OpenBSD CVS

CVS log for src/sbin/isakmpd/policy.h


[BACK] Up to [local] / src / sbin / isakmpd

Request diff between arbitrary revisions


Default branch: MAIN


Revision 1.18 / (download) - annotate - [select for diffs], Tue May 21 05:00:47 2024 UTC (11 days, 15 hours ago) by jsg
Branch: MAIN
CVS Tags: HEAD
Changes since 1.17: +1 -4 lines
Diff to previous 1.17 (colored)

remove prototypes with no matching function and externs with no var
partly checked by millert@

Revision 1.17 / (download) - annotate - [select for diffs], Sun Aug 5 09:43:09 2007 UTC (16 years, 10 months ago) by tom
Branch: MAIN
CVS Tags: OPENBSD_7_5_BASE, OPENBSD_7_5, OPENBSD_7_4_BASE, OPENBSD_7_4, OPENBSD_7_3_BASE, OPENBSD_7_3, OPENBSD_7_2_BASE, OPENBSD_7_2, OPENBSD_7_1_BASE, OPENBSD_7_1, OPENBSD_7_0_BASE, OPENBSD_7_0, OPENBSD_6_9_BASE, OPENBSD_6_9, OPENBSD_6_8_BASE, OPENBSD_6_8, OPENBSD_6_7_BASE, OPENBSD_6_7, OPENBSD_6_6_BASE, OPENBSD_6_6, OPENBSD_6_5_BASE, OPENBSD_6_5, OPENBSD_6_4_BASE, OPENBSD_6_4, OPENBSD_6_3_BASE, OPENBSD_6_3, OPENBSD_6_2_BASE, OPENBSD_6_2, OPENBSD_6_1_BASE, OPENBSD_6_1, OPENBSD_6_0_BASE, OPENBSD_6_0, OPENBSD_5_9_BASE, OPENBSD_5_9, OPENBSD_5_8_BASE, OPENBSD_5_8, OPENBSD_5_7_BASE, OPENBSD_5_7, OPENBSD_5_6_BASE, OPENBSD_5_6, OPENBSD_5_5_BASE, OPENBSD_5_5, OPENBSD_5_4_BASE, OPENBSD_5_4, OPENBSD_5_3_BASE, OPENBSD_5_3, OPENBSD_5_2_BASE, OPENBSD_5_2, OPENBSD_5_1_BASE, OPENBSD_5_1, OPENBSD_5_0_BASE, OPENBSD_5_0, OPENBSD_4_9_BASE, OPENBSD_4_9, OPENBSD_4_8_BASE, OPENBSD_4_8, OPENBSD_4_7_BASE, OPENBSD_4_7, OPENBSD_4_6_BASE, OPENBSD_4_6, OPENBSD_4_5_BASE, OPENBSD_4_5, OPENBSD_4_4_BASE, OPENBSD_4_4, OPENBSD_4_3_BASE, OPENBSD_4_3, OPENBSD_4_2_BASE, OPENBSD_4_2
Changes since 1.16: +3 -2 lines
Diff to previous 1.16 (colored)

Allow key exchange with RSA signature authentication to work with
Cisco IOS and other initiators that only send their certs in response
to CERT_REQUEST.

With input and help from cloder@, Stuart Henderson, mpf@, and several
others who did lots of testing - thanks to all.

ok hshoexer@

Revision 1.16 / (download) - annotate - [select for diffs], Tue Apr 5 22:53:50 2005 UTC (19 years, 2 months ago) by cloder
Branch: MAIN
CVS Tags: OPENBSD_4_1_BASE, OPENBSD_4_1, OPENBSD_4_0_BASE, OPENBSD_4_0, OPENBSD_3_9_BASE, OPENBSD_3_9, OPENBSD_3_8_BASE, OPENBSD_3_8
Changes since 1.15: +1 -3 lines
Diff to previous 1.15 (colored)

Now that X509 is de-featurized, no need for USE_X509 in regress tests.
Start compiling the X509 regress test again, for the first time since
2002 when DLOPEN stuff was removed.  Kill remnants of DLOPEN defines
left around in other Makefiles.  Allow isakmpd to compile if USE_KEYNOTE
is not defined.

