aboutsummaryrefslogtreecommitdiff
path: root/security/strongswan
Commit message (Collapse)AuthorAgeFilesLines
* Add option for enabling mediation feature (like STUN for IPSec peers)Olivier Cochard2017-05-101-1/+4
| | | | | | | | Approved by: strongswan@nanoteq.com (maintainer) Sponsored by: Orange Notes: svn path=/head/; revision=440527
* Update security/strongswan to 5.5.2Renato Botelho2017-04-123-12/+28
| | | | | | | | | PR: 218430 Approved by: maintainer Sponsored by: Rubicon Communications (Netgate) Notes: svn path=/head/; revision=438397
* - Chase ldns shlip bumpMartin Wilke2017-03-031-0/+1
| | | | | | | PR: 217495 Notes: svn path=/head/; revision=435306
* Update security/strongswan to 5.5.1Renato Botelho2016-11-218-12/+16
| | | | | | | | | | PR: 213844 Approved by: strongswan@Nanoteq.com (maintainer) Obtained from: pfSense Sponsored by: Rubicon Communications (Netgate) Notes: svn path=/head/; revision=426700
* security/strongswan: Fix build with LibreSSLJohn Marino2016-09-121-0/+11
| | | | | | | Approved by: SSL blanket Notes: svn path=/head/; revision=421949
* Update security/strongswan to 5.5.0Renato Botelho2016-07-192-7/+8
| | | | | | | | PR: 211095 Submitted by: strongswan@Nanoteq.com (maintainer) Notes: svn path=/head/; revision=418809
* security/strongswan: unbreak FreeBSD 9 buildsJason Unovitch2016-04-031-0/+13
| | | | | | | | | | | - Add patch to include sys/endian.h header PR: 208446 Submitted by: strongswan@Nanoteq.com (maintainer) MFH: 2016Q2 (build fix blanket) Notes: svn path=/head/; revision=412481
* Remove ${PORTSDIR}/ from dependencies, categories r, s, t, and u.Mathieu Arnold2016-04-011-5/+5
| | | | | | | | With hat: portmgr Sponsored by: Absolight Notes: svn path=/head/; revision=412349
* Update security/strongswan to 5.4.0Renato Botelho2016-03-233-9/+6
| | | | | | | | | | PR: 208219 Approved by: swan@nanoteq.com (maintainer) Obtained from: pfSense Sponsored by: Rubicon Communications (Netgate) Notes: svn path=/head/; revision=411720
* - bump PORTREVISION on ports depending on unboundOlli Hauer2016-03-151-1/+1
| | | | | | | | PR: 207948 Submitted by: jaap@NLnetLabs.nl (maintainer) Notes: svn path=/head/; revision=411143
* security/strongswan: enable options to increase usefulness of default pkgJason Unovitch2016-02-171-3/+6
| | | | | | | | | | | | | - Enable PKI, SWANCTL, and VICI options (no external dependencies) - Document IMPLIES dependency on VICI for SWANCTL; mention in SWANCTL_DESC - Bump PORTREVISION PR: 205438 Reported by: Nick B <nicblais@clkroot.net> Submitted by: strongswan@Nanoteq.com (maintainer) Notes: svn path=/head/; revision=409026
* - Update unbound to 1.5.7Erwin Lansing2016-02-041-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | - Bump PORTREVISIOn on dependent ports Some Upgrade Notes: This release fixes a validation failure for nodata with wildcards and emptynonterminals. Fixes OpenSSL Library compability. Fixes correct response for malformed EDNS queries. For crypto in libunbound there is libnettle support. Qname minimisation is implemented. Use qname-minimisation: yes to enable it. This version sends the full query name when an error is found for intermediate names. It should therefore not fail for names on nonconformant servers. It combines well with harden-below-nxdomain: yes because those nxdomains are probed by the qname minimisation, and that