48 Commits
Author SHA1 Message Date
Avesh Agarwal 0736b8591f Fixes strongswan swanctl service issue rhbz#1193106 2015-02-20 09:46:50 -05:00
Avesh Agarwal 255d313e3c Enabled ccm, and ctr plugins as it seems enabling just openssl does
not work for using ccm and ctr algos.
2014-12-18 12:38:26 -05:00
Avesh Agarwal 0156e20714 Enabled aes-ccm, and aes-ctr plugins 2014-12-18 12:37:10 -05:00
Avesh Agarwal 7be7900038 New strongswan developer release 5.2.2dr1 2014-12-08 14:02:05 -05:00
Avesh Agarwal 5e61a32f25 1167331: Enabled native systemd support.
- Does not disable old systemd, starter, ipsec.conf support yet.
2014-11-24 12:37:47 -05:00
Avesh Agarwal 73578a365a 1167331: Enabled native systemd support.
- Does not disable old systemd, starter, ipsec.conf support yet.
2014-11-24 12:18:22 -05:00
Avesh Agarwal de8cd547ce New upstream release 5.2.1 2014-10-30 12:08:20 -04:00
Avesh Agarwal 527a5e99d0 New upstream release candidate 5.2.1rc1 2014-10-16 14:04:50 -04:00
Avesh Agarwal 6076fd449e New upstream release 5.2.0
- The Attestation IMC/IMV pair supports the IMA-NG
  measurement format
- Aikgen tool to generate an Attestation Identity Key bound
  to a TPM
- Swanctl tool to provide a portable, complete IKE
  configuration and control interface for the command
  line using vici interface with libvici library
- PT-EAP transport protocol (RFC 7171) for TNC
- Enabled support for acert for checking X509 attribute certificate
- Updated patches, removed selinux patch as upstream has fixed it
  in this release.
- Updated spec file with minor cleanups
2014-07-15 14:06:03 -04:00
Avesh Agarwal 0ae42b48af New upstream developer release 5.2.0dr4
- Attestation IMV/IMC supports IMA-NG measurement format now
- Aikgen tool to generate an Attestation Identity Key bound
  to a TPM
- PT-EAP transport protocol (RFC 7171) for TNC
- vici plugin provides IKE Configuration Interface for charon
- Enabled support for acert for checking X509 attribute certificate
- Updated patches
- Updated spec file with minor cleanups
2014-05-22 19:52:13 -04:00
Avesh Agarwal 72d43cc20b Fixed full hardening for strongswan (full relro and PIE).
The previous macros had a typo and did not work
  (see bz#1067119).
- Fixed tnc package description to reflect the current state of
  the package.
- Fixed pki binary and moved it to /usr/libexece/strongswan as
  others binaries are there too.
2014-02-20 12:53:46 -05:00
Avesh Agarwal 1ca0c0e019 Resolves: 973315
- Resolves: 1036844
2013-12-02 16:11:46 -05:00
Avesh Agarwal 4fa580f8cd Resolves: 973315
- Resolves: 1036844
2013-12-02 16:07:57 -05:00
Avesh Agarwal 5f86e09419 Resolves: 973315
- Resolves: 1036844
2013-12-02 15:52:52 -05:00
Avesh Agarwal 1c9aa914d8 Support for PT-TLS (RFC 6876)
- Support for SWID IMC/IMV
- Support for command line IKE client charon-cmd
- Changed location of pki to /usr/bin
- Added swid tags files
- Added man pages for pki and charon-cmd
- Renamed pki to strongswan-pki to avoid conflict with
  pki-core/pki-tools package.
- Update local patches
- Fixes CVE-2013-6075
- Fixes CVE-2013-6076
- Fixed autoconf/automake issue as configure.ac got changed
  and it required running autoreconf during the build process.
- added strongswan signature file to the sources.
- Fixed initialization crash of IMV and IMC particularly
  attestation imv/imc as libstrongswas was not getting
  initialized.
