 1.54: +18 -1 lines
Diff to previous 1.54 (colored)

Some text on KEY_ID payloads.

Revision 1.54 / (download) - annotate - [select for diffs], Wed Jun 27 03:31:42 2001 UTC (22 years, 11 months ago) by angelos
Branch: MAIN
Changes since 1.53: +27 -27 lines
Diff to previous 1.53 (colored)

Consistently use "IPsec" capitalization (jsyn@nthought.com)

Revision 1.53 / (download) - annotate - [select for diffs], Tue Jun 5 11:20:28 2001 UTC (23 years ago) by angelos
Branch: MAIN
Changes since 1.52: +1 -6 lines
Diff to previous 1.52 (colored)

Remove BUGS section, as the only bug mentioned there was removed
earlier today :-)

Revision 1.42.2.1 / (download) - annotate - [select for diffs], Tue May 8 12:45:23 2001 UTC (23 years, 1 month ago) by ho
Branch: OPENBSD_2_8
Changes since 1.42: +62 -14 lines
Diff to previous 1.42 (colored) next main 1.43 (colored)

Pull in isakmpd from 2.9 to 2.8 branch.

Revision 1.52 / (download) - annotate - [select for diffs], Sat May 5 00:49:38 2001 UTC (23 years, 1 month ago) by angelos
Branch: MAIN
Changes since 1.51: +5 -1 lines
Diff to previous 1.51 (colored)

Document default-phase2-suites tag.

Revision 1.51 / (download) - annotate - [select for diffs], Mon Apr 30 13:53:26 2001 UTC (23 years, 1 month ago) by ho
Branch: MAIN
Changes since 1.50: +12 -1 lines
Diff to previous 1.50 (colored)

Add a FILES section describing default and sample file locations.

Revision 1.50 / (download) - annotate - [select for diffs], Thu Apr 5 23:04:53 2001 UTC (23 years, 2 months ago) by ho
Branch: MAIN
CVS Tags: OPENBSD_2_9_BASE, OPENBSD_2_9
Changes since 1.49: +3 -3 lines
Diff to previous 1.49 (colored)

Style.

Revision 1.49 / (download) - annotate - [select for diffs], Wed Mar 7 07:33:53 2001 UTC (23 years, 3 months ago) by angelos
Branch: MAIN
Changes since 1.48: +8 -6 lines
Diff to previous 1.48 (colored)

Add KEY_ID support (mostly from roland@digitalvampire.org)

Revision 1.48 / (download) - annotate - [select for diffs], Sat Jan 27 12:03:33 2001 UTC (23 years, 4 months ago) by niklas
Branch: MAIN
Changes since 1.47: +2 -2 lines
Diff to previous 1.47 (colored)

(c) 2001

Revision 1.47 / (download) - annotate - [select for diffs], Fri Jan 26 11:08:58 2001 UTC (23 years, 4 months ago) by niklas
Branch: MAIN
Changes since 1.46: +3 -3 lines
Diff to previous 1.46 (colored)

Merge with EOM 1.57

author: ho
Lifetime is KILOBYTES not BYTES. Noticed by <jj@dynarc.se>

Revision 1.46 / (download) - annotate - [select for diffs], Fri Dec 15 14:31:18 2000 UTC (23 years, 5 months ago) by aaron
Branch: MAIN
Changes since 1.45: +2 -2 lines
Diff to previous 1.45 (colored)

.Sh EXAMPLE -> .Sh EXAMPLES. Even if there's only one example, at least
this is consistent.

Revision 1.45 / (download) - annotate - [select for diffs], Tue Dec 12 01:46:05 2000 UTC (23 years, 5 months ago) by niklas
Branch: MAIN
Changes since 1.44: +37 -2 lines
Diff to previous 1.44 (colored)

Merge with EOM 1.55

author: angelos
Add Default-phase-1-ID tag in [General], and document its use.

author: angelos
isakmpd can now negotiate transport protocol/ports (either through the
configuration file or through kernel ACQUIREs).

