History log of /illumos-gate/usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ikeadm.c
Revision Date Author Comments Expand
41c215c2c904345b56d6263ee3376d767d06b9d7 19-Apr-2010 Paul Wernau <Paul.Wernau@Sun.COM>

PSARC 2010/101 in.iked preshared key file extensions 6511591 Support at least remote-prefixes for preshared key entries

5d01c1725841da079798c99eb5c461391c29d323 12-Apr-2010 Vladimir Kotal <Vladimir.Kotal@Sun.COM>

PSARC 2010/102 ikeadm dump algs 6927650 provide the list of DH groups in ikeadm 6927657 provide the list of algorithms offered by iked for IKE in ikeadm

46c08a974e0e3e8aa24a730da1270e5b046bda29 11-Mar-2010 Bill Sommerfeld <sommerfeld@sun.com>

PSARC 2010/055 ECP and RFC5114 groups for IKE 6586320 RFC 4753 ECP groups needed for IKE 6900895 RFC 5114 ECP Diffie-Hellman groups 6897862 RFC 5114 integer modulus Diffie-Hellman groups

510c3f914054fe5a373967f2397b3d61a91c5bb9 22-Dec-2009 Vladimir Kotal <Vladimir.Kotal@Sun.COM>

6874992 in.iked does not use network byte order for IP address in sendto() call 6874983 ikedoor.h is not C++ safe 6885833 IPsec utilities should print lifetimes in human readable format 6889086 ikeadm reports kilobyte lifetimes with wrong units 6898492 iked should enforce lower maximum values for lifetimes 6897711 iked debug output should be less confusing for average sysadmin 6902926 SOFT kilobyte expires for inbound SAs should make it to userland and be reacted upon

d0115d88cdf265fa2cc0481f8a6db735be47f2b9 20-Nov-2009 Mark Fenwick <Mark.Fenwick@Sun.COM>

6900753 Calls to dump_key in ikeadm.c could be refactored 6896962 ipsecconf incorrectly parses misconfigured hyphenated tokens 6898695 ipsecalgs -s causes kernel buffer corruption 6440628 ipseckey should ensure that argument is a file before parsing

5d3b8cb7141cfa596d20cdc5043b8a6df635938d 03-Nov-2009 Bill Sommerfeld <sommerfeld@sun.com>

PSARC/2008/252 Labeled IPsec phase 1 6886771 Labeled IPsec phase 1 6808727 Alignment error panic in tsol_can_accept_raw() 6894979 nightly -0 + -p builds then destroys SUNW0on

Makefile ikeadm.c ipseckey.c /illumos-gate/usr/src/cmd/ptools/pfiles/pfiles.c /illumos-gate/usr/src/cmd/truss/print.c /illumos-gate/usr/src/cmd/tsol/tnctl/tnzonecfg /illumos-gate/usr/src/lib/libipsecutil/Makefile.com /illumos-gate/usr/src/lib/libipsecutil/common/ikedoor.h /illumos-gate/usr/src/lib/libipsecutil/common/ipsec_util.c /illumos-gate/usr/src/lib/libipsecutil/common/ipsec_util.h /illumos-gate/usr/src/lib/libipsecutil/common/mapfile-vers /illumos-gate/usr/src/tools/scripts/nightly.sh /illumos-gate/usr/src/uts/common/inet/ip/icmp.c /illumos-gate/usr/src/uts/common/inet/ip/icmp_opt_data.c /illumos-gate/usr/src/uts/common/inet/ip/ip.c /illumos-gate/usr/src/uts/common/inet/ip/ip6.c /illumos-gate/usr/src/uts/common/inet/ip/ip_opt_data.c /illumos-gate/usr/src/uts/common/inet/ip/ip_sadb.c /illumos-gate/usr/src/uts/common/inet/ip/ipclassifier.c /illumos-gate/usr/src/uts/common/inet/ip/ipsecah.c /illumos-gate/usr/src/uts/common/inet/ip/ipsecesp.c /illumos-gate/usr/src/uts/common/inet/ip/sadb.c /illumos-gate/usr/src/uts/common/inet/ip/spd.c /illumos-gate/usr/src/uts/common/inet/ip/tn_ipopt.c /illumos-gate/usr/src/uts/common/inet/ip/tnet.c /illumos-gate/usr/src/uts/common/inet/ipclassifier.h /illumos-gate/usr/src/uts/common/inet/ipsec_impl.h /illumos-gate/usr/src/uts/common/inet/iptun/iptun.c /illumos-gate/usr/src/uts/common/inet/mib2.h /illumos-gate/usr/src/uts/common/inet/sadb.h /illumos-gate/usr/src/uts/common/inet/sctp/sctp.c /illumos-gate/usr/src/uts/common/inet/sctp/sctp_bind.c /illumos-gate/usr/src/uts/common/inet/sctp/sctp_common.c /illumos-gate/usr/src/uts/common/inet/sctp/sctp_cookie.c /illumos-gate/usr/src/uts/common/inet/sctp/sctp_error.c /illumos-gate/usr/src/uts/common/inet/sctp/sctp_impl.h /illumos-gate/usr/src/uts/common/inet/sctp/sctp_opt_data.c /illumos-gate/usr/src/uts/common/inet/sctp/sctp_snmp.c /illumos-gate/usr/src/uts/common/inet/tcp/tcp.c /illumos-gate/usr/src/uts/common/inet/tcp/tcp_opt_data.c /illumos-gate/usr/src/uts/common/inet/udp/udp.c /illumos-gate/usr/src/uts/common/inet/udp/udp_opt_data.c /illumos-gate/usr/src/uts/common/net/pfkeyv2.h /illumos-gate/usr/src/uts/common/os/policy.c /illumos-gate/usr/src/uts/common/os/priv_defs /illumos-gate/usr/src/uts/common/os/putnext.c /illumos-gate/usr/src/uts/common/sys/policy.h /illumos-gate/usr/src/uts/common/sys/socket.h /illumos-gate/usr/src/uts/common/sys/tsol/label.h /illumos-gate/usr/src/uts/common/sys/tsol/tnet.h
628b0c67908adce18522d53bb2bf8d6c3b321579 21-Oct-2009 Mark Fenwick <Mark.Fenwick@Sun.COM>

