Re: [Xorp-users] MD5 Support
From: Vincent Jardin (vjardin_at_free.fr)
Date: 08/13/04
- Previous message: Roman Kurakin: "Sppp & Cronyx (cp(4), ct(4) and cx(4)) testers required"
- In reply to: Bruce M Simpson: "Re: [Xorp-users] MD5 Support"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
To: Bruce M Simpson <bms@spc.org>, Nathan K <doesnotcount@hotmail.com> Date: Fri, 13 Aug 2004 19:39:23 +0200
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
> Future Directions for XORP
> --------------------------
>
> As PF_KEY is somewhat standardized (RFC 2367 Informational) and well
> documented (UNIX Network Programming Vol1 2e Fenner et al) this is a
> portable way of achieving this across the BSDs. Linux (FreeS/WAN et
> cetera) may be another story.
FYI, Linux does support PF_KEY too.
>
> Future Directions for TCP-MD5
> -----------------------------
>
> This would however require that applications such as Quagga and XORP speak
> fluent PF_KEY in the BSD dialect.
I think that the routing protocols will have to speak fluently PF_KEY because
even for OSPFv2/MD5 or RIP/MD5 the keys could be provided by a "key daemon".
This concept is already described by the RFC 2367, section 1.2 and section
5.3 (OSPF Securrity Example).
Regards,
Vincent
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (FreeBSD)
iD8DBQFBHPzRj1uHAMmANdgRAprWAKDtG8oLQUa7SevIgqVNyjZpzsguoACfZMUy
LsKFJkGeWhH+lhXNZw7ShA4=
=Lvtl
-----END PGP SIGNATURE-----
_______________________________________________
freebsd-net@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-net
To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"
- Previous message: Roman Kurakin: "Sppp & Cronyx (cp(4), ct(4) and cx(4)) testers required"
- In reply to: Bruce M Simpson: "Re: [Xorp-users] MD5 Support"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Relevant Pages
|
|