Index: head/security/strongswan/Makefile =================================================================== --- head/security/strongswan/Makefile (revision 401114) +++ head/security/strongswan/Makefile (revision 401115) @@ -1,139 +1,139 @@ # Created by: Riaan Kruger # $FreeBSD$ PORTNAME= strongswan PORTVERSION= 5.3.3 -PORTREVISION= 1 +PORTREVISION= 2 CATEGORIES= security MASTER_SITES= http://download.strongswan.org/ \ http://download2.strongswan.org/ MAINTAINER= strongswan@nanoteq.com COMMENT= Open Source IKEv2 IPsec-based VPN solution LICENSE= GPLv2 USES= cpe execinfo libtool:keepla pkgconfig tar:bzip2 USE_OPENSSL= yes USE_RC_SUBR= strongswan GNU_CONFIGURE= yes USE_LDCONFIG= ${PREFIX}/lib/ipsec INSTALL_TARGET= install-strip CONFIGURE_ARGS= --enable-kernel-pfkey \ --enable-kernel-pfroute \ --disable-kernel-netlink \ --disable-scripts \ --disable-gmp \ --enable-openssl \ --enable-eap-identity \ --enable-eap-md5 \ --enable-eap-tls \ --enable-eap-mschapv2 \ --enable-eap-peap \ --enable-eap-ttls \ --enable-md4 \ --enable-blowfish \ --enable-addrblock \ --enable-whitelist \ --enable-cmd \ --with-group=wheel \ --with-lib-prefix=${PREFIX} OPTIONS_DEFINE= CURL EAPAKA3GPP2 EAPDYNAMIC EAPRADIUS EAPSIMFILE GCM IKEv1 \ IPSECKEY KERNELLIBIPSEC LOADTESTER LDAP MYSQL PKI SCEP SMP \ SQLITE SWANCTL TESTVECTOR UNBOUND UNITY VICI XAUTH OPTIONS_DEFAULT= IKEv1 BUILTIN OPTIONS_SINGLE= PRINTF_HOOKS OPTIONS_SINGLE_PRINTF_HOOKS= BUILTIN VSTR LIBC OPTIONS_SUB= yes CURL_DESC= Enable CURL to fetch CRL/OCSP EAPAKA3GPP2_DESC= Enable EAP AKA with 3gpp2 backend EAPDYNAMIC_DESC= Enable EAP dynamic proxy module EAPRADIUS_DESC= Enable EAP Radius proxy authentication EAPSIMFILE_DESC= Enable EAP SIM with file backend GCM_DESC= Enable GCM AEAD wrapper crypto plugin IKEv1_DESC= Enable IKEv1 support IPSECKEY_DESC= Enable authentication with IPSECKEY resource records with DNSSEC KERNELLIBIPSEC_DESC= Enable IPSec userland backend LOADTESTER_DESC= Enable load testing plugin TESTVECTOR_DESC= Enable crypto test vectors PKI_DESC= Enable PKI tools SCEP_DESC= Enable Simple Certificate Enrollment Protocol SMP_DESC= Enable XML-based management protocol (DEPRECATED) SWANCTL_DESC= Install swanctl UNBOUND_DESC= Enable DNSSEC-enabled resolver UNITY_DESC= Enable Cisco Unity extension plugin VICI_DESC= Enable VICI management protocol XAUTH_DESC= Enable XAuth password verification BUILTIN_DESC= Use builtin printf hooks LIBC_DESC= Use libc printf hooks VSTR_DESC= Use devel/vstr printf hooks # Extra options CURL_CONFIGURE_ON= --enable-curl CURL_LIB_DEPENDS= libcurl.so:${PORTSDIR}/ftp/curl EAPAKA3GPP2_CONFIGURE_ON= --enable-eap-aka --enable-eap-aka-3gpp2 EAPAKA3GPP2_LIB_DEPENDS=libgmp.so:${PORTSDIR}/math/gmp EAPDYNAMIC_CONFIGURE_ON=--enable-eap-dynamic EAPRADIUS_CONFIGURE_ON= --enable-eap-radius EAPSIMFILE_CONFIGURE_ON=--enable-eap-sim --enable-eap-sim-file GCM_CONFIGURE_ON= --enable-gcm IKEv1_CONFIGURE_OFF= --disable-ikev1 IPSECKEY_CONFIGURE_ON= --enable-ipseckey KERNELLIBIPSEC_CONFIGURE_ON= --enable-kernel-libipsec LOADTESTER_CONFIGURE_ON=--enable-load-tester LDAP_CONFIGURE_ON= --enable-ldap LDAP_USE= OPENLDAP=yes MYSQL_CONFIGURE_ON= --enable-mysql MYSQL_USE= MYSQL=yes