Re: mast(4)

Sandy Harris <[email protected]> Sat, 15 Mar 2003 09:41:32 +0800
Newsgroups gmane.network.freeswan.devel
Message-ID <[email protected]>
"John S. Denker" wrote:

> Obviously it's not worth revising tncfg since a major
> goal of KLIPS-ng is to get rid of the whole idea of
> "attachment" between ipsec devices and anything else.
> 
> But we should make a conscious effort to say "raw
> device" and keep the notion of "physical device" out
> of the KLIPS-ng documentation.

When you talk of KLIPS-ng, do you mean something:

	distrbuted by FreeS/WAN team, patches users or
	  distribution builders must apply?

or	code to be submitted for inclusion in the
	  mainline kernel, patches to the IPsec
	  code in 2.5?

As I see it, the latter should obviously be the
default choice.

There would need to be overwhelmingly good reasons
to even consider the former. I've heard none, but
when you talk of KLIPS-ng there seems to be an
assumption tht te team will go that route.

Docs on the IPsec in 2.5 kernels:
http://www.lartc.org/howto/lartc.ipsec.html

Related userland tools:
http://sourceforge.net/projects/ipsec-tools

I'd say that at this point, the team should be
looking at IPsec for 2.6:

	Pluto II (Goofy?) to run atop the
	  mainline kernel IPsec stuff

	patches to the mainline stuff

With a bit of luck, we could have every Linux
box on the planet capable of IPsec soon, and
make it easy for distributions to ship with
OE as the default.