aboutsummaryrefslogtreecommitdiffstats
path: root/linux/README.freeswan
blob: 7d868e4cb2313bd2898d4bd949e6bf4b53983191 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
*
* RCSID $Id: README.freeswan,v 1.1 2004/03/15 20:35:25 as Exp $
*

               ****************************************
               * IPSEC for Linux, Release 2.xx series *
               ****************************************



1. Files

The contents of linux/net/ipsec/ (see below) join the linux kernel source tree.
as provided for higher up.

The programs/ directory contains the user-level utilities which you need
to run IPSEC.  See the top-level top/INSTALL to compile and install them.

The test/ directory contains test scripts.

The doc/ directory contains -- what else -- documentation. 

1.1. Kernel files

The following are found in net/ipsec/:

Makefile			The Makefile
Config.in			The configuration script for make menuconfig
defconfig			Configuration defaults for first time.

radij.c				General-purpose radix-tree operations

ipcomp.c			IPCOMP interface code.

pfkey_v2.c			PF_KEYv2 socket interface code.
pfkey_v2_parser.c		PF_KEYv2 message parsing and processing code.

ipsec_init.c			Initialization code, /proc interface.
ipsec_radij.c			Interface with the radix tree code.
ipsec_netlink.c			Interface with the netlink code.
ipsec_xform.c			Routines and structures common to transforms.
ipsec_tunnel.c			The outgoing packet processing code.
ipsec_rcv.c			The incoming packet processing code.
ipsec_md5c.c			Somewhat modified RSADSI MD5 C code.
ipsec_sha1.c			Somewhat modified Steve Reid SHA-1 C code.

sysctl_net_ipsec.c		/proc/sys/net/ipsec/* variable definitions.

version.c			symbolic link to project version.

radij.h				Headers for radij.c

ipcomp.h			Headers used by IPCOMP code.

ipsec_radij.h			Interface with the radix tree code.
ipsec_netlink.h			Headers used by the netlink interface.
ipsec_encap.h			Headers defining encapsulation structures.
ipsec_xform.h			Transform headers.
ipsec_tunnel.h			Headers used by tunneling code.
ipsec_ipe4.h			Headers for the IP-in-IP code.
ipsec_ah.h			Headers common to AH transforms.
ipsec_md5h.h			RSADSI MD5 headers.
ipsec_sha1.h			SHA-1 headers.
ipsec_esp.h			Headers common to ESP transfroms.
ipsec_rcv.h			Headers for incoming packet processing code.

1.2. User-level files.

The following are found in utils/:

eroute.c	Create an "extended route" source code
spi.c		Set up Security Associations source code
spigrp.c        Link SPIs together source code.
tncfg.c         Configure the tunneling features of the virtual interface
		source code
klipsdebug.c	Set/reset klips debugging features source code.
version.c	symbolic link to project version.

eroute.8	Create an "extended route" manual page
spi.8		Set up Security Associations manual page
spigrp.8        Link SPIs together manual page
tncfg.8         Configure the tunneling features of the virtual interface
		manual page
klipsdebug.8	Set/reset klips debugging features manual page

eroute.5	/proc/net/ipsec_eroute format manual page
spi.5		/proc/net/ipsec_spi format manual page
spigrp.5	/proc/net/ipsec_spigrp format manual page
tncfg.5		/proc/net/ipsec_tncfg format manual page
klipsdebug.5	/proc/net/ipsec_klipsdebug format manual page
version.5	/proc/net/ipsec_version format manual page
pf_key.5	/proc/net/pf_key format manual page

Makefile	Utilities makefile.

*.8		Manpages for the respective utils.


1.3. Test files

The test scripts are locate in testing/ and and documentation is found
at doc/src/umltesting.html. Automated testing via "make check" is available
provided that the User-Mode-Linux patches are available.

*
* $Log: README.freeswan,v $
* Revision 1.1  2004/03/15 20:35:25  as
* added files from freeswan-2.04-x509-1.5.3
*
* Revision 1.11  2002/07/28 23:00:14  mcr
* 	removed docs on "test" directory.
* 	some slight "updates"
*
* Revision 1.10  2002/05/06 21:34:19  mcr
* Moved from linux/README,v
*
* Revision 1.9  2002/04/24 07:36:35  mcr
* Moved from ./klips/README,v
*
* Revision 1.8  2000/11/06 05:42:58  rgb
* Updated file list (had not been done in 2 years?).
*
* Revision 1.7  2000/08/21 17:30:09  rgb
* Remove any references to src/.
*
* Revision 1.6  1999/04/06 04:54:22  rgb
* Fix/Add RCSID Id: and Log: bits to make PHMDs happy.  This includes
* patch shell fixes.
*
* Revision 1.5  1998/11/25 04:54:34  rgb
* Updated files section to include newer transforms and other files.
*
* Revision 1.4  1998/05/01 03:47:17  rgb
* Minor cleanup of utils filenames overlooked in major overhaul.
*
* Revision 1.3  1998/05/01 03:40:31  rgb
* Major overhaul.
* Removed install/initialise section with pointers to top-level INSTALL.txt.
* Updated filelists and providing descriptions of all files.
* Removed usage example and moved it to doc/*_setup.txt.
*
* Revision 1.2  1998/04/09 03:01:13  henry
* INSTALL.txt moves up, loses its installation instructions, and turns
* into the klips README.
*
* Revision 1.1.1.1  1998/04/08 05:35:13  henry
* RGB's ipsec-0.8pre2.tar.gz ipsec-0.8
*
*
* Revision 0.7  rgb
* Cleaned up several transmission bugs.
*
* Revision 0.6  1997/09?  ak
* Hooked in esp des-md5-96.
* Added copyrights.
* 
* Revision 0.5  1997/06/03 04:28:46  ji
* Added transport mode.
* Added esp 3des-md5-96.
*
* Revision 0.4  1997/01/14 21:35:31  ji
* Added new transforms.
* Cleaned up the user-level programs.
*
* Revision 0.3  1996/11/20 11:59:33  ji
* *** empty log message ***
*
*
* New in this release (0.3; works with the 2.0.24 kernel)
*
*   > Cleaned up a fair amount of crud.
*   > Fixed truncated names of /proc/net entries.
*   > Made RCS versioning visible to the external release.
*   > Rationalized debugging facilities.
*   > Rationalized untar directory structure.
*   > Fixed non-incrementing IV in DES-CBC
*   > Cleaned up this file a bit and provided additional examples