Component: ike1
58 changelog entries across 32 version(s)
Activity over time (changelog entries per month)
- fixed an issue where policies could be released too early before re-acquisition;
- removed unsupported NAT-D drafts with invalid payload numbers;
- fixed invalid key length on phase1 negotiation;
- log an error when non-RSA keys are being used;
- fixed Phase 1 when using aggressive exchange mode (introduced in v7.10);
- disallow "remote-id" setting for identity;
- fixed XAuth responder trying to recreate phase 1;
- improved expired IPsec-SA processing;
- fixed "my-id=address" parameter usage together with certificate authentication;
- fixed 'rsa-signature-hybrid' authentication method;
- fixed memory leak on multiple CR payloads;
- fixed policy update with and without mode configuration;
- rekey phase 1 as responder for Windows initiators;
- allow using "my-id" parameter with XAuth;
- allow using "my-id" parameter with XAuth;
- improved stability when performing policy lookup on non-existant peer;
- added error message when specifying "my-id" for XAuth identity;
- added support for "UNITY_DEF_DOMAIN" and "UNITY_SPLITDNS_NAME" payload attributes;
- do not try to keep phase 2 when purging phase 1;
- improved policy lookup with specific protocol;
- improved stability when performing policy lookup on non-existant peer;
- rekey phase 1 rekeying as responder for Windows initiators;
- rekey phase 1 rekeying as responder for Windows initiators;
- fixed minor spelling mistake in logs;
- adjusted debug packet logging topics;
- improved stability for transport mode policies on initiator side;
- improved stability for transport mode policies on initiator side;
- do not allow using RSA-key and RSA-signature authentication methods simultaneously on single peer;
- fixed memory leak;
- added unsafe configuration warning for main mode with pre-shared-key authentication;
- purge both SAs when timer expires;
- zero out reserved bytes in NAT-OA payload;
- display error message when peer requests "mode-config" when it is not configured;
- do not accept "mode-config" reply more than once;
- fixed wildcard policy lookup on responder;
- fixed crash on XAUTH if user does not exist;
- fixed memory corruption when IPv6 is used;
- improved stability on phase1 rekeying;
- fixed "aes-ctr" and "aes-gcm" encryption algorithms (introduced v6.41);
- DPD retry interval set to 5 seconds;
- disallow peer creation using base mode;
- fixed crash on xauth if user does not exist;
- fixed memory corruption when IPv6 is used;
- improved stability on phase1 rekeying;
- release mismatched PH2 peer IDs;
- use /32 netmask if none provided by mode config;
- fixed crash after downgrade if DH groups 19,20,21 were used for phase1;
- fixed RSA authentication for Windows clients behind NAT;
- fixed initiator ID comparison to NAT-OA;
- remove PH1 and PH2 when "mode-config" exchange fails;
- fixed initiator ID comparison to NAT-OA;
- fixed crash on xauth message;
- fixed crash on xauth message;
- removed xauth login length limitation;
- fixed ph2 ID logging;
- fixed “xauth” Radius login;
- fixed responder xauth trailing null;
- fixed ph1 rekey in setups with mode-cfg;