Nikos Mavrogiannopoulos
4a2a80dc7d
Updated the included http-parser
2014-03-11 13:19:06 +01:00
Nikos Mavrogiannopoulos
8a1ab0e32d
Print a compact version of the DTLS ciphersuite.
2014-03-10 19:25:47 +01:00
Nikos Mavrogiannopoulos
35c31bc0b7
Allow TUN_MTU command only in authenticated state
2014-03-10 10:41:27 +01:00
Nikos Mavrogiannopoulos
6028e5d81d
simplified handle_auth_res()
2014-03-10 10:41:27 +01:00
Nikos Mavrogiannopoulos
f55185b39c
doc update
2014-03-09 21:42:00 +01:00
Nikos Mavrogiannopoulos
4f9e06d16d
Do not block in TLS and DTLS reads
...
This prevents an issue where a client disconnects but the server
is blocked on a DTLS read without being able to detect the
disconnection.
2014-03-09 21:40:07 +01:00
Nikos Mavrogiannopoulos
a0723ccee9
check return value of tls_send()
2014-03-09 21:37:33 +01:00
Nikos Mavrogiannopoulos
6c331db70a
move bytes2human in occtl.c to allow compilation without libnl
2014-03-09 21:31:51 +01:00
Nikos Mavrogiannopoulos
28e64c4eec
doc update
2014-03-02 19:36:50 +01:00
Nikos Mavrogiannopoulos
e72414459a
provide the bandwidth limit through d-bus
2014-03-02 13:24:44 +01:00
Nikos Mavrogiannopoulos
949fbacf32
doc update
2014-03-01 17:38:22 +01:00
Nikos Mavrogiannopoulos
a0ba998222
occtl will print the user's dns, nbns, routes, and iroutes.
2014-03-01 15:29:17 +01:00
Nikos Mavrogiannopoulos
20cc945383
Warn when setting a default route the wrong way.
2014-03-01 14:23:22 +01:00
Nikos Mavrogiannopoulos
65f8be6eb6
bumped version
2014-02-26 23:10:07 +01:00
Nikos Mavrogiannopoulos
cbc827ae99
doc update
2014-02-24 21:22:18 +01:00
Nikos Mavrogiannopoulos
c75dad511d
doc update
2014-02-24 21:21:47 +01:00
Nikos Mavrogiannopoulos
1a996e5ebe
doc update
2014-02-24 19:15:32 +01:00
Nikos Mavrogiannopoulos
66d66ba1c5
Added options to explicitly disable checking for certain libraries
2014-02-24 19:13:05 +01:00
Nikos Mavrogiannopoulos
194462a600
use remove_proc() instead of user_disconnected() when killing children.
2014-02-23 11:50:01 +01:00
Nikos Mavrogiannopoulos
3dfeab0174
doc update
2014-02-22 12:54:55 +01:00
Nikos Mavrogiannopoulos
de1f63605b
updated sample
2014-02-22 12:54:40 +01:00
Nikos Mavrogiannopoulos
95a0b6abc3
Added the rekey-method config option.
2014-02-22 12:51:34 +01:00
Nikos Mavrogiannopoulos
25afdb5949
use RND_RANDOM for the generation of SID
2014-02-22 10:00:32 +01:00
Nikos Mavrogiannopoulos
5ac591a37e
doc update
2014-02-18 19:42:21 +01:00
Nikos Mavrogiannopoulos
7b73aee479
when mobile-dpd and mobile-idle-timeout are not set, they get values from their non-mobile counterpart.
2014-02-18 19:39:37 +01:00
Nikos Mavrogiannopoulos
c47266ede0
doc update
2014-02-18 18:56:40 +01:00
Nikos Mavrogiannopoulos
6ee0899e22
Added the mobile-idle-timeout config option.
2014-02-18 18:54:50 +01:00
Nikos Mavrogiannopoulos
b550489c88
better messages from pam authentication module
2014-02-18 18:39:44 +01:00
Nikos Mavrogiannopoulos
d361bd608d
only print an authentication failure message if the maximum tries have been reached
2014-02-18 18:36:58 +01:00
Nikos Mavrogiannopoulos
a609cf58b7
send disconnect packet instead of server terminate when disconnecting a user.
2014-02-18 18:32:10 +01:00
Nikos Mavrogiannopoulos
367976ca34
Implemented Idle timeout.
...
When set, a client that does not have any non-control traffic
for that period is getting disconnected.
2014-02-18 18:09:23 +01:00
Nikos Mavrogiannopoulos
2399aafe35
modified priorities
2014-02-18 13:11:38 +01:00
Nikos Mavrogiannopoulos
bc10b97207
added debug message in remove_proc
2014-02-18 09:04:21 +01:00
Nikos Mavrogiannopoulos
c5c38e92bd
Do not allow DPD to be disabled.
...
Doing so would prevent the server from dropping inactive
connections. If the dpd values are not configured, set some
reasonable defaults.
2014-02-17 22:40:32 +01:00
Nikos Mavrogiannopoulos
faf0a7133b
doc update
2014-02-17 22:22:07 +01:00
Nikos Mavrogiannopoulos
2bd6f5a6a1
Added the mobile-dpd configuration option.
...
This option allows setting a different DPD value for
mobile clients to allow them going to sleep for longer time.
2014-02-17 22:17:09 +01:00
Nikos Mavrogiannopoulos
821f56f5e1
doc update
2014-02-17 20:21:08 +01:00
Nikos Mavrogiannopoulos
be332174f8
Simplified debugging by allowing multiple levels.
...
'ocserv -d' now accepts a numeric option from 0 (no debugging) to 9
(maximum verbosity).
2014-02-17 20:19:39 +01:00
Nikos Mavrogiannopoulos
1eab85479c
better log names.
2014-02-17 15:53:34 +01:00
Nikos Mavrogiannopoulos
4cf84152e5
doc update
2014-02-17 15:46:35 +01:00
Nikos Mavrogiannopoulos
882c37b17a
Added profile.xml to the distributed files
2014-02-17 15:36:33 +01:00
Nikos Mavrogiannopoulos
8c2acab693
Added 'See Also' section in occtl.8
2014-02-17 15:25:07 +01:00
Nikos Mavrogiannopoulos
f85ee029a8
doc update
2014-02-17 08:43:28 +01:00
Nikos Mavrogiannopoulos
3cf1d409db
better wording
2014-02-16 22:48:15 +01:00
Nikos Mavrogiannopoulos
991455065f
simplified handling of CISCO reconnecting clients.
...
Instead of having a client use the initial SID over and over,
re-set the SID cookie, during authentication when needed. That
way we avoid having expensive checks to ensure uniqueness of SID.
2014-02-16 22:47:45 +01:00
Nikos Mavrogiannopoulos
9d3453877f
eliminated double [m]
2014-02-16 21:31:32 +01:00
Nikos Mavrogiannopoulos
247ac9e683
Indicate the main process in message logging, to distinguish from worker messages.
2014-02-16 19:25:15 +01:00
Nikos Mavrogiannopoulos
d339be261e
Better messages in password asking.
2014-02-16 19:19:25 +01:00
Nikos Mavrogiannopoulos
24403dddcb
doc update
2014-02-16 19:12:54 +01:00
Nikos Mavrogiannopoulos
fd7f3e65ce
Allow a number of retries in plain password authentication.
2014-02-16 19:10:49 +01:00