PSARC 2009/513 Changes to IPsec ESP to support Combined mode ciphers 6704686 IPsec/ESP needs to support Combined mode ciphers 6704682 IPsec/ESP should use AES-CCM 6884664 IPsec/ESP should support AES-GCM Mode 6840342 ipsecalgs out of memory error 6764184 tab instead of space in sadb.h

/illumos-gate/usr/src/cmd/cmd-inet/etc/ipsecalgs ikeadm.c ipsecalgs.c ipsecconf.c ipseckey.c /illumos-gate/usr/src/head/netdb.h /illumos-gate/usr/src/lib/libipsecutil/common/algs.c /illumos-gate/usr/src/lib/libipsecutil/common/ipsec_util.c /illumos-gate/usr/src/lib/libipsecutil/common/ipsec_util.h /illumos-gate/usr/src/lib/libnsl/ipsec/algs.c /illumos-gate/usr/src/pkgdefs/common_files/i.ipsecalgsbase /illumos-gate/usr/src/uts/common/inet/ip/ipdrop.c /illumos-gate/usr/src/uts/common/inet/ip/ipsecah.c /illumos-gate/usr/src/uts/common/inet/ip/ipsecesp.c /illumos-gate/usr/src/uts/common/inet/ip/sadb.c /illumos-gate/usr/src/uts/common/inet/ip/spd.c /illumos-gate/usr/src/uts/common/inet/ip/spdsock.c /illumos-gate/usr/src/uts/common/inet/ipdrop.h /illumos-gate/usr/src/uts/common/inet/ipsec_impl.h /illumos-gate/usr/src/uts/common/inet/ipsec_info.h /illumos-gate/usr/src/uts/common/inet/sadb.h /illumos-gate/usr/src/uts/common/net/pfkeyv2.h /illumos-gate/usr/src/uts/common/net/pfpolicy.h
dc739cedf7e901527200983a5e928904324c74cb 24-Apr-2009 Dan McDonald <danmcd@sun.com>

6824443 Make in.iked a 64-bit process when possible.

bfe6f8f50e1ad7cfc72f4665989dc9e25e82e872 18-Mar-2009 Vladimir Kotal <Vladimir.Kotal@Sun.COM>

6520458 ikeadm should have command line history capabilities 4313953 ipseckey(1m) needs line editing support. 6814629 ipseckey should employ strict checking for {dump,flush} commands

c7777ac86feebafbc8c24a8a6d8e4d9915137fe6 21-Jan-2009 Paul Wernau <Paul.Wernau@Sun.COM>

PSARC 2008/525 ikeadm token login 6219638 in.iked(1m) should not have to read PKCS#11 pins off-disk 6780866 ikeadm should use authorizations

a14de6c8943e2a4c5078465aa6fccbf1a343e893 21-Nov-2008 Dan McDonald <danmcd@sun.com>

6762791 race condition found in ipsecah during ipsec-persock test 6767912 DPD needs to be less aggressive. 6768512 ikeadm(1m) doesn't print in-progress DPD

