FreeS/WAN 2.03-pre0 and 2.6.0, SHA-1 Bug and Fix (2.x), VPN Security Critique

Claudia Schmeing <[email protected]> Wed, 24 Sep 2003 01:23:07 -0400
Newsgroups gmane.network.freeswan.user,gmane.network.freeswan.devel
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----



lists.freeswan.org Email Summary for Tuesday September 23, 2003
===============================================================================
by Claudia Schmeing                                        [email protected]


This week, 2.03-pre0 has been released. 2.03 will be our first offering with 
support for 2.6 kernel native IPsec, and our first item reports on some of the
efforts to test that new support. In item 2, we report that a SHA-1 bug, that's 
been affecting some 2.x users, is fixed in 2.03-pre0.

On a lighter note, check out Jacco de Leuw's fantastic interop page, mentioned
in item 5.

Enjoy.




This Week in Brief....

1.  Using FreeS/WAN 2.03-pre0 and 2.6.0
2.  SHA-1 Bug and Fix (2.x)
3.  IPsec port selectors in 2.04
4.  VPN Security Critique not applicable to IPsec
5.  Neat Stuff: interop page


 ------------------------------------------------------------------------------


1.  Using FreeS/WAN 2.03-pre0 and 2.6.0
    ===================================
    5 posts Sep 23
    http://lists.freeswan.org/archives/design/2003-September/msg00057.html

With 2.03-pre0, the FreeS/WAN team has a pre-release with initial support for 
the 2.6.0 kernel's native IPsec. We expect it will take a few releases
to test and and perfect a FreeS/WAN version which runs well on 2.6.

Some essential design differences in the new kernel will change FreeS/WAN's 
behaviour, perhaps for the better. Here's one example. In Herbert Xu's words, 
"In 2.6, the policy engine is detached from routing decisions." Because of this
design, Opportunistic Encryption on the local LAN will now be possible with 2.6.
D. Hugh Redelmeier commented,

    This is actually a good change, but with unfortunate side-effects.
                                                                                
    Why good?  The fact (in KLIPS-based FreeS/WAN) that a more specific
    route exempts traffic from IPsec is fundamentally wrong.  The
    right way to exempt traffic is to ask to exempt it.

For the moment, users wishing to test FreeS/WAN with 2.6 will require
ipsec-tools' "setkey" program. Tools within "setkey" facilitate some basic 
FreeS/WAN functionality. For example, as Herbert Xu pointed out, setkey is 
needed to reset kernel SPD (Security Policy Database) state when FreeS/WAN's 
Pluto keying daemon is restarted.

FreeS/WAN still requires a number of small changes to adjust well to the 
kernel code shift. For instance, Sam Sgro suggested:
                                                         
    We have to update our tools to display (and possibly manipulate) SPD states.

We encourage ambitious users to try the new kernel and pre0 release.
A new FreeS/WAN document, 2.6.known-issues, will keep track of essential 
pointers for operating FreeS/WAN on 2.6 kernels. Feedback from 2.6 testing is 
welcome at [email protected].



2.  SHA-1 Bug and Fix (2.x)
    =======================
    1 post Sep 17
    http://lists.freeswan.org/archives/users/2003-September/msg00462.html

Sam Sgro issued this warning to SHA-1 users:

    Are you running a Linux FreeS/WAN 2.00, 2.01, and 2.02, and interoperating 
    with other IPsec implementations? If so, this fix may be relevant to you.
    The SHA1 implementation in those releases is flawed; while negotiations for 
    ESP_3DES_HMAC_SHA1 will succeed, actually receiving SHA1 hashed packets 
    will fail. "klipsdebug=all" will log errors...

Sam added:

    SHA1 support is not critical for many FreeS/WAN deployments. FreeS/WAN to 
    FreeS/WAN tunnels have always used MD5 thanks to the nature of the IKE 
    proposals, the W2k/XP native clients propose MD5, etc. 

He included a fix, which is also in 2.03-pre0.



3.  IPsec port selectors in 2.04
    ============================
    5 posts Sep 19 - 21
    http://lists.freeswan.org/archives/design/2003-September/msg00047.html


More new features are coming in 2.04, slated for late October. MCR
dropped this hint:

    2.04 will have the port-selector code from the X.509 patch (but won't
    have X.509 compiled in by default), so this should be possible.

For folks using KLIPS (FreeS/WAN) kernel code, this should help address 
problems using IPsec on the local LAN; see the thread for more.



4.  VPN Security Critique not applicable to IPsec
    =============================================
    2 posts Sep 22 -23
    http://lists.freeswan.org/archives/users/2003-September/msg00588.html

Simon Matthews pointed out to the lists this rather smart, detailed critique of 
several Linux VPNs (cipe, vtun, tinc), which had been linked to from 
slashdot.org: 
http://www.mit.edu:8008/bloom-picayune/crypto/14238
Simon asked if the concerns expressed were relevant to FreeS/WAN.

Sam Sgro responded that they were not, but commented:

    For a good, critical analysis of IPsec's flaws, you can read Niels Ferguson 
    and Bruce Schneier's evaluation:
    http://www.counterpane.com/ipsec.ps.gz



5.  Neat Stuff: interop page
    ========================

There's a terrific web page by Jacco de Leuw on using FreeS/WAN with Microsoft 
IPsec and L2TP. Check it out here:

http://www.jacco2.dds.nl/networking/freeswan-l2tp.html


 ------------------------------------------------------------------------------
lists.freeswan.org Email Summary                          Tuesday, Sep 23, 2003

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3ia
Charset: noconv

iQCVAwUBP3EpwnDIYXPDEHodAQHcogP+PHtTbC2K9aCJRdFkaNwhlHnManC8qaRL
YiDKoCdGrc0ragHHEHkTJfO8TgEoMpblNHASzcSS6P9pHc/wEn5N5DCMdhDADi7S
MEB4t2+uLA6YVym0KVG5lwSlgTb7eo99axbK6BxHuuXmQ45X86wxilQ9Ic19m/oJ
Gw2trnyLPBA=
=Ln2+
-----END PGP SIGNATURE-----