Re: IPSec in 2.5 Kernel?

Paul Wouters <[email protected]> Wed, 19 Mar 2003 00:16:46 +0100 (MET)
Newsgroups gmane.network.freeswan.devel
Message-ID <[email protected]>
On Tue, 18 Mar 2003, John S. Denker wrote:

> What would it take to get state-of-the-art IPsec into
> the mainline kernel development process?

The only viable way I see, with the current positions of Gilmore, Torvalds,
Miller and Daniel, is to ensure that kernel level ipsec talks to both
KAME/Racoon and FreeS/WAN userland.

Though this shouldnt stop freeswan from supporting linux-2.5 natively.
I, as a non-kernel hacker with extreme limited C experience managed to tweak
sources to work (back around 2.5.33). It should take mcr, rgb or kenb
not more then a day to support 2.5.

One way or another, the kernel is getting its ipsec. As long as we ensure
our userland can talk to it, the politics of the game shouldn't hamper
the deployment of kernel-ipsec/kame/racoon or freeswan-ipsec/freeswan

Paul