<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="/source/rss.xsl.xml"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
    <title>Changes in ipsec_util.c</title>
    <description></description>
    <language>en</language>
    <copyright>Copyright 2015</copyright>
    <generator>Java</generator><item>
        <title>33f5ff17089e3a43e6e730bf80384c233123dbd9 - 2077 lots of unreachable breaks in illumos gate</title>
        <link>http://kernelsources.org:8080/source/history/titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c#33f5ff17089e3a43e6e730bf80384c233123dbd9</link>
        <description>2077 lots of unreachable breaks in illumos gateReviewed by: Dan McDonald &lt;danmcd@nexenta.com&gt;Reviewed by: Garrett D&apos;Amore &lt;garrett@damore.org&gt;Approved by: Richard Lowe &lt;richlowe@richlowe.net&gt;

            List of files:
            /titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c</description>
        <pubDate>Sat, 18 Feb 2012 19:52:02 +0100</pubDate>
        <dc:creator>Milan Jurik &lt;milan.jurik@xylab.cz&gt;</dc:creator>
    </item>
<item>
        <title>510c3f914054fe5a373967f2397b3d61a91c5bb9 - 6874992 in.iked does not use network byte order for IP address in sendto() call</title>
        <link>http://kernelsources.org:8080/source/history/titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c#510c3f914054fe5a373967f2397b3d61a91c5bb9</link>
        <description>6874992 in.iked does not use network byte order for IP address in sendto() call6874983 ikedoor.h is not C++ safe6885833 IPsec utilities should print lifetimes in human readable format6889086 ikeadm reports kilobyte lifetimes with wrong units6898492 iked should enforce lower maximum values for lifetimes6897711 iked debug output should be less confusing for average sysadmin6902926 SOFT kilobyte expires for inbound SAs should make it to userland and be reacted upon

            List of files:
            /titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c</description>
        <pubDate>Tue, 22 Dec 2009 10:52:46 +0100</pubDate>
        <dc:creator>Vladimir Kotal &lt;Vladimir.Kotal@Sun.COM&gt;</dc:creator>
    </item>
<item>
        <title>5d3b8cb7141cfa596d20cdc5043b8a6df635938d - PSARC/2008/252 Labeled IPsec phase 1</title>
        <link>http://kernelsources.org:8080/source/history/titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c#5d3b8cb7141cfa596d20cdc5043b8a6df635938d</link>
        <description>PSARC/2008/252 Labeled IPsec phase 16886771 Labeled IPsec phase 16808727 Alignment error panic in tsol_can_accept_raw()6894979 nightly -0 + -p builds then destroys SUNW0on

            List of files:
            /titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c</description>
        <pubDate>Tue, 03 Nov 2009 00:39:20 +0100</pubDate>
        <dc:creator>Bill Sommerfeld &lt;sommerfeld@sun.com&gt;</dc:creator>
    </item>
<item>
        <title>628b0c67908adce18522d53bb2bf8d6c3b321579 - PSARC 2009/513 Changes to IPsec ESP to support Combined mode ciphers</title>
        <link>http://kernelsources.org:8080/source/history/titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c#628b0c67908adce18522d53bb2bf8d6c3b321579</link>
        <description>PSARC 2009/513 Changes to IPsec ESP to support Combined mode ciphers6704686 IPsec/ESP needs to support Combined mode ciphers6704682 IPsec/ESP should use AES-CCM6884664 IPsec/ESP should support AES-GCM Mode6840342 ipsecalgs out of memory error6764184 tab instead of space in sadb.h

            List of files:
            /titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c</description>
        <pubDate>Wed, 21 Oct 2009 06:00:54 +0200</pubDate>
        <dc:creator>Mark Fenwick &lt;Mark.Fenwick@Sun.COM&gt;</dc:creator>
    </item>
<item>
        <title>a1ba878124e55e106e12f717d2b0aa3d6c531858 - 6848192 get_ipsa_pair() does not always follow bucket lock entry rules, could potentially deadlock.</title>
        <link>http://kernelsources.org:8080/source/history/titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c#a1ba878124e55e106e12f717d2b0aa3d6c531858</link>
        <description>6848192 get_ipsa_pair() does not always follow bucket lock entry rules, could potentially deadlock.6846548 PF_KEY diagnostics need to be more specific6853208 ipsecalgs(1m) does not cope when there are no algorithms registered.6856693 sadb_update_sa() checks for duplicate SADB_UPDATE messages in the wrong place.6846547 Faulty PF_KEY replies should not cause in.iked to halt

