Nikos Mavrogiannopoulos
f2bef25cdc
sample.config: use new paths
2016-06-17 11:54:07 +02:00
Nikos Mavrogiannopoulos
3eb5dd360e
doc update
2016-04-17 10:45:26 +02:00
Nikos Mavrogiannopoulos
ade786a0f1
radius: replace experimental Group-Name with Class attribute
...
The current format allows to handle multiple groups and is used
by several radius servers.
Suggested by Yick Xie.
2016-04-01 15:33:11 +02:00
Nikos Mavrogiannopoulos
0b4333d7ee
ocserv: warn when conflicting supplemental config options are specified
...
That is, do not allow radius' groupconfig=true option to be combined
with config-per-user/group. This reduces frustration since these options
are incompatible.
2016-04-01 15:32:27 +02:00
Nikos Mavrogiannopoulos
435c78fa3d
doc: eliminated references to HOSTNAME
...
It was never available in the up/down scripts.
2016-03-05 16:45:39 +01:00
Nikos Mavrogiannopoulos
63d3b98cad
use more consistent naming in internal messages
2016-03-05 14:00:50 +01:00
Nikos Mavrogiannopoulos
010257c6a2
Simplified cookie handling
...
This change set eliminates the need for cryptographically authenticated
cookies and relies on sec-module providing accurate information on
the SID provided by the client.
2016-02-23 15:31:17 +01:00
Nikos Mavrogiannopoulos
aa6bd829d4
increased the default cookie rekey time to 3 days
2016-02-21 12:43:20 +01:00
Nikos Mavrogiannopoulos
b130bd9214
config: increased the default auth-timeout value to 4mins
...
This provides slow users more time to enter their username,
password.
2016-02-13 14:49:08 +01:00
Nikos Mavrogiannopoulos
89f02bad02
config: put kkdcp options into brackets
...
That is not necessary for the existing examples, but may be
in future ones, as they may contain characters that libopts doesn't
like.
2016-02-08 19:27:39 +01:00
Nikos Mavrogiannopoulos
b6df22c8c3
Reload the certificates and private keys on SIGHUP
...
Until now this part of the configuration was static, but
there is the need to reload certificates and keys, e.g., on
renewal.
2016-01-26 12:51:05 +01:00
Nikos Mavrogiannopoulos
c61e5eb47b
doc: document that ocserv-fw requiring options are available in Linux systems only
2016-01-25 11:16:06 +01:00
Nikos Mavrogiannopoulos
d0fc4ce92b
doc: added more info on isolate-workers
2016-01-20 13:12:37 +01:00
Nikos Mavrogiannopoulos
c662641768
README.radius: added Connect-Info attribute
2016-01-17 23:13:04 +01:00
Nikos Mavrogiannopoulos
e4cedfb898
README-radius: added more text for Framed-Route format
2016-01-01 23:35:24 +02:00
Nikos Mavrogiannopoulos
3b0342c678
doc update
2015-12-08 14:35:30 +01:00
Nikos Mavrogiannopoulos
14d19b3e9a
Enhanced configuration option 'restrict-user-to-ports'
...
This enhancement allows to negate the rules and allow the user connecting
to all ports except the specified.
2015-12-07 11:15:56 +01:00
Nikos Mavrogiannopoulos
d910c8952b
doc: list 'route=default' as an example
2015-12-02 10:41:16 +01:00
Nikos Mavrogiannopoulos
eabfbe8473
Added configuration option 'restrict-user-to-ports'
...
This option is intended to allow restricting users to accessing
specific ports once they enter the VPN. The rules set using this
option will be enforced by the ocserv-fw script.
