[Swan-commit] Changes to ref refs/heads/master

2018-10-19 Thread Andrew Cagney
New commits: commit 5b81f2795aaf92840717ebeeba9a416b6a5246c7 Author: Andrew Cagney Date: Fri Oct 19 12:30:02 2018 -0400 rnd: cleanups Add add fill_rnd_chunk(), log NSS reason when a failure. Scramble ikev2_secret_of_the_day[]. Delete rndarc4.c Use uint8_t.

[Swan-commit] Changes to ref refs/heads/master

2018-10-19 Thread Andrew Cagney
New commits: commit af53598b2ef0385ff650449ff4962863d8f53d20 Author: Andrew Cagney Date: Fri Oct 19 14:05:51 2018 -0400 packets: sprinkle the names *in_pbs* and *out_pbs* more Trying to help callers know what type of pbs should be passed in. Document suspect calls to

[Swan] mis-matched phase 2 settings cause infinite rekeys, high load, and broad failure across unrelated tunnels

2018-10-19 Thread Dharma Indurthy
Hey, folks. My colleague Terell described this issue about a month ago. For background, we have libreswan server running that supports ~150 connections. We proceeded with a libreswan upgrade to 3.25. ipsec verify: Verifying installed system and configuration files Version check and ipsec

[Swan-commit] Changes to ref refs/heads/master

2018-10-19 Thread Paul Wouters
Rebased ref, commits from common ancestor: commit 0ddc02bc39eaa62e632c0bcebc57c2aabc4095da Author: Kai Engert Date: Fri Oct 19 15:15:49 2018 -0400 building: Add NSS_HAS_IPSEC_PROFILE= flag This flag can be set when NSS supports certificate validation using the IPsec profile.

[Swan-commit] Changes to ref refs/heads/master

2018-10-19 Thread Andrew Cagney
New commits: commit 224169df0546bf7e31962fea6ecf17462432cfc5 Author: Andrew Cagney Date: Fri Oct 19 11:22:53 2018 -0400 ikev2: drop write-only sk.header and sk.padding fields ___ Swan-commit mailing list Swan-commit@lists.libreswan.org

[Swan-commit] Changes to ref refs/heads/master

2018-10-19 Thread Andrew Cagney
New commits: commit 47945cc457a8bf2cb28bc0d58adeb98fb727b0a1 Author: Andrew Cagney Date: Fri Oct 19 11:11:00 2018 -0400 packets: replace 'i' with fp->size more readable ___ Swan-commit mailing list Swan-commit@lists.libreswan.org

[Swan-commit] Changes to ref refs/heads/master

2018-10-19 Thread Andrew Cagney
New commits: commit e2ce63fedea554f30361d5999164d5b153eff78d Author: Andrew Cagney Date: Thu Oct 18 16:12:14 2018 -0400 ikev2: re-implement stf_status v2_record_outbound_fragment() by mimicking open_v2SK_payload() The SK and SKF headers are different, and the calling code has