lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-Id: <1382085730-3415-1-git-send-email-steffen.klassert@secunet.com>
Date:	Fri, 18 Oct 2013 10:42:06 +0200
From:	Steffen Klassert <steffen.klassert@...unet.com>
To:	David Miller <davem@...emloft.net>
Cc:	Herbert Xu <herbert@...dor.apana.org.au>,
	Steffen Klassert <steffen.klassert@...unet.com>,
	netdev@...r.kernel.org
Subject: pull request (net-next): ipsec-next 2013-10-18

1) Don't use a wildcard SA if a more precise one is in acquire state,
   from Fan Du.

2) Simplify the SA lookup when using wildcard source. We need to check
   only the destination in this case, from Fan Du.

3) Add a receive path hook for IPsec virtual tunnel interfaces
   to xfrm6_mode_tunnel.

4) Add support for IPsec virtual tunnel interfaces to ipv6.

Please pull or let me know if there are problems.

Thanks!

The following changes since commit b32418705107265dfca5edfe2b547643e53a732e:

  bonding: RCUify bond_set_rx_mode() (2013-09-30 22:26:41 -0700)

are available in the git repository at:

  git://git.kernel.org/pub/scm/linux/kernel/git/klassert/ipsec-next.git master

for you to fetch changes up to ed1efb2aefbbc6f5a3da5b42158bfb753ba6fe82:

  ipv6: Add support for IPsec virtual tunnel interfaces (2013-10-10 12:00:01 +0200)

----------------------------------------------------------------
Fan Du (2):
      xfrm: Force SA to be lookup again if SA in acquire state
      xfrm: Simplify SA looking up when using wildcard source

Steffen Klassert (2):
      ipv6: Add a receive path hook for vti6 in xfrm6_mode_tunnel.
      ipv6: Add support for IPsec virtual tunnel interfaces

 include/net/xfrm.h           |    2 +
 net/ipv6/Kconfig             |   11 +
 net/ipv6/Makefile            |    1 +
 net/ipv6/ip6_vti.c           | 1056 ++++++++++++++++++++++++++++++++++++++++++
 net/ipv6/xfrm6_mode_tunnel.c |   69 +++
 net/xfrm/xfrm_state.c        |    4 +-
 6 files changed, 1141 insertions(+), 2 deletions(-)
 create mode 100644 net/ipv6/ip6_vti.c
--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