2015-12-02 10:38:12 +01:00
Nikos Mavrogiannopoulos
53376c96a2
doc: document the behavior of restrict-user-to-routes in case of defaultroute
2015-11-29 20:24:32 +01:00
Nikos Mavrogiannopoulos
f86fb99b50
doc update
2015-11-24 00:29:31 +01:00
Nikos Mavrogiannopoulos
c7fe48f372
scripts: export the routes,no-routes and dns servers
2015-11-23 10:53:43 +01:00
Nikos Mavrogiannopoulos
8d03519fb2
doc update
2015-11-17 11:02:26 +01:00
Nikos Mavrogiannopoulos
2473633b8d
Added cookie key rotation
2015-11-17 08:33:38 +01:00
Nikos Mavrogiannopoulos
8cb807d27d
design.md: document a possible optimization in IPC protocol
2015-11-13 12:46:36 +01:00
Nikos Mavrogiannopoulos
65004a55df
Added configuration option tunnel-all-dns
2015-11-10 13:50:03 +01:00
Nikos Mavrogiannopoulos
5138a39116
Added a draft design document
2015-11-10 13:49:56 +01:00
Nikos Mavrogiannopoulos
0b8f4beb8b
Added user-specific configuration options dpd, mobile-dpd, keepalive, max-same-clients
2015-11-10 13:49:13 +01:00
Nikos Mavrogiannopoulos
d72424b9c0
doc update
2015-10-30 14:40:49 +01:00
Nikos Mavrogiannopoulos
4ae1c3e2ff
occtl and ocpasswd were moved into separate directories
2015-10-30 13:51:19 +01:00
Nikos Mavrogiannopoulos
5a10283125
Added the config option expose-iroutes
...
This allows the server to advertise routes offered by few clients
to all clients except the ones offering them.
2015-10-25 22:43:54 +01:00
Nikos Mavrogiannopoulos
40bd1550c1
ipv6: introduced ipv6-subnet-prefix config option
...
That option allows to specify the IPv6 subnet prefix to be given
to client. That is, allow providing the clients networks larger
than /128. Set the option to 128 to simulate the previous behavior
of ocserv.
2015-10-24 19:26:48 +02:00
Nikos Mavrogiannopoulos
e5d02eb228
plain auth: support OTP authentication using usersfile
...
That adds a dependency on liboath.
2015-09-25 15:03:38 +02:00
Nikos Mavrogiannopoulos
568d6fa767
mention the possibility of proxy arp
2015-09-24 09:52:18 +02:00
Nikos Mavrogiannopoulos
a135c90e54
README-radius: use /etc/radcli for paths
2015-09-23 00:07:16 +02:00
Nikos Mavrogiannopoulos
a8ea052bbf
doc: converted README.radius to markdown and link it from README.md
2015-09-19 20:43:44 +02:00
Nikos Mavrogiannopoulos
0461787fcc
doc update
2015-09-18 16:45:53 +02:00
Nikos Mavrogiannopoulos
1bfa6e7648
Reinstated the PAM accounting method
...
It can be used to check for a valid PAM account, even when
certificates or another authentication method is in use.
2015-09-18 16:45:32 +02:00
Nikos Mavrogiannopoulos
f2caadbe83
updated documentation for CRL reload
2015-09-14 17:59:58 +02:00
Nikos Mavrogiannopoulos
edba5fc23e
removed pam accounting method from config file
...
Reported by Stuart Henderson.
2015-09-05 00:16:06 +02:00
Nikos Mavrogiannopoulos
1c64073cf2
pam: removed accounting; it served no purpose
...
In fact it could even cause issues in the security-module
depending on what was configured in PAM.
2015-08-31 16:19:48 +02:00
Nikos Mavrogiannopoulos
2a949e99c4
configure: discover suitable sed program
2015-08-17 14:20:41 +02:00
Nikos Mavrogiannopoulos
17e71dccd8
Added support for proxy protocol (v2)
2015-07-15 13:03:58 +02:00
Nikos Mavrogiannopoulos
3f48b31a9e
use quotes in all examples to avoid issues in modifications
2015-06-29 15:33:16 +02:00
Nikos Mavrogiannopoulos
8b186fb53a
Allow specifying a PIN and SRK PIN in the config file
...
That pin will be used to decrypt encrypted key files as well.
2015-06-25 14:12:57 +02:00
Nikos Mavrogiannopoulos
3e6b8fadb3
updated radcli URLs
2015-06-05 23:57:03 +02:00
Nikos Mavrogiannopoulos
2bce9455a0
use radcli as the radius library if found
2015-06-05 22:36:02 +02:00
Nikos Mavrogiannopoulos
d5c9fe7b02
added NAS-Identifier into dictionary
2015-06-03 19:52:33 +02:00
Nikos Mavrogiannopoulos
89500cb205
removed dbus option
2015-05-26 16:12:49 +02:00
Nikos Mavrogiannopoulos
f954983f7a
sample.config: bring in par with ocserv-args.def
2015-05-23 11:16:43 +02:00