mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Jesse Pollard <pollard@tomcat.admin.navo.hpc.mil>
To: justin@soze.net, Nitin Dhingra <nitin.dhingra@dcmtech.co.in>
Cc: "'linux-kernel@vger.kernel.org'" <linux-kernel@vger.kernel.org>
Subject: Re: IPsec in Kernel??
Date: Thu, 12 Jul 2001 09:29:05 -0500 (CDT)	[thread overview]
Message-ID: <200107121429.JAA66935@tomcat.admin.navo.hpc.mil> (raw)

Justin Guyett <justin@soze.net>:
> On Thu, 12 Jul 2001, Nitin Dhingra wrote:
> 
> > Is there any possibility that IPsec will be provided in
> > the kernel ?
> 
> The maintainers won't accept code from anyone in the US for fear that
> export regulations may tighten again retroactively, so any merge into the
> kernel would require a seperate maintainer either to maintain the fork,
> and/or to constantly merge in new changes from the original freeswan
> project.
> 
> The current in-kernel portion of freeswan doesn't get along well with
> advanced routing, and doesn't take advantage of SMP, so I'd be rather
> disappointed if it got forked and merged in its current form.
> 
> Some things that would be nice:
>  integration with advanced routing
>  /proc interface so connections can be added on the fly
>  module-only option (freeswan's latest snapshots seem to have this)
>  take advantage of SMP
>  implement AES
>  use of kernel crypto patch / openssl for userland rsa stuff
>  move all non-optional parts of the updown scripts into the ipsec program,
>   a la openbsd where the shell script portion isn't hundreds of lines for
>   one tunnel.
>  no bloat (a 3.5 meg ipsec module doesn't seem very reasonable)

It also needs to support more than just encrypted IP tunnels.

I'm hoping the Linux security module will eventually be able to have modules
for IPSec plus remote user authentication, socket/data labeling.

-------------------------------------------------------------------------
Jesse I Pollard, II
Email: pollard@navo.hpc.mil

Any opinions expressed are solely my own.

             reply	other threads:[~2001-07-12 14:30 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2001-07-12 14:29 Jesse Pollard [this message]
  -- strict thread matches above, loose matches on Subject: below --
2001-07-12  6:31 Nitin Dhingra
2001-07-12 14:03 ` Justin Guyett

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=200107121429.JAA66935@tomcat.admin.navo.hpc.mil \
    --to=pollard@tomcat.admin.navo.hpc.mil \
    --cc=justin@soze.net \
    --cc=linux-kernel@vger.kernel.org \
    --cc=nitin.dhingra@dcmtech.co.in \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®