Component: ike2
257 changelog entries across 109 version(s)
Releases by channel (stacked)
- prefer SAN instead of DN from certificate for ID payload;
- added support for ECDSA certificate authentication (rfc4754);
- prefer SAN instead of DN from certificate for ID payload;
- do not send "User-Name" attribute to RADIUS server if not provided;
- improved XAuth identity conversion on upgrade;
- improved subsequent phase 2 initialization when no childs exist;
- properly handle certificates with empty "Subject";
- retry RSA signature validation with deduced digest from certificate;
- send split networks over DHCP (option 249) to Windows initiators if DHCP Inform is received;
- show weak pre-shared-key warning;
- added option to specify certificate chain;
- added peer identity validation for RSA auth (disabled after upgrade);
- allow to match responder peer by "my-id=fqdn" field;
- fixed local address lookup when initiating new connection;
- retry RSA signature validation with deduced digest from certificate;
- allow to match responder peer by "my-id=fqdn" field;
- added peer identity validation for RSA auth (disabled after upgrade);
- allow to match responder peer by "my-id=fqdn" field;
- properly handle certificates with empty "Subject";
- send split networks over DHCP (option 249) to Windows initiators if DHCP Inform is received;
- added option to specify certificate chain;
- send split networks over DHCP (option 249) to Windows initiators if DHCP Inform is received;
- show weak pre-shared-key warning;
- improved subsequent phase 2 initialization when no childs exist;
- fixed rare authentication and encryption key mismatches after rekey with PFS enabled;
- improved subsequent phase 2 initialization when no child exist;
- fixed rare authentication and encryption key mismatches after rekey with PFS enabled;
- added option to specify certificate chain;
- fixed local address lookup when initiating new connection;
- fixed rare authentication and encryption key mismatches after rekey with PFS enabled;
- fixed initiator first policy selection;
- fixed rekeyed child deletion during another exchange;
- improved basic exchange logging readability;
- use "/32" netmask by default on initiator if not provided by responder;
- fixed initiator first policy selection;
- fixed rekeyed child deletion during another exchange;
- improved basic exchange logging readability;
- use "/32" netmask by default on initiator if not provided by responder;
- use "policy-template-group" parameter when picking proposal as initiator;
- use "policy-template-group" parameter when picking proposal as initiator;
- use "policy-template-group" parameter when picking proposal as initiator;
- fixed framed IP address received from RADIUS server;
- fixed framed IP address received from RADIUS server;
- added support for multiple split networks;
- delay rekeyed peer outbound SA installation;
- improve half-open connection handling;
- kill connection when peer changes address;
- use peer configuration address when available on empty TSi;
- delay rekeyed peer outbound SA installation;
- improve half-open connection handling;
- delay rekeyed peer outbound SA installation;
- improve half-open connection handling;