Re: IPSec in 2.5 Kernel?

"John S. Denker" <[email protected]> Fri, 21 Mar 2003 10:10:23 -0500
Newsgroups gmane.network.freeswan.devel
Message-ID <[email protected]>
On 03/20/2003 07:20 PM, Derek Atkins wrote:

 > Unfortunately it appears that no, there is no way
 > to set up multiple "anonymous" sessions -- and racoon has
 > no concept of a "road warrior".  It assumes that IDs are
 > IP Addresses.
 >
 > I'll work to fix that.

OK, this is a big step in the right direction.

Perhaps this will serve as the beginning of a
polite discussion of what features The Community
would like to see in Linux-IPsec.

There ought to be a discussion of
  -- what features have been implemented and are
known to work well
  -- what features have been implemented and need
testing
  -- what features have been promised but not yet
implemented
  -- what features are considered desirable but
haven't been promised
  -- what features are considered undesirable.

If there exists a document discussing such issues,
please let us know how to find it.  If it does not
yet exist, I'm sure The Community can help formulate
it by providing a number of nontrivial constructive
suggestions.

I recommend communicating with The Community sooner
rather than later.  The RFCs do not represent the
sum total of what The Community knows about IPsec.