tangled
alpha
login
or
join now
jcs.org
/
openbsd-src
0
fork
atom
jcs's openbsd hax
openbsd
0
fork
atom
overview
issues
pulls
pipelines
openbsd-src
/
regress
/
sbin
/
ipsecctl
/
at
master
422 files
Makefile
Add tests with the ipsec.conf SA bundle keyword.
9 years ago
ak128
Make tests more readable by using predefined keyfiles. Add test for tcpmd5 using a key from a file.
20 years ago
ak160
Make tests more readable by using predefined keyfiles. Add test for tcpmd5 using a key from a file.
20 years ago
ak256
Make tests more readable by using predefined keyfiles. Add test for tcpmd5 using a key from a file.
20 years ago
ak384
Make tests more readable by using predefined keyfiles. Add test for tcpmd5 using a key from a file.
20 years ago
ak512
Make tests more readable by using predefined keyfiles. Add test for tcpmd5 using a key from a file.
20 years ago
ek128
Make tests more readable by using predefined keyfiles. Add test for tcpmd5 using a key from a file.
20 years ago
ek160
Make tests more readable by using predefined keyfiles. Add test for tcpmd5 using a key from a file.
20 years ago
ek192
Make tests more readable by using predefined keyfiles. Add test for tcpmd5 using a key from a file.
20 years ago
ek224
AES-CTR, AES-GCM, AES-GMAC are disallowed with manual SAs
13 years ago
ek256
AES-CTR, AES-GCM, AES-GMAC are disallowed with manual SAs
13 years ago
ek288
AES-CTR, AES-GCM, AES-GMAC are disallowed with manual SAs
13 years ago
ek64
Make tests more readable by using predefined keyfiles. Add test for tcpmd5 using a key from a file.
20 years ago
ek80
Make tests more readable by using predefined keyfiles. Add test for tcpmd5 using a key from a file.
20 years ago
ike1.in
regression tests for isakmp/ike
20 years ago
ike1.ok
Adjust for the new default MODP group
9 years ago
ike10.in
allow specification of encapsulated protocol for ike; ok hshoexer
20 years ago
ike10.ok
Adjust for the new default MODP group
9 years ago
ike11.in
regression tests for "local"
20 years ago
ike11.ok
Adjust for the new default MODP group
9 years ago
ike12.in
tests for rule expansion and ike
20 years ago
ike12.ok
Adjust for the new default MODP group
9 years ago
ike13.in
tests for rule expansion and ike
20 years ago
ike13.ok
Adjust for the new default MODP group
9 years ago
ike14.in
tests for rule expansion and ike
20 years ago
ike14.ok
Adjust for the new default MODP group
9 years ago
ike15.in
add some regress for v6; ok hshoexer@
20 years ago
ike15.ok
Adjust for the new default MODP group
9 years ago
ike16.in
add some regress for v6; ok hshoexer@
20 years ago
ike16.ok
sync with transform-name-fix
13 years ago
ike17.in
add some regress for v6; ok hshoexer@
20 years ago
ike17.ok
Adjust for the new default MODP group
9 years ago
ike18.in
add some regress for v6; ok hshoexer@
20 years ago
ike18.ok
Adjust for the new default MODP group
9 years ago
ike19.in
add some regress for v6; ok hshoexer@
20 years ago
ike19.ok
Adjust for the new default MODP group
9 years ago
ike2.in
regression tests for isakmp/ike
20 years ago
ike2.ok
Adjust for the new default MODP group
9 years ago
ike20.in
add some regress for v6; ok hshoexer@
20 years ago
ike20.ok
Adjust for the new default MODP group
9 years ago
ike21.in
add some regress for v6; ok hshoexer@
20 years ago
ike21.ok
Adjust for the new default MODP group
9 years ago
ike22.in
add some regress for v6; ok hshoexer@
20 years ago
ike22.ok
Adjust for the new default MODP group
9 years ago
ike23.in
add some regress for v6; ok hshoexer@
20 years ago
ike23.ok
Adjust for the new default MODP group
9 years ago
ike29.in
add some regress for v6; ok hshoexer@
20 years ago
ike29.ok
Adjust for the new default MODP group
9 years ago
ike3.in
regression tests for isakmp/ike
20 years ago
ike3.ok
Adjust for the new default MODP group
9 years ago
ike30.in
add some regress for v6; ok hshoexer@
20 years ago
ike30.ok
Adjust for the new default MODP group
9 years ago
ike31.in
add some regress for v6; ok hshoexer@
20 years ago
ike31.ok
Adjust for the new default MODP group
9 years ago
ike32.in
Rename "life" to "lifetime" to match iked.