Revision 1.44 / (download) - annotate - [select for diffs], Thu Nov 23 12:56:06 2000 UTC (23 years, 6 months ago) by niklas
Branch: MAIN
Changes since 1.43: +2 -2 lines
Diff to previous 1.43 (colored)

Merge with EOM 1.53

author: niklas
sync with OpenBSD

Revision 1.43 / (download) - annotate - [select for diffs], Thu Nov 9 22:50:06 2000 UTC (23 years, 6 months ago) by aaron
Branch: MAIN
Changes since 1.42: +3 -3 lines
Diff to previous 1.42 (colored)

Remove -offset indent so these lines don't wrap over 80 chars; deraadt@

Revision 1.42 / (download) - annotate - [select for diffs], Mon Oct 16 23:28:22 2000 UTC (23 years, 7 months ago) by niklas
Branch: MAIN
CVS Tags: OPENBSD_2_8_BASE
Branch point for: OPENBSD_2_8
Changes since 1.41: +15 -5 lines
Diff to previous 1.41 (colored)

Merge with EOM 1.52

author: niklas
heh, backspace as a continuation character, yeah right!

author: angelos
Mention Remote-ID tag in ISAKMP-peer section, and also that it doesn't
currently work.

author: angelos
It's "Local-address", not "Listen-address" in the ISAKMP-peer section.

author: angelos
Mention RIPEMD.

Revision 1.41 / (download) - annotate - [select for diffs], Mon Oct 9 23:27:31 2000 UTC (23 years, 7 months ago) by niklas
Branch: MAIN
Changes since 1.40: +46 -3 lines
Diff to previous 1.40 (colored)

samples/VPN-3way-template.conf: Merge with EOM 1.8
samples/VPN-east.conf: Merge with EOM 1.12
samples/VPN-west.conf: Merge with EOM 1.13
samples/policy: Merge with EOM 1.6
samples/singlehost-west.conf: Merge with EOM 1.9
samples/singlehost-east.conf: Merge with EOM 1.9
conf.c: Merge with EOM 1.37
ipsec.c: Merge with EOM 1.133
ipsec_num.cst: Merge with EOM 1.4
isakmpd.conf.5: Merge with EOM 1.48
isakmpd.policy.5: Merge with EOM 1.21
policy.c: Merge with EOM 1.46

author: angelos
AES support.

Revision 1.40 / (download) - annotate - [select for diffs], Sat Oct 7 07:00:08 2000 UTC (23 years, 8 months ago) by niklas
Branch: MAIN
Changes since 1.39: +3 -2 lines
Diff to previous 1.39 (colored)

conf.h: Merge with EOM 1.13
gmp_util.c: Merge with EOM 1.7
isakmpd.conf.5: Merge with EOM 1.47

author: ho
(c)-2000

Revision 1.39 / (download) - annotate - [select for diffs], Thu Aug 3 07:24:14 2000 UTC (23 years, 10 months ago) by niklas
Branch: MAIN
Changes since 1.38: +22 -17 lines
Diff to previous 1.38 (colored)

Merge with EOM 1.46

author: ho
Mention 'Default' tag in Phase 1 section, modify peer tag descriptions
to match. Phase 1 peer transport 'udp' is now a default value. The
'Stayalive' flag died long ago, remove it from the example. Also
remove reference to the likewise dead 'Next-hop' tag. Some minor cleanup.

Revision 1.38 / (download) - annotate - [select for diffs], Thu Jun 8 20:51:00 2000 UTC (23 years, 11 months ago) by niklas
Branch: MAIN
Changes since 1.37: +50 -5 lines
Diff to previous 1.37 (colored)

Merge with EOM 1.45

author: angelos
Some more text.

author: angelos
Allow exchange of KeyNote credentials over IKE. Multiple credentials
may be passed in a single CERT payload. KeyNote is used if a
directory named as the local ID we use in an exchange exists in the
KeyNote directory (default: /etc/isakmpd/keynote/). Note that
asymmetric credentials are possible (use KeyNote in one direction and
X509 in the other); such authentication is envisioned to be the most
common: the clients will use KeyNote credentials to authenticate and
authorize with a server, whilst the server will just provide an X509
certificate proving its binding to the IP address or ID.

Totally asymmetric authentication (e.g., shared key in one direction,
RSA in the other) is not supported by the IKE protocol.

author: ho
Update re DOI:IPSEC and default p1/p2 lifetimes.

