Thread (5 messages) flat view 5 messages, 3 authors, 2014-10-01

Re: [PATCH RFC ipsec-next] xfrm: Add sysctl option to enforce inbound policies for transport mode

From: Herbert Xu <herbert@gondor.apana.org.au>
Date: 2014-09-29 13:46:24

On Fri, Sep 19, 2014 at 11:24:38AM +0200, Steffen Klassert wrote:
Ccing Herbert Xu.

On Tue, Sep 16, 2014 at 12:49:39PM +0200, Tobias Brunner wrote:
quoted
Currently inbound policies for transport mode SAs are not enforced.
If no policy is found or if the templates don't match this is not
considered an error for transport mode SAs.
The strict inbound policy enforcement was implemented by Herbert.
The commit predates our git history but can be found in the history
tree:

git://git.kernel.org/pub/scm/linux/kernel/git/tglx/history.git

It was the following commit:

commit 8fe7ee2ba983fd89b2555dce5930ffd0f7f6c361
Author: Herbert Xu [off-list ref]
Date:   Thu Oct 23 14:57:11 2003 -0700

    [IPSEC]: Strengthen policy checks.

Maybe Herbert remembers why this was done only for tunnel mode.
Yes I remember :) Please refer to the following thread:

http://www.spinics.net/lists/linux-net/msg07342.html

Cheers,
-- 
Email: Herbert Xu [off-list ref]
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help