netdev
[Top] [All Lists]

Re: Problem in IKE implemenation in linux(RACE CONDITION)

To: pranav@xxxxxxxxxxxxxxxx
Subject: Re: Problem in IKE implemenation in linux(RACE CONDITION)
From: Michael Richardson <mcr@xxxxxxxxxxxxxxxxxxxxxx>
Date: Sat, 31 Jul 2004 08:10:50 -0400
Cc: netdev-bounce@xxxxxxxxxxx, netdev@xxxxxxxxxxx
In-reply-to: Message from "Pranav" <pranav@nodeinfotech.com> of "Thu, 29 Jul 2004 15:08:08 +0530." <BLEAIJDEHOOAGALIAAKBIEJNCAAA.pranav@nodeinfotech.com>
References: <BLEAIJDEHOOAGALIAAKBIEJNCAAA.pranav@nodeinfotech.com>
Sender: netdev-bounce@xxxxxxxxxxx
-----BEGIN PGP SIGNED MESSAGE-----


>>>>> "Pranav" == Pranav  <pranav@xxxxxxxxxxxxxxxx> writes:
    Pranav> hi everyone, I am working on IKE implementaion on linux.  i
    Pranav> have got a problem in negoatiation when both the peers start
    Pranav> negotiating at the same time, both peers acting as initiator
    Pranav> causing race condition.

    Pranav> Race condition happens only when both the peer's start the
    Pranav> same application(like ping or telnet)with eachother at the
    Pranav> same time.

  Yes, in general you have to create both tunnels for receive.
  It is up to you to decide which tunnel to create for sending. 
  If you want to get rid of them, then wait 5 minutes, and then rekey
the tunnels.

- --
]     "Elmo went to the wrong fundraiser" - The Simpson         |  firewalls  [
]   Michael Richardson,    Xelerance Corporation, Ottawa, ON    |net architect[
] mcr@xxxxxxxxxxxxx      http://www.sandelman.ottawa.on.ca/mcr/ |device driver[
] panic("Just another Debian GNU/Linux using, kernel hacking, security guy"); [
  


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (GNU/Linux)
Comment: Finger me for keys

iQCVAwUBQQt/04qHRg3pndX9AQHCyAQAull2/qeUcL0mfxKyeRKRsiViMAMgNiDA
KH62L05FP4mbiCrdhGBppaIIuK/hcu9axp8VQ7IDWS/Pa5S6FmMquegaJPTDGohd
3wZZi6vlBq4LiVnVqcBpFinNTP5dH43vfDNK42WSV+fUjrVc09uX9XWXhmFXh593
knlESrpooPI=
=Wq/Q
-----END PGP SIGNATURE-----

<Prev in Thread] Current Thread [Next in Thread>