<feed xmlns='http://www.w3.org/2005/Atom'>
<title>tteras/strongswan/src/libcharon/plugins/kernel_pfkey, branch master</title>
<subtitle>tteras' strongSwan tree
</subtitle>
<id>https://git-old.alpinelinux.org/user/tteras/strongswan/atom?h=master</id>
<link rel='self' href='https://git-old.alpinelinux.org/user/tteras/strongswan/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git-old.alpinelinux.org/user/tteras/strongswan/'/>
<updated>2017-11-08T15:35:38Z</updated>
<entry>
<title>kernel-pfkey: Support anti-replay windows &gt; 2k</title>
<updated>2017-11-08T15:35:38Z</updated>
<author>
<name>Tobias Brunner</name>
<email>tobias@strongswan.org</email>
</author>
<published>2017-11-07T13:26:14Z</published>
<link rel='alternate' type='text/html' href='https://git-old.alpinelinux.org/user/tteras/strongswan/commit/?id=88a8fba1c76eda1c39dce4d0b2038c760f6d6140'/>
<id>urn:sha1:88a8fba1c76eda1c39dce4d0b2038c760f6d6140</id>
<content type='text'>
FreeBSD 11.1 supports a new extension to configure larger anti-replay
windows, now configured as number of packets.

Fixes #2461.
</content>
</entry>
<entry>
<title>kernel-pfkey: Don't include keys in SADB_UPDATE message to update IPs on FreeBSD</title>
<updated>2017-11-08T15:34:12Z</updated>
<author>
<name>Tobias Brunner</name>
<email>tobias@strongswan.org</email>
</author>
<published>2017-11-03T08:37:44Z</published>
<link rel='alternate' type='text/html' href='https://git-old.alpinelinux.org/user/tteras/strongswan/commit/?id=21a500a092e4a2a0f91118846fede5f445d59d31'/>
<id>urn:sha1:21a500a092e4a2a0f91118846fede5f445d59d31</id>
<content type='text'>
The FreeBSD kernel explicitly rejects messages containing keys for mature SAs.