- Enabled fips support
- Enabled TNC's ifmap support
- Enabled TNC's pdp support
- Fixed hardocded package name in this spec file
2013-11-01 15:25:00 -04:00
Avesh Agarwal 285d7534b8 Support for PT-TLS (RFC 6876)
- Support for SWID IMC/IMV
- Support for command line IKE client charon-cmd
- Changed location of pki to /usr/bin
- Added swid tags files
- Added man pages for pki and charon-cmd
- Renamed pki to strongswan-pki to avoid conflict with
  pki-core/pki-tools package.
- Update local patches
- Fixes CVE-2013-6075
- Fixes CVE-2013-6076
- Fixed autoconf/automake issue as configure.ac got changed
  and it required running autoreconf during the build process.
- added strongswan signature file to the sources.
2013-11-01 15:09:30 -04:00
Avesh Agarwal 2cef5e58a7 Support for PT-TLS (RFC 6876)
- Support for SWID IMC/IMV
- Support for command line IKE client charon-cmd
- Changed location of pki to /usr/bin
- Added swid tags files
- Added man pages for pki and charon-cmd
- Renamed pki to strongswan-pki to avoid conflict with
  pki-core/pki-tools package.
- Update local patches
- Fixes CVE-2013-6075
- Fixes CVE-2013-6076
- Fixed autoconf/automake issue as configure.ac got changed
  and it required running autoreconf during the build process.
- added strongswan signature file to the sources.
2013-11-01 15:08:47 -04:00
Avesh Agarwal b43681bf1b Support for PT-TLS (RFC 6876)
- Support for SWID IMC/IMV
- Support for command line IKE client charon-cmd
- Changed location of pki to /usr/bin
- Added swid tags files
- Added man pages for pki and charon-cmd
- Renamed pki to strongswan-pki to avoid conflict with
  pki-core/pki-tools package.
- Update local patches
- Fixes CVE-2013-6075
- Fixes CVE-2013-6076
- Fixed autoconf/automake issue as configure.ac got changed
  and it required running autoreconf during the build process.
- added strongswan signature file to the sources.
2013-11-01 15:04:43 -04:00
Avesh Agarwal 710e5ac471 Support for PT-TLS (RFC 6876)
- Support for SWID IMC/IMV
- Support for command line IKE client charon-cmd
- Changed location of pki to /usr/bin
- Added swid tags files
- Added man pages for pki and charon-cmd
- Renamed pki to strongswan-pki to avoid conflict with
  pki-core/pki-tools package.
- Update local patches
- Fixes CVE-2013-6075
- Fixes CVE-2013-6076
- Fixed autoconf/automake issue as configure.ac got changed
  and it required running autoreconf during the build process.
- added strongswan signature file to the sources.
2013-11-01 14:49:56 -04:00
Avesh Agarwal 07bd95ec67 Fixed initialization crash of IMV and IMC particularly
attestation imv/imc as libstrongswas was not getting
  initialized.
2013-09-12 13:23:21 -04:00
Avesh Agarwal 5c4f5c4a52 Fixed initialization crash of IMV and IMC particularly
attestation imv/imc as libstrongswas was not getting
  initialized.
2013-09-12 13:21:54 -04:00
Avesh Agarwal 764be31e95 Fixed initialization crash of IMV and IMC particularly
attestation imv/imc as libstrongswas was not getting
  initialized.
2013-09-12 13:18:45 -04:00
Avesh Agarwal c5fe3b3899 Enabled fips support
- Enabled TNC's ifmap support
- Enabled TNC's pdp support
- Fixed hardocded package name in this spec file
2013-08-30 15:43:32 -04:00
Avesh Agarwal d0792a1bf6 Enabled fips support
- Enabled TNC's ifmap support
- Enabled TNC's pdp support
- Fixed hardocded package name in this spec file
2013-08-30 15:41:45 -04:00
Avesh Agarwal 5c3c2f4422 Enabled fips support
- Enabled TNC's ifmap support
- Enabled TNC's pdp support
- Fixed hardocded package name in this spec file
2013-08-30 15:37:43 -04:00
Avesh Agarwal c2f05ffb59 Fixed linker error when compilating malloc-speed that
lrt is missing. Did not have this problem on f19 and F20.
