41c215c2c904345b56d6263ee3376d767d06b9d7 |
|
19-Apr-2010 |
Paul Wernau <Paul.Wernau@Sun.COM> |
PSARC 2010/101 in.iked preshared key file extensions
6511591 Support at least remote-prefixes for preshared key entries |
5d01c1725841da079798c99eb5c461391c29d323 |
|
12-Apr-2010 |
Vladimir Kotal <Vladimir.Kotal@Sun.COM> |
PSARC 2010/102 ikeadm dump algs
6927650 provide the list of DH groups in ikeadm
6927657 provide the list of algorithms offered by iked for IKE in ikeadm |
46c08a974e0e3e8aa24a730da1270e5b046bda29 |
|
11-Mar-2010 |
Bill Sommerfeld <sommerfeld@sun.com> |
PSARC 2010/055 ECP and RFC5114 groups for IKE
6586320 RFC 4753 ECP groups needed for IKE
6900895 RFC 5114 ECP Diffie-Hellman groups
6897862 RFC 5114 integer modulus Diffie-Hellman groups |
510c3f914054fe5a373967f2397b3d61a91c5bb9 |
|
22-Dec-2009 |
Vladimir Kotal <Vladimir.Kotal@Sun.COM> |
6874992 in.iked does not use network byte order for IP address in sendto() call
6874983 ikedoor.h is not C++ safe
6885833 IPsec utilities should print lifetimes in human readable format
6889086 ikeadm reports kilobyte lifetimes with wrong units
6898492 iked should enforce lower maximum values for lifetimes
6897711 iked debug output should be less confusing for average sysadmin
6902926 SOFT kilobyte expires for inbound SAs should make it to userland and be reacted upon |
d0115d88cdf265fa2cc0481f8a6db735be47f2b9 |
|
20-Nov-2009 |
Mark Fenwick <Mark.Fenwick@Sun.COM> |
6900753 Calls to dump_key in ikeadm.c could be refactored
6896962 ipsecconf incorrectly parses misconfigured hyphenated tokens
6898695 ipsecalgs -s causes kernel buffer corruption
6440628 ipseckey should ensure that argument is a file before parsing |
5d3b8cb7141cfa596d20cdc5043b8a6df635938d |
|
03-Nov-2009 |
Bill Sommerfeld <sommerfeld@sun.com> |
PSARC/2008/252 Labeled IPsec phase 1
6886771 Labeled IPsec phase 1
6808727 Alignment error panic in tsol_can_accept_raw()
6894979 nightly -0 + -p builds then destroys SUNW0on |
628b0c67908adce18522d53bb2bf8d6c3b321579 |
|
21-Oct-2009 |
Mark Fenwick <Mark.Fenwick@Sun.COM> |
PSARC 2009/513 Changes to IPsec ESP to support Combined mode ciphers
6704686 IPsec/ESP needs to support Combined mode ciphers
6704682 IPsec/ESP should use AES-CCM
6884664 IPsec/ESP should support AES-GCM Mode
6840342 ipsecalgs out of memory error
6764184 tab instead of space in sadb.h |
dc739cedf7e901527200983a5e928904324c74cb |
|
24-Apr-2009 |
Dan McDonald <danmcd@sun.com> |
6824443 Make in.iked a 64-bit process when possible. |
bfe6f8f50e1ad7cfc72f4665989dc9e25e82e872 |
|
18-Mar-2009 |
Vladimir Kotal <Vladimir.Kotal@Sun.COM> |
6520458 ikeadm should have command line history capabilities
4313953 ipseckey(1m) needs line editing support.
