2017-01-07 13:55:16

by Christian Göttsche

[permalink] [raw]
Subject: [refpolicy] ipsec module: rewrite for strongswan 5.5

The reference modules version of the IPsec module did not fit my needs
for running strongswan in version 5.5, so I rewrote the whole module.
The redraft drops support for the old strongswan daemon pluto and also
for the raccon and setkey applications, where the last version seems
to be from the 27th of February 2014.
Now I'd like to have feedback on the module and on dropping the support.

The policy modules files are attached and a unclear diff is available
on https://github.com/TresysTechnology/refpolicy/pull/80/files

Best Regards,
Christian G?ttsche
-------------- next part --------------
A non-text attachment was scrubbed...
Name: ipsec.if
Type: application/octet-stream
Size: 3899 bytes
Desc: not available
Url : http://oss.tresys.com/pipermail/refpolicy/attachments/20170107/2c8fee11/attachment.obj
-------------- next part --------------
A non-text attachment was scrubbed...
Name: ipsec.te
Type: application/octet-stream
Size: 4426 bytes
Desc: not available
Url : http://oss.tresys.com/pipermail/refpolicy/attachments/20170107/2c8fee11/attachment-0001.obj
-------------- next part --------------
A non-text attachment was scrubbed...
Name: ipsec.fc
Type: application/octet-stream
Size: 1632 bytes
Desc: not available
Url : http://oss.tresys.com/pipermail/refpolicy/attachments/20170107/2c8fee11/attachment-0002.obj


2017-01-10 01:42:27

by Chris PeBenito

[permalink] [raw]
Subject: [refpolicy] ipsec module: rewrite for strongswan 5.5

On 01/07/17 08:55, cgzones via refpolicy wrote:
> The reference modules version of the IPsec module did not fit my needs
> for running strongswan in version 5.5, so I rewrote the whole module.
> The redraft drops support for the old strongswan daemon pluto and also
> for the raccon and setkey applications, where the last version seems

Are all of these IPsec tools obsolete, or unmaintained? I don't want to
remove policy that is still relevant.


> to be from the 27th of February 2014.
> Now I'd like to have feedback on the module and on dropping the support.
>
> The policy modules files are attached and a unclear diff is available
> on https://github.com/TresysTechnology/refpolicy/pull/80/files

--
Chris PeBenito