Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: linux-ipsec: to be or not to be, that is the config question

From: Henry Spencer <henry(at)spsystems.net>
Date: Mon Jun 22 1998 - 11:48:45 EDT


> > Given that we now have klipsdebug to turn debugging on and off, is there

Verbosity differences should probably be under the control of klipsdebug. If it's useful to adjust it at all, it's useful to be able to adjust it at run time.

It seems to me that speed is not a significant issue if the only overhead (when debugging is switched off) is checking a flag now and then. Only if some of the flag checks are inside tight inner loops (seems unlikely), or if there is significant debug code which is run without a flag check, is there really a speed issue. If (as is usually the case) hundreds of other operations are done between flag checks, the speed price is so small that it's well worth paying. (There are always people who grudge even a fraction of a percent in overhead, but they're already used to having to custom-build their systems.)

Code size is more of an issue, especially since Linux has some limits in this area. But numbers matter. RGB, can you compare size with debugging on and off? (Or commit the compile fix and I can do that.)

> I don't think a separate option for each transform is all that useful, but

Yes, I should have mentioned that -- I agree that it's worth making the experimental/out-of-date stuff optional.

> In addition,
> we may want a switch for minimal IPSEC conformance transform inclusion.

This is the area where I hesitate. I can see a possibility of ending up with a bunch of different switches for different situations, each of which turns on a different combination of transforms, and it's not clear to me that that's really an improvement, especially since there will always be requests for just one more combination. It might be better to leave in the switches for individual transforms, but have them all default to on (subject to the experimental/out-of-date switch) and just tell people "it shouldn't normally be necessary to mess with those switches, they are present to cover special needs".

Do you need help?X

I'd appreciate feedback from other folks on this list -- potential users! -- who might have some idea of how much they'd want to customize things like the set of available transforms.

                                                          Henry Spencer
                                                       henry@spsystems.net
                                                     (henry@zoo.toronto.edu)
Received on Mon Jun 22 12:25:54 1998

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:22 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library