will both stop privacy sensitive traffic and reduce nonsense traffic to authority servers. So consider enabling both. In this implementation IPv6 reverse lookups add several labels per increment, because otherwise those lookups would be very slow. [ Reference https://tools.ietf.org/html/draft-ietf-dnsop-qname-minimisation-08 ] More details at <http://unbound.net> PR: 206347 Submitted by: Jaap Akkerhuis <jaap@NLnetLabs.nl> Approved by: maintainer timeout Sponsored by: DK Hostmaster A/S Notes: svn path=/head/; revision=408047
* Bump PORTREVISION to help users with custom OPTIONS to get the fixRenato Botelho2015-12-031-0/+1
| | | | | | | committed in r402880, as suggested by AMDmi3 Notes: svn path=/head/; revision=402881
* Add @sample to gcm.conf missed when I introduced it. No bump on PORTREVISIONRenato Botelho2015-12-031-1/+1
| | | | | | | | | | since GCM is disabled by default Submitted by: Jose Luis Duran Obtained from: https://github.com/pfsense/FreeBSD-ports/pull/2 Notes: svn path=/head/; revision=402880
* Update security/strongswan to 5.3.5Renato Botelho2015-12-022-3/+3
| | | | | | | | | | PR: 204959 Approved by: strongswan@Nanoteq.com (maintainer) Obtained from: pfSense Sponsored by: Rubicon Communications (Netgate) Notes: svn path=/head/; revision=402817
* Update security/strongswan to 5.3.4Renato Botelho2015-11-164-98/+3
| | | | | | | | | | | | PR: 204597 Submitted by: strongswan@nanoteq.com (maintainer) MFH: 2015Q4 Security: CVE 2015-8023 Security: https://github.com/strongswan/strongswan/commit/453e204ac40dfff2e0978e8f84a5f8ff0cbc45e2 Sponsored by: Rubicon Communications (Netgate) Notes: svn path=/head/; revision=401762
* Backport a couple of commits from master, that will be present in 5.3.4:Renato Botelho2015-11-093-1/+95
| | | | | | | | | | | | | | | | | | - dff2d05bb9 [1]: kernel-pfKey: Enable AES-CTR - 04f22cdabc [2]: VICI: add NAT information Bump PORTREVISION [1] https://github.com/strongswan/strongswan/commit/dff2d05bb9bec684b3b2efdafc9a47219550bbe1 [2] https://github.com/strongswan/strongswan/commit/04f22cdabc1c97d38692f95392429839f0fa90d1 PR: 204398 Approved by: maintainer Obtained from: pfSense Sponsored by: Rubicon Communications (Netgate) Notes: svn path=/head/; revision=401115
* - Add a new option, SWANCTL, to install swanctll utilityRenato Botelho2015-10-292-2/+30
| | | | | | | | | | | | | | - When VICI option is selected, install libvici.h to include directory, it's useful when you need to build a custom code linked to libvici - Pass path to USE_LDCONFIG otherwise libraries will not be visible PR: 204098 Approved by: maintainer Obtained from: pfSense Sponsored by: Rubicon Communications (Netgate) Notes: svn path=/head/; revision=400455
* - Add a new option (VICI) to build VICI management protocolRenato Botelho2015-10-282-2/+14
| | | | | | | | | | - Change SMP option description to show users it's deprecated PR: 204090 Approved by: maintainer Notes: svn path=/head/; revision=400393
* strongSwan can be beuit using 3 different printf hooks: builtin, glibcRenato Botelho2015-10-271-1/+11
