samshot 2003mar13l fails to detect the CORRECT key in the DNS

Hugh Daniel <[email protected]> Fri, 28 Mar 2003 02:23:01 -0800
Newsgroups gmane.network.freeswan.devel
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----

  I have installed 2003mar13l on one machine, and it has clearly
failed on that one machine for one of the two critical things it was
supposed to have in it.

  Specify while it might check for _A_ key in the reverse DNS for it's
'public' interfaces it never checks to see if the secret half of that
key is in the /etc/ipsec.secrets file.  We must test for both a public
KEY in the DNS and it's secret counterpart in ipsec.secrets or we are
just pissing up wind.

  Obviously there needs to be a test for this in the testing system as
well.

  DHR?

  Long ago (most of a year) it was decided that exactly this test
should go into "ipsec verify" as well.  Ken or Paul, do either of you
have code for such a test?


		||ugh Daniel
		Testing Fool
		[email protected]

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3ia
Charset: noconv
Comment: For the matching public key, finger the Reply-To: address.

iQCVAwUBPoQidlZpdJR7FBQRAQEagwP+LMar1Cpu8fw95ecITB/TH1Rdk73n530m
VFLjuRESrMOzrmJhoaYJBChAxXjhRUf04eyemerUgkpMZfYohXg1XPic0Hm1RSng
ci6Aa7WEyy1uuoB33McngD4n+kBNy9wJX5HmapNUhGDS1ZlUs0m2n/mE4itwojTS
1LkPKXIxrgA=
=Fink
-----END PGP SIGNATURE-----