Component: ike2
257 changelog entries across 109 version(s)
Releases by channel (stacked)
- improved EAP message integrity checking;
- added support for IKEv2 Message Fragmentation (RFC7383);
- fixed EAP MSK length validation;
- fixed too small payload parsing;
- fixed local side NAT detection;
- fixed policy reference for pending acquire;
- retry RSA signature validation with deduced digest from certificate;
- fixed local side NAT detection;
- fixed local side NAT detection;
- fixed initiator child SA init without policy;
- fixed policy reference for pending acquire;
- retry RSA signature validation with deduced digest from certificate;
- added "prf-algorithm" support for phase 1;
- fixed initiator child SA init without policy;
- fixed policy reference for pending acquire;
- improved child SA rekeying process;
- retry RSA signature validation with deduced digest from certificate;
- added support for "INTERNAL_DNS_DOMAIN" payload attribute;
- added support for RADIUS Disconnect-Request message handling;
- added support for RFC8598;
- allow initiator address change before authentication;
- fixed authentication handling when initiator disconnects before RADIUS response;
- added support for RFC8598;
- allow initiator address change before authentication;
- fixed authentication handling when initiator disconnects before RADIUS response;
- added support for RADIUS Disconnect-Request message handling;
- fixed DHCP Inform package handling when received on PPPoE interface;
- added support for "INTERNAL_DNS_DOMAIN" payload attribute;
- fixed DHCP Inform package handling when received on PPPoE interface;
- improved CHILD SA rekey process with Apple iOS 13;
- improved stability when retransmitting first packet as responder;
- improved stability when retransmitting first packet as responder;
- improved CHILD SA rekey process with Apple iOS 13;
- fixed phase 1 rekeying (introduced in v6.45);
- fixed policy port selection for responder with natted initiator;
- fixed traffic selector address family selection when using IPv6;
- fixed phase 1 rekeying (introduced in v6.45);
- don't release policy on rekey when child not found;
- fixed ID validation with multiple SAN;
- fixed policy port selection for responder with natted initiator;
- fixed traffic selector address family selection when using IPv6;
- improved rekeying process with Windows initiators;
- properly start all initiators to the same remote address;
- fixed IPv6 policy generation (introduced in v6.46beta28);
- fixed traffic selector address family selection when using IPv6;
- properly start all initiators to the same remote address;
- don't release policy on rekey when child not found;
- fixed ID validation with multiple SAN;
- fixed policy port selection for responder with natted initiator;
- improved rekeying process with Windows initiators;
- added support for ECDSA certificate authentication (rfc4754);
- added support for IKE SA rekeying for initiator;
- do not send "User-Name" attribute to RADIUS server if not provided;
- improved certificate verification when multiple CA certificates received from responder;
- improved child SA rekeying process;
- improved XAuth identity conversion on upgrade;
- prefer SAN instead of DN from certificate for ID payload;
- added support for IKE rekeying for initiator;
- improved child SA rekeying process;
- fixed pre-shared-key authentication failure (introduced in v6.45beta34);
- improved certificate verification when multiple CA certificates received from responder;
- fixed first child SA generation (introduced in v6.45beta34);