<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="/source/rss.xsl.xml"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
    <title>Changes in ipseckey.c</title>
    <description></description>
    <language>en</language>
    <copyright>Copyright 2015</copyright>
    <generator>Java</generator><item>
        <title>f02131e024f67c2f5ecda4e85e852a0edb3cea0a - 6945640 ipseckey won&apos;t create SA between ipv6 link-local and multicast address; dumps core instead</title>
        <link>http://kernelsources.org:8080/source/history/titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c#f02131e024f67c2f5ecda4e85e852a0edb3cea0a</link>
        <description>6945640 ipseckey won&apos;t create SA between ipv6 link-local and multicast address; dumps core instead6949084 pfp_delete_rule() has use-after-free problem

            List of files:
            /titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c</description>
        <pubDate>Mon, 21 Jun 2010 09:53:32 +0200</pubDate>
        <dc:creator>Vladimir Kotal &lt;Vladimir.Kotal@Sun.COM&gt;</dc:creator>
    </item>
<item>
        <title>df8eb1c6f8abc69ad7de0e40e0ea573eb3000b0b - 6913939 &apos;ipseckey get esp inbound&apos; cores</title>
        <link>http://kernelsources.org:8080/source/history/titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c#df8eb1c6f8abc69ad7de0e40e0ea573eb3000b0b</link>
        <description>6913939 &apos;ipseckey get esp inbound&apos; cores

            List of files:
            /titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c</description>
        <pubDate>Thu, 07 Jan 2010 23:36:11 +0100</pubDate>
        <dc:creator>Vladimir Kotal &lt;Vladimir.Kotal@Sun.COM&gt;</dc:creator>
    </item>
<item>
        <title>510c3f914054fe5a373967f2397b3d61a91c5bb9 - 6874992 in.iked does not use network byte order for IP address in sendto() call</title>
        <link>http://kernelsources.org:8080/source/history/titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c#510c3f914054fe5a373967f2397b3d61a91c5bb9</link>
        <description>6874992 in.iked does not use network byte order for IP address in sendto() call6874983 ikedoor.h is not C++ safe6885833 IPsec utilities should print lifetimes in human readable format6889086 ikeadm reports kilobyte lifetimes with wrong units6898492 iked should enforce lower maximum values for lifetimes6897711 iked debug output should be less confusing for average sysadmin6902926 SOFT kilobyte expires for inbound SAs should make it to userland and be reacted upon

            List of files:
            /titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c</description>
        <pubDate>Tue, 22 Dec 2009 10:52:46 +0100</pubDate>
        <dc:creator>Vladimir Kotal &lt;Vladimir.Kotal@Sun.COM&gt;</dc:creator>
    </item>
<item>
        <title>d0115d88cdf265fa2cc0481f8a6db735be47f2b9 - 6900753 Calls to dump_key in ikeadm.c could be refactored</title>
        <link>http://kernelsources.org:8080/source/history/titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c#d0115d88cdf265fa2cc0481f8a6db735be47f2b9</link>
        <description>6900753 Calls to dump_key in ikeadm.c could be refactored6896962 ipsecconf incorrectly parses misconfigured hyphenated tokens6898695 ipsecalgs -s causes kernel buffer corruption6440628 ipseckey should ensure that argument is a file before parsing

            List of files:
            /titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c</description>
        <pubDate>Fri, 20 Nov 2009 23:54:27 +0100</pubDate>
        <dc:creator>Mark Fenwick &lt;Mark.Fenwick@Sun.COM&gt;</dc:creator>
    </item>
<item>
        <title>5d3b8cb7141cfa596d20cdc5043b8a6df635938d - PSARC/2008/252 Labeled IPsec phase 1</title>
        <link>http://kernelsources.org:8080/source/history/titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c#5d3b8cb7141cfa596d20cdc5043b8a6df635938d</link>
        <description>PSARC/2008/252 Labeled IPsec phase 16886771 Labeled IPsec phase 16808727 Alignment error panic in tsol_can_accept_raw()6894979 nightly -0 + -p builds then destroys SUNW0on