| | | | | | | | | | | | | | | | | | | | | | | | | (compatible with FreeBSD's libc) and vstr (devel/vstr). Since it's not selected any of them on CONFIGURE_ARGS, it uses auto, and end up using glibc. pfSense users reported memory leaks on strongSwan [2] [3] and a it was reported to upstream [1]. Add a single option and let user choose which printf hook to use, and change default to use builtin. Bump PORTREVISION due to default change [1] https://wiki.strongswan.org/issues/1106 [2] https://forum.pfsense.org/index.php?topic=96767.0 [3] https://redmine.pfsense.org/issues/5149 PR: 204051 Approved by: maintainer Obtained from: pfSense MFH: 2015Q4 Sponsored by: Rubicon Communications (Netgate) Notes: svn path=/head/; revision=400233
* Fix pkg-descr, Strongswan supports IKEv1 since version 5.0.0Renato Botelho2015-09-211-1/+2
| | | | | | | | | Spotted by: Jim Thompson <jim@netgate.com> Approved by: strongswan@Nanoteq.com (maintainer) Sponsored by: Rubicon Communications (Netgate) Notes: svn path=/head/; revision=397487
* Update security/strongswan to 5.3.3Renato Botelho2015-09-215-24/+5
| | | | | | | | | PR: 203178 Approved by: strongswan@Nanoteq.com (maintainer) Sponsored by: Rubicon Communications (Netgate) Notes: svn path=/head/; revision=397485
* Update to 5.3.2Renato Botelho2015-06-094-4/+23
| | | | | | | | | | | PR: 200721 Approved by: strongswan@Nanoteq.com (maintainer) MFH: 2015Q2 Security: CVE-2015-3991 Sponsored by: Netgate Notes: svn path=/head/; revision=388905
* Fix PLIST when EAPAKA3GPP2 is unset and EAPDYNAMIC is setRenato Botelho2015-04-242-8/+2
| | | | | | | | | PR: 199652 Approved by: stronswan@Nanoteq.com (maintainer) Sponsored by: Netgate Notes: svn path=/head/; revision=384631
* - Add CPE infoDmitry Marakasov2015-04-221-1/+1
| | | | | | | Approved by: portmgr blanket Notes: svn path=/head/; revision=384528
* Add patches to fix Strongswan Management ProtocolMark Felder2015-04-164-5/+29
| | | | | | | | | | | | | | | SMP is an XML control interface for Strongswan used by pfSense and Opnsense. SMP has been deprecated by upstream since 5.2.0 in favor of a newer IPC mechanism called VICI. As a result upstream is not motivated to take patches for SMP, and this uses non-portable strlcpy anyway. The code has not been deleted from the project and if we can bludgeon it into a working state I see no harm. PR: 199442 Notes: svn path=/head/; revision=384108
* - Update to 5.3.0Renato Botelho2015-04-013-8/+11
| | | | | | | | | | | - Add a new option UNITY, to enable Cisco unity extension plugin PR: 199064 Approved by: maintainer Sponsored by: Netgate Notes: svn path=/head/; revision=382902
* - Add GCM and SMP optionsRenato Botelho2015-02-252-4/+21
| | | | | | | | | | | | | | - Add pkgconfig to the list of dependencies - Enable IKEv1 OPTION by default - Bump PORTREVISION PR: 197824 Submitted by: Franco Fichtner <franco@lastsummer.de> (based on) Reworked by: strongswan@Nanoteq.com (maintainer) Approved by: strongswan@Nanoteq.com (maintainer) Notes: svn path=/head/; revision=379892
* - Update to 5.2.2Renato Botelho2015-01-092-3/+5
| | | | | | | | | | | - Add LICENSE PR: 196615 Approved by: strongswan@Nanoteq.com (maintainer) Security: CVE-2014-9221 Notes: svn path=/head/; revision=376625
* - Update to version 5.2.1 [1]Pawel Pekala2014-12-145-60/+44
| | | | | | | | | | | - Convert to USES=execinfo - Fix LDAP, MYSQL options PR: 195580 [1] Submitted by: maintainer [1] Notes: svn path=/head/; revision=374724
* Remove useless %DBaptiste Daroussin2014-10-311-8/+8
| | | | | | | Notified by: antoine Notes: svn path=/head/; revision=371863
* Simplify plistBaptiste Daroussin2014-10-311-30/+10