Revision 1.37 / (download) - annotate - [select for diffs], Tue May 2 14:36:18 2000 UTC (24 years, 1 month ago) by niklas
Branch: MAIN
CVS Tags: OPENBSD_2_7_BASE, OPENBSD_2_7
Changes since 1.36: +66 -13 lines
Diff to previous 1.36 (colored)

Merge with EOM 1.42

author: ho
Add initial text on auto-generated parts of the configuration.
Reorder example somewhat.

author: niklas
Doc fixes from OpenBSD

Revision 1.36 / (download) - annotate - [select for diffs], Wed Apr 12 21:47:59 2000 UTC (24 years, 1 month ago) by aaron
Branch: MAIN
Changes since 1.35: +2 -2 lines
Diff to previous 1.35 (colored)

Trailing whitespace begone!

Revision 1.35 / (download) - annotate - [select for diffs], Fri Apr 7 22:23:14 2000 UTC (24 years, 2 months ago) by niklas
Branch: MAIN
Changes since 1.34: +2 -2 lines
Diff to previous 1.34 (colored)

apps/certpatch/certpatch.8: Merge with EOM 1.5
isakmpd.8: Merge with EOM 1.20
isakmpd.conf.5: Merge with EOM 1.40
isakmpd.policy.5: Merge with EOM 1.13

author: niklas
Changes from OpenBSD

Revision 1.34 / (download) - annotate - [select for diffs], Fri Apr 7 22:06:57 2000 UTC (24 years, 2 months ago) by niklas
Branch: MAIN
Changes since 1.33: +2 -2 lines
Diff to previous 1.33 (colored)

Merge with EOM 1.39

author: angelos
Add text on CAs and policies.

Revision 1.33 / (download) - annotate - [select for diffs], Thu Mar 23 21:39:56 2000 UTC (24 years, 2 months ago) by aaron
Branch: MAIN
Changes since 1.32: +15 -9 lines
Diff to previous 1.32 (colored)

More pedantic man page formatting insanity, lalala

Revision 1.32 / (download) - annotate - [select for diffs], Wed Mar 22 04:06:17 2000 UTC (24 years, 2 months ago) by angelos
Branch: MAIN
Changes since 1.31: +10 -2 lines
Diff to previous 1.31 (colored)

Add some text about CA certificates and policies (suggested by Paul
Hoffman).

Revision 1.31 / (download) - annotate - [select for diffs], Sat Mar 18 22:55:59 2000 UTC (24 years, 2 months ago) by aaron
Branch: MAIN
Changes since 1.30: +77 -56 lines
Diff to previous 1.30 (colored)

Remove hard sentence breaks, and some other cleanup along the way.

Revision 1.30 / (download) - annotate - [select for diffs], Mon Jan 31 08:38:28 2000 UTC (24 years, 4 months ago) by niklas
Branch: MAIN
Changes since 1.29: +3 -3 lines
Diff to previous 1.29 (colored)

ike_quick_mode.c: Merge with EOM 1.109
isakmpd.conf.5: Merge with EOM 1.38
message.c: Merge with EOM 1.142
pf_key_v2.c: Merge with EOM 1.35
x509.c: Merge with EOM 1.31

author: niklas
(c) 2000

Revision 1.29 / (download) - annotate - [select for diffs], Wed Jan 26 15:22:52 2000 UTC (24 years, 4 months ago) by niklas
Branch: MAIN
Changes since 1.28: +5 -4 lines
Diff to previous 1.28 (colored)

Merge with EOM 1.37

date: 2000/01/25 11:19:34;  author: niklas;  state: Exp;  lines: +3 -3
useable->usable; from openbsd

author: angelos
Oops on previous PFS-policy patch. Small fixes in the manpages.

author: angelos
Default value for policy-file.

Revision 1.28 / (download) - annotate - [select for diffs], Sat Jan 22 13:39:28 2000 UTC (24 years, 4 months ago) by aaron
Branch: MAIN
Changes since 1.27: +3 -3 lines
Diff to previous 1.27 (colored)

Spell it "usable", not "useable", for consistency across the man pages.