            List of files:
            /titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c</description>
        <pubDate>Tue, 03 Nov 2009 00:39:20 +0100</pubDate>
        <dc:creator>Bill Sommerfeld &lt;sommerfeld@sun.com&gt;</dc:creator>
    </item>
<item>
        <title>628b0c67908adce18522d53bb2bf8d6c3b321579 - PSARC 2009/513 Changes to IPsec ESP to support Combined mode ciphers</title>
        <link>http://kernelsources.org:8080/source/history/titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c#628b0c67908adce18522d53bb2bf8d6c3b321579</link>
        <description>PSARC 2009/513 Changes to IPsec ESP to support Combined mode ciphers6704686 IPsec/ESP needs to support Combined mode ciphers6704682 IPsec/ESP should use AES-CCM6884664 IPsec/ESP should support AES-GCM Mode6840342 ipsecalgs out of memory error6764184 tab instead of space in sadb.h

            List of files:
            /titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c</description>
        <pubDate>Wed, 21 Oct 2009 06:00:54 +0200</pubDate>
        <dc:creator>Mark Fenwick &lt;Mark.Fenwick@Sun.COM&gt;</dc:creator>
    </item>
<item>
        <title>bfe6f8f50e1ad7cfc72f4665989dc9e25e82e872 - 6520458 ikeadm should have command line history capabilities</title>
        <link>http://kernelsources.org:8080/source/history/titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c#bfe6f8f50e1ad7cfc72f4665989dc9e25e82e872</link>
        <description>6520458 ikeadm should have command line history capabilities4313953 ipseckey(1m) needs line editing support.6814629 ipseckey should employ strict checking for {dump,flush} commands

            List of files:
            /titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c</description>
        <pubDate>Wed, 18 Mar 2009 19:49:20 +0100</pubDate>
        <dc:creator>Vladimir Kotal &lt;Vladimir.Kotal@Sun.COM&gt;</dc:creator>
    </item>
<item>
        <title>9c2c14ab194d42014417b385d6bf226ba1a37995 - PSARC 2008/523 IPsec session failover</title>
        <link>http://kernelsources.org:8080/source/history/titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c#9c2c14ab194d42014417b385d6bf226ba1a37995</link>
        <description>PSARC 2008/523 IPsec session failover6398024 IPsec should support session failover across machines6545486 PF_KEY needs to set an SA&apos;s sequence number

            List of files:
            /titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c</description>
        <pubDate>Tue, 30 Sep 2008 01:18:37 +0200</pubDate>
        <dc:creator>Thejaswini Singarajipura &lt;Thejaswini.Singarajipura@Sun.COM&gt;</dc:creator>
    </item>
<item>
        <title>38d95a786e32a3f7e21450bff371f0778db4c181 - PSARC/2008/232 Paired IPsec Security Associations</title>
        <link>http://kernelsources.org:8080/source/history/titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c#38d95a786e32a3f7e21450bff371f0778db4c181</link>
        <description>PSARC/2008/232 Paired IPsec Security Associations6584918 in.iked will exit if you try and add a duplicate rule with ikeadm6595953 Remove SCCS keywords from ipsec{ah,esp}, keysock, and spdsock6628201 Inbound and Outbound IPsec SA&apos;s should be treated as a pair.6643439 check_rule() in in.iked does not sanity check kilobyte based lifetime values6668752 ikeadm(1m) get defaults displays wrong value for p2_softlife_kb6669211 Need a way to disable Soft Expires when using in.iked(1m)6670612 sadb_address_proto and sadb_address_prefixlen need to be initialized in NAT_T extensions.6674203 Ordering of src/dst address extensions in pf_key messages is inconsistent.6676436 ipseckey(1m) error messages could be less cryptic6683004 Updating hard_usetime on an IPsec SA will cause it to evaporate.6703265 in.iked can dump core if avl_nearest() returns NULL

