Re: IPSec in 2.5 Kernel?

Ken Bantoft <[email protected]> Wed, 19 Mar 2003 10:33:12 -0500 (EST)
Newsgroups gmane.network.freeswan.devel
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----


On Wed, 19 Mar 2003, Paul Wouters wrote:

> > Are you certain what the _current_ positons are in all cases, or
> > making assumptions?
> 
> I've received quite the emotional emails from Derek, Linus and Alan yes.
> I haven't heard from John, but through Hugh I take it nothing much has
> changed so far. AFAIK, the stalemate is still there. Not sure if people
> are talking about this, I hope they are.

I've been lurking around (Paul forwarded me a bunch of emails from his 
exchanges) but I think I'll sort-of jump since, since I'm an unknown 
player.

Nothing has stopped anyone from forking FreeS/WAN into something like, 
say, Super FreeS/WAN, and including code that Hugh Daniel and John Gilmour 
don't agree with - like NAT Traversal, and 1DES.  I've done it, you can 
do it, we can all do it.


> > As I see it, the FreeS/WAN project should now drop all effort
> > toward KLIPS-ng and instead aim at
> > 
> > 	supporting Pluto over the mainline kernel IPsec in 2.6
> > 	getting the good ideas of KLIPS or KLIPS-ng into that
> > 	 mainline kernel code	
> 
> Yes, but that means convincing those people that some features, such as
> OE are not toy features, but essential freedom issues. I did have some
> email exchange with Derek, so I hope that helped.

Yes, KLIPSv1 is, at best, an ugly hack.  I've been reading JSD's mast 
papers, and that seems to be the best way to go from a technical 
persepctive, since it handles some of the soon-to-be more popular cases 
of assigning IP addresses to road warriors, and other cases with ease.


> > I believe the mainline stuff supports some undesirable "features"
> > such as single DES encryption. That's OK, as long as Pluto won't
> > negotiate them. By making Pluto available, we may keep users away
> > from other daemons that will.
> 
> Perhaps it is time to give people the tools to cut themselves. There
> will always be 1DES patches out there. Perhaps it is better to warn
> loudly and support it, then to drive people away. 

That's the stance JuanJo and I have taken with ALG & Super FreeS/WAN 
patches.  We now include 1DES support, but you must explicitly turn it on 
in the config, and it warns() each time the module is inserted into the 
kernel.  Maybe we should taint() ?


> Btw. I still don't see how pluto will get into big distro's, eg RedHat.
> Since they embarked on their own kernel ipsec, they should do the same
> for userland. The best we can hope for is that all parties coordinate
> those areas where thinks might break or conflict with each other, and
> ensure both kernel and userlands combine nicely. So that if someone
> decides to pick klips, he doesn't need to recompile the entire stock
> RedHat kernel, or visa versa for SuSe.

And of course... if different distros pick different userland tools, 
inter-op could be nothing shy of a nightmare.  That's something I don't 
want to see happen, so I'll be starting to work with Kernel 2.5 IPSec in 
April to see how well it inter-ops with (Super) FreeS/WAN and some other 
IPSec enabled devices I have access to.

> > It is not enough to make Pluto run over 2.5 kernel IPsec.
> > The objective should be really good IPsec for the 2.6
> > kernel.
> 
> Everyone agrees here.

Yes.



- -- 
Ken Bantoft                The Unoffical FreeS/WAN Site:
[email protected]            http://www.freeswan.ca
                           PGP Key: finger [email protected]
"Random numbers should not be generated with a method 
chosen at random."  		-- Donald Knuth,

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3ia
Charset: noconv

iQCVAwUBPniNuliWUusaxGxpAQEsRgP/bBhZdh0vEyXCERBJh+8Quv2LSWCSVv3R
b63KXepon5hNE57MrXpS3hBjq0mwSifYjhXfBEXUfNMkFjtQZNFEnpXoobbHTgJb
L5j3BpbEeRQaq79Ad7k5EimZaxiWyfRV1sWv8o3U973x4DmnizL/Wo49kHXFJmLa
P8xSP5rKZM4=
=nndu
-----END PGP SIGNATURE-----