Revision 1.15 / (download) - annotate - [select for diffs], Fri Jun 25 20:25:34 2004 UTC (19 years, 11 months ago) by hshoexer
Branch: MAIN
CVS Tags: OPENBSD_3_7_BASE, OPENBSD_3_7, OPENBSD_3_6_BASE, OPENBSD_3_6
Changes since 1.14: +2 -1 lines
Diff to previous 1.14 (colored)

Keynote policy checking can now be disabled by "-K" switch and config tag
"Use-Keynote".  Default is to use keynote.

ok henning@ ho@

Revision 1.14 / (download) - annotate - [select for diffs], Wed Apr 28 20:20:32 2004 UTC (20 years, 1 month ago) by hshoexer
Branch: MAIN
Changes since 1.13: +9 -12 lines
Diff to previous 1.13 (colored)

remove unused variable and shorten names of two other.  Removed some spaces
while around.

ok ho@ markus@

Revision 1.13 / (download) - annotate - [select for diffs], Thu Apr 15 18:39:26 2004 UTC (20 years, 1 month ago) by deraadt
Branch: MAIN
Changes since 1.12: +30 -28 lines
Diff to previous 1.12 (colored)

partial move to KNF.  More to come.  This has happened because there
are a raft of source code auditors who are willing to help improve this
code only if this is done, and hey, isakmpd does need our standard
auditing process.  ok ho hshoexer

Revision 1.12 / (download) - annotate - [select for diffs], Wed Jun 4 07:31:17 2003 UTC (21 years ago) by ho
Branch: MAIN
CVS Tags: OPENBSD_3_5_BASE, OPENBSD_3_5, OPENBSD_3_4_BASE, OPENBSD_3_4
Changes since 1.11: +1 -6 lines
Diff to previous 1.11 (colored)

Remove the rest of clauses 3 and 4. Approved by Niklas Hallqvist, Angelos
D. Keromytis and Niels Provos.

Revision 1.11 / (download) - annotate - [select for diffs], Wed May 14 18:10:30 2003 UTC (21 years ago) by ho
Branch: MAIN
Changes since 1.10: +1 -5 lines
Diff to previous 1.10 (colored)

Policy file default defined twice, kill the local copy.

Revision 1.10 / (download) - annotate - [select for diffs], Mon Jun 10 18:08:58 2002 UTC (21 years, 11 months ago) by ho
Branch: MAIN
CVS Tags: OPENBSD_3_3_BASE, OPENBSD_3_3, OPENBSD_3_2_BASE, OPENBSD_3_2
Changes since 1.9: +1 -33 lines
Diff to previous 1.9 (colored)

The dlopen() stuff goes away.

Revision 1.9 / (download) - annotate - [select for diffs], Wed Aug 15 13:06:53 2001 UTC (22 years, 9 months ago) by ho
Branch: MAIN
CVS Tags: OPENBSD_3_1_BASE, OPENBSD_3_1, OPENBSD_3_0_BASE, OPENBSD_3_0
Changes since 1.8: +2 -2 lines
Diff to previous 1.8 (colored)

Some more style...

Revision 1.8 / (download) - annotate - [select for diffs], Thu May 31 20:21:08 2001 UTC (23 years ago) by angelos
Branch: MAIN
Changes since 1.7: +5 -1 lines
Diff to previous 1.7 (colored)

Routines for handling KeyNote cert representation.

