Nikos Mavrogiannopoulos
f4d14f7000
sec-mod: will exit if it fails to process commands from main
2015-03-02 09:00:18 +01:00
Nikos Mavrogiannopoulos
65c83c6e84
added option to completely disable compression support
2015-03-01 09:50:24 +01:00
David Woodhouse
bbe272a0b4
Stop using 1ULL as the base value to be shifted in LZS GET_BITS()
...
Keeping this as an int is fine; it'll never be shifted by more than 9. And
the promotion of (src[0] << (bits - bits_left)) from int to unsigned long
long makes Coverity unhappy because of the sign-extension.
(patch copied from openconnect)
Signed-off-by: David Woodhouse <David.Woodhouse@intel.com >
2015-03-01 09:46:43 +01:00
Nikos Mavrogiannopoulos
4aa726bd9c
main-ctl-unix: avoid using remove_proc() unless necessary
2015-02-27 22:51:49 +01:00
Nikos Mavrogiannopoulos
58a3c7fd58
close stdin and stdout descriptors by default
2015-02-27 22:45:06 +01:00
Nikos Mavrogiannopoulos
c0838241d0
updated log message
2015-02-27 22:40:26 +01:00
Nikos Mavrogiannopoulos
d89862811f
tests: added missing file
2015-02-27 22:39:57 +01:00
Nikos Mavrogiannopoulos
4eafc3c847
client stats are conveyed to master through sec-mod
...
That way both can keep a more accurate picture of user statistics.
2015-02-27 22:33:58 +01:00
Nikos Mavrogiannopoulos
7a11fa615c
worker only sends stats to sec-mod
2015-02-27 21:51:30 +01:00
Nikos Mavrogiannopoulos
ee7cba2fd2
sec-mod: simplified session open and close handling
2015-02-27 21:45:23 +01:00
Nikos Mavrogiannopoulos
fa55722897
connects and disconnects to main are logged with LOG_INFO
2015-02-27 21:37:12 +01:00
Nikos Mavrogiannopoulos
b1fe057f8c
tests: kerberos-test includes check on KKDCP functionality
2015-02-27 15:07:10 +01:00
Nikos Mavrogiannopoulos
8bc43d6977
kkdcp.asn: use GeneralString for KerberosString to follow RFC1510
2015-02-27 15:01:20 +01:00
Nikos Mavrogiannopoulos
dd8b53f655
worker: send correct ipv4 address when an IPv6 is present
2015-02-27 14:11:39 +01:00
Nikos Mavrogiannopoulos
1e18234d2f
kkdcp: fixes in post handler
2015-02-27 14:10:44 +01:00
Nikos Mavrogiannopoulos
d0ae4e7e78
removed pointless checks
2015-02-27 14:05:14 +01:00
Nikos Mavrogiannopoulos
c8cd64c9ca
tun: combined code used in SIOCIFDESTROY case
2015-02-27 14:03:54 +01:00
Nikos Mavrogiannopoulos
09d682d213
tlslib: eliminated pointless check
2015-02-27 14:02:22 +01:00
Nikos Mavrogiannopoulos
da6f439d27
tlslib: call va_end earlier to avoid memory leak
2015-02-27 14:01:25 +01:00
Nikos Mavrogiannopoulos
c80c8dc15b
config: expand_brackets_string tolerates null values
2015-02-27 14:00:15 +01:00
Nikos Mavrogiannopoulos
01fd48f093
occtl-unix: removed dead code
2015-02-27 13:58:44 +01:00
Nikos Mavrogiannopoulos
449dddb13e
worker: fixed caching of message received from main
2015-02-27 13:55:06 +01:00
Nikos Mavrogiannopoulos
17dbc5a29f
config: print the primary authentication method only once
2015-02-27 13:52:18 +01:00
Nikos Mavrogiannopoulos
fa6fa5306b
radius: eliminate dead variable
2015-02-27 13:50:01 +01:00
Nikos Mavrogiannopoulos
3f12eac4db
tests: corrected copyright dates
2015-02-27 10:34:46 +01:00
Nikos Mavrogiannopoulos
bfb4f1f95b
tests: added check for IP banning subsystem
2015-02-27 09:06:53 +01:00
Nikos Mavrogiannopoulos
4bbf27a1e8
don't attempt keeping scores for banning if banning is disabled
2015-02-27 08:57:26 +01:00
Nikos Mavrogiannopoulos
b8b1d5a212
occtl: unban -> unban ip
2015-02-27 08:52:50 +01:00
Nikos Mavrogiannopoulos
56bb8e1be1
sec-mod: do not reply on session close cmd
2015-02-27 07:50:59 +01:00
Nikos Mavrogiannopoulos
ea69621318
don't print message on adding a banned entry if already banned
2015-02-26 21:37:41 +01:00
Nikos Mavrogiannopoulos
0f5b9d1ebd
print the accurate time on banned IP expiration
2015-02-26 21:35:35 +01:00
Nikos Mavrogiannopoulos
1f6340f1fa
occtl: banned IPs -> IPs in ban list
2015-02-26 21:17:08 +01:00
Nikos Mavrogiannopoulos
9f95d086d9
removed unused variables and structures
2015-02-26 21:15:17 +01:00
Nikos Mavrogiannopoulos
3acd229e81
occtl: pretty print uptime
2015-02-26 21:13:13 +01:00
Nikos Mavrogiannopoulos
6e9b202aa8
occtl: pretty print expiration time in bans
2015-02-26 21:07:51 +01:00
Nikos Mavrogiannopoulos
e64528c9f1
occtl: avoid crash on empty cmdline argument
2015-02-26 20:59:03 +01:00
Nikos Mavrogiannopoulos
056730e931
removed duplicate entries in makefile
2015-02-26 20:58:49 +01:00
Nikos Mavrogiannopoulos
9a97565a60
occtl: rename show ip points to show ip ban points
2015-02-26 20:49:39 +01:00
Nikos Mavrogiannopoulos
15f0733f7d
PAM accounting is only included when PAM is enabled
2015-02-26 20:40:29 +01:00
Nikos Mavrogiannopoulos
9c9ac721c2
include kkdcp_asn1_tab.c only when GSSAPI is included
2015-02-26 20:39:53 +01:00
Nikos Mavrogiannopoulos
2c23c86d48
removed unused parameter of select()
2015-02-26 20:36:49 +01:00
Nikos Mavrogiannopoulos
24842d837e
include security/pam_appl.h only when PAM is enabled
2015-02-26 20:36:20 +01:00
Nikos Mavrogiannopoulos
f725c08576
removed obsolete file
2015-02-26 20:32:13 +01:00
Nikos Mavrogiannopoulos
9552638acd
occtl: added cache and completion for IP addresses
2015-02-26 16:27:19 +01:00
Nikos Mavrogiannopoulos
17c1c3d381
sanitize IP addresses provided by occtl
2015-02-26 16:15:40 +01:00
Nikos Mavrogiannopoulos
ac1e057158
occtl: allow listing only bans, or points
2015-02-26 15:52:59 +01:00
Nikos Mavrogiannopoulos
596cc35ff3
do not continuously extend the expiration time of banned IP entry
2015-02-26 15:40:58 +01:00
Nikos Mavrogiannopoulos
73ba4c06cb
doc update
2015-02-26 14:37:06 +01:00
Nikos Mavrogiannopoulos
0326ec168b
occtl: added ability to list banned, and unban IPs
2015-02-26 14:33:38 +01:00
Nikos Mavrogiannopoulos
bbee3767dc
sec-mod: don't use a timeout value in select()
...
There is no need for that.
2015-02-26 13:41:39 +01:00