13 years ago
ike32.ok
Adjust for the new default MODP group
9 years ago
ike33.in
Rename "life" to "lifetime" to match iked.
13 years ago
ike33.ok
Adjust for the new default MODP group
9 years ago
ike34.in
really, this is the correct *.ok output, what was generated in the past was due to recently fixed code move some ike?? to ikefail?
20 years ago
ike34.ok
Adjust for the new default MODP group
9 years ago
ike35.in
really, this is the correct *.ok output, what was generated in the past was due to recently fixed code move some ike?? to ikefail?
20 years ago
ike35.ok
Adjust for the new default MODP group
9 years ago
ike36.in
add some regress for v6; ok hshoexer@
20 years ago
ike36.ok
Adjust for the new default MODP group
9 years ago
ike37.in
add some regress for v6; ok hshoexer@
20 years ago
ike37.ok
Adjust for the new default MODP group
9 years ago
ike38.in
add some regress for v6; ok hshoexer@
20 years ago
ike38.ok
sync with transform-name-fix
13 years ago
ike39.in
add some regress for v6; ok hshoexer@
20 years ago
ike39.ok
Adjust for the new default MODP group
9 years ago
ike4.in
regression tests for isakmp/ike
20 years ago
ike4.ok
Adjust for the new default MODP group
9 years ago
ike40.in
add some regress for v6; ok hshoexer@
20 years ago
ike40.ok
Adjust for the new default MODP group
9 years ago
ike41.in
Rename "life" to "lifetime" to match iked.
13 years ago
ike41.ok
Adjust for the new default MODP group
9 years ago
ike42.in
check port modifiers in ike rules
20 years ago
ike42.ok
Adjust for the new default MODP group
9 years ago
ike43.in
check port modifiers in ike rules
20 years ago
ike43.ok
Adjust for the new default MODP group
9 years ago
ike46.in
Add a transport mode specifier to ike rules. Tunnel mode remains the default. "looks right" hshoexer@
20 years ago
ike46.ok
Adjust for the new default MODP group
9 years ago
ike47.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ike47.ok
Adjust for the new default MODP group
9 years ago
ike48.in
new tests for default peer usage
20 years ago
ike48.ok
Adjust for the new default MODP group
9 years ago
ike49.in
new tests for default peer usage
20 years ago
ike49.ok
Adjust for the new default MODP group
9 years ago
ike5.in
adopt to recent changes
20 years ago
ike5.ok
sync with transform-name-fix
13 years ago
ike50.in
yet another test.
20 years ago
ike50.ok
Adjust for the new default MODP group
9 years ago
ike51.in
tests similar to ike49 and ike50, but with ipv6 addresses.
20 years ago
ike51.ok
Adjust for the new default MODP group
9 years ago
ike52.in
tests similar to ike49 and ike50, but with ipv6 addresses.
20 years ago
ike52.ok
Adjust for the new default MODP group
9 years ago
ike53.in
Add support for IKE AH rules to ipsecctl. Man page input by jmc@. ok hshoexer@
19 years ago
ike53.ok
Adjust for the new default MODP group
9 years ago
ike54.in
Add support for IKE AH rules to ipsecctl. Man page input by jmc@. ok hshoexer@
19 years ago
ike54.ok
Adjust for the new default MODP group
9 years ago
ike55.in
Add support for IKE AH rules to ipsecctl. Man page input by jmc@. ok hshoexer@
19 years ago
ike55.ok
Adjust for the new default MODP group
9 years ago
ike56.in
don't pass -1 as a netmask; report vicviq at gmail.com
19 years ago
ike56.ok
Adjust for the new default MODP group
9 years ago
ike57.in
move autodetection of the ID type to the parser. this way the static flows have the correct ID, too. ok hshoexer, reyk
19 years ago
ike57.ok
Adjust for the new default MODP group
9 years ago
ike58.in
Do not crash when lists include the "any" keyword. Reported by <ralf.horstmann at gmx.net>, thanks!
