netdev
[Top] [All Lists]

Re: PATCH: IPSEC acquire in presence of multiple managers

To: Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx>
Subject: Re: PATCH: IPSEC acquire in presence of multiple managers
From: Patrick McHardy <kaber@xxxxxxxxx>
Date: Sat, 26 Mar 2005 02:23:38 +0100
Cc: jamal <hadi@xxxxxxxxxx>, "David S. Miller" <davem@xxxxxxxxxx>, Masahide NAKAMURA <nakam@xxxxxxxxxxxxxx>, Shinta Sugimoto <shinta.sugimoto@xxxxxxxxxxxx>, netdev <netdev@xxxxxxxxxxx>
In-reply-to: <20050326005855.GA23533@xxxxxxxxxxxxxxxxxxx>
References: <1111795927.1089.749.camel@xxxxxxxxxxxxxxxx> <20050326003058.GA22930@xxxxxxxxxxxxxxxxxxx> <1111798470.1090.774.camel@xxxxxxxxxxxxxxxx> <20050326005855.GA23533@xxxxxxxxxxxxxxxxxxx>
Sender: netdev-bounce@xxxxxxxxxxx
User-agent: Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.7.6) Gecko/20050324 Debian/1.7.6-1
Herbert Xu wrote:
On Fri, Mar 25, 2005 at 07:54:31PM -0500, jamal wrote:

It seems that we dont support any acquires from userspace to kernel


I haven't checked af_key but netlink does support that.  All you have
to do is send messages to the correct multicast group.

Of course whether any of the KMs actually deal with it is a different
story :)

af_key implements the second part of RFC2367 §3.1.6, canceling
an acquire request by sending an acquire message to the kernel with
the same sequence number as the initial acquire request. It doesn't
support the third part, acting as KM for userspace.

Regards
Patrick

<Prev in Thread] Current Thread [Next in Thread>