Re: Applying NAT-T patch



On Thu, May 31, 2007 at 09:37:30AM +0000, Matthew Grooms wrote:
[....]
The rest of the patch is ok and will be included today.


Does that mean that only a single issue mentioned by Bjoern has not been
addressed in the latest version of the patch set?

I integrated Bjoern's patch to my own compile when he sent it, but, I
don't understand how, I didn't report his patch to the official NAT-T
patch (where I was sure I did it).

I just sent another mail in this thread to confirm that the patch is
up to date now.


What about the setkey program? Does it need to be patched to read
security associations that use natt extensions? Perhaps the ipsec tools
version can be imported to replace the stock freebsd version?

That is another quite old discussion.
ipsec-tools's setkey changed quite a lot from system's one, and
actually, using the NAT-T patch means "forget system's setkey for at
least some features".

system's setkey will work as it worked before as soon as it have been
recompiled (needed as some PFkey structs size changed), but won't dump
NAT-T related informations.

To have such informations, you'll have to use ipsec-tools's setkey.

I really hope this makes into head before the 7 branch.

Looks like we were all waiting for each others, but it should be
better now.




Yvan.

--
NETASQ
http://www.netasq.com
_______________________________________________
freebsd-net@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-net
To unsubscribe, send any mail to "freebsd-net-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: Crypto API and keyed non-HMAC digest algorithms / Michael MIC
    ... The included patch combines changesets for both the setkey ... Fixed error codes in return values of the digest setkey handler. ... +static inline int crypto_digest_setkey(struct crypto_tfm *tfm, ...
    (Linux-Kernel)
  • Re: Crypto API and keyed non-HMAC digest algorithms / Michael MIC
    ... > I think that adding a setkey method for digests is the simplest approach. ... I took a quick look at the CRC32C patch and it looked like the only ... Added support for using keyed digest with an optional dit_setkey handler. ... allows new ones to add setkey handler that can be used to initialize the ...
    (Linux-Kernel)
  • Re: Crypto API and keyed non-HMAC digest algorithms / Michael MIC
    ... > Here's the digest setkey part of the previous combined patch; ... but allows new ones to add setkey handler that can be ...
    (Linux-Kernel)
  • Re: [PATCH] IPSec fixes
    ... On Fri, 16 Jan 2004, Hajimu UMEMOTO wrote: ... > Without the patch, I could reproduce a panic easily by setkey. ...
    (freebsd-current)
  • constant 401 errors, all sites, all users
    ... Recommended Update for Windows XP ... NAT-T and Firewall Rulesets ... Because the new NAT-T code is designed around the IETF RFC ... Ok so once this patch is implemented ... ...
    (microsoft.public.inetserver.iis.security)