Revision 1.7 / (download) - annotate - [select for diffs], Sat Oct 7 06:57:08 2000 UTC (23 years, 8 months ago) by niklas
Branch: MAIN
CVS Tags: OPENBSD_2_9_BASE, OPENBSD_2_9, OPENBSD_2_8_BASE, OPENBSD_2_8
Changes since 1.6: +6 -4 lines
Diff to previous 1.6 (colored)

cert.c: Merge with EOM 1.18
cert.h: Merge with EOM 1.8
libcrypto.c: Merge with EOM 1.14
policy.h: Merge with EOM 1.12
x509.h: Merge with EOM 1.11

author: niklas
Multiple subject name matching, makes certificate interop with PGPnet at least
partly working.  Added some error checking.

Revision 1.6 / (download) - annotate - [select for diffs], Thu Jun 8 20:50:52 2000 UTC (23 years, 11 months ago) by niklas
Branch: MAIN
Changes since 1.5: +28 -3 lines
Diff to previous 1.5 (colored)

Merge with EOM 1.11

author: angelos
Different policy/Keynote sessions per Phase 1 SA.

author: angelos
Allow exchange of KeyNote credentials over IKE. Multiple credentials
may be passed in a single CERT payload. KeyNote is used if a
directory named as the local ID we use in an exchange exists in the
KeyNote directory (default: /etc/isakmpd/keynote/). Note that
asymmetric credentials are possible (use KeyNote in one direction and
X509 in the other); such authentication is envisioned to be the most
common: the clients will use KeyNote credentials to authenticate and
authorize with a server, whilst the server will just provide an X509
certificate proving its binding to the IP address or ID.

Totally asymmetric authentication (e.g., shared key in one direction,
RSA in the other) is not supported by the IKE protocol.

author: angelos
A few more definitions.

author: angelos
Some more support for KeyNote credential exchange (not yet done).

Revision 1.5 / (download) - annotate - [select for diffs], Tue May 2 14:36:43 2000 UTC (24 years, 1 month ago) by niklas
Branch: MAIN
CVS Tags: OPENBSD_2_7_BASE, OPENBSD_2_7
Changes since 1.4: +6 -2 lines
Diff to previous 1.4 (colored)

Merge with EOM 1.7

author: angelos
Move POLICY_FILE_DEFAULT definition to the .h file.

Revision 1.4 / (download) - annotate - [select for diffs], Fri Apr 7 22:03:35 2000 UTC (24 years, 2 months ago) by niklas
Branch: MAIN
Changes since 1.3: +4 -4 lines
Diff to previous 1.3 (colored)

Merge with EOM 1.6

author: niklas
Hmm keynote does not exist in a dynamically linked version

Revision 1.3 / (download) - annotate - [select for diffs], Sun Feb 20 16:30:20 2000 UTC (24 years, 3 months ago) by niklas
Branch: MAIN
Changes since 1.2: +4 -2 lines
Diff to previous 1.2 (colored)

Merge with EOM 1.5

author: niklas
Allow isakmpd builders to remove optional parts and save bytes.

Revision 1.2 / (download) - annotate - [select for diffs], Thu Aug 26 22:28:33 1999 UTC (24 years, 9 months ago) by niklas
Branch: MAIN
CVS Tags: OPENBSD_2_6_BASE, OPENBSD_2_6
Changes since 1.1: +34 -2 lines
Diff to previous 1.1 (colored)

Merge with EOM 1.4

author: niklas
typo

author: niklas
Support dynamic loading of libkeynote too.  Build isakmpd static by default.
Stylistic cleanup of keynote policy code.  Correct some libcrypto calls.

Revision 1.1 / (download) - annotate - [select for diffs], Wed Jul 7 22:10:28 1999 UTC (24 years, 11 months ago) by niklas
Branch: MAIN

policy.h: Merge with EOM 1.2
policy.c: Merge with EOM 1.2

author: niklas
Remove $EOM$ from Eom repository version

author: niklas
New file, for keynote policy handling. By angelos@openbsd.org

This form allows you to request diff's between any two revisions of a file. You may select a symbolic revision name using the selection box or you may type in a numeric name using the type-in text box.