Re: upgrade 1.9x -> 2.00 support and version 2 issue

Michael Richardson <[email protected]>
Newsgroups gmane.network.freeswan.devel
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----


>>>>> "Paul" == Paul Wouters <[email protected]> writes:
    Paul> I just noticed my crypto was off, and noticed:

    Paul> [root@kgbvax root]# service ipsec start ipsec_setup:
    Paul> (/etc/ipsec.conf, line 9) we only support version 2 ipsec.conf
    Paul> files -- `start' aborted

    Paul> ipsec --version Linux FreeS/WAN U2.00-pre6/K(no kernel code
    Paul> presently loaded)

    Paul> Are we really not going to support running 2.x on 1.x config files? 

  That's correct.

    Paul> This is a setup with just plain static tunnels, and I don't see any
    Paul> reason why it shouldn't work. I can understand OE would break,
    Paul> since it changed so much, but do we have to break simple static
    Paul> tunnels?

    Paul> Also, it would be nice if it had installed an ipsec.conf-new or
    Paul> something for me to peek at the new syntax.

  it is in /usr/local/share/doc/freeswan/ipsec.conf-sample

    Paul> That said, I see (at least in the source):
    Paul> /usr/src/freeswan-2.00-pre6/doc/ipsec.conf.2_to_1

  All of the defaults have changed.

  If you think that everything is okay, you can put "version 2" at the top.

    Paul> This is rather confusing, since the "if you put this in front"
    Paul> remark is (I think) only about the "version 2" line, and not about
    Paul> the whole thing, and people will confuse the remark to mean to put
    Paul> the entire file above their original, and end up with two setup and
    Paul> default sections.

  It is sufficient to have it as the first non-blank, non-comment line.
  I agree that the comment should move in the document.

]       ON HUMILITY: to err is human. To moo, bovine.           |  firewalls  [
]   Michael Richardson, Sandelman Software Works, Ottawa, ON    |net architect[
] [email protected] http://www.sandelman.ottawa.on.ca/ |device driver[
] panic("Just another Debian GNU/Linux using, kernel hacking, security guy"); [
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (GNU/Linux)
Comment: Finger me for keys

iQCVAwUBPklumoqHRg3pndX9AQEbwQQAx2KDNrQWtFjpW54Ygza8egLzojBTS4XS
U1j3+zYjYlTodPzSXgxvekPMQVnjaoA1QJtVH8xyTbmLOIoB4uY16ipD89Z6xdxr
5Soxe6S6TzHhiJf+Z6vh1NiYaYEZhWHk5Xt8q/FXGR1tSfJ0+8fXphXOF74mQ86S
/zotVXXH5WE=
=X3b3
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.