History log of /onnv-gate/usr/src/lib/libipsecutil/common/ipsec_util.c (Results 1 – 19 of 19)
Revision (<<< Hide revision tags) (Show revision tags >>>) Date Author Comments
Revision tags: onnv_147, onnv_146, onnv_145, onnv_144, onnv_143, onnv_142, onnv_141, onnv_140, onnv_139, onnv_138, onnv_137, onnv_136, onnv_135, onnv_134, onnv_133, onnv_132, onnv_131
# 11379:752a9bf31c52 22-Dec-2009 Vladimir Kotal <Vladimir.Kotal@Sun.COM>

6874992 in.iked does not use network byte order for IP address in sendto() call
6874983 ikedoor.h is not C++ safe
6885833 IPsec utilities should print lifetimes in human readable format
6889086 ikead

6874992 in.iked does not use network byte order for IP address in sendto() call
6874983 ikedoor.h is not C++ safe
6885833 IPsec utilities should print lifetimes in human readable format
6889086 ikeadm reports kilobyte lifetimes with wrong units
6898492 iked should enforce lower maximum values for lifetimes
6897711 iked debug output should be less confusing for average sysadmin
6902926 SOFT kilobyte expires for inbound SAs should make it to userland and be reacted upon

show more ...


Revision tags: onnv_130, onnv_129, onnv_128
# 10934:e209937a4f19 02-Nov-2009 Bill Sommerfeld <sommerfeld@sun.com>

PSARC/2008/252 Labeled IPsec phase 1
6886771 Labeled IPsec phase 1
6808727 Alignment error panic in tsol_can_accept_raw()
6894979 nightly -0 + -p builds then destroys SUNW0on


Revision tags: onnv_127
# 10824:c47254a96e5d 21-Oct-2009 Mark Fenwick <Mark.Fenwick@Sun.COM>

PSARC 2009/513 Changes to IPsec ESP to support Combined mode ciphers
6704686 IPsec/ESP needs to support Combined mode ciphers
6704682 IPsec/ESP should use AES-CCM
6884664 IPsec/ESP should support AES

PSARC 2009/513 Changes to IPsec ESP to support Combined mode ciphers
6704686 IPsec/ESP needs to support Combined mode ciphers
6704682 IPsec/ESP should use AES-CCM
6884664 IPsec/ESP should support AES-GCM Mode
6840342 ipsecalgs out of memory error
6764184 tab instead of space in sadb.h

show more ...


Revision tags: onnv_126, onnv_125, onnv_124, onnv_123, onnv_122, onnv_121, onnv_120, onnv_119
# 10019:1e29dbfb7b3b 02-Jul-2009 Mark Fenwick <Mark.Fenwick@Sun.COM>

6848192 get_ipsa_pair() does not always follow bucket lock entry rules, could potentially deadlock.
6846548 PF_KEY diagnostics need to be more specific
6853208 ipsecalgs(1m) does not cope when there

6848192 get_ipsa_pair() does not always follow bucket lock entry rules, could potentially deadlock.
6846548 PF_KEY diagnostics need to be more specific
6853208 ipsecalgs(1m) does not cope when there are no algorithms registered.
6856693 sadb_update_sa() checks for duplicate SADB_UPDATE messages in the wrong place.
6846547 Faulty PF_KEY replies should not cause in.iked to halt

show more ...


Revision tags: onnv_118, onnv_117, onnv_116, onnv_115, onnv_114, onnv_113, onnv_112
# 9086:d01fbcc0eff6 18-Mar-2009 Vladimir Kotal <Vladimir.Kotal@Sun.COM>

6520458 ikeadm should have command line history capabilities
4313953 ipseckey(1m) needs line editing support.
6814629 ipseckey should employ strict checking for {dump,flush} commands


Revision tags: onnv_111, onnv_110, onnv_109, onnv_108, onnv_107, onnv_106, onnv_105, onnv_104, onnv_103, onnv_102, onnv_101, onnv_100
# 7749:e809938bf15f 29-Sep-2008 Thejaswini Singarajipura <Thejaswini.Singarajipura@Sun.COM>

