CVSROOT: /cvs
Module name: src
Changes by: [email protected] 2026/10/02 19:31:30
Modified files:
sbin/isakmpd : conf.c conf.h connection.c connection.h
exchange.c exchange.h field.c field.h
ike_auth.c ipsec.c isakmpd.8 isakmpd.c log.c
log.h message.c message.h monitor.c monitor.h
nat_traversal.c pf_key_v2.c policy.c sa.c sa.h
timer.c timer.h transport.c transport.h udp.c
udp_encap.c ui.c ui.h util.c util.h virtual.c
Log message:
Franz Bettag sent a report & diff repairing the privsep monitor's
dangerous file behavior in /var/run, and I was shocked at what it
does. isakmpd never had a proper diagnosis and control program like
other daemons do, and instead accepts weird commands on a fifo and
splats files dangerously. Some path names can be manipulated. This
2600 line diff removes all of this session debugging mechanism which
is the main cause of that unsafe design. There are no reuseable parts
in that code (it cannot be reconstructed into a proper control program
interface). As a result, the privsep monitor now has unveil to the
config directory, and the network speaking process is "stdio sendfd
route recvfd inet". There is some loss of functionality, since some
users had gotten used to the decrepit debugging / logging interface to
repair sessions which would not negotiate.
This is almost completely unmaintained code from early OpenBSD days
with an incorrect privsep design, and many users have migrated to
using iked(8) which does IKEv2 protocol. RFC9395 also provides valuable
guidance here. Everyone is urged to avoid using this program. If IKEv1
protocol is still a part of your life roll up sleeves and try to write a
high-quality control interface using lessons from the IKEv2 iked(8) code.
Great conversations and help from Franz Bettag finding code to delete.
comments & tests from sthen mvs robert; also ok markus bluhm hshoexer