FreeS/WAN 2.03-pre0 and 2.6.0, SHA-1 Bug and Fix (2.x), VPN Security Critique
Claudia Schmeing <[email protected]> Wed, 24 Sep 2003 01:23:07 -0400
| Newsgroups | gmane.network.freeswan.user,gmane.network.freeswan.devel |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- lists.freeswan.org Email Summary for Tuesday September 23, 2003 =============================================================================== by Claudia Schmeing [email protected] This week, 2.03-pre0 has been released. 2.03 will be our first offering with support for 2.6 kernel native IPsec, and our first item reports on some of the efforts to test that new support. In item 2, we report that a SHA-1 bug, that's been affecting some 2.x users, is fixed in 2.03-pre0. On a lighter note, check out Jacco de Leuw's fantastic interop page, mentioned in item 5. Enjoy. This Week in Brief.... 1. Using FreeS/WAN 2.03-pre0 and 2.6.0 2. SHA-1 Bug and Fix (2.x) 3. IPsec port selectors in 2.04 4. VPN Security Critique not applicable to IPsec 5. Neat Stuff: interop page ------------------------------------------------------------------------------ 1. Using FreeS/WAN 2.03-pre0 and 2.6.0 =================================== 5 posts Sep 23 http://lists.freeswan.org/archives/design/2003-September/msg00057.html With 2.03-pre0, the FreeS/WAN team has a pre-release with initial support for the 2.6.0 kernel's native IPsec. We expect it will take a few releases to test and and perfect a FreeS/WAN version which runs well on 2.6. Some essential design differences in the new kernel will change FreeS/WAN's behaviour, perhaps for the better. Here's one example. In Herbert Xu's words, "In 2.6, the policy engine is detached from routing decisions." Because of this design, Opportunistic Encryption on the local LAN will now be possible with 2.6. D. Hugh Redelmeier commented, This is actually a good change, but with unfortunate side-effects. Why good? The fact (in KLIPS-based FreeS/WAN) that a more specific route exempts traffic from IPsec is fundamentally wrong. The right way to exempt traffic is to ask to exempt it. For the moment, users wishing to test FreeS/WAN with 2.6 will require ipsec-tools' "setkey" program. Tools within "setkey" facilitate some basic FreeS/WAN functionality. For example, as Herbert Xu pointed out, setkey is needed to reset kernel SPD (Security Policy Database) state when FreeS/WAN's Pluto keying daemon is restarted. FreeS/WAN still requires a number of small changes to adjust well to the kernel code shift. For instance, Sam Sgro suggested: We have to update our tools to display (and possibly manipulate) SPD states. We encourage ambitious users to try the new kernel and pre0 release. A new FreeS/WAN document, 2.6.known-issues, will keep track of essential pointers for operating FreeS/WAN on 2.6 kernels. Feedback from 2.6 testing is welcome at [email protected]. 2. SHA-1 Bug and Fix (2.x) ======================= 1 post Sep 17 http://lists.freeswan.org/archives/users/2003-September/msg00462.html Sam Sgro issued this warning to SHA-1 users: Are you running a Linux FreeS/WAN 2.00, 2.01, and 2.02, and interoperating with other IPsec implementations? If so, this fix may be relevant to you. The SHA1 implementation in those releases is flawed; while negotiations for ESP_3DES_HMAC_SHA1 will succeed, actually receiving SHA1 hashed packets will fail. "klipsdebug=all" will log errors... Sam added: SHA1 support is not critical for many FreeS/WAN deployments. FreeS/WAN to FreeS/WAN tunnels have always used MD5 thanks to the nature of the IKE proposals, the W2k/XP native clients propose MD5, etc. He included a fix, which is also in 2.03-pre0. 3. IPsec port selectors in 2.04 ============================ 5 posts Sep 19 - 21 http://lists.freeswan.org/archives/design/2003-September/msg00047.html More new features are coming in 2.04, slated for late October. MCR dropped this hint: 2.04 will have the port-selector code from the X.509 patch (but won't have X.509 compiled in by default), so this should be possible. For folks using KLIPS (FreeS/WAN) kernel code, this should help address problems using IPsec on the local LAN; see the thread for more. 4. VPN Security Critique not applicable to IPsec ============================================= 2 posts Sep 22 -23 http://lists.freeswan.org/archives/users/2003-September/msg00588.html Simon Matthews pointed out to the lists this rather smart, detailed critique of several Linux VPNs (cipe, vtun, tinc), which had been linked to from slashdot.org: http://www.mit.edu:8008/bloom-picayune/crypto/14238 Simon asked if the concerns expressed were relevant to FreeS/WAN. Sam Sgro responded that they were not, but commented: For a good, critical analysis of IPsec's flaws, you can read Niels Ferguson and Bruce Schneier's evaluation: http://www.counterpane.com/ipsec.ps.gz 5. Neat Stuff: interop page ======================== There's a terrific web page by Jacco de Leuw on using FreeS/WAN with Microsoft IPsec and L2TP. Check it out here: http://www.jacco2.dds.nl/networking/freeswan-l2tp.html ------------------------------------------------------------------------------ lists.freeswan.org Email Summary Tuesday, Sep 23, 2003 -----BEGIN PGP SIGNATURE----- Version: 2.6.3ia Charset: noconv iQCVAwUBP3EpwnDIYXPDEHodAQHcogP+PHtTbC2K9aCJRdFkaNwhlHnManC8qaRL YiDKoCdGrc0ragHHEHkTJfO8TgEoMpblNHASzcSS6P9pHc/wEn5N5DCMdhDADi7S MEB4t2+uLA6YVym0KVG5lwSlgTb7eo99axbK6BxHuuXmQ45X86wxilQ9Ic19m/oJ Gw2trnyLPBA= =Ln2+ -----END PGP SIGNATURE-----