Re: IPSec in 2.5 Kernel?
Ken Bantoft <[email protected]> Wed, 19 Mar 2003 10:33:12 -0500 (EST)
| Newsgroups | gmane.network.freeswan.devel |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- On Wed, 19 Mar 2003, Paul Wouters wrote: > > Are you certain what the _current_ positons are in all cases, or > > making assumptions? > > I've received quite the emotional emails from Derek, Linus and Alan yes. > I haven't heard from John, but through Hugh I take it nothing much has > changed so far. AFAIK, the stalemate is still there. Not sure if people > are talking about this, I hope they are. I've been lurking around (Paul forwarded me a bunch of emails from his exchanges) but I think I'll sort-of jump since, since I'm an unknown player. Nothing has stopped anyone from forking FreeS/WAN into something like, say, Super FreeS/WAN, and including code that Hugh Daniel and John Gilmour don't agree with - like NAT Traversal, and 1DES. I've done it, you can do it, we can all do it. > > As I see it, the FreeS/WAN project should now drop all effort > > toward KLIPS-ng and instead aim at > > > > supporting Pluto over the mainline kernel IPsec in 2.6 > > getting the good ideas of KLIPS or KLIPS-ng into that > > mainline kernel code > > Yes, but that means convincing those people that some features, such as > OE are not toy features, but essential freedom issues. I did have some > email exchange with Derek, so I hope that helped. Yes, KLIPSv1 is, at best, an ugly hack. I've been reading JSD's mast papers, and that seems to be the best way to go from a technical persepctive, since it handles some of the soon-to-be more popular cases of assigning IP addresses to road warriors, and other cases with ease. > > I believe the mainline stuff supports some undesirable "features" > > such as single DES encryption. That's OK, as long as Pluto won't > > negotiate them. By making Pluto available, we may keep users away > > from other daemons that will. > > Perhaps it is time to give people the tools to cut themselves. There > will always be 1DES patches out there. Perhaps it is better to warn > loudly and support it, then to drive people away. That's the stance JuanJo and I have taken with ALG & Super FreeS/WAN patches. We now include 1DES support, but you must explicitly turn it on in the config, and it warns() each time the module is inserted into the kernel. Maybe we should taint() ? > Btw. I still don't see how pluto will get into big distro's, eg RedHat. > Since they embarked on their own kernel ipsec, they should do the same > for userland. The best we can hope for is that all parties coordinate > those areas where thinks might break or conflict with each other, and > ensure both kernel and userlands combine nicely. So that if someone > decides to pick klips, he doesn't need to recompile the entire stock > RedHat kernel, or visa versa for SuSe. And of course... if different distros pick different userland tools, inter-op could be nothing shy of a nightmare. That's something I don't want to see happen, so I'll be starting to work with Kernel 2.5 IPSec in April to see how well it inter-ops with (Super) FreeS/WAN and some other IPSec enabled devices I have access to. > > It is not enough to make Pluto run over 2.5 kernel IPsec. > > The objective should be really good IPsec for the 2.6 > > kernel. > > Everyone agrees here. Yes. - -- Ken Bantoft The Unoffical FreeS/WAN Site: [email protected] http://www.freeswan.ca PGP Key: finger [email protected] "Random numbers should not be generated with a method chosen at random." -- Donald Knuth, -----BEGIN PGP SIGNATURE----- Version: 2.6.3ia Charset: noconv iQCVAwUBPniNuliWUusaxGxpAQEsRgP/bBhZdh0vEyXCERBJh+8Quv2LSWCSVv3R b63KXepon5hNE57MrXpS3hBjq0mwSifYjhXfBEXUfNMkFjtQZNFEnpXoobbHTgJb L5j3BpbEeRQaq79Ad7k5EimZaxiWyfRV1sWv8o3U973x4DmnizL/Wo49kHXFJmLa P8xSP5rKZM4= =nndu -----END PGP SIGNATURE-----