Revision 1.27 / (download) - annotate - [select for diffs], Fri Oct 1 14:09:58 1999 UTC (24 years, 8 months ago) by niklas
Branch: MAIN
CVS Tags: OPENBSD_2_6_BASE, OPENBSD_2_6
Changes since 1.26: +17 -11 lines
Diff to previous 1.26 (colored)

Merge with EOM 1.34

author: niklas
Typo fix from alex@openbsd.org

author: angelos
Allow "Life" to be ANY

author: angelos
Allow "ANY" in some fields

Revision 1.26 / (download) - annotate - [select for diffs], Thu Sep 23 04:12:02 1999 UTC (24 years, 8 months ago) by alex
Branch: MAIN
Changes since 1.25: +2 -2 lines
Diff to previous 1.25 (colored)

Typo fixes.

Revision 1.25 / (download) - annotate - [select for diffs], Thu Aug 26 22:28:43 1999 UTC (24 years, 9 months ago) by niklas
Branch: MAIN
Changes since 1.24: +38 -2 lines
Diff to previous 1.24 (colored)

Merge with EOM 1.31

author: angelos
Document the ID section/tag for Phase 1 exchanges.

Revision 1.24 / (download) - annotate - [select for diffs], Sun Jul 18 09:49:07 1999 UTC (24 years, 10 months ago) by niklas
Branch: MAIN
Changes since 1.23: +3 -2 lines
Diff to previous 1.23 (colored)

Merge with EOM 1.30

author: niklas
More sync with OpenBSD version

Revision 1.23 / (download) - annotate - [select for diffs], Sun Jul 18 09:33:33 1999 UTC (24 years, 10 months ago) by niklas
Branch: MAIN
Changes since 1.22: +8 -6 lines
Diff to previous 1.22 (colored)

samples/VPN-east.conf: Merge with EOM 1.7
samples/VPN-west.conf: Merge with EOM 1.7
samples/singlehost-west.conf: Merge with EOM 1.4
samples/singlehost-east.conf: Merge with EOM 1.4
README.PKI: Merge with EOM 1.3
ike_auth.c: Merge with EOM 1.33
isakmpd.conf.5: Merge with EOM 1.28

author: niklas
Moving the PRIVKEY tag into the X509-certificates section, renaming it to
Private-key.  Also rename the keynote policy file.

Revision 1.22 / (download) - annotate - [select for diffs], Sat Jul 17 21:54:39 1999 UTC (24 years, 10 months ago) by niklas
Branch: MAIN
Changes since 1.21: +22 -5 lines
Diff to previous 1.21 (colored)

regress/rsakeygen/Makefile: Merge with EOM 1.4
regress/rsakeygen/rsakeygen.c: Merge with EOM 1.8
regress/x509/Makefile: Merge with EOM 1.6
regress/x509/x509test.c: Merge with EOM 1.6
regress/Makefile: Merge with EOM 1.8
samples/VPN-east.conf: Merge with EOM 1.6
samples/VPN-west.conf: Merge with EOM 1.6
samples/singlehost-east.conf: Merge with EOM 1.3
samples/singlehost-west.conf: Merge with EOM 1.3
sysdep/openbsd/Makefile.sysdep: Merge with EOM 1.5
x509.h: Merge with EOM 1.6
x509.c: Merge with EOM 1.17
DESIGN-NOTES: Merge with EOM 1.46
Makefile: Merge with EOM 1.55
cert.c: Merge with EOM 1.11
cert.h: Merge with EOM 1.6
exchange.c: Merge with EOM 1.109
exchange.h: Merge with EOM 1.26
ike_auth.c: Merge with EOM 1.32
ike_phase_1.c: Merge with EOM 1.7
init.c: Merge with EOM 1.16
isakmpd.conf.5: Merge with EOM 1.27
README.PKI: Merge with EOM 1.1

author: niklas
From Niels Provos, edited by me: certificate support using SSLeay

Revision 1.21 / (download) - annotate - [select for diffs], Fri Jul 9 13:35:49 1999 UTC (24 years, 10 months ago) by aaron
Branch: MAIN
Changes since 1.20: +2 -2 lines
Diff to previous 1.20 (colored)

- remove all trailing whitespace
     * except when it is escaped with a `\' at the end of the line
- fix remaining .Nm usage as well
- this is from a patch I received from kwesterback@home.com, who has been
  working on some scripts for fixing formatting errors in mdoc'd man pages

Ok, so there could be a cost/benefit debate with this commit, but since I have
the patch we might as well commit it...