19 years ago
ike58.ok
Adjust for the new default MODP group
9 years ago
ike59.in
Add a regression test for handling addresses with trailing '/32' and address type IPV4_ADDR.
18 years ago
ike59.ok
Adjust for the new default MODP group
9 years ago
ike6.in
regression tests for isakmp/ike
20 years ago
ike6.ok
Adjust for the new default MODP group
9 years ago
ike60.in
Do not use "egress" keyword as it expands to an actual interface, which might be different on different machines. Use some fixed addresses instead.
17 years ago
ike60.ok
Adjust for the new default MODP group
9 years ago
ike61.in
Regression tests for source flow NAT support. OK hshoexer@, markus@.
17 years ago
ike61.ok
Adjust for the new default MODP group
9 years ago
ike62.in
Allow to specify ike and flow explicitly without peer. The any keyword as argument for the peer parameter will do that. An ike without peer creates the peer-default config. A flow without peer acquires a host-to-host SA.
17 years ago
ike62.ok
Adjust for the new default MODP group
9 years ago
ike63.in
Add regress tests with IPv4 and IPv6 addresses for the srcid and/or dstid.
16 years ago
ike63.ok
Adjust for the new default MODP group
9 years ago
ike64.in
Add regress tests with IPv4 and IPv6 addresses for the srcid and/or dstid.
16 years ago
ike64.ok
Adjust for the new default MODP group
9 years ago
ike65.in
Add regress tests with IPv4 and IPv6 addresses for the srcid and/or dstid.
16 years ago
ike65.ok
Adjust for the new default MODP group
9 years ago
ike66.in
Add regress tests with IPv4 and IPv6 addresses for the srcid and/or dstid.
16 years ago
ike66.ok
Adjust for the new default MODP group
9 years ago
ike67.in
Add regress tests with IPv4 and IPv6 addresses for the srcid and/or dstid.
16 years ago
ike67.ok
Adjust for the new default MODP group
9 years ago
ike68.in
Add regress tests with IPv4 and IPv6 addresses for the srcid and/or dstid.
16 years ago
ike68.ok
Adjust for the new default MODP group
9 years ago
ike7.in
regression tests for isakmp/ike
20 years ago
ike7.ok
Adjust for the new default MODP group
9 years ago
ike8.in
Regression tests for "any" keyword.
20 years ago
ike8.ok
Adjust for the new default MODP group
9 years ago
ike9.in
fix the "ike dynamic" test. dynamic automatically uses the local hostname, we skip this behaviour by overriding the srcid. the regression test now validates the DPD-settings only.
20 years ago
ike9.ok
Adjust for the new default MODP group
9 years ago
ikedel1.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel1.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel10.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel10.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel11.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel11.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel12.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel12.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel13.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel13.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel14.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel14.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel15.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel15.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel16.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel16.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel17.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel17.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel18.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel18.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel19.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel19.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel2.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel2.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel20.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel20.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel21.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel21.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel22.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel22.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel23.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel23.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel29.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel29.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel3.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel3.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel30.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel30.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel31.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel31.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel32.in
Rename "life" to "lifetime" to match iked.
13 years ago
ikedel32.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel33.in
Rename "life" to "lifetime" to match iked.
13 years ago
ikedel33.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel34.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel34.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel35.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel35.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel36.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel36.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel37.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel37.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel38.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel38.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel39.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel39.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel4.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel4.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel40.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel40.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel41.in
Rename "life" to "lifetime" to match iked.
13 years ago
ikedel41.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel42.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel42.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel43.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel43.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel46.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel46.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel47.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel47.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel5.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel5.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel6.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel6.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel7.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel7.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel8.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel8.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedel9.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedel9.ok
Isakmpd acquire mode did not work with a config generated from ipsec.conf. The config created by isakmpd dynamically was different from the config that ipsecctl generated out of ipsec.conf.
