netdev
[Top] [All Lists]

Re: off by one error in 3des cbc keying

To: ahu@xxxxxxx (bert hubert)
Subject: Re: off by one error in 3des cbc keying
From: kuznet@xxxxxxxxxxxxx
Date: Mon, 11 Nov 2002 20:18:55 +0300 (MSK)
Cc: davem@xxxxxxxxxx, gem@xxxxxxxxxxx, netdev@xxxxxxxxxxx
In-reply-to: <20021111100109.GB18677@xxxxxxxxxxxxxxx> from "bert hubert" at Nov 11, 2 11:01:09 am
Sender: netdev-bounce@xxxxxxxxxxx
Hello!

> [alexey's nameserver is off, cc to netdev@xxxxxxxxxxx, perhaps he sees it
> there]

Unlikely. I think while our network is down list exploders just
drop mails unlike normal mail agents. :-)


> I wonder, is 'incoming bypass' implemented yet?

It is. But your example shows that something is wrong there. Fix will follow
later.


> Key refreshing/updating doesn't appear to work either, after they key has
> expired, all bets are off.

What does happen in logs/setkey -D? Actually, before sending previous
large patch dealing with expire timers I got it to the point where keys
are refreshed nicely at _one_ side, another required reboot and the test
was not accomplished.

Alexey


<Prev in Thread] Current Thread [Next in Thread>