diff options
author | Tobias Brunner <tobias@strongswan.org> | 2015-02-25 08:18:58 +0100 |
---|---|---|
committer | Tobias Brunner <tobias@strongswan.org> | 2015-03-04 13:47:53 +0100 |
commit | eb251906298b529fa53b8a99746a9a7a9f318dd5 (patch) | |
tree | c9acb4791db7bc62c1440f7b6c7a46043e3da142 /src/libhydra/plugins/kernel_pfkey/kernel_pfkey_ipsec.c | |
parent | 1a31fe5580e2e78b63eab16377dd81101b53316a (diff) | |
download | strongswan-eb251906298b529fa53b8a99746a9a7a9f318dd5.tar.bz2 strongswan-eb251906298b529fa53b8a99746a9a7a9f318dd5.tar.xz |
ikev2: Don't destroy the SA if an IKE_SA_INIT with unexpected MID is received
This reverts 8f727d800751 ("Clean up IKE_SA state if IKE_SA_INIT request
does not have message ID 0") because it allowed to close any IKE_SA by
sending an IKE_SA_INIT with an unexpected MID and both SPIs set to those
of that SA.
The next commit will prevent SAs from getting created for IKE_SA_INIT messages
with invalid MID.
Fixes #816.
Diffstat (limited to 'src/libhydra/plugins/kernel_pfkey/kernel_pfkey_ipsec.c')
0 files changed, 0 insertions, 0 deletions