            List of files:
            /titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c</description>
        <pubDate>Thu, 02 Jul 2009 05:57:22 +0200</pubDate>
        <dc:creator>Mark Fenwick &lt;Mark.Fenwick@Sun.COM&gt;</dc:creator>
    </item>
<item>
        <title>bfe6f8f50e1ad7cfc72f4665989dc9e25e82e872 - 6520458 ikeadm should have command line history capabilities</title>
        <link>http://kernelsources.org:8080/source/history/titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c#bfe6f8f50e1ad7cfc72f4665989dc9e25e82e872</link>
        <description>6520458 ikeadm should have command line history capabilities4313953 ipseckey(1m) needs line editing support.6814629 ipseckey should employ strict checking for {dump,flush} commands

            List of files:
            /titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c</description>
        <pubDate>Wed, 18 Mar 2009 19:49:20 +0100</pubDate>
        <dc:creator>Vladimir Kotal &lt;Vladimir.Kotal@Sun.COM&gt;</dc:creator>
    </item>
<item>
        <title>9c2c14ab194d42014417b385d6bf226ba1a37995 - PSARC 2008/523 IPsec session failover</title>
        <link>http://kernelsources.org:8080/source/history/titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c#9c2c14ab194d42014417b385d6bf226ba1a37995</link>
        <description>PSARC 2008/523 IPsec session failover6398024 IPsec should support session failover across machines6545486 PF_KEY needs to set an SA&apos;s sequence number

            List of files:
            /titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c</description>
        <pubDate>Tue, 30 Sep 2008 01:18:37 +0200</pubDate>
        <dc:creator>Thejaswini Singarajipura &lt;Thejaswini.Singarajipura@Sun.COM&gt;</dc:creator>
    </item>
<item>
        <title>c51cb4bc539e1650eb5bb4f805cc779bfce99c06 - 6728539 64-bit version of libipsecutil</title>
        <link>http://kernelsources.org:8080/source/history/titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c#c51cb4bc539e1650eb5bb4f805cc779bfce99c06</link>
        <description>6728539 64-bit version of libipsecutil

            List of files:
            /titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c</description>
        <pubDate>Wed, 13 Aug 2008 21:09:36 +0200</pubDate>
        <dc:creator>Dan McDonald &lt;danmcd@sun.com&gt;</dc:creator>
    </item>
<item>
        <title>4a179720b93e6200ddafd0f29ceabf9c78eff756 - 6719641 RFC 3947 section 7 (port-reassignment) on paired-ESP and IKE SAs on the non-NAT side.</title>
        <link>http://kernelsources.org:8080/source/history/titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c#4a179720b93e6200ddafd0f29ceabf9c78eff756</link>
        <description>6719641 RFC 3947 section 7 (port-reassignment) on paired-ESP and IKE SAs on the non-NAT side.

            List of files:
            /titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c</description>
        <pubDate>Wed, 09 Jul 2008 21:35:35 +0200</pubDate>
        <dc:creator>danmcd &lt;none@none&gt;</dc:creator>
    </item>
<item>
        <title>38d95a786e32a3f7e21450bff371f0778db4c181 - PSARC/2008/232 Paired IPsec Security Associations</title>
        <link>http://kernelsources.org:8080/source/history/titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c#38d95a786e32a3f7e21450bff371f0778db4c181</link>
        <description>PSARC/2008/232 Paired IPsec Security Associations6584918 in.iked will exit if you try and add a duplicate rule with ikeadm6595953 Remove SCCS keywords from ipsec{ah,esp}, keysock, and spdsock6628201 Inbound and Outbound IPsec SA&apos;s should be treated as a pair.6643439 check_rule() in in.iked does not sanity check kilobyte based lifetime values6668752 ikeadm(1m) get defaults displays wrong value for p2_softlife_kb6669211 Need a way to disable Soft Expires when using in.iked(1m)6670612 sadb_address_proto and sadb_address_prefixlen need to be initialized in NAT_T extensions.6674203 Ordering of src/dst address extensions in pf_key messages is inconsistent.6676436 ipseckey(1m) error messages could be less cryptic6683004 Updating hard_usetime on an IPsec SA will cause it to evaporate.6703265 in.iked can dump core if avl_nearest() returns NULL

            List of files:
            /titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c</description>
        <pubDate>Tue, 20 May 2008 19:53:08 +0200</pubDate>
        <dc:creator>markfen &lt;none@none&gt;</dc:creator>
    </item>
<item>
        <title>a12f8217a48c5bd9b5b2492e3feb316d3c89501b - 6658263 ipseckey and ikeadm don&apos;t print ASN.1 ID values</title>
        <link>http://kernelsources.org:8080/source/history/titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c#a12f8217a48c5bd9b5b2492e3feb316d3c89501b</link>
        <description>6658263 ipseckey and ikeadm don&apos;t print ASN.1 ID values