18 years ago
ikedeldel1.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedeldel1.ok
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedeldel47.in
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikedeldel47.ok
Add a bunch of test for deletion of ike rules, add a test for "to any" rules without a peer specified. These tests resulted in the recent fix in ipsecctl/ike.c.
20 years ago
ikefail1.in
add some regress for v6; ok hshoexer@
20 years ago
ikefail1.ok
Update to match improved address family check.
19 years ago
ikefail11.in
Remove bogus input line.
19 years ago
ikefail11.ok
Add new "reached end of file while parsing quoted string" as expected error message.
18 years ago
ikefail12.in
Add some regression tests for odd ipsecctl behaviour noticed by Prabhu Gurumurt. Test ikefail10 should fail, but does not and needs to be fixed.
19 years ago
ikefail12.ok
Add new "reached end of file while parsing quoted string" as expected error message.
18 years ago
ikefail13.in
Regression tests for source flow NAT support. OK hshoexer@, markus@.
17 years ago
ikefail13.ok
Regression tests for source flow NAT support. OK hshoexer@, markus@.
17 years ago
ikefail14.in
If the "peer" address is not specified or derived from "to" for "ike" rules in ipsec.conf, the default peer is used. In theory ipsecctl -f ipsec.conf can configure the default peer for each "ike" entry. As isakmpd only supports one default peer, the last "ike" rule that uses a default peer wins. This configuration is then significant for all "ike" rules that use the default peer.
17 years ago
ikefail14.ok
Adjust for the new default MODP group
9 years ago
ikefail2.in
add some regress for v6; ok hshoexer@
20 years ago
ikefail2.ok
add some regress for v6; ok hshoexer@
20 years ago
ikefail3.in
check port modifiers in ike rules
20 years ago
ikefail3.ok
check port modifiers in ike rules
20 years ago
ikefail4.in
really, this is the correct *.ok output, what was generated in the past was due to recently fixed code move some ike?? to ikefail?
20 years ago
ikefail4.ok
Update to match improved address family check.
19 years ago
ikefail5.in
really, this is the correct *.ok output, what was generated in the past was due to recently fixed code move some ike?? to ikefail?
20 years ago
ikefail5.ok
Update to match improved address family check.
19 years ago
ikefail6.in
Add support for IKE AH rules to ipsecctl. Man page input by jmc@. ok hshoexer@
19 years ago
ikefail6.ok
Adjust for the new default MODP group
9 years ago
ikefail8.in
Add some regression tests for odd ipsecctl behaviour noticed by Prabhu Gurumurt. Test ikefail10 should fail, but does not and needs to be fixed.
19 years ago
ikefail8.ok
previous commit to parse.y was undone. adopt these two regression tests.
19 years ago
ikefail9.in
Add some regression tests for odd ipsecctl behaviour noticed by Prabhu Gurumurt. Test ikefail10 should fail, but does not and needs to be fixed.
19 years ago
ikefail9.ok
previous commit to parse.y was undone. adopt these two regression tests.
19 years ago
ipsec1.in
Some basic regression tests for ipsecctl, not connected yet.
20 years ago
ipsec1.ok
adopt to recent changes and add some more tests
20 years ago
ipsec10.in
Some basic regression tests for ipsecctl, not connected yet.
20 years ago
ipsec10.ok
adopt to recent changes and add some more tests
20 years ago
ipsec11.in
Some basic regression tests for ipsecctl, not connected yet.
20 years ago
ipsec11.ok
adopt to recent changes and add some more tests
20 years ago
ipsec12.in
Some basic regression tests for ipsecctl, not connected yet.
20 years ago
ipsec12.ok
adopt to recent changes and add some more tests
20 years ago
ipsec13.in
Regression tests for "any" keyword.
20 years ago
ipsec13.ok
adopt to recent changes and add some more tests
20 years ago
ipsec14.in
ipip support: ip-in-ip w/o gif(4); ok hshoexer
20 years ago
ipsec14.ok
update regress for non-crypto flow 'type use' case
14 years ago
ipsec15.in
regression tests for "local"
20 years ago
ipsec15.ok
adopt to recent changes and add some more tests
20 years ago
ipsec16.in
add regress tests for dynamic, bypass, deny and the macros.
