FreeS/WAN Email Summary: 2.6 code in snapshots; FreeS/WAN with USAGI; SmartCard support in X.509 patch
Claudia Schmeing <[email protected]> Mon, 25 Aug 2003 22:50:18 -0400
| Newsgroups | gmane.network.freeswan.user,gmane.network.freeswan.devel |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- lists.freeswan.org Email Summary for Tuesday August 26, 2003 =============================================================================== by Claudia Schmeing [email protected] After a break, our summary of FreeS/WAN related happenings returns! This issue will help you catch up with our technical developments: how FreeS/WAN has been adapting to the new kernel IPsec functionality, and Andreas Steffen's new SmartCard support. It'll also let you know about our recent Ottawa Linux Symposium talks, and changes to our mailing lists. This issue has been sent to the users' and design lists. If you'd like to receive the List In Brief regularly, please sign up at https://lists.freeswan.org . Enjoy. In this issue.... 1. FreeS/WAN to Support 2.6 Kernel IPsec 2. FreeS/WAN with USAGI IPsec 3. SmartCard support in X.509 patch 4. FreeS/WAN talks at Ottawa Linux Symposium 5. FreeS/WAN Lists Moved ------------------------------------------------------------------------------ 1. FreeS/WAN to Support 2.6 Kernel IPsec ===================================== 1 post Aug 25 https://mj2.freeswan.org/archives/2003-August/msg00396.html Dave Miller and Alexei Kuznetsov have coded a new IPsec implementation for the mainline 2.6 kernel code, and Dave Miller has backported the changes to 2.4. There is also a new set of userland tools (ipsec-tools) based on Raccoon, but which do not have the full functionality offered by FreeS/WAN or Super FreeS/WAN userland tools. For more information on the new project, see http://lartc.org/howto/lartc.ipsec.html . To allow FreeS/WAN's userland tools to run with this code, Herbert Xu has created a patch, available at http://gondor.apana.org.au/~herbert/ . Thanks, Herbert! Herbert's work is already integrated into the FreeS/WAN nightly snapshots, and it will be released with 2.03, scheduled for September. The team is aiming for a FreeS/WAN version which will run seamlessly on a kernel which features either KLIPS or 2.6 native IPsec. In the interim, however, the team plans an immanent 2.02 release. It will incorporate a number of small, helpful changes amassed over the summer, for example: * "myid=", which allows simple configuration of an iOE (initiator-only OE) ID * a spec file for rpmbuild so that people can more easily build RPMs from source. 2.02-pre1 is available from ftp://ftp.xs4all.nl/pub/crypto/freeswan/development . 2. FreeS/WAN with USAGI IPsec ========================== 1 post Aug 19 https://mj2.freeswan.org/archives/2003-August/msg00324.html Since FreeS/WAN 1.9, Kurt Garloff has maintained the FreeS/WAN code which ships with SUSE Linux. Now, SUSE will be using USAGI's IPv6 functionality, which includes kernel level IPsec. As a result Kurt has patched FreeS/WAN userland to work with USAGI kernel level IPsec. Kurt commented: Unfortunately the pfkey interface is poorly standardized and the one from USAGI is quite different from what KLIPS does (which is different from what kernel 2.6 does). He added: I have FreeS/WAN packages on my webpage http://www.suse.de/~garloff/linux/FreeSWAN/ for USAGI and non-USAGI SuSE kernels. Unfortunately, the USAGI packages do not have all the SuperFreeS/WAN features (the non USAGI ones do have all the important things). The FreeS/WAN team now potentially may need to deal with three sets of kernel code. 3. SmartCard support in X.509 patch ======================================== 2 posts Aug 17 - 21 https://mj2.freeswan.org/archives/2003-August/msg00305.html As of version 1.4.0, the X.509 patch for FreeS/WAN features SmartCard support, using the PCKS#15 Cryptographic Token Information Format Standard, as implemented in the OpenSC smartcard library. OpenSC (http://www.opensc.org) library 8.0 is required to use the patch. The most recent version of the patch is 1.4.4. In addition to the SmartCard support, it includes a fix for an OE bug, and new functionality to aid in transition between certificates. As a reminder, you can get FreeS/WAN with X.509 one of two ways: * Download FreeS/WAN source (http://www.freeswan.org), patch with the X.509 patch (http://www.strongsec.com/freeswan), compile and install. * Download pre-patched FreeS/WAN code (as source or RPMs) from http://www.freeswan.ca. * Install Super FreeS/WAN (http://www.freeswan.ca), a version of FreeS/WAN pre-patched with many useful add-ons. Thanks again to Andreas Steffen and his team for all their hard work on FreeS/WAN's X.509 capabilities. 4. FreeS/WAN talks at Ottawa Linux Symposium ========================================= The Ottawa Linux Symposium (http://www.linuxsymposium.org) has long been a favourite meeting place for the FreeS/WAN team, project volunteers and FreeS/WAN afficionados. This year's event featured two FreeS/WAN related talks. Ken Bantoft of freeswan.ca talked about using FreeS/WAN along with other tools (heartbeat and zebra) to create high availability, load balanced secure connections. Abstract: http://www.linuxsymposium.org/2003/view_abstract.php?talk=14 Notes: http://www.freeswan.ca/docs/HA/ Claudia Schmeing gave a talk on Opportunistic Encryption, accompanied by Sam Sgro's demonstration of a quick and painless OE setup. Abstract: http://www.linuxsymposium.org/2003/view_abstract.php?talk=163 Notes: http://raven.crowgirl.com/talks/ols_2003_talk.html Slides: http://raven.crowgirl.com/talks/ols_2003_slides/ols_2003_slides.html 5. FreeS/WAN Lists Moved ===================== 3 posts Aug 12 - 17 https://mj2.freeswan.org/archives/2003-August/msg00217.html The FreeS/WAN mailing lists have moved! They'll rely on majordomo 2, rather than the mailman software we've been using for the past year. Their new home is https://mj2.freeswan.org; and lists.freeswan.org has been redirected to point there. Existing list members should automatically be resubscribed. List archives, including back archives, are at https://mj2.freeswan.org . Ken Bantoft maintains filtered archives of the old and new lists, at http://lists.freeswan.ca . ------------------------------------------------------------------------------ lists.freeswan.org Email Summary Tuesday, Aug 26, 2003 -----BEGIN PGP SIGNATURE----- Version: 2.6.3ia Charset: noconv iQCVAwUBP0rKJnDIYXPDEHodAQG5hgQAgsYluHMXajMrvQbyhtzF3uDZtlV+0HPh zsUxxJW971ApWgpuVa+SJEfnGluWG6kOzfy7UFVvHbWMuTVFkv66pVTUnAGNbe0k UNdWdUEFuwA/MwFz1B9L6oMgGJAO2OvLvGnHDAfIQhB1OpRqEhGV/dygUHUyV8zp x/mW/e0Fows= =PHnM -----END PGP SIGNATURE-----