Announce: Release 2.05 -- Authentication Header Removed

Claudia Schmeing <[email protected]> Mon, 9 Feb 2004 23:16:11 -0500
Newsgroups gmane.network.freeswan.user,gmane.network.freeswan.devel
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
                                                                                
Hi all,
                                                                                
                                                                                
The FreeS/WAN team has shipped release 2.05, our first release with AH
(Authentication Header) removed!
                                                                                
As part of our continuing efforts to create a lightweight, robust
Opportunistic Encryption (OE) product, (and inspired by Schneier and
Ferguson's critique of IPsec), we've removed AH from FreeS/WAN. For more
information, see http://www.freeswan.org/no_ah.html.
                                                                                
Still in the "experimental support stage" is lwdnsq (lightweight DNS queue),
a mini resolver designed to provide resilient, authenticated DNS lookups to
facilitate OE. lwdnsq now supports DNSsec.
                                                                                
FreeS/WAN now by default generates RSA keys of random length for
authentication. If variable key lengths are widely deployed, FreeS/WAN
will not provide a "sweet spot" key length where crackers could easily focus
their efforts. A generic attack on FreeS/WAN might then require a more diverse
and thorough approach. For more, see the design-list discussion of this topic
at http://lists.freeswan.org/archives/design/2003-October/msg00055.html .
                                                                                
Please see our CHANGES file for more detail.
                                                                                
                                                                                
Cheers,
                                                                                
Claudia
                                                                                
-----BEGIN PGP SIGNATURE-----
Version: 2.6.3ia
Charset: noconv
                                                                                
iQCVAwUBQCfPcnDIYXPDEHodAQGoEAP9Fq8IGplON2xnctgcYZMzwM9KqlwmJ/M9
28fzjsOTawEErL77KDMBXC0m4n5Ji6Ot7/jCOORZ2RfSnLBPb3XtHKwwOAIWXTP8
+t0ztUnuKf+JaxGY4oTkwbxpeYJjpnyemnpMQ23Q4uLWzRMiuKpVTQJVvYrkz8VH
RjnW7Ou62/k=
=zmYb
-----END PGP SIGNATURE-----