189 Commits

Author SHA1 Message Date
Pavel Šimerda
c0813448cc don't touch the config with sed 2014-03-05 16:52:49 +01:00
Pavel Šimerda
b4d5c81110 commented patches 2014-03-04 09:06:55 +01:00
Pavel Šimerda
624f2dd52e remove obsolete patches 2014-03-04 08:17:29 +01:00
Pavel Šimerda
1acf1a26e4 compile strongswan with xauth-pam plugin 2014-03-03 22:58:26 +01:00
Pavel Šimerda
c936b3d318 bump to 5.1.2 2014-03-03 22:46:53 +01:00
Avesh Agarwal
72d43cc20b Fixed full hardening for strongswan (full relro and PIE).
The previous macros had a typo and did not work
  (see bz#1067119).
- Fixed tnc package description to reflect the current state of
  the package.
- Fixed pki binary and moved it to /usr/libexece/strongswan as
  others binaries are there too.
2014-02-20 12:53:46 -05:00
Pavel Šimerda
b97f57cef9 #903638 - SELinux is preventing /usr/sbin/xtables-multi from 'read' accesses on the chr_file /dev/random 2014-02-19 10:15:54 +01:00
Pavel Šimerda
31f572c3a7 Removed redundant patches and *.spec commands caused by branch merging 2014-01-09 10:43:31 +01:00
Pavel Šimerda
827399ee8c rebuilt 2014-01-08 13:08:49 +01:00
Pavel Šimerda
b5963e1653 Merge remote-tracking branch 'origin/el6'
Conflicts:
	.gitignore
	libstrongswan-plugin.patch
	libstrongswan-settings-debug.patch
	sources
	strongswan-init.patch
	strongswan-pts-ecp-disable.patch
	strongswan.spec
2014-01-07 15:41:33 +01:00
Avesh Agarwal
5f86e09419 Resolves: 973315
- Resolves: 1036844
2013-12-02 15:52:52 -05:00
Avesh Agarwal
710e5ac471 Support for PT-TLS (RFC 6876)
- Support for SWID IMC/IMV
- Support for command line IKE client charon-cmd
- Changed location of pki to /usr/bin
- Added swid tags files
- Added man pages for pki and charon-cmd
- Renamed pki to strongswan-pki to avoid conflict with
  pki-core/pki-tools package.
- Update local patches
- Fixes CVE-2013-6075
- Fixes CVE-2013-6076
- Fixed autoconf/automake issue as configure.ac got changed
  and it required running autoreconf during the build process.
- added strongswan signature file to the sources.
2013-11-01 14:49:56 -04:00
Avesh Agarwal
764be31e95 Fixed initialization crash of IMV and IMC particularly
attestation imv/imc as libstrongswas was not getting
  initialized.
2013-09-12 13:18:45 -04:00
Avesh Agarwal
5c3c2f4422 Enabled fips support
- Enabled TNC's ifmap support
- Enabled TNC's pdp support
- Fixed hardocded package name in this spec file
2013-08-30 15:37:43 -04:00
Avesh Agarwal
80bb1ce4b2 rhbz#981429: New upstream release
- Fixes CVE-2013-5018: rhbz#991216, rhbz#991215
- Fixes rhbz#991859 failed to build in rawhide
- Updated local patches and removed which are not needed
- Fixed errors around charon-nm
- Added plugins libstrongswan-pkcs12.so, libstrongswan-rc2.so,
  libstrongswan-sshkey.so
- Added utility imv_policy_manager
2013-08-07 16:04:59 -04:00
Jamie Nguyen
12770476b6 Rename strongswan-NetworkManager to strongswan-charon-nm 2013-07-25 07:53:04 +01:00
Jamie Nguyen
b82295b178 Rename strongswan-NetworkManager to strongswan-charon-nm 2013-07-25 07:46:02 +01:00
Jamie Nguyen
492496d78f Conditionalize NM subpackage as NM on EL6 is too old 2013-07-15 23:58:06 +01:00
Jamie Nguyen
6106c07f9e Add /etc/strongswan/ipsec.d and missing subdirectories 2013-07-15 23:58:03 +01:00
Jamie Nguyen
79e547f661 Patch to change 'ipsec scepclient' to 'strongswan scepclient' 2013-07-15 23:58:00 +01:00
Jamie Nguyen
4db20548af Patch to change 'ipsec _updown' to 'strongswan _updown' 2013-07-15 23:57:54 +01:00
Jamie Nguyen
a011295026 Enable hardened_build as it meets the criteria (#984429) 2013-07-15 23:57:51 +01:00
Jamie Nguyen
e323196d1b NetworkManager subpackage is missing a license (#984490) 2013-07-15 23:57:47 +01:00
Jamie Nguyen
b8944e4e75 Update system related dependencies and scriptlets 2013-07-15 23:57:44 +01:00
Jamie Nguyen
2df6f4d197 Fix various minor rpmlint errors 2013-07-15 23:57:41 +01:00
Jamie Nguyen
70b72e4d7f Fix broken systemd unit file (#984300) 2013-07-15 23:57:38 +01:00
Jamie Nguyen
f3c41f08e2 %files section packages some files as directories (#984437) 2013-07-15 23:57:35 +01:00
Avesh Agarwal
e0b5ee21d4 Patch to fix a major crash issue when Freeradius loads
attestatiom-imv and does not initialize libstrongswan which
  causes crash due to calls to PTS algorithms probing APIs.