Fixes #2457.
</content>
</entry>
<entry>
<title>linked-list: Change return value of find_first() and signature of its callback</title>
<updated>2017-05-26T11:56:44Z</updated>
<author>
<name>Tobias Brunner</name>
<email>tobias@strongswan.org</email>
</author>
<published>2017-05-16T10:11:24Z</published>
<link rel='alternate' type='text/html' href='https://git-old.alpinelinux.org/user/tteras/strongswan/commit/?id=2e4d110d1e94a3be9da06894832492ff469eec37'/>
<id>urn:sha1:2e4d110d1e94a3be9da06894832492ff469eec37</id>
<content type='text'>
This avoids the unportable five pointer hack.
</content>
</entry>
<entry>
<title>linked-list: Change interface of callback for invoke_function()</title>
<updated>2017-05-26T11:56:44Z</updated>
<author>
<name>Tobias Brunner</name>
<email>tobias@strongswan.org</email>
</author>
<published>2017-05-15T15:51:19Z</published>
<link rel='alternate' type='text/html' href='https://git-old.alpinelinux.org/user/tteras/strongswan/commit/?id=8a2e4d4a8b87f5e8a5e5f663ee8eddd47988fa2c'/>
<id>urn:sha1:8a2e4d4a8b87f5e8a5e5f663ee8eddd47988fa2c</id>
<content type='text'>
This avoids the unportable five pointer hack.
</content>
</entry>
<entry>
<title>kernel-pfkey: Update SA addresses if supported by the kernel</title>
<updated>2017-05-23T15:58:50Z</updated>
<author>
<name>Tobias Brunner</name>
<email>tobias@strongswan.org</email>
</author>
<published>2017-02-07T08:57:09Z</published>
<link rel='alternate' type='text/html' href='https://git-old.alpinelinux.org/user/tteras/strongswan/commit/?id=bf08e39441f54466078ca81802a7482b3e8f91a2'/>
<id>urn:sha1:bf08e39441f54466078ca81802a7482b3e8f91a2</id>
<content type='text'>
Upcoming FreeBSD kernels will support updating the addresses of existing
SAs with new SADB_X_EXT_NEW_ADDRESS_SRC|DST extensions for the SADB_UPDATE
message.
</content>
</entry>
<entry>
<title>kernel-pfkey: Use new encap flag on Mac OS X when updating SAs</title>
<updated>2017-05-23T15:58:50Z</updated>
<author>
<name>Tobias Brunner</name>
<email>tobias@strongswan.org</email>
</author>
<published>2017-02-07T08:55:50Z</published>
<link rel='alternate' type='text/html' href='https://git-old.alpinelinux.org/user/tteras/strongswan/commit/?id=a080cfece0c19cd73ce731b124d68a601b34867e'/>
<id>urn:sha1:a080cfece0c19cd73ce731b124d68a601b34867e</id>
<content type='text'>
</content>
</entry>
<entry>
<title>kernel: Make range of SPIs for IPsec SAs configurable</title>
<updated>2017-03-02T07:52:56Z</updated>
<author>
<name>Tobias Brunner</name>
<email>tobias@strongswan.org</email>
</author>
<published>2017-02-21T18:21:01Z</published>
<link rel='alternate' type='text/html' href='https://git-old.alpinelinux.org/user/tteras/strongswan/commit/?id=6d86d0f51699612ad886b3f1b8773e81324e3b2a'/>
<id>urn:sha1:6d86d0f51699612ad886b3f1b8773e81324e3b2a</id>
<content type='text'>
</content>
</entry>
<entry>
<title>kernel-pfkey: Use the same priority range for trap and regular policies</title>
<updated>2017-02-08T09:36:38Z</updated>
<author>
<name>Tobias Brunner</name>
<email>tobias@strongswan.org</email>
</author>
<published>2016-10-11T13:14:27Z</published>
<link rel='alternate' type='text/html' href='https://git-old.alpinelinux.org/user/tteras/strongswan/commit/?id=3c46ce283404c6336f36a69a4842ab837db23d66'/>
<id>urn:sha1:3c46ce283404c6336f36a69a4842ab837db23d66</id>
<content type='text'>
Same as the change in the kernel-netlink plugin.
</content>
</entry>
<entry>
<title>kernel-pfkey: Set state to SADB_SASTATE_MATURE when adding/updating SAs</title>
<updated>2017-01-25T16:30:57Z</updated>
<author>
<name>Tobias Brunner</name>
<email>tobias@strongswan.org</email>
</author>
<published>2017-01-16T16:01:33Z</published>
<link rel='alternate' type='text/html' href='https://git-old.alpinelinux.org/user/tteras/strongswan/commit/?id=4ae2209e3d26c48932760ef048f7078c0e2edb1e'/>
<id>urn:sha1:4ae2209e3d26c48932760ef048f7078c0e2edb1e</id>
<content type='text'>
Picky kernels might otherwise reject our messages as RFC 2367 explicitly
mandates this.

Fixes #2212.
</content>
</entry>
<entry>
<title>kernel-pfkey: Only set the replay window for inbound SAs</title>
<updated>2016-06-17T16:46:33Z</updated>
<author>
<name>Tobias Brunner</name>
<email>tobias@strongswan.org</email>
</author>
<published>2016-06-17T12:52:11Z</published>
<link rel='alternate' type='text/html' href='https://git-old.alpinelinux.org/user/tteras/strongswan/commit/?id=21aa924233b5e0d53ce454d63e98f92714a2081e'/>
<id>urn:sha1:21aa924233b5e0d53ce454d63e98f92714a2081e</id>
<content type='text'>
It is not necessary for outbound SAs and might waste memory when large
window sizes are used.
</content>
</entry>
</feed>