20 years ago
ipsec16.ok
adopt to recent changes and add some more tests
20 years ago
ipsec17.in
add regress tests for dynamic, bypass, deny and the macros.
20 years ago
ipsec17.ok
adopt regression tests to recent change
20 years ago
ipsec18.in
add regress tests for dynamic, bypass, deny and the macros.
20 years ago
ipsec18.ok
adopt regression tests to recent change
20 years ago
ipsec19.in
both 'proto 50' and 'proto esp' must work in flow specifications
19 years ago
ipsec19.ok
both 'proto 50' and 'proto esp' must work in flow specifications
19 years ago
ipsec2.in
Some basic regression tests for ipsecctl, not connected yet.
20 years ago
ipsec2.ok
adopt to recent changes and add some more tests
20 years ago
ipsec20.in
adopt to recent changes and add some more tests
20 years ago
ipsec20.ok
adopt to recent changes and add some more tests
20 years ago
ipsec21.in
adopt to recent changes and add some more tests
20 years ago
ipsec21.ok
adopt to recent changes and add some more tests
20 years ago
ipsec22.in
tests for rule expansion
20 years ago
ipsec22.ok
tests for rule expansion
20 years ago
ipsec23.in
tests for rule expansion
20 years ago
ipsec23.ok
If multiple to addresses but no peer are given in an ike or flow rule, the current to address is taken as peer during expansion. This makes the broken regress test ikefail7 obsolete as address family mismatch cannot happen anymore. ok hshoexer
18 years ago
ipsec24.in
tests for rule expansion
20 years ago
ipsec24.ok
If multiple to addresses but no peer are given in an ike or flow rule, the current to address is taken as peer during expansion. This makes the broken regress test ikefail7 obsolete as address family mismatch cannot happen anymore. ok hshoexer
18 years ago
ipsec25.in
add some regress for v6; ok hshoexer@
20 years ago
ipsec25.ok
add some regress for v6; ok hshoexer@
20 years ago
ipsec26.in
add some regress for v6; ok hshoexer@
20 years ago
ipsec26.ok
add some regress for v6; ok hshoexer@
20 years ago
ipsec27.in
add some regress for v6; ok hshoexer@
20 years ago
ipsec27.ok
add some regress for v6; ok hshoexer@
20 years ago
ipsec28.in
add some regress for v6; ok hshoexer@
20 years ago
ipsec28.ok
add some regress for v6; ok hshoexer@
20 years ago
ipsec29.in
add some regress for v6; ok hshoexer@
20 years ago
ipsec29.ok
add some regress for v6; ok hshoexer@
20 years ago
ipsec3.in
Some basic regression tests for ipsecctl, not connected yet.
20 years ago
ipsec3.ok
adopt to recent changes and add some more tests
20 years ago
ipsec30.in
add some regress for v6; ok hshoexer@
20 years ago
ipsec30.ok
add some regress for v6; ok hshoexer@
20 years ago
ipsec31.in
add some regress for v6; ok hshoexer@
20 years ago
ipsec31.ok
add some regress for v6; ok hshoexer@
20 years ago
ipsec32.in
add some regress for v6; ok hshoexer@
20 years ago
ipsec32.ok
add some regress for v6; ok hshoexer@
20 years ago
ipsec33.in
add some regress for v6; ok hshoexer@
20 years ago
ipsec33.ok
add some regress for v6; ok hshoexer@
20 years ago
ipsec34.in
add some regress for v6; ok hshoexer@
20 years ago
ipsec34.ok
add some regress for v6; ok hshoexer@
20 years ago
ipsec35.in
add some regress for v6; ok hshoexer@
20 years ago
ipsec35.ok
update regress for non-crypto flow 'type use' case
14 years ago
ipsec36.in
add some regress for v6; ok hshoexer@
20 years ago
ipsec36.ok
add some regress for v6; ok hshoexer@
20 years ago
ipsec37.in
add some regress for v6; ok hshoexer@
20 years ago
ipsec37.ok
add some regress for v6; ok hshoexer@
20 years ago
ipsec38.in
add some regress for v6; ok hshoexer@
20 years ago
ipsec38.ok
add some regress for v6; ok hshoexer@
20 years ago
ipsec39.in
add some regress for v6; ok hshoexer@
20 years ago
ipsec39.ok
fix this test, too.
