|
|||||||||||
|
Re: linux-ipsec: socket to kernel issues
From: Niels Provos <provos(at)power5.physnet.uni-hamburg.de>
Date: Sat May 16 1998 - 05:45:09 EDT -----BEGIN PGP SIGNED MESSAGE----- To understand your ideas better I will try to comment on them and you might possibly explain some more where I seem to be wrong.
William Allen Simpson writes:
> As I've mentioned elsewhere, in my variant of Karn code, we start from
> I was suggesting that we could store (a pointer to a pointer to) the SA
> I think this is a lot cleaner design than looking things up later in
for all sockets which have no associated SA/SPI conglomeration, for packets which have no associated socket:
At least the latter case seems to require a radix/routing table lookup. My experience with the OpenBSD code, basing the SA/SPI choice on routing tables, is that it is easy to implement in a fashion which requires minimal changes to the rest of the code. The benefit is quite a lot of flexibility. How did you implement host based SA/SPI choice? Via a conglomeration which does not get destroyed when an associated socket is killed? Using reference counters? > And remember, in this mutually hostile user scenario, as soon as the
Greetings
-----BEGIN PGP SIGNATURE-----
iQEUAwUBNV1gHjZ8FqYKL4flAQG3ywf3W9syndwBSgyMO6a6UsLW7NcCazuf0KoF
4/+vN3eOVk4mAgaA74lOWJw9KWSCERpKM3+kGrIVSW3xJwT6VVDooiWEI9rRVTda
u0Cltp/UqOw9665PJQgZzWW+hlGRlymMRSmvwSTkKS60lKIbmdxAFHWUQJKbDRJc
ggDMHNUcfzQw9oVUqhQjJ4+io6zA/M/t25m/uCAerO3rA9T4/s1B3WAAXhmVccSR
tGf6FSZzl0CBArrwlG9AkaUTHt91Mf8lMI1O93xDgsMa0Y3yKcMniUjnDU8uYwvC
oYvXNARsmOERcOIP3IMRVQWyuIJqXHiavhrtHWsq4k+PjcZzFD6N
=CVmY
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:10 EDT |
||||||||||
|
|||||||||||