2013-08-07 17:06:40 -04:00
Avesh Agarwal bc76bb8ca3 rhbz#981429: New upstream release
- Fixes CVE-2013-5018: rhbz#991216, rhbz#991215
- Fixes rhbz#991859 failed to build in rawhide
- Updated local patches and removed which are not needed
- Fixed errors around charon-nm
- Added plugins libstrongswan-pkcs12.so, libstrongswan-rc2.so,
  libstrongswan-sshkey.so
- Added utility imv_policy_manager
2013-08-07 16:28:08 -04:00
Avesh Agarwal 634a38ad93 rhbz#981429: New upstream release
- Fixes CVE-2013-5018: rhbz#991216, rhbz#991215
- Fixes rhbz#991859 failed to build in rawhide
- Updated local patches and removed which are not needed
- Fixed errors around charon-nm
- Added plugins libstrongswan-pkcs12.so, libstrongswan-rc2.so,
  libstrongswan-sshkey.so
- Added utility imv_policy_manager
2013-08-07 16:12:08 -04:00
Avesh Agarwal 80bb1ce4b2 rhbz#981429: New upstream release
- Fixes CVE-2013-5018: rhbz#991216, rhbz#991215
- Fixes rhbz#991859 failed to build in rawhide
- Updated local patches and removed which are not needed
- Fixed errors around charon-nm
- Added plugins libstrongswan-pkcs12.so, libstrongswan-rc2.so,
  libstrongswan-sshkey.so
- Added utility imv_policy_manager
2013-08-07 16:04:59 -04:00
Avesh Agarwal e0b5ee21d4 Patch to fix a major crash issue when Freeradius loads
attestatiom-imv and does not initialize libstrongswan which
  causes crash due to calls to PTS algorithms probing APIs.
  So this patch fixes the order of initialization. This issues
  does not occur with charon because libstrongswan gets
  initialized earlier.
- Patch that allows to outputs errors when there are permission
  issues when accessing strongswan.conf.
- Patch to make loading of modules configurable when libimcv
  is used in stand alone mode without charon with freeradius
  and wpa_supplicant.
2013-07-15 23:57:29 +01:00
Avesh Agarwal 8bc5b16e8f Enabled TNCCS 1.1 protocol
- Fixed libxm2-devel build dependency
- Patch to fix the issue with loading of plugins
2013-07-15 23:57:15 +01:00
Avesh Agarwal 84852c31c6 New upstream release
- Fixes fo CVE-2013-2944
- Enabled support for OS IMV/IMC
- Created and applied a patch to disable ECP in fedora, because
  Openssl in Fedora does not allow ECP_256 and ECP_384. It makes
  it non-compliant to TCG's PTS standard, but there is no choice
  right now. see redhat bz # 319901.
- Enabled Trousers support for TPM based operations.
2013-07-15 23:57:08 +01:00
Avesh Agarwal 348f644df7 Patch to fix a major crash issue when Freeradius loads
attestatiom-imv and does not initialize libstrongswan which
  causes crash due to calls to PTS algorithms probing APIs.
  So this patch fixes the order of initialization. This issues
  does not occur with charon because libstrongswan gets
  initialized earlier.
- Patch that allows to outputs errors when there are permission
  issues when accessing strongswan.conf.
- Patch to make loading of modules configurable when libimcv
  is used in stand alone mode without charon with freeradius
  and wpa_supplicant.
2013-07-15 23:54:56 +01:00
Avesh Agarwal 467ecdc00e Enabled TNCCS 1.1 protocol
- Fixed libxm2-devel build dependency
- Patch to fix the issue with loading of plugins
2013-07-15 23:54:51 +01:00
Avesh Agarwal 78378685d9 Patch to fix a major crash issue when Freeradius loads
attestatiom-imv and does not initialize libstrongswan which
  causes crash due to calls to PTS algorithms probing APIs.
  So this patch fixes the order of initialization. This issues
  does not occur with charon because libstrongswan gets
  initialized earlier.
- Patch that allows to outputs errors when there are permission
  issues when accessing strongswan.conf.
- Patch to make loading of modules configurable when libimcv
  is used in stand alone mode without charon with freeradius
  and wpa_supplicant.
