Component: ike2
257 changelog entries across 109 version(s)
Releases by channel (stacked)
- added support for "address", "key-id" and "dn" for Remote ID matching (CLI only);
- fixed active SA flush on responder after an unsuccessful peer connection attempt;
- fixed active SA flush on responder after an unsuccessful peer connection attempt;
- added support for "address", "key-id" and "dn" for Remote ID matching (CLI only);
- added support for ChaChaPoly1305 encryption;
- added support for DH Group 31 (EC25519) (CLI only);
- fixed rekey notify creation;
- improved certificate payload parsing;
- added support for ChaChaPoly1305 encryption;
- added support for ChaChaPoly1305 encryption;
- fixed rekey notify creation;
- improved certificate payload parsing;
- added support for ChaChaPoly1305 encryption (CLI only);
- added support for DH Group 31 (EC25519) (CLI only);
- allow sending certificate chain as initiator;
- allow sending certificate chain as initiator;
- allow sending certificate chain as initiator;
- ignore "INITIAL-CONTACT" payload on responder when "send-initial-contact" is disabled;
- ignore "INITIAL-CONTACT" payload on responder when "send-initial-contact" is disabled;
- added support for ASN.1 DN "my-id" value setting for initiators;
- check if TS is still valid after obtaining SPI;
- fixed initiator packet retransmit with DDOS cookie;
- check if TS is still valid after obtaining SPI;
- added "MS-CHAP-Domain" attribute to RADIUS requests;
- added "MS-CHAP-Domain" attribute to RADIUS requests;
- added support for ASN.1 DN "my-id" value setting for initiators;
- check if TS is still valid after obtaining SPI;
- added "MS-CHAP-Domain" attribute to RADIUS requests;
- fixed initiator packet retransmit with DDOS cookie;
- added "MS-CHAP-Domain" attribute to RADIUS requests;
- fixed DH group negotiation with EAP;
- fixed EAP MSK length validation (introduced in v6.48);
- fixed initial traffic selector's protocol and port in transport mode;
- fixed DH group negotiation with EAP;
- fixed initial traffic selector's protocol and port in transport mode;
- added support for ASN.1 DN "my-id" value setting for initiators;
- fixed EAP MSK length validation (introduced in v6.48);
- fixed phase 2 rekeying with enabled PFS (introduced in v6.48);
- improved stability when invalid certificate is configured (introduced in v6.48);
- properly register packet time after expensive CPU operations;
- added "prf-algorithm" support for phase 1;
- added support for IKEv2 Message Fragmentation (RFC7383);
- fixed EAP MSK length validation;
- fixed too small payload parsing;
- improved EAP message integrity checking;
- improved child SA rekeying process;