  So this patch fixes the order of initialization. This issues
  does not occur with charon because libstrongswan gets
  initialized earlier.
- Patch that allows to outputs errors when there are permission
  issues when accessing strongswan.conf.
- Patch to make loading of modules configurable when libimcv
  is used in stand alone mode without charon with freeradius
  and wpa_supplicant.
2013-07-15 23:57:29 +01:00
Avesh Agarwal
8bc5b16e8f Enabled TNCCS 1.1 protocol
- Fixed libxm2-devel build dependency
- Patch to fix the issue with loading of plugins
2013-07-15 23:57:15 +01:00
Avesh Agarwal
84852c31c6 New upstream release
- Fixes fo CVE-2013-2944
- Enabled support for OS IMV/IMC
- Created and applied a patch to disable ECP in fedora, because
  Openssl in Fedora does not allow ECP_256 and ECP_384. It makes
  it non-compliant to TCG's PTS standard, but there is no choice
  right now. see redhat bz # 319901.
- Enabled Trousers support for TPM based operations.
2013-07-15 23:57:08 +01:00
Jamie Nguyen
2949ac3d94 Conditionalize NM subpackage as NM on EL6 is too old 2013-07-15 23:40:59 +01:00
Jamie Nguyen
3da0616101 Add /etc/strongswan/ipsec.d and missing subdirectories 2013-07-15 23:24:02 +01:00
Jamie Nguyen
0b1747fb96 Patch to change 'ipsec scepclient' to 'strongswan scepclient' 2013-07-15 23:20:55 +01:00
Jamie Nguyen
f47589fbf7 Patch to change 'ipsec _updown' to 'strongswan _updown' 2013-07-15 23:20:55 +01:00
Jamie Nguyen
3f787be7c4 Enable hardened_build as it meets the criteria (#984429) 2013-07-15 23:20:54 +01:00
Jamie Nguyen
feae955175 NetworkManager subpackage is missing a license (#984490) 2013-07-15 23:20:54 +01:00
Jamie Nguyen
44b55823f7 Update system related dependencies and scriptlets 2013-07-15 23:20:54 +01:00
Jamie Nguyen
e33f133807 Fix various minor rpmlint errors 2013-07-15 23:20:46 +01:00
Jamie Nguyen
776e0df602 Fix broken systemd unit file (#984300) 2013-07-15 15:18:44 +01:00
Jamie Nguyen
b54e4b359e %files section packages some files as directories (#984437) 2013-07-15 15:10:29 +01:00
Avesh Agarwal
504a6c151f Patch to fix a major crash issue when Freeradius loads
attestatiom-imv and does not initialize libstrongswan which
  causes crash due to calls to PTS algorithms probing APIs.
  So this patch fixes the order of initialization. This issues
  does not occur with charon because libstrongswan gets
  initialized earlier.
- Patch that allows to outputs errors when there are permission
  issues when accessing strongswan.conf.
- Patch to make loading of modules configurable when libimcv
  is used in stand alone mode without charon with freeradius
  and wpa_supplicant.
2013-06-28 15:06:33 -04:00
Avesh Agarwal
44d903a54a Enabled TNCCS 1.1 protocol
- Fixed libxm2-devel build dependency
- Patch to fix the issue with loading of plugins
2013-06-11 12:01:15 -04:00
Avesh Agarwal
82c91d56c3 New upstream release
- Fixes fo CVE-2013-2944
- Enabled support for OS IMV/IMC
- Created and applied a patch to disable ECP in fedora, because
  Openssl in Fedora does not allow ECP_256 and ECP_384. It makes
  it non-compliant to TCG's PTS standard, but there is no choice
  right now. see redhat bz # 319901.
- Enabled Trousers support for TPM based operations.
2013-05-01 16:07:32 -04:00
Pavel Šimerda
bc95a594ac Merge remote-tracking branch 'origin/f18'
Conflicts:
	strongswan.spec
2013-04-20 04:10:16 +02:00
Pavel Šimerda
f6bdfbb5b6 bump for a common spec for rawhide/f19/f18/el6 2013-04-20 04:03:20 +02:00
Pavel Šimerda
5f6c91df4d Merge remote-tracking branch 'origin/f19' 2013-04-20 04:01:35 +02:00
Avesh Agarwal
d0964cb1b4 New upstream release
- Enabled curl and eap-identity plugins
- Enabled support for eap-radius plugin.
2013-04-19 16:29:03 -04:00
Avesh Agarwal
19e0d3b6d9 New upstream release
- Enabled curl and eap-identity plugins
2013-04-19 16:18:34 -04:00
Pavel Šimerda
45197f19c9 Add gettext-devel to BuildRequires because of epel6 2013-04-18 15:27:26 +02:00
Avesh Agarwal
2232b708dc Enabled support for eap-radius plugin. 2013-03-19 14:13:26 -04:00