Re: mast(4)
Sandy Harris <[email protected]> Sat, 15 Mar 2003 09:41:32 +0800
| Newsgroups | gmane.network.freeswan.devel |
|---|---|
| Message-ID | <[email protected]> |
"John S. Denker" wrote: > Obviously it's not worth revising tncfg since a major > goal of KLIPS-ng is to get rid of the whole idea of > "attachment" between ipsec devices and anything else. > > But we should make a conscious effort to say "raw > device" and keep the notion of "physical device" out > of the KLIPS-ng documentation. When you talk of KLIPS-ng, do you mean something: distrbuted by FreeS/WAN team, patches users or distribution builders must apply? or code to be submitted for inclusion in the mainline kernel, patches to the IPsec code in 2.5? As I see it, the latter should obviously be the default choice. There would need to be overwhelmingly good reasons to even consider the former. I've heard none, but when you talk of KLIPS-ng there seems to be an assumption tht te team will go that route. Docs on the IPsec in 2.5 kernels: http://www.lartc.org/howto/lartc.ipsec.html Related userland tools: http://sourceforge.net/projects/ipsec-tools I'd say that at this point, the team should be looking at IPsec for 2.6: Pluto II (Goofy?) to run atop the mainline kernel IPsec stuff patches to the mainline stuff With a bit of luck, we could have every Linux box on the planet capable of IPsec soon, and make it easy for distributions to ship with OE as the default.