diff options
author | Tobias Brunner <tobias@strongswan.org> | 2016-03-10 11:46:44 +0100 |
---|---|---|
committer | Tobias Brunner <tobias@strongswan.org> | 2016-03-10 11:46:44 +0100 |
commit | b4337c5b027871d6bb076b85d9a8699f86a74fa6 (patch) | |
tree | 9d3cf491012ee2cce5426c219e9f07d187316f3f | |
parent | dc57c1b81787d726d57f3e6c8f3c907876ef2fa5 (diff) | |
download | strongswan-b4337c5b027871d6bb076b85d9a8699f86a74fa6.tar.bz2 strongswan-b4337c5b027871d6bb076b85d9a8699f86a74fa6.tar.xz |
NEWS: Added note on online revocation checks during make-before-break reauthentication
-rw-r--r-- | NEWS | 9 |
1 files changed, 9 insertions, 0 deletions
@@ -11,6 +11,15 @@ strongswan-5.4.0 constraints against IKEv2 authentication in rightauth, which allows the use of different signature schemes for trustchain verification and authentication. +- The initiator of an IKEv2 make-before-break reauthentication now suspends + online certificate revocation checks (OCSP, CRLs) until the new IKE_SA and all + CHILD_SAs are established. This is required if the checks are done over the + CHILD_SA established with the new IKE_SA. This is not possible until the + initiator installs this SA and that only happens after the authentication is + completed successfully. So we suspend the checks during the reauthentication + and do them afterwards, if they fail the IKE_SA is closed. This change has no + effect on the behavior during the authentication of the initial IKE_SA. + - For the vici plugin a Vici:Session Perl CPAN module has been added to allow Perl applications to control and/or monitor the IKE daemon using the VICI interface, similar to the existing Python egg or Ruby gem. |