From: "David S. Miller" <davem@redhat.com>
To: pasky@pasky.ji.cz
Cc: zdzichu@irc.pl, linux-kernel@vger.kernel.org
Subject: Re: 2.4 and full ipv6 - will it happen?
Date: Thu, 12 Sep 2002 18:47:19 -0700 (PDT) [thread overview]
Message-ID: <20020912.184719.126771896.davem@redhat.com> (raw)
In-Reply-To: <20020912150609.GE21715@pasky.ji.cz>
From: Petr Baudis <pasky@pasky.ji.cz>
Date: Thu, 12 Sep 2002 17:06:09 +0200
- IPsec for IPv6
Without ipv4 part and stackable destination cache, we do
not see any way in which they could make this cleanly and
properly and thus make patch acceptable.
All of IPSEC is a routing and data representation problem, so unless
routing code of ipv6 was rewritten by USAGI folks to support
representation of security database (this means addition of
protocol/source_port/dest_port route demux selectors and also
RTA_IPSEC routing attribute for actual ESP/AH rule insertion), the
patch is not likely to be accepted.
So if done right, ipv4 would be just as easy to support and thusly
I make parallel ipv6/ipv4 support a requirement for any ipsec
implementation that goes into the tree.
I also want ipsec to be implemented using rtnetlink which doubly means
that it must be solved at the routing level.
This also means that PF_KEY socket implementation is merely translator
into rtnetlink messages and nothing more and that "ip" tool would be
used for manual keying.
The fact that I have so much to say about the implementation details
of ipsec might suggest something if you're paying attention :-) And
that's where I'll leave the topic of ipsec at the moment.
Otherwise I look forward to seeing their other patches, but I find it
strange that it takes them on the order months to submit things, which
I have maintained from the start. They work on this stuff nearly full
time and it is very important to them, they also have high claims as
to it's readiness, so what could possibly take so long?
next prev parent reply other threads:[~2002-09-13 1:53 UTC|newest]
Thread overview: 39+ messages / expand[flat|nested] mbox.gz Atom feed top
2002-08-19 4:39 Tomasz Torcz, BG
2002-08-19 4:37 ` David S. Miller
2002-08-19 5:16 ` Tomasz Torcz, BG
2002-08-19 5:12 ` David S. Miller
2002-08-19 23:34 ` Thunder from the hill
2002-08-19 23:23 ` David S. Miller
2002-08-19 23:49 ` Daniel Berlin
2002-08-19 23:54 ` Alan Cox
2002-08-20 0:32 ` Rik van Riel
2002-08-20 13:54 ` kuznet
2002-08-20 6:56 ` Thunder from the hill
2002-08-21 20:24 ` Kelsey Hudson
2002-08-21 21:31 ` Bernd Eckenfels
2002-08-21 21:44 ` Thunder from the hill
2002-08-21 22:03 ` Bernd Eckenfels
2002-08-21 23:13 ` Russell King
2002-08-22 0:05 ` Bernd Eckenfels
2002-08-22 6:08 ` Thunder from the hill
2002-08-26 18:55 ` Kelsey Hudson
2002-08-26 19:44 ` Bernd Eckenfels
2002-08-26 21:51 ` Michael H. Warfield
2002-08-26 23:48 ` Bernd Eckenfels
2002-08-27 16:07 ` Michael H. Warfield
2002-08-28 19:14 ` Bernd Eckenfels
2002-08-29 2:05 ` Michael H. Warfield
2002-08-29 18:47 ` Bernd Eckenfels
2002-08-21 22:08 ` Alan Cox
2002-08-22 6:12 ` Thunder from the hill
2002-08-22 12:27 ` Rik van Riel
2002-08-22 18:22 ` Alan Cox
2002-08-22 18:26 ` Bernd Eckenfels
2002-08-22 19:19 ` Russell King
2002-09-12 15:06 ` Petr Baudis
2002-09-13 1:47 ` David S. Miller [this message]
2002-08-19 7:27 ` Chris Wedgwood
2002-08-19 12:25 ` Alan Cox
2002-08-19 22:39 ` Kelsey Hudson
2002-08-20 6:17 ` Val Henson
2002-08-19 23:56 Leif Sawyer
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20020912.184719.126771896.davem@redhat.com \
--to=davem@redhat.com \
--cc=linux-kernel@vger.kernel.org \
--cc=pasky@pasky.ji.cz \
--cc=zdzichu@irc.pl \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®