SMP_LIB_DEPENDS= libxml2.so:${PORTSDIR}/textproc/libxml2 SMP_CONFIGURE_ON= --enable-smp SWANCTL_CONFIGURE_ON= --enable-swanctl SQLITE_CONFIGURE_ON= --enable-sqlite SQLITE_LIB_DEPENDS= libsqlite3.so:${PORTSDIR}/databases/sqlite3 TESTVECTOR_CONFIGURE_ON=--enable-test-vectors PKI_CONFIGURE_OFF= --disable-pki SCEP_CONFIGURE_OFF= --disable-scepclient UNBOUND_CONFIGURE_ON= --enable-unbound UNBOUND_LIB_DEPENDS= libunbound.so:${PORTSDIR}/dns/unbound UNITY_CONFIGURE_ON= --enable-unity VICI_CONFIGURE_ON= --enable-vici XAUTH_CONFIGURE_ON= --enable-xauth-eap --enable-xauth-generic BUILTIN_CONFIGURE_ON= --with-printf-hooks=builtin LIBC_CONFIGURE_ON= --with-printf-hooks=glibc VSTR_CONFIGURE_ON= --with-printf-hooks=vstr VSTR_LIB_DEPENDS= libvstr.so:devel/vstr .include .if ${PORT_OPTIONS:MEAPSIMFILE} || ${PORT_OPTIONS:MEAPAKA3GPP2} PLIST_SUB+= SIMAKA="" .else PLIST_SUB+= SIMAKA="@comment " .endif .if ${PORT_OPTIONS:MMYSQL} || ${PORT_OPTIONS:MSQLITE} CONFIGURE_ARGS+= --enable-attr-sql --enable-sql PLIST_SUB+= SQL="" .else PLIST_SUB+= SQL="@comment " .endif .if ${PORT_OPTIONS:MIKEv1} || ${PORT_OPTIONS:MXAUTH} PLIST_SUB+= XAUTHGEN="" .else PLIST_SUB+= XAUTHGEN="@comment " .endif post-install: .if ${PORT_OPTIONS:MVICI} ${INSTALL_DATA} ${WRKSRC}/src/libcharon/plugins/vici/libvici.h \ ${STAGEDIR}${PREFIX}/include .endif .if ${PORT_OPTIONS:MSWANCTL} ${MV} ${STAGEDIR}${PREFIX}/etc/swanctl/swanctl.conf \ ${STAGEDIR}${PREFIX}/etc/swanctl/swanctl.conf.sample .endif .include Index: head/security/strongswan/files/patch-backport-04f22cdabc.diff =================================================================== --- head/security/strongswan/files/patch-backport-04f22cdabc.diff (nonexistent) +++ head/security/strongswan/files/patch-backport-04f22cdabc.diff (revision 401115) @@ -0,0 +1,67 @@ +From 04f22cdabc1c97d38692f95392429839f0fa90d1 Mon Sep 17 00:00:00 2001 +From: Tobias Brunner +Date: Mon, 9 Nov 2015 11:39:54 +0100 +Subject: [PATCH] vici: Add NAT information when listing IKE_SAs + +The `nat-local` and `nat-remote` keys contain information on the NAT +status of the local and remote IKE endpoints, respectively. If a +responder did not detect a NAT but is configured to fake a NAT situation +this is indicated by `nat-fake` (if an initiator fakes a NAT situation +`nat-local` is set). If any NAT is detected or faked `nat-any` is set. + +Closes strongswan/strongswan#16. +--- + src/libcharon/plugins/vici/README.md | 4 ++++ + src/libcharon/plugins/vici/vici_query.c | 17 +++++++++++++++++ + 2 files changed, 21 insertions(+) + +diff --git a/src/libcharon/plugins/vici/README.md b/src/libcharon/plugins/vici/README.md +index e20e8ab..51a17e2 100644 +--- src/libcharon/plugins/vici/README.md ++++ src/libcharon/plugins/vici/README.md +@@ -587,6 +587,10 @@ command. + initiator = + initiator-spi = + responder-spi = ++ nat-local = ++ nat-remote = ++ nat-fake = ++ nat-any = + encr-alg = + encr-keysize = + integ-alg = +diff --git a/src/libcharon/plugins/vici/vici_query.c b/src/libcharon/plugins/vici/vici_query.c +index 98d264f..265a17e 100644 +--- src/libcharon/plugins/vici/vici_query.c ++++ src/libcharon/plugins/vici/vici_query.c +@@ -222,6 +222,18 @@ static void list_task_queue(private_vici_query_t *this, vici_builder_t *b, + } + + /** ++ * Add an IKE_SA condition to the given builder ++ */ ++static void add_condition(vici_builder_t *b, ike_sa_t *ike_sa, ++ char *key, ike_condition_t cond) ++{ ++ if (ike_sa->has_condition(ike_sa, cond)) ++ { ++ b->add_kv(b, key, "yes"); ++ } ++} ++ ++/** + * List details of an IKE_SA + */ + static void list_ike(private_vici_query_t *this, vici_builder_t *b, +@@ -265,6 +277,11 @@ static void list_ike(private_vici_query_t *this, vici_builder_t *b, + b->add_kv(b, "initiator-spi", "%.16"PRIx64, id->get_initiator_spi(id)); + b->add_kv(b, "responder-spi", "%.16"PRIx64, id->get_responder_spi(id)); + ++ add_condition(b, ike_sa, "nat-local", COND_NAT_HERE); ++ add_condition(b, ike_sa, "nat-remote", COND_NAT_THERE); ++ add_condition(b, ike_sa, "nat-fake", COND_NAT_FAKE); ++ add_condition(b, ike_sa, "nat-any", COND_NAT_ANY); ++ + proposal = ike_sa->get_proposal(ike_sa); + if (proposal) + { Property changes on: head/security/strongswan/files/patch-backport-04f22cdabc.diff ___________________________________________________________________ Added: fbsd:nokeywords ## -0,0 +1 ## +yes \ No newline at end of property Added: svn:eol-style ## -0,0 +1 ## +native \ No newline at end of property Added: svn:mime-type ## -0,0 +1 ## +text/plain \ No newline at end of property Index: head/security/strongswan/files/patch-backport-dff2d05bb9.diff =================================================================== --- head/security/strongswan/files/patch-backport-dff2d05bb9.diff (nonexistent) +++ head/security/strongswan/files/patch-backport-dff2d05bb9.diff (revision 401115) @@ -0,0 +1,27 @@ +From dff2d05bb9bec684b3b2efdafc9a47219550bbe1 Mon Sep 17 00:00:00 2001 +From: Renato Botelho +Date: Fri, 6 Nov 2015 17:07:38 -0200 +Subject: [PATCH] kernel-pfkey: Enable ENCR_AES_CTR when it's available + +Obtained-from: pfSense +Sponsored-by: Rubicon Communications (Netgate) +Closes strongswan/strongswan#17. +--- + src/libhydra/plugins/kernel_pfkey/kernel_pfkey_ipsec.c | 4 +++- + 1 file changed, 3 insertions(+), 1 deletion(-) + +diff --git a/src/libhydra/plugins/kernel_pfkey/kernel_pfkey_ipsec.c b/src/libhydra/plugins/kernel_pfkey/kernel_pfkey_ipsec.c +index 5027e17..0df6fb5 100644 +--- src/libhydra/plugins/kernel_pfkey/kernel_pfkey_ipsec.c ++++ src/libhydra/plugins/kernel_pfkey/kernel_pfkey_ipsec.c +@@ -843,7 +843,9 @@ static kernel_algorithm_t encryption_algs[] = { + /* {ENCR_DES_IV32, 0 }, */ + {ENCR_NULL, SADB_EALG_NULL }, + {ENCR_AES_CBC, SADB_X_EALG_AESCBC }, +-/* {ENCR_AES_CTR, SADB_X_EALG_AESCTR }, */ ++#ifdef SADB_X_EALG_AESCTR ++ {ENCR_AES_CTR, SADB_X_EALG_AESCTR }, ++#endif + /* {ENCR_AES_CCM_ICV8, SADB_X_EALG_AES_CCM_ICV8 }, */ + /* {ENCR_AES_CCM_ICV12, SADB_X_EALG_AES_CCM_ICV12 }, */ + /* {ENCR_AES_CCM_ICV16, SADB_X_EALG_AES_CCM_ICV16 }, */ Property changes on: head/security/strongswan/files/patch-backport-dff2d05bb9.diff ___________________________________________________________________ Added: fbsd:nokeywords ## -0,0 +1 ## +yes \ No newline at end of property Added: svn:eol-style ## -0,0 +1 ## +native \ No newline at end of property Added: svn:mime-type ## -0,0 +1 ## +text/plain \ No newline at end of property