PSARC 2008/523 IPsec session failover
6398024 IPsec should support session failover across machines
6545486 PF_KEY needs to set an SA's sequence number


Revision tags: onnv_99, onnv_98, onnv_97
# 7320:be2d7cfa6ac5 13-Aug-2008 Dan McDonald <danmcd@sun.com>

6728539 64-bit version of libipsecutil


Revision tags: onnv_96, onnv_95
# 7066:2abfdb8a0350 09-Jul-2008 danmcd

6719641 RFC 3947 section 7 (port-reassignment) on paired-ESP and IKE SAs on the non-NAT side.


Revision tags: onnv_94, onnv_93, onnv_92, onnv_91
# 6668:9fa3fc23fb8f 20-May-2008 markfen

PSARC/2008/232 Paired IPsec Security Associations
6584918 in.iked will exit if you try and add a duplicate rule with ikeadm
6595953 Remove SCCS keywords from ipsec{ah,esp}, keysock, and spdsock
66282

PSARC/2008/232 Paired IPsec Security Associations
6584918 in.iked will exit if you try and add a duplicate rule with ikeadm
6595953 Remove SCCS keywords from ipsec{ah,esp}, keysock, and spdsock
6628201 Inbound and Outbound IPsec SA's should be treated as a pair.
6643439 check_rule() in in.iked does not sanity check kilobyte based lifetime values
6668752 ikeadm(1m) get defaults displays wrong value for p2_softlife_kb
6669211 Need a way to disable Soft Expires when using in.iked(1m)
6670612 sadb_address_proto and sadb_address_prefixlen need to be initialized in NAT_T extensions.
6674203 Ordering of src/dst address extensions in pf_key messages is inconsistent.
6676436 ipseckey(1m) error messages could be less cryptic
6683004 Updating hard_usetime on an IPsec SA will cause it to evaporate.
6703265 in.iked can dump core if avl_nearest() returns NULL

show more ...


Revision tags: onnv_90, onnv_89, onnv_88, onnv_87, onnv_86, onnv_85
# 6119:ca8c45187903 29-Feb-2008 pwernau

6658263 ipseckey and ikeadm don't print ASN.1 ID values


Revision tags: onnv_84, onnv_83
# 5906:2e18cd516e53 25-Jan-2008 vk199839

6653436 iked should be more resilient to ipsecalgs contents


Revision tags: onnv_82, onnv_81, onnv_80, onnv_79, onnv_78, onnv_77, onnv_76, onnv_75, onnv_74, onnv_73
# 4987:9a60eca0a35c 04-Sep-2007 danmcd

PSARC 2007/449 Detangle IPsec NAT Traversal
6481450 nattymod calls putnext() on a freed queue.
6558864 remove nattymod
6558870 Implement SA last-used time and idle actions
6582318 "mandatory" is spel

PSARC 2007/449 Detangle IPsec NAT Traversal
6481450 nattymod calls putnext() on a freed queue.
6558864 remove nattymod
6558870 Implement SA last-used time and idle actions
6582318 "mandatory" is spelled wrong in pfiles
6584011 save_assoc() gets confused w.r.t. "proto".
6588015 Missing "encap udp" must be better diagnosed by ipseckey(1M).
6595368 Need "ipsec-nat-t" in /etc/services
6595877 ipseckey(1M) can produce output it can't read back in (line-too-big)

show more ...


Revision tags: onnv_72
# 4867:dd3be85f40a2 15-Aug-2007 pwernau

6585305 in.iked in debug mode needs to show phase 2 alg proposals and PF_KEY message contents


Revision tags: onnv_71
# 4757:b32d92764a7f 30-Jul-2007 danmcd

6576171 ipsec_kmc_map file processing is broken


Revision tags: onnv_70, onnv_69, onnv_68, onnv_67, onnv_66
# 4342:d140da8c7329 29-May-2007 pwernau

6561665 ipseckey -f does not understand "flush" keyword anymore


Revision tags: onnv_65
# 4235:037e335b7d68 15-May-2007 markfen

PSARC 2007/200 - Dedicated SMF services for IPsec/IKE
6185380 IPsec should be a separate (set) of smf(5) services
6440610 missing preshared remoteid line causes in.iked core dump on reading config
64