Revision 1.20 / (download) - annotate - [select for diffs], Wed Jul 7 22:07:00 1999 UTC (24 years, 11 months ago) by niklas
Branch: MAIN
Changes since 1.19: +11 -11 lines
Diff to previous 1.19 (colored)

Merge with EOM 1.26

author: niklas
Merge in fixes done in the OpenBSD tree

author: ho
Add keynote policy-file.

author: ho
No more Stayalive-flag.

Revision 1.19 / (download) - annotate - [select for diffs], Sat Jul 3 02:11:07 1999 UTC (24 years, 11 months ago) by aaron
Branch: MAIN
Changes since 1.18: +1 -2 lines
Diff to previous 1.18 (colored)

remove redundant .Pp macros

Revision 1.18 / (download) - annotate - [select for diffs], Wed Jun 2 06:34:27 1999 UTC (25 years ago) by niklas
Branch: MAIN
Changes since 1.17: +26 -6 lines
Diff to previous 1.17 (colored)

Merge with EOM 1.23

author: niklas
Doc fixes from OpenBSD

author: niklas
Some extra error checking, documentation and style wrt connections

author: niklas
Initial text for Passive-Connections

author: niklas
Doc fix from OpenBSD

Revision 1.17 / (download) - annotate - [select for diffs], Sun May 16 19:56:15 1999 UTC (25 years ago) by alex
Branch: MAIN
Changes since 1.16: +3 -3 lines
Diff to previous 1.16 (colored)

Cleanup xrefs under SEE ALSO.  Specifically:

  - Sort xrefs by section, and then alphabetically.
  - Add missing commas between xref items.
  - Remove commas from the last xref entry.
  - Remove duplicate entries.

Revision 1.16 / (download) - annotate - [select for diffs], Sat May 1 20:43:43 1999 UTC (25 years, 1 month ago) by niklas
Branch: MAIN
Changes since 1.15: +7 -2 lines
Diff to previous 1.15 (colored)

sysdep/openbsd/sysdep.c: Merge with EOM 1.7
DESIGN-NOTES: Merge with EOM 1.42
Makefile: Merge with EOM 1.51
app.c: Merge with EOM 1.6
conf.c: Merge with EOM 1.18
init.c: Merge with EOM 1.14
isakmpd.conf.5: Merge with EOM 1.19
pf_encap.c: Merge with EOM 1.64
pf_encap.h: Merge with EOM 1.12
pf_key_v2.h: Merge with EOM 1.3
sysdep.h: Merge with EOM 1.16
transport.c: Merge with EOM 1.40
ui.c: Merge with EOM 1.32

author: niklas
A new connection abstraction

Revision 1.15 / (download) - annotate - [select for diffs], Tue Apr 27 20:55:52 1999 UTC (25 years, 1 month ago) by niklas
Branch: MAIN
Changes since 1.14: +6 -4 lines
Diff to previous 1.14 (colored)

Merge with EOM 1.18

author: niklas
Mention aggressive mode

author: niklas
1999

Revision 1.14 / (download) - annotate - [select for diffs], Thu Apr 1 00:37:50 1999 UTC (25 years, 2 months ago) by niklas
Branch: MAIN
CVS Tags: OPENBSD_2_5_BASE, OPENBSD_2_5
Changes since 1.13: +7 -6 lines
Diff to previous 1.13 (colored)

Merge with EOM 1.16
Update sample config file

Revision 1.13 / (download) - annotate - [select for diffs], Wed Mar 31 23:47:23 1999 UTC (25 years, 2 months ago) by niklas
Branch: MAIN
Changes since 1.12: +4 -2 lines
Diff to previous 1.12 (colored)

Merge with EOM 1.15
Document Local-address

Revision 1.12 / (download) - annotate - [select for diffs], Wed Mar 31 20:30:21 1999 UTC (25 years, 2 months ago) by niklas
Branch: MAIN
Changes since 1.11: +12 -5 lines
Diff to previous 1.11 (colored)

Merge with EOM 1.14
Reflect reality

Revision 1.11 / (download) - annotate - [select for diffs], Wed Mar 31 00:51:29 1999 UTC (25 years, 2 months ago) by niklas
Branch: MAIN
Changes since 1.10: +8 -2 lines
Diff to previous 1.10 (colored)

Merge with EOM 1.13
Documet IPSec SA flags

Revision 1.10 / (download) - annotate - [select for diffs], Wed Mar 24 15:43:36 1999 UTC (25 years, 2 months ago) by niklas
Branch: MAIN
Changes since 1.9: +2 -2 lines
Diff to previous 1.9 (colored)

grammar

Revision 1.9 / (download) - annotate - [select for diffs], Wed Mar 24 14:43:53 1999 UTC (25 years, 2 months ago) by niklas
Branch: MAIN
Changes since 1.8: +11 -6 lines
Diff to previous 1.8 (colored)

Merge with EOM 1.12
Document Shared-SADB, and alter the ReplayWindow desc.

