2003-01-28 20:52:30

by Joy Latten

[permalink] [raw]
Subject: IPSec tools


I have started to take a look at the IPSec functionality on the 2.5 kernel.
I have some questions in the area of the userland applications for IPSec.
Is the direction to definitely use the KAME-based setkey and racoon
programs? If so, where will the ports of these programs live, on the KAME
site or somewhere else? While setkey seems to be working very well, racoon
is experiencing some problems. The availability of the ported source code
would allow for some debugging work to be performed.


Thanks,
Joy


2003-01-28 21:04:24

by David Miller

[permalink] [raw]
Subject: Re: IPSec tools

On Tue, 2003-01-28 at 13:00, [email protected] wrote:
> Is the direction to definitely use the KAME-based setkey and racoon
> programs?

Yes.

> If so, where will the ports of these programs live, on the KAME
> site or somewhere else? While setkey seems to be working very well, racoon
> is experiencing some problems. The availability of the ported source code
> would allow for some debugging work to be performed.

Initially we had a hacked copy distributed in iputils, but the KAME
folks have integrated all of our changes into their current sources.

Our initial port is at:

ftp://ftp.inr.ac.ru/ip-routing/iputils-ss021109-try.tar.bz2

but like I said the setkey/racoon in KAME's current sources should
just work.