PSARC 2007/200 - Dedicated SMF services for IPsec/IKE
6185380 IPsec should be a separate (set) of smf(5) services
6440610 missing preshared remoteid line causes in.iked core dump on reading config
6462741 ipsecconf should have an option to check config file syntax
6467954 ipseckey exit code on failure inconsistent
6468456 ipsecconf uses strcpy()
6479903 in.iked with SMF should use _enter_daemon_lock()
6488927 ipseckey(1M) could do a better job of dealing with multiple errors
6497802 in.iked should use smf(5) properties instead of /etc/default/ipsec
6519836 ipseckey, ipsecconf require uid == 0, but configured to use profile
6529086 ipsec utilities can't deal with large files
6538478 Timestamp in in.iked debug output does not understand daylight savings time
6542255 in.iked can dump core when forced to load a new ike.preshared file with ikeadm.
6543263 ikeadm uses strcpy()
6543267 ipseckey uses strcpy()
6544087 memory leak with preshared key reloading

show more ...


Revision tags: onnv_64
# 4064:66e3f3aebd89 19-Apr-2007 markfen

6500413 libipsecutil uses gettext() instead of dgettext()


Revision tags: onnv_63, onnv_62, onnv_61, onnv_60, onnv_59, onnv_58, onnv_57, onnv_56, onnv_55, onnv_54, onnv_53
# 3055:e5701846929e 03-Nov-2006 danmcd

PSARC 2005/516 IPsec Tunnel Reform
4882852 tunnels vs. inverse acquire.
4970365 Support of ESP tunnel mode within Solaris
5027528 in.iked should be more intelligent about tunnel addresses
6180161 nee

PSARC 2005/516 IPsec Tunnel Reform
4882852 tunnels vs. inverse acquire.
4970365 Support of ESP tunnel mode within Solaris
5027528 in.iked should be more intelligent about tunnel addresses
6180161 need to support multiple tunnels to a single nat
6208976 ipsecconf error messages make me think there are monsters under the bed
6313012 Clean up from removal of ipsec_inbound_debug_tag()
6351840 assertion failed: (ipha->ipha_protocol != 6) && (ipha->ipha_protocol != 17), ip.c, line: 15351
6359831 multicast tunnels don't get their IPsec policy checked.
6369094 ipseckey shouldn't accept/save-out encryption algorithm even it's none/any
6374560 ipseckey debug functions should be moved to libipsecutil
6374596 dump utilities need to be able to understand inner tunnel addresses and netmasks
6402781 Five dead declarations in IPsec code
6405338 spdsock leaks policy head references
6437366 NAT-OA payloads not processed early enough.
6465594 ipsec_policy_delete() uses wrong ipsec_selkey_t structure.
6467596 spdsock_ext_to_actvec() needs to reset "act" upon every SPD_ATTR_NEXT.
6470725 PF_POLICY shouldn't accept '0' for an algorithm value.
6475903 Outbound DROP rules are not enforced
6480815 INVERSE_ACQUIRE failures leak in in.iked
6482403 Race in in.iked, early door call vs. rest of initialization code
6482653 Don't accept UDP-encapsulated ESP on non-NAT SAs.
6487857 Post-ACQUIRE, AH+ESP packets misinitalized ipha/ip6

show more ...


Revision tags: onnv_52, onnv_51, onnv_50, onnv_49, onnv_48, onnv_47, onnv_46, onnv_45, onnv_44, onnv_43, onnv_42, onnv_41, onnv_40, onnv_39, onnv_38, onnv_37, onnv_36, onnv_35, onnv_34, onnv_33, onnv_32, onnv_31, onnv_30, onnv_29, onnv_28, onnv_27, onnv_26, onnv_25, onnv_24, onnv_23, onnv_22, onnv_21, onnv_20, onnv_19, onnv_18
# 0:68f95e015346 14-Jun-2005 stevel@tonic-gate

OpenSolaris Launch