netdev
[Top] [All Lists]

Re: current IPSEC/SKIP implementations?

To: "Michael H. Warfield" <mhw@xxxxxxxxxxxx>
Subject: Re: current IPSEC/SKIP implementations?
From: Richard Guy Briggs <rgb@xxxxxxxxxxxxxxxxxxxxx>
Date: Tue, 11 Jan 2000 00:46:19 -0500
Cc: Greg Simpson <gws@xxxxxxxxx>, netdev@xxxxxxxxxxx
In-reply-to: <20000110150009.A17303@xxxxxxxxxxxxxxxxxxx>
References: <Pine.LNX.4.00.10001101431350.19157-100000@xxxxxxxxxxxxxxxx> <20000110150009.A17303@xxxxxxxxxxxxxxxxxxx>
Sender: owner-netdev@xxxxxxxxxxx
On Mon, Jan 10, 2000 at 03:00:09PM -0500, Michael H. Warfield wrote:
> On Mon, Jan 10, 2000 at 02:32:36PM -0500, Greg Simpson wrote:
> 
> > Do you guys know the status of IPSEC within the linux kernel?

For the foreseeable future, IPSEC CANNOT be included in the kernel
because it is export restricted and it is being maintained and
distributed primarily from the USA.

It CAN be added afterwards by anyone (except where local law prohibits
its use, ie. USSR, Cuba, etc...)

This situation could change if the US government gives up its
pointless export restrictions on purely defensive technology, OR, the
main maintenance/distribution of the kernel leaves the US (Hey Linus,
going back to Finland anytime soon?)

> > I haven't been able to find any good, recently updated resources on this
> > topic, and ppp over ssh isn't perfect - or compatible with routers :)
> 
>       http://www.freeswan.org
> 
>       Currently in release version 1.2.  Daily snapshots are required
> if you are working with the 2.3.x kernels or want the latest toots and
> whistles.  Version 1.2 will patch the 2.2.x kernels.  Pluto (IKE) supports
> automatic keying.  Some patches exist for PKI and certificates.

The version 1.2 patches are fairly important, or get a new snapshot.
Another release is due around the end of January.  "Release Early,
Release Often"

>       Mailing list:   linux-ipsec@xxxxxxxxx
> 
>       FTP Site:       ftp://ftp.xs4all.nl/pub/crypto/freeswan
> 
> > TIA,
> 
> > -g
> 
>       Mike

Thanks Mike!

> -- 
>  Michael H. Warfield    |  (770) 985-6132   |  mhw@xxxxxxxxxxxx
>   (The Mad Wizard)      |  (770) 331-2437   |  http://www.wittsend.com/mhw/
>   NIC whois:  MHW9      |  An optimist believes we live in the best of all
>  PGP Key: 0xDF1DD471    |  possible worlds.  A pessimist is sure of it!

        slainte mhath, RGB
-- 
Richard Guy Briggs -- PGP key available            Auto-Free Ottawa! Canada
<http://www.conscoop.ottawa.on.ca/rgb/>               </www.flora.org/afo/>
Prevent Internet Wiretapping!         --       FreeS/WAN:<www.freeswan.org>
Thanks for voting Green! -- <green.ca>      Marillion:<www.marillion.co.uk>

Attachment: pgpj9GkwJlDj6.pgp
Description: PGP signature

<Prev in Thread] Current Thread [Next in Thread>