2933 compiler warning gags need better granularityReviewed by: Eric Schrock <eric.schrock@delphix.com>Approved by: Garrett D'Amore <garrett@damore.org>
2077 lots of unreachable breaks in illumos gateReviewed by: Dan McDonald <danmcd@nexenta.com>Reviewed by: Garrett D'Amore <garrett@damore.org>Approved by: Richard Lowe <richlowe@richlowe.net>
6916796 OSnet mapfiles should use version 2 link-editor syntax--HG--rename : usr/src/cmd/sgs/libelf/common/mapfile-common => usr/src/cmd/sgs/libelf/common/mapfile-versrename : usr/src/cmd/sgs/lin
6916796 OSnet mapfiles should use version 2 link-editor syntax--HG--rename : usr/src/cmd/sgs/libelf/common/mapfile-common => usr/src/cmd/sgs/libelf/common/mapfile-versrename : usr/src/cmd/sgs/link_audit/i386/mapfile-vers-bindings => usr/src/cmd/sgs/link_audit/common/mapfile-vers-bindingsrename : usr/src/cmd/sgs/link_audit/i386/mapfile-vers-perfcnt => usr/src/cmd/sgs/link_audit/common/mapfile-vers-perfcntrename : usr/src/cmd/sgs/link_audit/i386/mapfile-vers-symbindrep => usr/src/cmd/sgs/link_audit/common/mapfile-vers-symbindreprename : usr/src/cmd/sgs/link_audit/i386/mapfile-vers-truss => usr/src/cmd/sgs/link_audit/common/mapfile-vers-trussrename : usr/src/cmd/sgs/link_audit/i386/mapfile-vers-who => usr/src/cmd/sgs/link_audit/common/mapfile-vers-whorename : usr/src/common/mapfiles/i386/map.noexdata => usr/src/common/mapfiles/common/map.noexdatarename : usr/src/lib/libaio/sparc/mapfile-vers => usr/src/lib/libaio/common/mapfile-versrename : usr/src/lib/libelfsign/common/mapfile.map => usr/src/lib/libelfsign/common/mapfile-versrename : usr/src/lib/libpthread/sparc/mapfile-vers => usr/src/lib/libpthread/common/mapfile-versrename : usr/src/lib/librt/amd64/mapfile-vers => usr/src/lib/librt/common/mapfile-versrename : usr/src/lib/libsys/sparc/mapfile-vers => usr/src/lib/libsys/common/mapfile-versrename : usr/src/lib/libthread/sparc/mapfile-vers => usr/src/lib/libthread/common/mapfile-vers
show more ...
PSARC 2010/101 in.iked preshared key file extensions6511591 Support at least remote-prefixes for preshared key entries
PSARC 2010/102 ikeadm dump algs6927650 provide the list of DH groups in ikeadm6927657 provide the list of algorithms offered by iked for IKE in ikeadm
PSARC 2010/055 ECP and RFC5114 groups for IKE6586320 RFC 4753 ECP groups needed for IKE6900895 RFC 5114 ECP Diffie-Hellman groups6897862 RFC 5114 integer modulus Diffie-Hellman groups
6874992 in.iked does not use network byte order for IP address in sendto() call6874983 ikedoor.h is not C++ safe6885833 IPsec utilities should print lifetimes in human readable format6889086 ikead
6874992 in.iked does not use network byte order for IP address in sendto() call6874983 ikedoor.h is not C++ safe6885833 IPsec utilities should print lifetimes in human readable format6889086 ikeadm reports kilobyte lifetimes with wrong units6898492 iked should enforce lower maximum values for lifetimes6897711 iked debug output should be less confusing for average sysadmin6902926 SOFT kilobyte expires for inbound SAs should make it to userland and be reacted upon
PSARC/2008/252 Labeled IPsec phase 16886771 Labeled IPsec phase 16808727 Alignment error panic in tsol_can_accept_raw()6894979 nightly -0 + -p builds then destroys SUNW0on
PSARC 2009/513 Changes to IPsec ESP to support Combined mode ciphers6704686 IPsec/ESP needs to support Combined mode ciphers6704682 IPsec/ESP should use AES-CCM6884664 IPsec/ESP should support AES
PSARC 2009/513 Changes to IPsec ESP to support Combined mode ciphers6704686 IPsec/ESP needs to support Combined mode ciphers6704682 IPsec/ESP should use AES-CCM6884664 IPsec/ESP should support AES-GCM Mode6840342 ipsecalgs out of memory error6764184 tab instead of space in sadb.h
6881623 CRYPTO_num_locks() should be used instead of CRYPTO_NUM_LOCKS
6848192 get_ipsa_pair() does not always follow bucket lock entry rules, could potentially deadlock.6846548 PF_KEY diagnostics need to be more specific6853208 ipsecalgs(1m) does not cope when there
6848192 get_ipsa_pair() does not always follow bucket lock entry rules, could potentially deadlock.6846548 PF_KEY diagnostics need to be more specific6853208 ipsecalgs(1m) does not cope when there are no algorithms registered.6856693 sadb_update_sa() checks for duplicate SADB_UPDATE messages in the wrong place.6846547 Faulty PF_KEY replies should not cause in.iked to halt
