<feed xmlns='http://www.w3.org/2005/Atom'>
<title>tteras/strongswan/src/libcharon/plugins/kernel_pfkey, branch master</title>
<subtitle>tteras' strongSwan tree
</subtitle>
<link rel='alternate' type='text/html' href='https://git-old.alpinelinux.org/user/tteras/strongswan/'/>
<entry>
<title>kernel-pfkey: Support anti-replay windows &gt; 2k</title>
<updated>2017-11-08T15:35:38+00:00</updated>
<author>
<name>Tobias Brunner</name>
<email>tobias@strongswan.org</email>
</author>
<published>2017-11-07T13:26:14+00:00</published>
<link rel='alternate' type='text/html' href='https://git-old.alpinelinux.org/user/tteras/strongswan/commit/?id=88a8fba1c76eda1c39dce4d0b2038c760f6d6140'/>
<id>88a8fba1c76eda1c39dce4d0b2038c760f6d6140</id>
<content type='text'>
FreeBSD 11.1 supports a new extension to configure larger anti-replay
windows, now configured as number of packets.

Fixes #2461.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
FreeBSD 11.1 supports a new extension to configure larger anti-replay
windows, now configured as number of packets.

Fixes #2461.
</pre>
</div>
</content>
</entry>
<entry>
<title>kernel-pfkey: Don't include keys in SADB_UPDATE message to update IPs on FreeBSD</title>
<updated>2017-11-08T15:34:12+00:00</updated>
<author>
<name>Tobias Brunner</name>
<email>tobias@strongswan.org</email>
</author>
<published>2017-11-03T08:37:44+00:00</published>
<link rel='alternate' type='text/html' href='https://git-old.alpinelinux.org/user/tteras/strongswan/commit/?id=21a500a092e4a2a0f91118846fede5f445d59d31'/>
<id>21a500a092e4a2a0f91118846fede5f445d59d31</id>
<content type='text'>
The FreeBSD kernel explicitly rejects messages containing keys for mature SAs.

Fixes #2457.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
The FreeBSD kernel explicitly rejects messages containing keys for mature SAs.

