Component: ipsec,ike2
20 changelog entries across 9 version(s)
Releases by channel (stacked)
- fixed ppk child key generation during rekey;
- improved KE generation validation during initial setup and child SA creation;
- improved PPK handling by always using it when authorized, including additional Child SAs, and moved PPK processing to the Child SA task;
- use first child KE selection only during IKE_AUTH exchange;
- fixed ppk child key generation during rekey;
- use first child KE selection only during IKE_AUTH exchange;
- improved logging when remote ID is specified;
- use peer certificates also when identity has one set for peer matching;
- use peer certificates also when identity has one set for peer matching;
- fixed active connection termination;
- fixed SA payload validation;
- improved pending child SA cleanup and removal of dangling SAs during Phase 2 deletion;
- improved PPK handling by always using it when authorized, including additional Child SAs, and moved PPK processing to the Child SA task;
- fixed active connection termination;
- fixed SA payload validation;
- improved pending child SA cleanup and removal of dangling SAs during Phase 2 deletion;
- improved TSi validation to prevent modecfg address conflicts;
- improved KE generation validation during initial setup and child SA creation;
- improved logging when remote ID is specified;
- improved TSi validation to prevent modecfg address conflicts;