            List of files:
            /titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c</description>
        <pubDate>Tue, 20 May 2008 19:53:08 +0200</pubDate>
        <dc:creator>markfen &lt;none@none&gt;</dc:creator>
    </item>
<item>
        <title>a050d7e901ad972bf85a70cf6c67b5d4dd69395b - 6659486 ipseckey dumps core with encryption key and no other parameters</title>
        <link>http://kernelsources.org:8080/source/history/titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c#a050d7e901ad972bf85a70cf6c67b5d4dd69395b</link>
        <description>6659486 ipseckey dumps core with encryption key and no other parameters

            List of files:
            /titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c</description>
        <pubDate>Fri, 08 Feb 2008 20:19:19 +0100</pubDate>
        <dc:creator>pwernau &lt;none@none&gt;</dc:creator>
    </item>
<item>
        <title>23c73ecc8c565b8247ce7f888170bfbbce3e589c - 5053475 certlib_load() error messages need improving.</title>
        <link>http://kernelsources.org:8080/source/history/titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c#23c73ecc8c565b8247ce7f888170bfbbce3e589c</link>
        <description>5053475 certlib_load() error messages need improving.6614180 file permissions on public keys and CRLs should be more open6614741 keying material with insecure permissions should not be trusted

            List of files:
            /titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c</description>
        <pubDate>Wed, 24 Oct 2007 22:59:51 +0200</pubDate>
        <dc:creator>pwernau &lt;none@none&gt;</dc:creator>
    </item>
<item>
        <title>72c8fd38a6ea9ea08b62d28576758c1181f1012c - 6610537 ipseckey error output can get mangled on x86</title>
        <link>http://kernelsources.org:8080/source/history/titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c#72c8fd38a6ea9ea08b62d28576758c1181f1012c</link>
        <description>6610537 ipseckey error output can get mangled on x866610538 ipseckey can core dump with truncated input

            List of files:
            /titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c</description>
        <pubDate>Tue, 02 Oct 2007 07:40:41 +0200</pubDate>
        <dc:creator>markfen &lt;none@none&gt;</dc:creator>
    </item>
<item>
        <title>437220cd296f6d8b6654d6d52508b40b1e2d1ac7 - PSARC 2007/449 Detangle IPsec NAT Traversal</title>
        <link>http://kernelsources.org:8080/source/history/titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c#437220cd296f6d8b6654d6d52508b40b1e2d1ac7</link>
        <description>PSARC 2007/449 Detangle IPsec NAT Traversal6481450 nattymod calls putnext() on a freed queue.6558864 remove nattymod6558870 Implement SA last-used time and idle actions6582318 &quot;mandatory&quot; is spelled wrong in pfiles6584011 save_assoc() gets confused w.r.t. &quot;proto&quot;.6588015 Missing &quot;encap udp&quot; must be better diagnosed by ipseckey(1M).6595368 Need &quot;ipsec-nat-t&quot; in /etc/services6595877 ipseckey(1M) can produce output it can&apos;t read back in (line-too-big)--HG--rename : usr/src/uts/common/inet/ip/nattymod.c =&gt; deleted_files/usr/src/uts/common/inet/ip/nattymod.crename : usr/src/uts/intel/nattymod/Makefile =&gt; deleted_files/usr/src/uts/intel/nattymod/Makefilerename : usr/src/uts/sparc/nattymod/Makefile =&gt; deleted_files/usr/src/uts/sparc/nattymod/Makefile

            List of files:
            /titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c</description>
        <pubDate>Tue, 04 Sep 2007 15:48:33 +0200</pubDate>
        <dc:creator>danmcd &lt;none@none&gt;</dc:creator>
    </item>
<item>
        <title>bb3ed8dfcb84e1d06fdc5da3b0ca7758e737644b - 6585305 in.iked in debug mode needs to show phase 2 alg proposals and PF_KEY message contents</title>
        <link>http://kernelsources.org:8080/source/history/titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c#bb3ed8dfcb84e1d06fdc5da3b0ca7758e737644b</link>
        <description>6585305 in.iked in debug mode needs to show phase 2 alg proposals and PF_KEY message contents

