Re: Minor IPSec bug + solution

From: Herbert Xu
Date: Mon Sep 20 2004 - 06:07:31 EST


On Mon, Sep 20, 2004 at 09:49:49AM +0200, Martin Bouzek wrote:
>
> Ok. And would it be possible to check the protocols too (eg.
> tmpl->id.proto == x->id.proto)? If it is realy not possible to make the

Obviously not, since IPCOMP != IPIP.

> IPComp/required tunnel to work, it would be nice to mention it in for
> example the setkey man page. It could save quite lot of time to some
> people. (like me :-) ).

IPComp is the main reason why we have optional SAs at all. So
IPComp/required definitely does not make sense.

As to the documentation of this issue, feel free to write something up
and send it to either the kernel maintainers or one of the user-space
projects.

Cheers,
--
Visit Openswan at http://www.openswan.org/
Email: Herbert Xu ~{PmV>HI~} <herbert@xxxxxxxxxxxxxxxxxxx>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/