2013-06-28 15:20:51 -04:00
Avesh Agarwal 504a6c151f Patch to fix a major crash issue when Freeradius loads
attestatiom-imv and does not initialize libstrongswan which
  causes crash due to calls to PTS algorithms probing APIs.
  So this patch fixes the order of initialization. This issues
  does not occur with charon because libstrongswan gets
  initialized earlier.
- Patch that allows to outputs errors when there are permission
  issues when accessing strongswan.conf.
- Patch to make loading of modules configurable when libimcv
  is used in stand alone mode without charon with freeradius
  and wpa_supplicant.
2013-06-28 15:06:33 -04:00
Avesh Agarwal 517e1ea8a4 Enabled TNCCS 1.1 protocol
- Fixed libxm2-devel build dependency
- Patch to fix the issue with loading of plugins
2013-06-11 12:15:25 -04:00
Avesh Agarwal 44d903a54a Enabled TNCCS 1.1 protocol
- Fixed libxm2-devel build dependency
- Patch to fix the issue with loading of plugins
2013-06-11 12:01:15 -04:00
Avesh Agarwal b0b4eb8e3b New upstream release
- Fixes for CVE-2013-2944
- Enabled support for OS IMV/IMC
- Created and applied a patch to disable ECP in fedora, because
  Openssl in Fedora does not allow ECP_256 and ECP_384. It makes
  it non-compliant to TCG's PTS standard, but there is no choice
  right now. see redhat bz # 319901.
- Enabled Trousers support for TPM based operations.
2013-05-01 16:30:44 -04:00
Avesh Agarwal a8013e7310 New upstream release
- Fixes for CVE-2013-2944
- Enabled support for OS IMV/IMC
- Created and applied a patch to disable ECP in fedora, because
  Openssl in Fedora does not allow ECP_256 and ECP_384. It makes
  it non-compliant to TCG's PTS standard, but there is no choice
  right now. see redhat bz # 319901.
- Enabled Trousers support for TPM based operations.
2013-05-01 16:27:20 -04:00
Avesh Agarwal 82c91d56c3 New upstream release
- Fixes fo CVE-2013-2944
- Enabled support for OS IMV/IMC
- Created and applied a patch to disable ECP in fedora, because
  Openssl in Fedora does not allow ECP_256 and ECP_384. It makes
  it non-compliant to TCG's PTS standard, but there is no choice
  right now. see redhat bz # 319901.
- Enabled Trousers support for TPM based operations.
2013-05-01 16:07:32 -04:00
Avesh Agarwal d0964cb1b4 New upstream release
- Enabled curl and eap-identity plugins
- Enabled support for eap-radius plugin.
2013-04-19 16:29:03 -04:00
Avesh Agarwal 19e0d3b6d9 New upstream release
- Enabled curl and eap-identity plugins
2013-04-19 16:18:34 -04:00
Avesh Agarwal dfa0e8f1bd New upstream release
- Enabled curl and eap-identity plugins
2013-04-19 16:03:08 -04:00
Avesh Agarwal 2232b708dc Enabled support for eap-radius plugin. 2013-03-19 14:13:26 -04:00
Avesh Agarwal 6e30907909 Enabled support for eap-radius plugin. 2013-03-19 14:09:44 -04:00
Avesh Agarwal 4de243f5fa Update to upstream release 5.0.2
- Created sub package strongswan-tnc-imcvs that provides trusted network
  connect's IMC and IMV funtionality. Specifically it includes PTS
  based IMC/IMV for TPM based remote attestation and scanner and test
  IMCs and IMVs. The Strongswan's IMC/IMV dynamic libraries can be used
  by any third party TNC Client/Server implementation possessing a
  standard IF-IMC/IMV interface.
2013-03-11 16:02:12 -04:00
Avesh Agarwal 58e377631b New upstream release
- Created sub package strongswan-tnc-imcvs that provides trusted network
  connect's IMC and IMV funtionality. Specifically it includes PTS
  based IMC/IMV for TPM based remote attestation and scanner and test
  IMCs and IMVs. The Strongswan's IMC/IMV dynamic libraries can be used
  by any third party TNC Client/Server implementation possessing a
  standard IF-IMC/IMV interface.

- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild
2013-03-05 17:24:38 -05:00