            List of files:
            /titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c</description>
        <pubDate>Wed, 15 Aug 2007 16:14:07 +0200</pubDate>
        <dc:creator>pwernau &lt;none@none&gt;</dc:creator>
    </item>
<item>
        <title>ec4858345aa8c9134ae2563545c54823cd78b5c8 - 6477017 ipseckey could should not reject a hex string that starts &apos;0x&apos;</title>
        <link>http://kernelsources.org:8080/source/history/titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c#ec4858345aa8c9134ae2563545c54823cd78b5c8</link>
        <description>6477017 ipseckey could should not reject a hex string that starts &apos;0x&apos;6499919 ipseckey should throw out encryption keys for &quot;null&quot; algorithm

            List of files:
            /titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c</description>
        <pubDate>Fri, 29 Jun 2007 20:59:22 +0200</pubDate>
        <dc:creator>pwernau &lt;none@none&gt;</dc:creator>
    </item>
<item>
        <title>25e435e0812a1f7baf9b71795cee95da3f7b9098 - 6561665 ipseckey -f does not understand &quot;flush&quot; keyword anymore</title>
        <link>http://kernelsources.org:8080/source/history/titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c#25e435e0812a1f7baf9b71795cee95da3f7b9098</link>
        <description>6561665 ipseckey -f does not understand &quot;flush&quot; keyword anymore

            List of files:
            /titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c</description>
        <pubDate>Tue, 29 May 2007 22:04:40 +0200</pubDate>
        <dc:creator>pwernau &lt;none@none&gt;</dc:creator>
    </item>
<item>
        <title>e3320f40ba20e6851e73a3237eedf089700bf001 - PSARC 2007/200 - Dedicated SMF services for IPsec/IKE</title>
        <link>http://kernelsources.org:8080/source/history/titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c#e3320f40ba20e6851e73a3237eedf089700bf001</link>
        <description>PSARC 2007/200 - Dedicated SMF services for IPsec/IKE6185380 IPsec should be a separate (set) of smf(5) services6440610 missing preshared remoteid line causes in.iked core dump on reading config6462741 ipsecconf should have an option to check config file syntax6467954 ipseckey exit code on failure inconsistent6468456 ipsecconf uses strcpy()6479903 in.iked with SMF should use _enter_daemon_lock()6488927 ipseckey(1M) could do a better job of dealing with multiple errors6497802 in.iked should use smf(5) properties instead of /etc/default/ipsec6519836 ipseckey, ipsecconf require uid == 0, but configured to use profile6529086 ipsec utilities can&apos;t deal with large files6538478 Timestamp in in.iked debug output does not understand daylight savings time6542255 in.iked can dump core when forced to load a new ike.preshared file with ikeadm.6543263 ikeadm uses strcpy()6543267 ipseckey uses strcpy()6544087 memory leak with preshared key reloading--HG--rename : usr/src/cmd/cmd-inet/usr.sbin/ikeadm.c =&gt; usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ikeadm.crename : usr/src/cmd/cmd-inet/usr.sbin/ikecert.sh =&gt; usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ikecert.shrename : usr/src/cmd/cmd-inet/usr.sbin/ipsecalgs.c =&gt; usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipsecalgs.crename : usr/src/cmd/cmd-inet/usr.sbin/ipsecconf.c =&gt; usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipsecconf.crename : usr/src/cmd/cmd-inet/usr.sbin/ipseckey.c =&gt; usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c

            List of files:
            /titanic_50/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c</description>
        <pubDate>Tue, 15 May 2007 07:36:44 +0200</pubDate>
        <dc:creator>markfen &lt;none@none&gt;</dc:creator>
    </item>
</channel>
</rss>
