Re: IPSec in 2.5 Kernel?

Derek Atkins <[email protected]> 19 Mar 2003 12:12:49 -0500
Newsgroups gmane.network.freeswan.devel
Message-ID <[email protected]>
Paul Wouters <[email protected]> writes:

> > Opportunistic Encryption has the potential to get large portions
> > of the net encrypted by default. It may be the only realistic way
> > to do that, and this has been a project goal all along.
> 
> I think, and hope, that Derrick sees how important OE is, but I can
> imagine he has other priorities (Like get IKE working in the first place)

I certainly understand the importance of OE, but as you said it is not
high on my list.  I've already got a working IKE, and that's already
available in a few contexts (ipsec-tools.sourceforge.net).

I'm not sure what kernel hooks you need for OE.  The existing code has
the concept of "require ipsec" and "use ipsec"...  Require means that
no non-IPsec packets will be passed; Use means that IPsec will be used
if an SA exists.  I _believe_ that both Require and Use policies will
signal IKE to start a negotiation, but I'd have to re-examine that code
to verify.

My immediate priority is finishing the NAT-T implementation in IKE.
However, patches for other features are certainly welcome.

-derek

-- 
       Derek Atkins
       Computer and Internet Security Consultant
       [email protected]             www.ihtfp.com