Quality of FreeS/WAN support

Hugh Daniel <[email protected]> Mon, 02 Jun 2003 18:41:17 -0700
Newsgroups gmane.network.freeswan.user,gmane.network.freeswan.devel
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----

  One of our (major) FreeS/WAN volunteers just said:

  "FreeS/WAN is probably one of the best supported IPSec implementations
out there..."
		--  Ken Bantoff

and I thanked him for this and the realized I did not really know of
this was true.

  So in true scientific tradition I decided to try to find out by
asking a very non-random sample two questions about how FreeS/WAN
might be better.


  The first question is simple, "How can we support FreeS/WAN users
like _you_ better?".

  Note that we could just assign a FreeS/WAN developer to live under
your computer room floor or fly one to you when ever you had a
question, and also note that that will NOT be happening!  What I mean
is what can _we_ as a community of volunteers do together that would
make your job easer and help you to use FreeS/WAN in more places and
ways.

  While I don't want to limit the suggestions, I am looking for simple
concrete things that we as a community can do.  Maybe you want a Wikki
server, maybe you know of a particular mail list archiver that does
good WAIS indexing, maybe you want folks to post configuration setup
dumps.

  Maybe you have seen some other project or an IPsec vendor with a
SOMETHING that you found just ever so useful, tell use how it was
useful to you and where to find an example to look at.

  Maybe you think our doc needs to be rearranged, if so then grab the
FreeS/WAN ToC (Table of Contents) and redo it and tell us _why_ your
ordering is different and better.  Yea it's a bit of work, but then
you become not just a FreeS/WAN user but a FreeS/WAN contributor.

  Lastly there was the claim it's self, that FreeS/WAN is one of the
best supported IPsec's out there, is it true?  If you have had better
support from some other IPsec vendor, then tell us about it.  If you
think we are best, we will only blush a little if you complement us!


  So this brings me to the next question for folks using FreeS/WAN,
are you using our Opportunistic Encryption (OE)?  If not (and this is
the most important question in this email...), why not?

  The whole idea of FreeS/WAN was to do OE and not make just another
IPsec system.  OE should be useful as it is, and should be much more
useful soon with WAVEsec (see www.wavesec.org) and other
improvements coming soon.

  For instance, what would convince you to re-configure your hand
crafted VPN or X.509 mess move it all to OE?  Is there some admin tool
that would make OE more useful then traditional VPN?  Is there some
very common situation where a focused end user OE HOWTO for _just_
that situation cause your users to want OE maybe?


  Due to being busy I myself am unlikely to be able to respond
directly to most posts, but I would like to provide forward thanks to
everyone who takes the time to write a response and even more thanks
to folks who write contributions (code, doc, screeds) as that is how
Free & Open Source grows more useful for all.

		||ugh Daniel
		[email protected]

			Systems Testing & Project mis-Management
			The Linux FreeS/WAN Project
			http://www.freeswan.org

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3ia
Charset: noconv
Comment: For the matching public key, finger the Reply-To: address.

iQCVAwUBPtv8qVZpdJR7FBQRAQGTagP/eBUkfnTy21uyKmLPjFiWLylYCcVwHhxs
JNpeK+czYvPQVvvw/zr2QdXVJJmmQJwXtLWnc52nvguXN197m3pZfi7d8Jtn/gUx
B+pejpDUK7rlVHJWVwH04R+MXkNph/ToHMMKdLeX9XE7AH4vX4JlSy0hxs2GYyhM
vscwApP9Rdk=
=Uk7m
-----END PGP SIGNATURE-----