netdev
[Top] [All Lists]

Re: PATCH: IPSEC acquire in presence of multiple managers

To: jamal <hadi@xxxxxxxxxx>
Subject: Re: PATCH: IPSEC acquire in presence of multiple managers
From: Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx>
Date: Sat, 26 Mar 2005 11:30:58 +1100
Cc: "David S. Miller" <davem@xxxxxxxxxx>, Masahide NAKAMURA <nakam@xxxxxxxxxxxxxx>, Shinta Sugimoto <shinta.sugimoto@xxxxxxxxxxxx>, netdev <netdev@xxxxxxxxxxx>
In-reply-to: <1111795927.1089.749.camel@xxxxxxxxxxxxxxxx>
References: <1111795927.1089.749.camel@xxxxxxxxxxxxxxxx>
Sender: netdev-bounce@xxxxxxxxxxx
User-agent: Mutt/1.5.6+20040907i
On Fri, Mar 25, 2005 at 07:12:07PM -0500, jamal wrote:
> 
> Acquire should be supported by both pfkey and netlink.
> However, it stops to send acquire message from the kernel on first
> success.
> It is possible that one or the other manager maybe passively monitoring
> and needs to see those messages.

Yes that's a good catch.

One problem though is that if theal real KM is dead but the passive
monitor is still there then the kernel will have to wait for the
larval states to time out.

It can happen without the patch too if the KM dies after the message
is delivered.  This will make it slightly more likely.

I guess that's something we'll just have to live with.

Cheers,
-- 
Visit Openswan at http://www.openswan.org/
Email: Herbert Xu ~{PmV>HI~} <herbert@xxxxxxxxxxxxxxxxxxx>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt

<Prev in Thread] Current Thread [Next in Thread>