6881623 CRYPTO_num_locks() should be used instead of CRYPTO_NUM_LOCKS
6848192 get_ipsa_pair() does not always follow bucket lock entry rules, could potentially deadlock.6846548 PF_KEY diagnostics need to be more specific6853208 ipsecalgs(1m) does not cope when there
6848192 get_ipsa_pair() does not always follow bucket lock entry rules, could potentially deadlock.6846548 PF_KEY diagnostics need to be more specific6853208 ipsecalgs(1m) does not cope when there are no algorithms registered.6856693 sadb_update_sa() checks for duplicate SADB_UPDATE messages in the wrong place.6846547 Faulty PF_KEY replies should not cause in.iked to halt
show more ...
6806387 Move OpenSSL from ON to SFW
6824443 Make in.iked a 64-bit process when possible.
6520458 ikeadm should have command line history capabilities4313953 ipseckey(1m) needs line editing support.6814629 ipseckey should employ strict checking for {dump,flush} commands
6798660 Cadmium .NOT file processing problem with CWD relative file pathsContributed by Richard Lowe6785284 Mapfile versioning rules need to be more visible to gatelings6800164 Standard file exclu
6798660 Cadmium .NOT file processing problem with CWD relative file pathsContributed by Richard Lowe6785284 Mapfile versioning rules need to be more visible to gatelings6800164 Standard file exclusion mechanism needed for Cadmium tools
PSARC 2008/525 ikeadm token login6219638 in.iked(1m) should not have to read PKCS#11 pins off-disk6780866 ikeadm should use authorizations
6449514 move OpenSSL from /usr/sfw to /usr, /lib6457487 clean up Makefile for cmd/openssl6686002 move /usr/lib/libkmf and plugins to /lib - PSARC 2007/6746686004 move libcryptoutil and libelfsign
6449514 move OpenSSL from /usr/sfw to /usr, /lib6457487 clean up Makefile for cmd/openssl6686002 move /usr/lib/libkmf and plugins to /lib - PSARC 2007/6746686004 move libcryptoutil and libelfsign from /usr/lib to /lib - PSARC 2007/6746700122 cryptosvc should be able to start before filesystem/usr
PSARC 2008/523 IPsec session failover6398024 IPsec should support session failover across machines6545486 PF_KEY needs to set an SA's sequence number
6728539 64-bit version of libipsecutil
6724924 memory leak plugging subverted ASN.1 printing functionality in ikeadm/ipseckey
6719641 RFC 3947 section 7 (port-reassignment) on paired-ESP and IKE SAs on the non-NAT side.
PSARC/2008/232 Paired IPsec Security Associations6584918 in.iked will exit if you try and add a duplicate rule with ikeadm6595953 Remove SCCS keywords from ipsec{ah,esp}, keysock, and spdsock66282
PSARC/2008/232 Paired IPsec Security Associations6584918 in.iked will exit if you try and add a duplicate rule with ikeadm6595953 Remove SCCS keywords from ipsec{ah,esp}, keysock, and spdsock6628201 Inbound and Outbound IPsec SA's should be treated as a pair.6643439 check_rule() in in.iked does not sanity check kilobyte based lifetime values6668752 ikeadm(1m) get defaults displays wrong value for p2_softlife_kb6669211 Need a way to disable Soft Expires when using in.iked(1m)6670612 sadb_address_proto and sadb_address_prefixlen need to be initialized in NAT_T extensions.6674203 Ordering of src/dst address extensions in pf_key messages is inconsistent.6676436 ipseckey(1m) error messages could be less cryptic6683004 Updating hard_usetime on an IPsec SA will cause it to evaporate.6703265 in.iked can dump core if avl_nearest() returns NULL
6699935 memory leak in print_asn1_name()
PSARC 2008/014 SHA-2 support for IPsec and IKE6586319 Need to enable SHA-256,384,512 support in AH, ESP, and IKE6663271 sha2_mac_verify_atomic() function is missing SHA384 exceptions
6658263 ipseckey and ikeadm don't print ASN.1 ID values
6653436 iked should be more resilient to ipsecalgs contents
5053475 certlib_load() error messages need improving.6614180 file permissions on public keys and CRLs should be more open6614741 keying material with insecure permissions should not be trusted
6516622 ACQUIRE-specified lifetimes are now ignored by in.iked6609988 superfluous debugging in isakmp_udp.c6612767 Logfile time stamp for in.iked a bit OTT6612771 Some in.iked messages contain inf
6516622 ACQUIRE-specified lifetimes are now ignored by in.iked6609988 superfluous debugging in isakmp_udp.c6612767 Logfile time stamp for in.iked a bit OTT6612771 Some in.iked messages contain information thats no longer useful
PSARC 2007/449 Detangle IPsec NAT Traversal6481450 nattymod calls putnext() on a freed queue.6558864 remove nattymod6558870 Implement SA last-used time and idle actions6582318 "mandatory" is spel
PSARC 2007/449 Detangle IPsec NAT Traversal6481450 nattymod calls putnext() on a freed queue.6558864 remove nattymod6558870 Implement SA last-used time and idle actions6582318 "mandatory" is spelled wrong in pfiles6584011 save_assoc() gets confused w.r.t. "proto".6588015 Missing "encap udp" must be better diagnosed by ipseckey(1M).6595368 Need "ipsec-nat-t" in /etc/services6595877 ipseckey(1M) can produce output it can't read back in (line-too-big)--HG--rename : usr/src/uts/common/inet/ip/nattymod.c => deleted_files/usr/src/uts/common/inet/ip/nattymod.crename : usr/src/uts/intel/nattymod/Makefile => deleted_files/usr/src/uts/intel/nattymod/Makefilerename : usr/src/uts/sparc/nattymod/Makefile => deleted_files/usr/src/uts/sparc/nattymod/Makefile
PSARC/2006/662 Make err/warn part of Solaris's libc6495220 add err() et al. to libc--HG--rename : usr/src/lib/libipsecutil/common/err.h => usr/src/head/err.hrename : usr/src/lib/libipsecutil/com
PSARC/2006/662 Make err/warn part of Solaris's libc6495220 add err() et al. to libc--HG--rename : usr/src/lib/libipsecutil/common/err.h => usr/src/head/err.hrename : usr/src/lib/libipsecutil/common/err.c => usr/src/lib/libc/port/gen/err.c
6585305 in.iked in debug mode needs to show phase 2 alg proposals and PF_KEY message contents
6576171 ipsec_kmc_map file processing is broken
PSARC/2007/409 RFC 3526 Diffie-Hellman groups for IKE4886779 RFC 3526 Diffie-Hellman groups for IKE
6561665 ipseckey -f does not understand "flush" keyword anymore
123