| | | | Notes: svn path=/head/; revision=371861
* - Switch dns/unbound to USES=libtool, drop .la filesDmitry Marakasov2014-08-221-0/+1
| | | | | | | | | | - Bump dependent ports as .so version has changed - While here, add LICENSE_FILE to dns/getdns Approved by: portmgr blanket Notes: svn path=/head/; revision=365620
* security/strongswan: Upgrade version 5.1.3 => 5.2.0John Marino2014-08-196-140/+124
| | | | | | | | | | | | While here, including missing library files and use install-strip target. Maintainer added a crash fix patch while reviewing. PR: 192366 Submitted by: dewayne (heruristicssystems.com.au) Approved by: maintainer (strongswan nanoteq.com) Notes: svn path=/head/; revision=365377
* net/openldap24-*:Tijl Coosemans2014-07-241-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | - Convert to USES=libtool and bump dependent ports - Avoid USE_AUTOTOOLS - Don't use PTHREAD_LIBS - Use MAKE_CMD databases/glom: - Drop :keepla - Add INSTALL_TARGET=install-strip databases/libgda4* databases/libgda5*: - Convert to USES=libtool and bump dependent ports - USES=tar:xz - Use INSTALL_TARGET=install-strip - Use @sample databases/libgdamm: - Drop :keepla - USES=tar:bzip2 - Use INSTALL_TARGET=install-strip databases/libgdamm5: - Add INSTALL_TARGET=install-strip - Drop --enable-static (inherited from old repocopy) devel/anjuta x11-toolkits/py-gnome-extras: - Drop :keepla dns/powerdns dns/powerdns-devel: - Convert to USES=libtool - Add INSTALL_TARGET=install-strip - Disable static modules - Stop creating library symlinks with .0 suffix, not needed for dynamically opened modules mail/dovecot2: - Add USES=libtool mail/dovecot2-pigeonhole: - Drop CONFIGURE_TARGET (incorrect for Dragonfly) - Add USES=libtool and INSTALL_TARGET=install-strip math/gnumeric: - USES=libtool tar:xz Approved by: portmgr (implicit, bump unstaged ports) Notes: svn path=/head/; revision=362835
* - Chase database/sqlite3 slib bumpMartin Wilke2014-06-271-0/+1
| | | | | | | Approved by: portmgr (myself) Notes: svn path=/head/; revision=359586
* security/strongswan: update 5.1.1 -> 5.1.3 with security updateKurt Jaeger2014-05-154-10/+246
| | | | | | | | | | | | | | | - Update strongSwan port to 5.1.3 to resolve CVE 2014-2338 - Fixed rcvar issue with FreeBSD 10 (ports/186865) - Added building of additional tools included in strongswan (ports/186867) - libtool fix - pkg-plist updated PR: ports/189132, ports/186865, ports/186867 Submitted by: Robert Sevat, Dewayne Geraghty, Francois ten Krooden (maintainer) Approved by: jadawin (mentor) Notes: svn path=/head/; revision=354114
* - Use OPTIONS_SUB=yesBernhard Froehlich2014-02-141-5/+5
| | | | | | | | | | - Prefer ${INSTALL_DATA} over ${MV} - Whitespace fix Thanks to: garga@ Notes: svn path=/head/; revision=344214
* - Remove MANx, man pages are already moved to plistAntoine Brodin2014-02-091-9/+5
| | | | | | | - Use new LIB_DEPENDS syntax Notes: svn path=/head/; revision=343534
* - Add missing manpagesBernhard Froehlich2014-02-072-0/+8
| | | | | | | | | PR: ports/186264 Submitted by: HASHI Hiroaki <hashiz@meridiani.jp> Approved by: strongswan <strongswan@Nanoteq.com> (maintainer) Notes: svn path=/head/; revision=343254
* - Update to 5.1.1Bernhard Froehlich2014-01-273-70/+90