9c2c14ab194d42014417b385d6bf226ba1a37995 30-Sep-2008 Thejaswini Singarajipura <Thejaswini.Singarajipura@Sun.COM>

PSARC 2008/523 IPsec session failover 6398024 IPsec should support session failover across machines 6545486 PF_KEY needs to set an SA's sequence number

ikeadm.c ipseckey.c /illumos-gate/usr/src/lib/libipsecutil/common/ikedoor.h /illumos-gate/usr/src/lib/libipsecutil/common/ipsec_util.c /illumos-gate/usr/src/lib/libipsecutil/common/ipsec_util.h /illumos-gate/usr/src/uts/common/inet/ip/ip.c /illumos-gate/usr/src/uts/common/inet/ip/ip_sadb.c /illumos-gate/usr/src/uts/common/inet/ip/ipdrop.c /illumos-gate/usr/src/uts/common/inet/ip/ipsecah.c /illumos-gate/usr/src/uts/common/inet/ip/ipsecesp.c /illumos-gate/usr/src/uts/common/inet/ip/keysock.c /illumos-gate/usr/src/uts/common/inet/ip/sadb.c /illumos-gate/usr/src/uts/common/inet/ipdrop.h /illumos-gate/usr/src/uts/common/inet/sadb.h /illumos-gate/usr/src/uts/common/net/pfkeyv2.h /illumos-gate/usr/src/uts/intel/ia32/ml/modstubs.s /illumos-gate/usr/src/uts/intel/ip/ip.global-objs.debug64 /illumos-gate/usr/src/uts/intel/ip/ip.global-objs.obj64 /illumos-gate/usr/src/uts/sparc/ip/ip.global-objs.debug64 /illumos-gate/usr/src/uts/sparc/ip/ip.global-objs.obj64 /illumos-gate/usr/src/uts/sparc/ml/modstubs.s
4b56a00321e0ce508e55cc5e43e3ad7b00005a39 28-Aug-2008 Daniel Anderson <Daniel.Anderson@Sun.COM>

5007142 Add ntohll and htonll to sys/byteorder.h 6717509 Need to use bswap/bswapq for byte swap of 64-bit integer on x32/x64 PSARC 2008/474 Add 64-bit htonll() and ntohll() byte order conversion functions

ikeadm.c /illumos-gate/usr/src/cmd/iscsi/iscsitgtd/t10_spc.h /illumos-gate/usr/src/common/crypto/aes/aes_impl.c /illumos-gate/usr/src/common/crypto/aes/amd64/aesopt.h /illumos-gate/usr/src/common/crypto/blowfish/blowfish_impl.c /illumos-gate/usr/src/common/crypto/des/des_impl.c /illumos-gate/usr/src/common/crypto/md4/md4.c /illumos-gate/usr/src/common/crypto/md5/md5_byteswap.h /illumos-gate/usr/src/common/crypto/modes/ccm.c /illumos-gate/usr/src/common/crypto/modes/ctr.c /illumos-gate/usr/src/common/crypto/sha1/sha1.c /illumos-gate/usr/src/common/crypto/sha2/sha2.c /illumos-gate/usr/src/lib/libc/amd64/gen/byteorder.s /illumos-gate/usr/src/lib/libc/i386/Makefile.com /illumos-gate/usr/src/lib/libc/i386/gen/byteorder64.c /illumos-gate/usr/src/lib/libc/port/mapfile-vers /illumos-gate/usr/src/lib/libc/sparc/gen/byteorder.c /illumos-gate/usr/src/lib/libc/sparcv9/gen/byteorder.c /illumos-gate/usr/src/lib/libdhcputil/common/dhcp_inittab.c /illumos-gate/usr/src/stand/lib/xdr/byteorder.c /illumos-gate/usr/src/uts/common/crypto/io/dca_3des.c /illumos-gate/usr/src/uts/common/sys/byteorder.h /illumos-gate/usr/src/uts/intel/amd64/ml/amd64.il /illumos-gate/usr/src/uts/intel/asm/byteorder.h /illumos-gate/usr/src/uts/intel/ia32/ml/i86_subr.s /illumos-gate/usr/src/uts/intel/ia32/ml/ia32.il
349233ace357d403f2fb770a150c3150994ac8ab 18-Mar-2008 pwernau <none@none>

6671705 ikeadm dump p1 shows bogus values for keylength 6673306 ikeadm does not print phase 1 oakley group used in negotiation 6673443 ikeadm shows PRF as unknown when it should be unavailable

