would the new release of ipsec6 with X.509 support have protocol level
support?
Friday, 7 February 2003 7:06 PM
To: <[email protected]>, <[email protected]>
cc:
From: "Gessler Gerhard" <[email protected]>
Subject: RE: [Design] pfkeyv2 : proto feild in address extension
Hi,
we (IABG) did not implement further pfkeyv2 code for handling port and
protocal as Pluto (the FreeS/WAN IKE-daemon) was not able to negotiate SAs
with that granularity at that time.
I think Pluto is still only able to do this with an additional patch, if my
memory serves.
Hope this helps,
Gerhard
--------------------------------------------
Gerhard Geßler
Communication Networks, IABG mbH
Einsteinstr. 20
85521 Ottobrunn, Germany
Telefon: +49 89 6088 - 2021
Fax: +49 89 6088 - 2845
E-Mail: [email protected]
> -----Original Message-----
> From: [email protected]
> [mailto:[email protected]]
> Sent: Friday, February 07, 2003 1:12 PM
> To: [email protected]
> Cc: Gessler Gerhard
> Subject: [Design] pfkeyv2 : proto feild in address extension
>
>
> hi
> while trying to add protocol entry into the sadb from used
> space i saw in
> the pfkeyv2 code that the proto element within the address
> extension has
> not been used.The pf key v2 RFC also gives it as a MUST
> condition, that
> the transport layer protocol should be given within the
> proto feild of the
> address extension.
>
> i wanted to know why proto field within the address
> extension has not been
> used by freeswan to implement protocol level granularity, i
> havent tried
> doing this myself yet, so i wanted to enquire if there are
> some problems to
> it.
>
> thanks and regards.
>
> _______________________________________________
> Design mailing list
> [email protected]
> http://lists.freeswan.org/mailman/listinfo/design
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.