20 years ago
ipsec4.in
Some basic regression tests for ipsecctl, not connected yet.
20 years ago
ipsec4.ok
adopt to recent changes and add some more tests
20 years ago
ipsec40.in
add some regress for v6; ok hshoexer@
20 years ago
ipsec40.ok
add some regress for v6; ok hshoexer@
20 years ago
ipsec41.in
add some regress for v6; ok hshoexer@
20 years ago
ipsec41.ok
add some regress for v6; ok hshoexer@
20 years ago
ipsec42.in
add some regress for v6; ok hshoexer@
20 years ago
ipsec42.ok
add some regress for v6; ok hshoexer@
20 years ago
ipsec43.in
add some regress for v6; ok hshoexer@
20 years ago
ipsec43.ok
add some regress for v6; ok hshoexer@
20 years ago
ipsec44.in
add some regress for v6; ok hshoexer@
20 years ago
ipsec44.ok
add some regress for v6; ok hshoexer@
20 years ago
ipsec5.in
Some basic regression tests for ipsecctl, not connected yet.
20 years ago
ipsec5.ok
adopt to recent changes and add some more tests
20 years ago
ipsec50.in
add some regress for v6; ok hshoexer@
20 years ago
ipsec50.ok
add some regress for v6; ok hshoexer@
20 years ago
ipsec51.in
check port modifiers in flow rules; ok hshoexer@
20 years ago
ipsec51.ok
check port modifiers in flow rules; ok hshoexer@
20 years ago
ipsec52.in
check port modifiers in flow rules; ok hshoexer@
20 years ago
ipsec52.ok
check port modifiers in flow rules; ok hshoexer@
20 years ago
ipsec53.in
allow rule if there is at least _one_ matching address family combination. this allows 'flow from lo0 to 127.0.0.1' if lo0 has an ipv6 address. ok itojun@, hshoexer@
19 years ago
ipsec53.ok
allow rule if there is at least _one_ matching address family combination. this allows 'flow from lo0 to 127.0.0.1' if lo0 has an ipv6 address. ok itojun@, hshoexer@
19 years ago
ipsec54.in
If multiple to addresses but no peer are given in an ike or flow rule, the current to address is taken as peer during expansion. This makes the broken regress test ikefail7 obsolete as address family mismatch cannot happen anymore. ok hshoexer
18 years ago
ipsec54.ok
If multiple to addresses but no peer are given in an ike or flow rule, the current to address is taken as peer during expansion. This makes the broken regress test ikefail7 obsolete as address family mismatch cannot happen anymore. ok hshoexer
18 years ago
ipsec55.in
If multiple to addresses but no peer are given in an ike or flow rule, the current to address is taken as peer during expansion. This makes the broken regress test ikefail7 obsolete as address family mismatch cannot happen anymore. ok hshoexer
18 years ago
ipsec55.ok
If multiple to addresses but no peer are given in an ike or flow rule, the current to address is taken as peer during expansion. This makes the broken regress test ikefail7 obsolete as address family mismatch cannot happen anymore. ok hshoexer
18 years ago
ipsec56.in
If multiple to addresses but no peer are given in an ike or flow rule, the current to address is taken as peer during expansion. This makes the broken regress test ikefail7 obsolete as address family mismatch cannot happen anymore. ok hshoexer
18 years ago
ipsec56.ok
If multiple to addresses but no peer are given in an ike or flow rule, the current to address is taken as peer during expansion. This makes the broken regress test ikefail7 obsolete as address family mismatch cannot happen anymore. ok hshoexer
18 years ago
ipsec57.in
If multiple to addresses but no peer are given in an ike or flow rule, the current to address is taken as peer during expansion. This makes the broken regress test ikefail7 obsolete as address family mismatch cannot happen anymore. ok hshoexer
18 years ago
ipsec57.ok
If multiple to addresses but no peer are given in an ike or flow rule, the current to address is taken as peer during expansion. This makes the broken regress test ikefail7 obsolete as address family mismatch cannot happen anymore. ok hshoexer
18 years ago
ipsec58.in
Allow to specify ike and flow explicitly without peer. The any keyword as argument for the peer parameter will do that. An ike without peer creates the peer-default config. A flow without peer acquires a host-to-host SA.