0358d3a672326bc66debe0a1c3a2372cd9f0f662 01-Mar-2008 danmcd <none@none>

PSARC 2008/014 SHA-2 support for IPsec and IKE 6586319 Need to enable SHA-256,384,512 support in AH, ESP, and IKE 6663271 sha2_mac_verify_atomic() function is missing SHA384 exceptions

a12f8217a48c5bd9b5b2492e3feb316d3c89501b 29-Feb-2008 pwernau <none@none>

6658263 ipseckey and ikeadm don't print ASN.1 ID values

1a6921e0a06eec4387aac4c955214dd83b01028d 10-Oct-2007 markfen <none@none>

6516622 ACQUIRE-specified lifetimes are now ignored by in.iked 6609988 superfluous debugging in isakmp_udp.c 6612767 Logfile time stamp for in.iked a bit OTT 6612771 Some in.iked messages contain information thats no longer useful

bb3ed8dfcb84e1d06fdc5da3b0ca7758e737644b 15-Aug-2007 pwernau <none@none>

6585305 in.iked in debug mode needs to show phase 2 alg proposals and PF_KEY message contents

020bf065e1bb984c4ee576cc386225b74a65bfaf 26-Jul-2007 markfen <none@none>

PSARC/2007/409 RFC 3526 Diffie-Hellman groups for IKE 4886779 RFC 3526 Diffie-Hellman groups for IKE

25e435e0812a1f7baf9b71795cee95da3f7b9098 29-May-2007 pwernau <none@none>

6561665 ipseckey -f does not understand "flush" keyword anymore

e3320f40ba20e6851e73a3237eedf089700bf001 15-May-2007 markfen <none@none>

PSARC 2007/200 - Dedicated SMF services for IPsec/IKE 6185380 IPsec should be a separate (set) of smf(5) services 6440610 missing preshared remoteid line causes in.iked core dump on reading config 6462741 ipsecconf should have an option to check config file syntax 6467954 ipseckey exit code on failure inconsistent 6468456 ipsecconf uses strcpy() 6479903 in.iked with SMF should use _enter_daemon_lock() 6488927 ipseckey(1M) could do a better job of dealing with multiple errors 6497802 in.iked should use smf(5) properties instead of /etc/default/ipsec 6519836 ipseckey, ipsecconf require uid == 0, but configured to use profile 6529086 ipsec utilities can't deal with large files 6538478 Timestamp in in.iked debug output does not understand daylight savings time 6542255 in.iked can dump core when forced to load a new ike.preshared file with ikeadm. 6543263 ikeadm uses strcpy() 6543267 ipseckey uses strcpy() 6544087 memory leak with preshared key reloading --HG-- rename : usr/src/cmd/cmd-inet/usr.sbin/ikeadm.c => usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ikeadm.c rename : usr/src/cmd/cmd-inet/usr.sbin/ikecert.sh => usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ikecert.sh rename : usr/src/cmd/cmd-inet/usr.sbin/ipsecalgs.c => usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipsecalgs.c rename : usr/src/cmd/cmd-inet/usr.sbin/ipsecconf.c => usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipsecconf.c rename : usr/src/cmd/cmd-inet/usr.sbin/ipseckey.c => usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c

/illumos-gate/usr/src/Targetdirs /illumos-gate/usr/src/cmd/Makefile.cmd /illumos-gate/usr/src/cmd/cmd-inet/usr.sbin/Makefile Makefile ikeadm.c ikecert.sh ipsecalgs.c ipsecalgs.xml ipsecconf.c ipseckey.c manual-key.xml policy.xml /illumos-gate/usr/src/cmd/cvcd/cvc.xml /illumos-gate/usr/src/cmd/dcs/sparc/sun4u/dcs.xml /illumos-gate/usr/src/cmd/sckmd/sckmd.xml /illumos-gate/usr/src/cmd/svc/milestone/net-init /illumos-gate/usr/src/lib/libipsecutil/common/err.c /illumos-gate/usr/src/lib/libipsecutil/common/err.h /illumos-gate/usr/src/lib/libipsecutil/common/ipsec_util.c /illumos-gate/usr/src/lib/libipsecutil/common/ipsec_util.h /illumos-gate/usr/src/lib/libipsecutil/common/mapfile-vers /illumos-gate/usr/src/lib/libsecdb/exec_attr.txt /illumos-gate/usr/src/lib/libsecdb/help/profiles/RtNetIPsec.html /illumos-gate/usr/src/lib/libsecdb/prof_attr.txt /illumos-gate/usr/src/pkgdefs/SUNWcsr/postinstall /illumos-gate/usr/src/pkgdefs/SUNWcsr/preinstall /illumos-gate/usr/src/pkgdefs/SUNWcsr/prototype_com /illumos-gate/usr/src/tools/scripts/bfu.sh