            List of files:
            /titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c</description>
        <pubDate>Fri, 29 Feb 2008 20:48:50 +0100</pubDate>
        <dc:creator>pwernau &lt;none@none&gt;</dc:creator>
    </item>
<item>
        <title>e70cf235eec3f1ae9c3a34fa4c2e4a13df0b7c86 - 6653436 iked should be more resilient to ipsecalgs contents</title>
        <link>http://kernelsources.org:8080/source/history/titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c#e70cf235eec3f1ae9c3a34fa4c2e4a13df0b7c86</link>
        <description>6653436 iked should be more resilient to ipsecalgs contents

            List of files:
            /titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c</description>
        <pubDate>Fri, 25 Jan 2008 09:56:02 +0100</pubDate>
        <dc:creator>vk199839 &lt;none@none&gt;</dc:creator>
    </item>
<item>
        <title>437220cd296f6d8b6654d6d52508b40b1e2d1ac7 - PSARC 2007/449 Detangle IPsec NAT Traversal</title>
        <link>http://kernelsources.org:8080/source/history/titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c#437220cd296f6d8b6654d6d52508b40b1e2d1ac7</link>
        <description>PSARC 2007/449 Detangle IPsec NAT Traversal6481450 nattymod calls putnext() on a freed queue.6558864 remove nattymod6558870 Implement SA last-used time and idle actions6582318 &quot;mandatory&quot; is spelled wrong in pfiles6584011 save_assoc() gets confused w.r.t. &quot;proto&quot;.6588015 Missing &quot;encap udp&quot; must be better diagnosed by ipseckey(1M).6595368 Need &quot;ipsec-nat-t&quot; in /etc/services6595877 ipseckey(1M) can produce output it can&apos;t read back in (line-too-big)--HG--rename : usr/src/uts/common/inet/ip/nattymod.c =&gt; deleted_files/usr/src/uts/common/inet/ip/nattymod.crename : usr/src/uts/intel/nattymod/Makefile =&gt; deleted_files/usr/src/uts/intel/nattymod/Makefilerename : usr/src/uts/sparc/nattymod/Makefile =&gt; deleted_files/usr/src/uts/sparc/nattymod/Makefile

            List of files:
            /titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c</description>
        <pubDate>Tue, 04 Sep 2007 15:48:33 +0200</pubDate>
        <dc:creator>danmcd &lt;none@none&gt;</dc:creator>
    </item>
<item>
        <title>bb3ed8dfcb84e1d06fdc5da3b0ca7758e737644b - 6585305 in.iked in debug mode needs to show phase 2 alg proposals and PF_KEY message contents</title>
        <link>http://kernelsources.org:8080/source/history/titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c#bb3ed8dfcb84e1d06fdc5da3b0ca7758e737644b</link>
        <description>6585305 in.iked in debug mode needs to show phase 2 alg proposals and PF_KEY message contents

            List of files:
            /titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c</description>
        <pubDate>Wed, 15 Aug 2007 16:14:07 +0200</pubDate>
        <dc:creator>pwernau &lt;none@none&gt;</dc:creator>
    </item>
<item>
        <title>c99ab7ce48c9556fb9c08660f6dafac6e1d382a1 - 6576171 ipsec_kmc_map file processing is broken</title>
        <link>http://kernelsources.org:8080/source/history/titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c#c99ab7ce48c9556fb9c08660f6dafac6e1d382a1</link>
        <description>6576171 ipsec_kmc_map file processing is broken

            List of files:
            /titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c</description>
        <pubDate>Mon, 30 Jul 2007 19:32:47 +0200</pubDate>
        <dc:creator>danmcd &lt;none@none&gt;</dc:creator>
    </item>
<item>
        <title>25e435e0812a1f7baf9b71795cee95da3f7b9098 - 6561665 ipseckey -f does not understand &quot;flush&quot; keyword anymore</title>
        <link>http://kernelsources.org:8080/source/history/titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c#25e435e0812a1f7baf9b71795cee95da3f7b9098</link>
        <description>6561665 ipseckey -f does not understand &quot;flush&quot; keyword anymore