6806387 Move OpenSSL from ON to SFW
6824443 Make in.iked a 64-bit process when possible.
6520458 ikeadm should have command line history capabilities4313953 ipseckey(1m) needs line editing support.6814629 ipseckey should employ strict checking for {dump,flush} commands
6798660 Cadmium .NOT file processing problem with CWD relative file pathsContributed by Richard Lowe6785284 Mapfile versioning rules need to be more visible to gatelings6800164 Standard file exclu
6798660 Cadmium .NOT file processing problem with CWD relative file pathsContributed by Richard Lowe6785284 Mapfile versioning rules need to be more visible to gatelings6800164 Standard file exclusion mechanism needed for Cadmium tools
PSARC 2008/525 ikeadm token login6219638 in.iked(1m) should not have to read PKCS#11 pins off-disk6780866 ikeadm should use authorizations
6449514 move OpenSSL from /usr/sfw to /usr, /lib6457487 clean up Makefile for cmd/openssl6686002 move /usr/lib/libkmf and plugins to /lib - PSARC 2007/6746686004 move libcryptoutil and libelfsign
6449514 move OpenSSL from /usr/sfw to /usr, /lib6457487 clean up Makefile for cmd/openssl6686002 move /usr/lib/libkmf and plugins to /lib - PSARC 2007/6746686004 move libcryptoutil and libelfsign from /usr/lib to /lib - PSARC 2007/6746700122 cryptosvc should be able to start before filesystem/usr
PSARC 2008/523 IPsec session failover6398024 IPsec should support session failover across machines6545486 PF_KEY needs to set an SA's sequence number
6728539 64-bit version of libipsecutil
6724924 memory leak plugging subverted ASN.1 printing functionality in ikeadm/ipseckey
6719641 RFC 3947 section 7 (port-reassignment) on paired-ESP and IKE SAs on the non-NAT side.
PSARC/2008/232 Paired IPsec Security Associations6584918 in.iked will exit if you try and add a duplicate rule with ikeadm6595953 Remove SCCS keywords from ipsec{ah,esp}, keysock, and spdsock66282
PSARC/2008/232 Paired IPsec Security Associations6584918 in.iked will exit if you try and add a duplicate rule with ikeadm6595953 Remove SCCS keywords from ipsec{ah,esp}, keysock, and spdsock6628201 Inbound and Outbound IPsec SA's should be treated as a pair.6643439 check_rule() in in.iked does not sanity check kilobyte based lifetime values6668752 ikeadm(1m) get defaults displays wrong value for p2_softlife_kb6669211 Need a way to disable Soft Expires when using in.iked(1m)6670612 sadb_address_proto and sadb_address_prefixlen need to be initialized in NAT_T extensions.6674203 Ordering of src/dst address extensions in pf_key messages is inconsistent.6676436 ipseckey(1m) error messages could be less cryptic6683004 Updating hard_usetime on an IPsec SA will cause it to evaporate.6703265 in.iked can dump core if avl_nearest() returns NULL
6699935 memory leak in print_asn1_name()
PSARC 2008/014 SHA-2 support for IPsec and IKE6586319 Need to enable SHA-256,384,512 support in AH, ESP, and IKE6663271 sha2_mac_verify_atomic() function is missing SHA384 exceptions
6658263 ipseckey and ikeadm don't print ASN.1 ID values
12