17 years ago
ipsec58.ok
Allow to specify ike and flow explicitly without peer. The any keyword as argument for the peer parameter will do that. An ike without peer creates the peer-default config. A flow without peer acquires a host-to-host SA.
17 years ago
ipsec6.in
Some basic regression tests for ipsecctl, not connected yet.
20 years ago
ipsec6.ok
adopt to recent changes and add some more tests
20 years ago
ipsec7.in
Some basic regression tests for ipsecctl, not connected yet.
20 years ago
ipsec7.ok
adopt to recent changes and add some more tests
20 years ago
ipsec8.in
Some basic regression tests for ipsecctl, not connected yet.
20 years ago
ipsec8.ok
adopt to recent changes and add some more tests
20 years ago
ipsec9.in
Some basic regression tests for ipsecctl, not connected yet.
20 years ago
ipsec9.ok
adopt to recent changes and add some more tests
20 years ago
ipsecfail1.in
fix this tests. Enable a bunch of new sa tests
20 years ago
ipsecfail1.ok
Update to match improved address family check.
19 years ago
ipsecfail2.in
check port modifiers in flow rules; ok hshoexer@
20 years ago
ipsecfail2.ok
check port modifiers in flow rules; ok hshoexer@
20 years ago
ipsecfail3.in
If multiple to addresses but no peer are given in an ike or flow rule, the current to address is taken as peer during expansion. This makes the broken regress test ikefail7 obsolete as address family mismatch cannot happen anymore. ok hshoexer
18 years ago
ipsecfail3.ok
If multiple to addresses but no peer are given in an ike or flow rule, the current to address is taken as peer during expansion. This makes the broken regress test ikefail7 obsolete as address family mismatch cannot happen anymore. ok hshoexer
18 years ago
sa1.in
We switched to aes cbc quite some time ago, so also use the correct key sizes here, too. We now have to use 128 bit key instead of 160.
19 years ago
sa1.ok
We switched to aes cbc quite some time ago, so also use the correct key sizes here, too. We now have to use 128 bit key instead of 160.
19 years ago
sa10.in
ipip support: ip-in-ip w/o gif(4); ok hshoexer
20 years ago
sa10.ok
ipip support: ip-in-ip w/o gif(4); ok hshoexer
20 years ago
sa11.in
Remove obsolete DES-CBC tests
9 years ago
sa11.ok
Remove obsolete DES-CBC tests
9 years ago
sa12.in
tests for transport mode, not connected yet
20 years ago
sa12.ok
add trailing \
20 years ago
sa13.in
We switched to aes cbc quite some time ago, so also use the correct key sizes here, too. We now have to use 128 bit key instead of 160.
19 years ago
sa13.ok
We switched to aes cbc quite some time ago, so also use the correct key sizes here, too. We now have to use 128 bit key instead of 160.
19 years ago
sa14.in
prepare some more tests for v6
20 years ago
sa14.ok
add trailing \
20 years ago
sa15.in
We switched to aes cbc quite some time ago, so also use the correct key sizes here, too. We now have to use 128 bit key instead of 160.
19 years ago
sa15.ok
We switched to aes cbc quite some time ago, so also use the correct key sizes here, too. We now have to use 128 bit key instead of 160.
19 years ago
sa16.in
prepare some more tests for v6
20 years ago
sa16.ok
add trailing \
20 years ago
sa17.in
prepare some more tests for v6
20 years ago
sa17.ok
add trailing \
20 years ago
sa18.in
Remove obsolete DES-CBC tests
9 years ago
sa18.ok
Remove obsolete DES-CBC tests
9 years ago
sa19.in
We switched to aes cbc quite some time ago, so also use the correct key sizes here, too. We now have to use 128 bit key instead of 160.
19 years ago
sa19.ok
We switched to aes cbc quite some time ago, so also use the correct key sizes here, too. We now have to use 128 bit key instead of 160.