            List of files:
            /titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c</description>
        <pubDate>Tue, 29 May 2007 22:04:40 +0200</pubDate>
        <dc:creator>pwernau &lt;none@none&gt;</dc:creator>
    </item>
<item>
        <title>e3320f40ba20e6851e73a3237eedf089700bf001 - PSARC 2007/200 - Dedicated SMF services for IPsec/IKE</title>
        <link>http://kernelsources.org:8080/source/history/titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c#e3320f40ba20e6851e73a3237eedf089700bf001</link>
        <description>PSARC 2007/200 - Dedicated SMF services for IPsec/IKE6185380 IPsec should be a separate (set) of smf(5) services6440610 missing preshared remoteid line causes in.iked core dump on reading config6462741 ipsecconf should have an option to check config file syntax6467954 ipseckey exit code on failure inconsistent6468456 ipsecconf uses strcpy()6479903 in.iked with SMF should use _enter_daemon_lock()6488927 ipseckey(1M) could do a better job of dealing with multiple errors6497802 in.iked should use smf(5) properties instead of /etc/default/ipsec6519836 ipseckey, ipsecconf require uid == 0, but configured to use profile6529086 ipsec utilities can&apos;t deal with large files6538478 Timestamp in in.iked debug output does not understand daylight savings time6542255 in.iked can dump core when forced to load a new ike.preshared file with ikeadm.6543263 ikeadm uses strcpy()6543267 ipseckey uses strcpy()6544087 memory leak with preshared key reloading--HG--rename : usr/src/cmd/cmd-inet/usr.sbin/ikeadm.c =&gt; usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ikeadm.crename : usr/src/cmd/cmd-inet/usr.sbin/ikecert.sh =&gt; usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ikecert.shrename : usr/src/cmd/cmd-inet/usr.sbin/ipsecalgs.c =&gt; usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipsecalgs.crename : usr/src/cmd/cmd-inet/usr.sbin/ipsecconf.c =&gt; usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipsecconf.crename : usr/src/cmd/cmd-inet/usr.sbin/ipseckey.c =&gt; usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c

            List of files:
            /titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c</description>
        <pubDate>Tue, 15 May 2007 07:36:44 +0200</pubDate>
        <dc:creator>markfen &lt;none@none&gt;</dc:creator>
    </item>
<item>
        <title>a74858089ab88f6b5b2788e8ca504c5586da8af5 - 6500413 libipsecutil uses gettext() instead of dgettext()</title>
        <link>http://kernelsources.org:8080/source/history/titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c#a74858089ab88f6b5b2788e8ca504c5586da8af5</link>
        <description>6500413 libipsecutil uses gettext() instead of dgettext()

            List of files:
            /titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c</description>
        <pubDate>Thu, 19 Apr 2007 18:27:57 +0200</pubDate>
        <dc:creator>markfen &lt;none@none&gt;</dc:creator>
    </item>
<item>
        <title>8810c16b934a2ad4f27aa86f95b0e8cec1c6ea46 - PSARC 2005/516 IPsec Tunnel Reform</title>
        <link>http://kernelsources.org:8080/source/history/titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c#8810c16b934a2ad4f27aa86f95b0e8cec1c6ea46</link>
        <description>PSARC 2005/516 IPsec Tunnel Reform4882852 tunnels vs. inverse acquire.4970365 Support of ESP tunnel mode within Solaris5027528 in.iked should be more intelligent about tunnel addresses6180161 need to support multiple tunnels to a single nat6208976 ipsecconf error messages make me think there are monsters under the bed6313012 Clean up from removal of ipsec_inbound_debug_tag()6351840 assertion failed: (ipha-&gt;ipha_protocol != 6) &amp;&amp; (ipha-&gt;ipha_protocol != 17), ip.c, line: 153516359831 multicast tunnels don&apos;t get their IPsec policy checked.6369094 ipseckey shouldn&apos;t accept/save-out encryption algorithm even it&apos;s none/any6374560 ipseckey debug functions should be moved to libipsecutil6374596 dump utilities need to be able to understand inner tunnel addresses and netmasks6402781 Five dead declarations in IPsec code6405338 spdsock leaks policy head references6437366 NAT-OA payloads not processed early enough.6465594 ipsec_policy_delete() uses wrong ipsec_selkey_t structure.6467596 spdsock_ext_to_actvec() needs to reset &quot;act&quot; upon every SPD_ATTR_NEXT.6470725 PF_POLICY shouldn&apos;t accept &apos;0&apos; for an algorithm value.6475903 Outbound DROP rules are not enforced6480815 INVERSE_ACQUIRE failures leak in in.iked6482403 Race in in.iked, early door call vs. rest of initialization code6482653 Don&apos;t accept UDP-encapsulated ESP on non-NAT SAs.6487857 Post-ACQUIRE, AH+ESP packets misinitalized ipha/ip6

            List of files:
            /titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c</description>
        <pubDate>Fri, 03 Nov 2006 16:10:24 +0100</pubDate>
        <dc:creator>danmcd &lt;none@none&gt;</dc:creator>
    </item>
<item>
        <title>7c478bd95313f5f23a4c958a745db2134aa03244 - OpenSolaris Launch</title>
        <link>http://kernelsources.org:8080/source/history/titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c#7c478bd95313f5f23a4c958a745db2134aa03244</link>
        <description>OpenSolaris Launch

            List of files:
            /titanic_51/usr/src/lib/libipsecutil/common/ipsec_util.c</description>
        <pubDate>Tue, 14 Jun 2005 09:00:00 +0200</pubDate>
        <dc:creator>stevel@tonic-gate &lt;none@none&gt;</dc:creator>
    </item>
</channel>
</rss>