| | | | | | | | | | | | | | | | | | - Added EAP dynamic proxy module - Added EAP Radius proxy authentication - Added DNSSEC/unbound support - Added kernel libipsec plugin - Changed configuration files to install to ${PREFIX}/etc/<filename>.conf.sample - Convert to new options format PR: ports/185535 Submitted by: Francois ten Krooden <strongswan@nanoteq.com> (maintainer) Security: CVE-2013-5018 Security: CVE-2013-6075 Security: CVE-2013-6076 Notes: svn path=/head/; revision=341405
* Add NO_STAGE all over the place in preparation for the staging support (cat: ↵Baptiste Daroussin2013-09-201-0/+1
| | | | | | | security) Notes: svn path=/head/; revision=327769
* - Update to 7.31.0Sunpoet Po-Chuan Hsieh2013-07-111-0/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | - Bump PORTREVISION for ftp/curl shlib change - Add TEST_DEPENDS - Convert to new options framework - Adjust options: - Add COOKIES - Add CYASSL, NSS, POLARSSL, THREADED_RESOLVER, TLS_SRP [1] - Add GSSAPI and SPNEGO [2] - Remove KERBEROS4 - Rename LIBIDN to IDN - Remove TRACKMEMORY [1] - Sort option handler - Add SLAVEDIRS: ftp/curl-hiphop - Cosmetic change - Cleanup Makefile header - While I'm here, fix typo (PORTREVSION) in x11-wm/ede/Makefile Changes: http://curl.haxx.se/changes.html PR: ports/172325 (-exp run), ports/177369 (based on) [1] Submitted by: Hirohisa Yamaguchi <umq@ueo.co.jp> [1], hrs (via email) [2] Exp run by: miwi Notes: svn path=/head/; revision=322783
* - update to version 5.0.4 which fixes CVE-2013-2944.Olli Hauer2013-05-034-4/+7
| | | | | | | | | | | | | | - add entry to vuxml - add CVE references to jankins vuxml entry while I'm here remove .sh from rc script PR: ports/178266 Submitted by: David Shane Holden <dpejesh@yahoo.com> Approved by: strongswan@nanoteq.com (maintainer) Notes: svn path=/head/; revision=317229
* - Update to 5.0.1TAKATSU Tomonari2013-01-075-84/+106
| | | | | | | | | | | | | - Change maintainer address - Trim Makefile header - Convert to new options framework - Cleanup PR: ports/173860 (based on) Submitted by: Riaan Kruger (maintainer) Notes: svn path=/head/; revision=310039
* In the rc.d scripts, change assignments to rcvar to use theDoug Barton2012-01-141-1/+1
| | | | | | | | | | | | | | literal name_enable wherever possible, and ${name}_enable when it's not, to prepare for the demise of set_rcvar(). In cases where I had to hand-edit unusual instances also modify formatting slightly to be more uniform (and in some cases, correct). This includes adding some $FreeBSD$ tags, and most importantly moving rcvar= to right after name= so it's clear that one is derived from the other. Notes: svn path=/head/; revision=289156
* update to 4.5.3Florian Smeets2011-09-226-123/+283
| | | | | | | | PR: ports/160401 Submitted by: Riaan Kruger <riaank@gmail.com> maintainer Notes: svn path=/head/; revision=282199
* - Update to 4.5.1 [1]Frederic Culot2011-04-295-113/+36
| | | | | | | | | | - Pet portlint(1) (change spaces into tabs and reformat IGNORE message) PR: ports/156711 [1] Submitted by: Riaan Kruger <riaank@gmail.com> (maintainer) Notes: svn path=/head/; revision=273328
* Sync to new bsd.autotools.mkAde Lovett2010-12-041-1/+1
| | | | Notes: svn path=/head/; revision=265663
* Strongswan is an open source IPsec-based VPN solution.Pav Lucistnik2010-08-265-0/+265
Strongswan for FreeBSD supports IKEv2 but NOT IKEv1. WWW: http://www.strongswan.org PR: ports/147431 Submitted by: Riaan Kruger <riaank@gmail.com> Notes: svn path=/head/; revision=260016