Fixes #2457.
</pre>
</div>
</content>
</entry>
<entry>
<title>linked-list: Change return value of find_first() and signature of its callback</title>
<updated>2017-05-26T11:56:44+00:00</updated>
<author>
<name>Tobias Brunner</name>
<email>tobias@strongswan.org</email>
</author>
<published>2017-05-16T10:11:24+00:00</published>
<link rel='alternate' type='text/html' href='https://git-old.alpinelinux.org/user/tteras/strongswan/commit/?id=2e4d110d1e94a3be9da06894832492ff469eec37'/>
<id>2e4d110d1e94a3be9da06894832492ff469eec37</id>
<content type='text'>
This avoids the unportable five pointer hack.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
This avoids the unportable five pointer hack.
</pre>
</div>
</content>
</entry>
<entry>
<title>linked-list: Change interface of callback for invoke_function()</title>
<updated>2017-05-26T11:56:44+00:00</updated>
<author>
<name>Tobias Brunner</name>
<email>tobias@strongswan.org</email>
</author>
<published>2017-05-15T15:51:19+00:00</published>
<link rel='alternate' type='text/html' href='https://git-old.alpinelinux.org/user/tteras/strongswan/commit/?id=8a2e4d4a8b87f5e8a5e5f663ee8eddd47988fa2c'/>
<id>8a2e4d4a8b87f5e8a5e5f663ee8eddd47988fa2c</id>
<content type='text'>
This avoids the unportable five pointer hack.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
This avoids the unportable five pointer hack.
</pre>
</div>
</content>
</entry>
<entry>
<title>kernel-pfkey: Update SA addresses if supported by the kernel</title>
<updated>2017-05-23T15:58:50+00:00</updated>
<author>
<name>Tobias Brunner</name>
<email>tobias@strongswan.org</email>
</author>
<published>2017-02-07T08:57:09+00:00</published>
<link rel='alternate' type='text/html' href='https://git-old.alpinelinux.org/user/tteras/strongswan/commit/?id=bf08e39441f54466078ca81802a7482b3e8f91a2'/>
<id>bf08e39441f54466078ca81802a7482b3e8f91a2</id>
<content type='text'>
Upcoming FreeBSD kernels will support updating the addresses of existing
SAs with new SADB_X_EXT_NEW_ADDRESS_SRC|DST extensions for the SADB_UPDATE
message.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Upcoming FreeBSD kernels will support updating the addresses of existing
SAs with new SADB_X_EXT_NEW_ADDRESS_SRC|DST extensions for the SADB_UPDATE
message.
</pre>
</div>
</content>
</entry>
<entry>
<title>kernel-pfkey: Use new encap flag on Mac OS X when updating SAs</title>
<updated>2017-05-23T15:58:50+00:00</updated>
<author>
<name>Tobias Brunner</name>
<email>tobias@strongswan.org</email>
</author>
<published>2017-02-07T08:55:50+00:00</published>
<link rel='alternate' type='text/html' href='https://git-old.alpinelinux.org/user/tteras/strongswan/commit/?id=a080cfece0c19cd73ce731b124d68a601b34867e'/>
<id>a080cfece0c19cd73ce731b124d68a601b34867e</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>kernel: Make range of SPIs for IPsec SAs configurable</title>
<updated>2017-03-02T07:52:56+00:00</updated>
<author>
<name>Tobias Brunner</name>
<email>tobias@strongswan.org</email>
</author>
<published>2017-02-21T18:21:01+00:00</published>
<link rel='alternate' type='text/html' href='https://git-old.alpinelinux.org/user/tteras/strongswan/commit/?id=6d86d0f51699612ad886b3f1b8773e81324e3b2a'/>
<id>6d86d0f51699612ad886b3f1b8773e81324e3b2a</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>kernel-pfkey: Use the same priority range for trap and regular policies</title>
<updated>2017-02-08T09:36:38+00:00</updated>
<author>
<name>Tobias Brunner</name>
<email>tobias@strongswan.org</email>
</author>
<published>2016-10-11T13:14:27+00:00</published>
<link rel='alternate' type='text/html' href='https://git-old.alpinelinux.org/user/tteras/strongswan/commit/?id=3c46ce283404c6336f36a69a4842ab837db23d66'/>
<id>3c46ce283404c6336f36a69a4842ab837db23d66</id>
<content type='text'>
Same as the change in the kernel-netlink plugin.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Same as the change in the kernel-netlink plugin.
</pre>
</div>
</content>
</entry>
<entry>
<title>kernel-pfkey: Set state to SADB_SASTATE_MATURE when adding/updating SAs</title>
<updated>2017-01-25T16:30:57+00:00</updated>
<author>
<name>Tobias Brunner</name>
<email>tobias@strongswan.org</email>
</author>
<published>2017-01-16T16:01:33+00:00</published>
<link rel='alternate' type='text/html' href='https://git-old.alpinelinux.org/user/tteras/strongswan/commit/?id=4ae2209e3d26c48932760ef048f7078c0e2edb1e'/>
<id>4ae2209e3d26c48932760ef048f7078c0e2edb1e</id>
<content type='text'>
Picky kernels might otherwise reject our messages as RFC 2367 explicitly
mandates this.

Fixes #2212.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Picky kernels might otherwise reject our messages as RFC 2367 explicitly
mandates this.

Fixes #2212.
</pre>
</div>
</content>
</entry>
<entry>
<title>kernel-pfkey: Only set the replay window for inbound SAs</title>
<updated>2016-06-17T16:46:33+00:00</updated>
<author>
<name>Tobias Brunner</name>
<email>tobias@strongswan.org</email>
</author>
<published>2016-06-17T12:52:11+00:00</published>
<link rel='alternate' type='text/html' href='https://git-old.alpinelinux.org/user/tteras/strongswan/commit/?id=21aa924233b5e0d53ce454d63e98f92714a2081e'/>
<id>21aa924233b5e0d53ce454d63e98f92714a2081e</id>
<content type='text'>
It is not necessary for outbound SAs and might waste memory when large
window sizes are used.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
It is not necessary for outbound SAs and might waste memory when large
window sizes are used.
</pre>
</div>
</content>
</entry>
</feed>
