Re: IPSec in 2.5 Kernel?

Ken Bantoft <[email protected]> Wed, 19 Mar 2003 20:42:31 -0500 (EST)
Newsgroups gmane.network.freeswan.devel
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----


On Wed, 19 Mar 2003, John S. Denker wrote:

> To the limited extent I can figure out where the
> "new kernel IPsec" venture is going, there's no
> discernible evidence that usability and scalability
> questions have even been asked, let alone addressed.
> Maybe it will all work out nicely, but I'm worried.

Then we should be looking at the code instead of discussing 
it's theoritical capabilities :)

> On 03/19/2003 07:36 PM, Sandy Harris wrote:
> 
> s> ... the position of key kernel developers has
> s> always been that they could not accept anything into the main
> s> kernel tree that they weren't allowed to change.
> 
> But as Ken points out:
> 
> k> Nothing has stopped anyone from forking FreeS/WAN into something
> k> like, say, Super FreeS/WAN, and including code that Hugh Daniel and
> k> John Gilmour don't agree with - like NAT Traversal, and 1DES. I've
> k> done it, you can do it, we can all do it.
> 
> Indeed!!!!
> 
> One could accept KLIPSv1 code or at least KLIPS ideas
> and change them as much as desired.  So the can't-change
> argument seems completely bogus to me.

The only arguement that comes to mind is Paul's - once KLIPS was forked, 
the FreeS/WAN team wouldn't be able to accept any patches back from the 
fork, if they were from US citizens.  It would make it difficult to prove 
in a court battle that the FreeS/WAN Team's version was "untainted" by any 
improvements done to the forked version.  A potential problem, but never 
realized.

> 2) I don't know whether to laugh or cry when I see
> people use the 1DES issue as an argument against
> FreeS/WAN.  It's a ridiculous argument.  Ken has
> shown the correct way to deal with the issue!

Thanks :)

>  > if different distros pick different userland tools,
>  > inter-op could be nothing shy of a nightmare.
> 
> That's where things are heading: porting KAME
> userland tools.  Nightmare squared.

Derek's posts today indicate that one of his goals (FreeS/WAN interop) has 
been accomplished, so part of that worry has gone away.  But for distro 
maintainers, and management tool writers, it's only just begun.



- -- 
Ken Bantoft                The Unoffical FreeS/WAN Site:
[email protected]            http://www.freeswan.ca
                           PGP Key: finger [email protected]
The good thing about standards is that there are so many 
to choose from.			-- Andrew S. Tanenbaum

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3ia
Charset: noconv

iQCVAwUBPnkciViWUusaxGxpAQESLwP/ZkvB/BX6ooaiD9T9r4ctFI3v2pjczcnG
w4j75Pd5ALfg84QgqbaB9Gyp5PlLDyV5bUl38zlImC6RSryoInJl1wFcYsdH+4tV
SeBd1vtJg1wWCm6euw/7LPucp01L/HfRXaMy2hF1Bv2bopmuAJ9vQQUAm4v2y1xK
SUOFCkoCIQE=
=ZhEV
-----END PGP SIGNATURE-----