19 years ago
sa2.in
some simple regression tests for static keying
20 years ago
sa2.ok
add trailing \
20 years ago
sa20.in
After deleting hifn(4) the only provider for the LZS compression algorithm is gone. Reomve all LZS references from the tree. The v42bis in isakmpd also looks unsupported. OK mvs@ patrick@ sthen@
4 years ago
sa20.ok
After deleting hifn(4) the only provider for the LZS compression algorithm is gone. Reomve all LZS references from the tree. The v42bis in isakmpd also looks unsupported. OK mvs@ patrick@ sthen@
4 years ago
sa21.in
Remove obsolete DES-CBC tests
9 years ago
sa21.ok
Remove obsolete DES-CBC tests
9 years ago
sa22.in
some more, not hooked up yet
20 years ago
sa22.ok
some more, not hooked up yet
20 years ago
sa23.in
Remove obsolete DES-CBC tests
9 years ago
sa23.ok
Remove obsolete DES-CBC tests
9 years ago
sa24.in
some more, not hooked up yet
20 years ago
sa24.ok
add trailing \
20 years ago
sa25.in
Add tests with the ipsec.conf SA bundle keyword.
9 years ago
sa25.ok
SA group has been renamed to bundle. Adapt test.
9 years ago
sa26.in
Add tests with the ipsec.conf SA bundle keyword.
9 years ago
sa26.ok
SA group has been renamed to bundle. Adapt test.
9 years ago
sa27.in
Add tests with the ipsec.conf SA bundle keyword.
9 years ago
sa27.ok
SA group has been renamed to bundle. Adapt test.
9 years ago
sa3.in
We switched to aes cbc quite some time ago, so also use the correct key sizes here, too. We now have to use 128 bit key instead of 160.
19 years ago
sa3.ok
We switched to aes cbc quite some time ago, so also use the correct key sizes here, too. We now have to use 128 bit key instead of 160.
19 years ago
sa4.in
some simple regression tests for static keying
20 years ago
sa4.ok
add trailing \
20 years ago
sa5.in
remove tests for keyed md5/sha1, we only have hmacs
20 years ago
sa5.ok
add trailing \
20 years ago
sa6.in
Remove obsolete DES-CBC tests
9 years ago
sa6.ok
Remove obsolete DES-CBC tests
9 years ago
sa7.in
We switched to aes cbc quite some time ago, so also use the correct key sizes here, too. We now have to use 128 bit key instead of 160.
19 years ago
sa7.ok
We switched to aes cbc quite some time ago, so also use the correct key sizes here, too. We now have to use 128 bit key instead of 160.
19 years ago
sa8.in
After deleting hifn(4) the only provider for the LZS compression algorithm is gone. Reomve all LZS references from the tree. The v42bis in isakmpd also looks unsupported. OK mvs@ patrick@ sthen@
4 years ago
sa8.ok
After deleting hifn(4) the only provider for the LZS compression algorithm is gone. Reomve all LZS references from the tree. The v42bis in isakmpd also looks unsupported. OK mvs@ patrick@ sthen@
4 years ago
sa9.in
Remove obsolete DES-CBC tests
9 years ago
sa9.ok
Remove obsolete DES-CBC tests
9 years ago
safail1.in
First simple regression tests for invalid rules
20 years ago
safail1.ok
adopt to recent changes
20 years ago
safail2.in
test invalid v6/v4 address combinations for SAs.
20 years ago
safail2.ok
Update to match improved address family check.
19 years ago
safail3.in
AES-CTR, AES-GCM, AES-GMAC are disallowed with manual SAs
13 years ago
safail3.ok
AES-CTR, AES-GCM, AES-GMAC are disallowed with manual SAs
13 years ago
tcpmd51.in
For tcpmd5 rules the keyword "key" changed to "authkey"
20 years ago
tcpmd51.ok
For tcpmd5 rules the keyword "key" changed to "authkey"
20 years ago
tcpmd52.in
For tcpmd5 rules the keyword "key" changed to "authkey"
20 years ago
tcpmd52.ok
For tcpmd5 rules the keyword "key" changed to "authkey"
20 years ago
tcpmd53.in
Make sure, tests using "file" work when obj/ directory is present.
20 years ago
tcpmd53.ok
Make tests more readable by using predefined keyfiles. Add test for tcpmd5 using a key from a file.
20 years ago