IPSec in 2.5 Kernel?

"John S. Denker" <[email protected]> Tue, 18 Mar 2003 13:20:34 -0500
Newsgroups gmane.network.freeswan.devel
Message-ID <[email protected]>
For background and context, see:
   http://lists.freeswan.org/pipermail/users/2003-March/019368.html


Ken wrote [in part, off list] --

 > I don't care too much which implementation "wins", since the
 > end-users will decide.

That sounds fine in principle ... but end-users
don't always choose wisely.  Betamax was superior
in virtually every way, but VHS won out because
of better marketing et cetera.

An even tighter and more frightening analogy is
MS versus unix.  MS was perceived to be easier to
get started with.  People who were getting started
weren't able to understand that they were going
to be trapped in a low-end quagmire.

If people who care about this stuff don't wake up
and smell the hemlock, Linux-IPsec is going to take
a giant step backwards.  It's going to look more
like KAME than FreeS/WAN.  That's a bad idea, for
reasons discussed at e.g.
   http://www.monmouth.com/~jsd/vpn/ipsec+routing/mast.htm

The FreeS/WAN community has a tremendous amount of
experience and understanding.  It would be a scandal
to let this go to waste.  We should be moving forward,
not backward.

What would it take to get state-of-the-art IPsec into
the mainline kernel development process?

What's the right forum for discussing this?