FreeS/WAN Email Summary: 2.6 code in snapshots; FreeS/WAN with USAGI; SmartCard support in X.509 patch

Claudia Schmeing <[email protected]> Mon, 25 Aug 2003 22:50:18 -0400
Newsgroups gmane.network.freeswan.user,gmane.network.freeswan.devel
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----



lists.freeswan.org Email Summary for Tuesday August 26, 2003
===============================================================================
by Claudia Schmeing                                        [email protected]



After a break, our summary of FreeS/WAN related happenings returns!

This issue will help you catch up with our technical developments: how
FreeS/WAN has been adapting to the new kernel IPsec functionality, and 
Andreas Steffen's new SmartCard support. It'll also let you know about our 
recent Ottawa Linux Symposium talks, and changes to our mailing lists.

This issue has been sent to the users' and design lists. If you'd like to 
receive the List In Brief regularly, please sign up at 
https://lists.freeswan.org .

Enjoy.



In this issue....

1.  FreeS/WAN to Support 2.6 Kernel IPsec
2.  FreeS/WAN with USAGI IPsec
3.  SmartCard support in X.509 patch
4.  FreeS/WAN talks at Ottawa Linux Symposium
5.  FreeS/WAN Lists Moved


 ------------------------------------------------------------------------------

1.  FreeS/WAN to Support 2.6 Kernel IPsec
    =====================================
    1 post Aug 25
    https://mj2.freeswan.org/archives/2003-August/msg00396.html

Dave Miller and Alexei Kuznetsov have coded a new IPsec implementation 
for the mainline 2.6 kernel code, and Dave Miller has backported the changes 
to 2.4. There is also a new set of userland tools (ipsec-tools) based on 
Raccoon, but which do not have the full functionality offered by FreeS/WAN 
or Super FreeS/WAN userland tools. For more information on the new project, 
see http://lartc.org/howto/lartc.ipsec.html  .

To allow FreeS/WAN's userland tools to run with this code, Herbert Xu has 
created a patch, available at http://gondor.apana.org.au/~herbert/ . 
Thanks, Herbert! Herbert's work is already integrated into the FreeS/WAN
nightly snapshots, and it will be released with 2.03, scheduled for September. 
The team is aiming for a FreeS/WAN version which will run seamlessly on a 
kernel which features either KLIPS or 2.6 native IPsec.

In the interim, however, the team plans an immanent 2.02 release. It will 
incorporate a number of small, helpful changes amassed over the summer, 
for example:
* "myid=", which allows simple configuration of an iOE (initiator-only OE) ID
* a spec file for rpmbuild so that people can more easily build RPMs from
source. 2.02-pre1 is available from
ftp://ftp.xs4all.nl/pub/crypto/freeswan/development .



2.  FreeS/WAN with USAGI IPsec
    ==========================
    1 post Aug 19
    https://mj2.freeswan.org/archives/2003-August/msg00324.html

Since FreeS/WAN 1.9, Kurt Garloff has maintained the FreeS/WAN code which ships 
with SUSE Linux. Now, SUSE will be using USAGI's IPv6 functionality,
which includes kernel level IPsec. As a result Kurt has patched
FreeS/WAN userland to work with USAGI kernel level IPsec. Kurt commented:

    Unfortunately the pfkey interface is poorly standardized and the
    one from USAGI is quite different from what KLIPS does (which is
    different from what kernel 2.6 does). 

He added:

    I have FreeS/WAN packages on my webpage
    http://www.suse.de/~garloff/linux/FreeSWAN/
    for USAGI and non-USAGI SuSE kernels. Unfortunately, the USAGI
    packages do not have all the SuperFreeS/WAN features (the non
    USAGI ones do have all the important things).

The FreeS/WAN team now potentially may need to deal with three sets of 
kernel code.



3.  SmartCard support in X.509 patch
    ========================================
    2 posts Aug 17 - 21
    https://mj2.freeswan.org/archives/2003-August/msg00305.html

As of version 1.4.0, the X.509 patch for FreeS/WAN features SmartCard support,
using the PCKS#15 Cryptographic Token Information Format Standard, as 
implemented in the OpenSC smartcard library. OpenSC (http://www.opensc.org) 
library 8.0 is required to use the patch.

The most recent version of the patch is 1.4.4. In addition to the SmartCard 
support, it includes a fix for an OE bug, and new functionality 
to aid in transition between certificates.

As a reminder, you can get FreeS/WAN with X.509 one of two ways:
* Download FreeS/WAN source (http://www.freeswan.org), patch with the 
X.509 patch (http://www.strongsec.com/freeswan), compile and install.
* Download pre-patched FreeS/WAN code (as source or RPMs) from 
http://www.freeswan.ca.
* Install Super FreeS/WAN (http://www.freeswan.ca), a version of FreeS/WAN
pre-patched with many useful add-ons.

Thanks again to Andreas Steffen and his team for all their hard work on 
FreeS/WAN's X.509 capabilities.



4.  FreeS/WAN talks at Ottawa Linux Symposium
    =========================================

The Ottawa Linux Symposium (http://www.linuxsymposium.org) has long been a
favourite meeting place for the FreeS/WAN team, project volunteers and 
FreeS/WAN afficionados. This year's event featured two FreeS/WAN related talks.

Ken Bantoft of freeswan.ca talked about using FreeS/WAN along with other
tools (heartbeat and zebra) to create high availability, load balanced 
secure connections.

Abstract:  http://www.linuxsymposium.org/2003/view_abstract.php?talk=14
Notes:     http://www.freeswan.ca/docs/HA/

Claudia Schmeing gave a talk on Opportunistic Encryption, accompanied by 
Sam Sgro's demonstration of a quick and painless OE setup.

Abstract:  http://www.linuxsymposium.org/2003/view_abstract.php?talk=163
Notes:     http://raven.crowgirl.com/talks/ols_2003_talk.html
Slides:    http://raven.crowgirl.com/talks/ols_2003_slides/ols_2003_slides.html



5.  FreeS/WAN Lists Moved
    =====================
    3 posts Aug 12 - 17
    https://mj2.freeswan.org/archives/2003-August/msg00217.html

The FreeS/WAN mailing lists have moved! They'll rely on majordomo 2,
rather than the mailman software we've been using for the past year. 
Their new home is https://mj2.freeswan.org; and lists.freeswan.org
has been redirected to point there. Existing list members should automatically 
be resubscribed.

List archives, including back archives, are at https://mj2.freeswan.org .

Ken Bantoft maintains filtered archives of the old and new lists, at
http://lists.freeswan.ca .

 ------------------------------------------------------------------------------
lists.freeswan.org Email Summary                          Tuesday, Aug 26, 2003

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3ia
Charset: noconv

iQCVAwUBP0rKJnDIYXPDEHodAQG5hgQAgsYluHMXajMrvQbyhtzF3uDZtlV+0HPh
zsUxxJW971ApWgpuVa+SJEfnGluWG6kOzfy7UFVvHbWMuTVFkv66pVTUnAGNbe0k
UNdWdUEFuwA/MwFz1B9L6oMgGJAO2OvLvGnHDAfIQhB1OpRqEhGV/dygUHUyV8zp
x/mW/e0Fows=
=PHnM
-----END PGP SIGNATURE-----