6814629 ipseckey should employ strict checking for {dump,flush} commands |
c7777ac86feebafbc8c24a8a6d8e4d9915137fe6 |
|
21-Jan-2009 |
Paul Wernau <Paul.Wernau@Sun.COM> |
PSARC 2008/525 ikeadm token login
6219638 in.iked(1m) should not have to read PKCS#11 pins off-disk
6780866 ikeadm should use authorizations |
a14de6c8943e2a4c5078465aa6fccbf1a343e893 |
|
21-Nov-2008 |
Dan McDonald <danmcd@sun.com> |
6762791 race condition found in ipsecah during ipsec-persock test
6767912 DPD needs to be less aggressive.
6768512 ikeadm(1m) doesn't print in-progress DPD |
9c2c14ab194d42014417b385d6bf226ba1a37995 |
|
30-Sep-2008 |
Thejaswini Singarajipura <Thejaswini.Singarajipura@Sun.COM> |
PSARC 2008/523 IPsec session failover
6398024 IPsec should support session failover across machines
6545486 PF_KEY needs to set an SA's sequence number |
4b56a00321e0ce508e55cc5e43e3ad7b00005a39 |
|
28-Aug-2008 |
Daniel Anderson <Daniel.Anderson@Sun.COM> |
5007142 Add ntohll and htonll to sys/byteorder.h
6717509 Need to use bswap/bswapq for byte swap of 64-bit integer on x32/x64
PSARC 2008/474 Add 64-bit htonll() and ntohll() byte order conversion functions |
349233ace357d403f2fb770a150c3150994ac8ab |
|
18-Mar-2008 |
pwernau <none@none> |
6671705 ikeadm dump p1 shows bogus values for keylength
6673306 ikeadm does not print phase 1 oakley group used in negotiation
6673443 ikeadm shows PRF as unknown when it should be unavailable |
0358d3a672326bc66debe0a1c3a2372cd9f0f662 |
|
01-Mar-2008 |
danmcd <none@none> |
PSARC 2008/014 SHA-2 support for IPsec and IKE
6586319 Need to enable SHA-256,384,512 support in AH, ESP, and IKE
6663271 sha2_mac_verify_atomic() function is missing SHA384 exceptions |
a12f8217a48c5bd9b5b2492e3feb316d3c89501b |
|
29-Feb-2008 |
pwernau <none@none> |
6658263 ipseckey and ikeadm don't print ASN.1 ID values |
1a6921e0a06eec4387aac4c955214dd83b01028d |
|
10-Oct-2007 |
markfen <none@none> |
6516622 ACQUIRE-specified lifetimes are now ignored by in.iked
6609988 superfluous debugging in isakmp_udp.c
6612767 Logfile time stamp for in.iked a bit OTT
6612771 Some in.iked messages contain information thats no longer useful |
bb3ed8dfcb84e1d06fdc5da3b0ca7758e737644b |
|
15-Aug-2007 |
pwernau <none@none> |
6585305 in.iked in debug mode needs to show phase 2 alg proposals and PF_KEY message contents |
020bf065e1bb984c4ee576cc386225b74a65bfaf |
|
26-Jul-2007 |
markfen <none@none> |
PSARC/2007/409 RFC 3526 Diffie-Hellman groups for IKE
4886779 RFC 3526 Diffie-Hellman groups for IKE |
25e435e0812a1f7baf9b71795cee95da3f7b9098 |
|
29-May-2007 |
pwernau <none@none> |
6561665 ipseckey -f does not understand "flush" keyword anymore |
e3320f40ba20e6851e73a3237eedf089700bf001 |
|
15-May-2007 |
markfen <none@none> |
PSARC 2007/200 - Dedicated SMF services for IPsec/IKE
6185380 IPsec should be a separate (set) of smf(5) services
6440610 missing preshared remoteid line causes in.iked core dump on reading config
6462741 ipsecconf should have an option to check config file syntax
6467954 ipseckey exit code on failure inconsistent
6468456 ipsecconf uses strcpy()
6479903 in.iked with SMF should use _enter_daemon_lock()
6488927 ipseckey(1M) could do a better job of dealing with multiple errors
6497802 in.iked should use smf(5) properties instead of /etc/default/ipsec
6519836 ipseckey, ipsecconf require uid == 0, but configured to use profile
6529086 ipsec utilities can't deal with large files
6538478 Timestamp in in.iked debug output does not understand daylight savings time
6542255 in.iked can dump core when forced to load a new ike.preshared file with ikeadm.
6543263 ikeadm uses strcpy()
6543267 ipseckey uses strcpy()
6544087 memory leak with preshared key reloading
--HG--
rename : usr/src/cmd/cmd-inet/usr.sbin/ikeadm.c => usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ikeadm.c
rename : usr/src/cmd/cmd-inet/usr.sbin/ikecert.sh => usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ikecert.sh
rename : usr/src/cmd/cmd-inet/usr.sbin/ipsecalgs.c => usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipsecalgs.c
rename : usr/src/cmd/cmd-inet/usr.sbin/ipsecconf.c => usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipsecconf.c
rename : usr/src/cmd/cmd-inet/usr.sbin/ipseckey.c => usr/src/cmd/cmd-inet/usr.sbin/ipsecutils/ipseckey.c |