Hi everybody,
Pretty soon the 2.5 kernel will have native ipsec. Now I know you are all
dying to play with that. I expect the first stuff to show up two weeks from
now, maybe earlier.
Dave Miller and Alexey Kuznetsov are working on it, parts are in 2.5.44
already, although you can't use them for IPSEC yet.
So if you are interested, now is the time to get 2.5 working on your system
so you can get going with IPSEC the moment it arrives. The 2.5 kernel really
needs deployments in order to figure out what is working right and what
isn't.
The IPSEC going in is NOT based on FreeS/WAN but it is heavily inspired by
the USAGI IPv6 patch. It also uses a modified CryptoAPI subsystem.
It appears that it will use userspace parts of FreeS/WAN though,
specifically 'pluto'.
There is no source yet, it is set to appear around 27 October, but may not
be merged immediately.
Regards,
bert
--
http://www.PowerDNS.com Versatile DNS Software & Services
http://lartc.org Linux Advanced Routing & Traffic Control HOWTO