Revision 1.8 / (download) - annotate - [select for diffs], Thu Mar 11 01:35:03 1999 UTC (25 years, 2 months ago) by pjanzen
Branch: MAIN
Changes since 1.7: +2 -2 lines
Diff to previous 1.7 (colored)

fix more comma splices that involve misuse of conjunctive adverbs

Revision 1.7 / (download) - annotate - [select for diffs], Fri Feb 26 03:45:09 1999 UTC (25 years, 3 months ago) by niklas
Branch: MAIN
Changes since 1.6: +238 -118 lines
Diff to previous 1.6 (colored)

Merge from the Ericsson repository
| revision 1.11
| date: 1999/02/25 11:09:39;  author: niklas;  state: Exp;  lines: +10 -1
| Make conf_get_num take a default value to give back when tag does not exist
| ----------------------------
| revision 1.10
| date: 1999/02/24 12:12:15;  author: niklas;  state: Exp;  lines: +228 -117
| Much better description of the config file
| ----------------------------

Revision 1.6 / (download) - annotate - [select for diffs], Mon Dec 21 01:02:25 1998 UTC (25 years, 5 months ago) by niklas
Branch: MAIN
Changes since 1.5: +352 -44 lines
Diff to previous 1.5 (colored)

Last months worth of work on isakmpd, lots done

Revision 1.5 / (download) - annotate - [select for diffs], Sat Nov 28 19:56:32 1998 UTC (25 years, 6 months ago) by aaron
Branch: MAIN
Changes since 1.4: +10 -11 lines
Diff to previous 1.4 (colored)

kill redundant .Nm macro arguments; other misc fixes

Revision 1.4 / (download) - annotate - [select for diffs], Fri Nov 20 23:47:42 1998 UTC (25 years, 6 months ago) by niklas
Branch: MAIN
Changes since 1.3: +27 -24 lines
Diff to previous 1.3 (colored)

match reality

Revision 1.3 / (download) - annotate - [select for diffs], Tue Nov 17 11:10:15 1998 UTC (25 years, 6 months ago) by niklas
Branch: MAIN
Changes since 1.2: +2 -1 lines
Diff to previous 1.2 (colored)

Add RCS Ids from the EOM repository

Revision 1.2 / (download) - annotate - [select for diffs], Sun Nov 15 00:43:59 1998 UTC (25 years, 6 months ago) by niklas
Branch: MAIN
Changes since 1.1: +1 -1 lines
Diff to previous 1.1 (colored)

openBSD RCS IDs

Revision 1.1.1.1 / (download) - annotate - [select for diffs] (vendor branch), Sun Nov 15 00:03:49 1998 UTC (25 years, 6 months ago) by niklas
Branch: NIKLAS
CVS Tags: NIKLAS_981114
Changes since 1.1: +0 -0 lines
Diff to previous 1.1 (colored)

Initial import of isakmpd, an IKE (ISAKMP/Oakley) implementation for the
OpenBSD IPSEC stack by me, Niklas Hallqvist and Niels Provos, funded by
Ericsson Radio Systems.  It is not yet complete or usable in a real scenario
but the missing pieces will soon be there.  The early commit is for people
who wants early access and who are not afraid of looking at source.
isakmpd interops with Cisco, Timestep, SSH & Pluto (Linux FreeS/WAN) so
far, so it is not that incomplete.  It is really mostly configuration that
is lacking.

Revision 1.1 / (download) - annotate - [select for diffs], Sun Nov 15 00:03:49 1998 UTC (25 years, 6 months ago) by niklas
Branch: MAIN

Initial revision

This form allows you to request diff's between any two revisions of a file. You may select a symbolic revision name using the selection box or you may type in a numeric name using the type-in text box.