Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: [Users] ANNOUNCE: strongswan-2.0.0 released

From: Andreas Steffen <andreas.steffen(at)strongsec.net>
Date: Fri Mar 19 2004 - 05:40:02 EST

The IKE/ISAKMP RFCs define a standardized set of error messages which can be sent to the peer in order to notify her/him of problems that occurred. Openswan contains the Notify patch coded by Mathieu Lafon, but error messages which are produced during Main Mode negotiation are usually not accepted, either because they are already encrypted or not yet encrypted. This generates very misleading warnings which are interpreted by most users as errors that occured on the own side, although the actual cause lies on the peer side.

My correction applies encryption to Notify messages as soon as the Diffie-Hellman secret becomes available and such messages will be accepted by the peer although he might not yet have reached the end of main mode. (This behaviour is in full compliance with the RFCs.

Regards

Andreas

  John P Santos wrote:

> Another question, what is this "Notification" that strongswan does that
> openswan does not?


Andreas Steffen                   e-mail: andreas.steffen@strongsec.com
strongSec GmbH                    home:   
http://www.strongsec.com
Alter Zürichweg 20                phone:  +41 1 730 80 64
CH-8952 Schlieren (Switzerland) fax: +41 1 730 80 65
==========================================[strong internet security]===

Content Security by MailMarshal



FreeS/WAN Users mailing list
users@lists.freeswan.org
https://mj2.freeswan.org/cgi-bin/mj_wwwusr Received on Fri Mar 19 08:54:14 2004
Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:02:21 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library