|
|||||||||||
|
Re: [Users] ANNOUNCE: strongswan-2.0.0 released
From: Andreas Steffen <andreas.steffen(at)strongsec.net>
Date: Fri Mar 19 2004 - 05:40:02 EST The IKE/ISAKMP RFCs define a standardized set of error messages which can be sent to the peer in order to notify her/him of problems that occurred. Openswan contains the Notify patch coded by Mathieu Lafon, but error messages which are produced during Main Mode negotiation are usually not accepted, either because they are already encrypted or not yet encrypted. This generates very misleading warnings which are interpreted by most users as errors that occured on the own side, although the actual cause lies on the peer side. My correction applies encryption to Notify messages as soon as the Diffie-Hellman secret becomes available and such messages will be accepted by the peer although he might not yet have reached the end of main mode. (This behaviour is in full compliance with the RFCs. Regards Andreas John P Santos wrote:
> Another question, what is this "Notification" that strongswan does that
Andreas Steffen e-mail: andreas.steffen@strongsec.com strongSec GmbH home: http://www.strongsec.com Alter Zürichweg 20 phone: +41 1 730 80 64CH-8952 Schlieren (Switzerland) fax: +41 1 730 80 65 ==========================================[strong internet security]=== Content Security by MailMarshal FreeS/WAN Users mailing list users@lists.freeswan.org https://mj2.freeswan.org/cgi-bin/mj_wwwusr Received on Fri Mar 19 08:54:14 2004 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:02:21 EDT |
||||||||||
|
|||||||||||