|
From: Martin G. <sou...@gl...> - 2003-12-10 00:13:39
|
On December 9, 2003 07:27 am, hzu...@ra... wrote: > I didn't see this error before, but I'm also not using FreeS/WAN. Just turn > off ALG for now. ;-) I have - it actually only affects ALG-sha2, all the others are OK. I just commented out the appropriate line in the script and deleted the corresponding file. > BUT I just did a few full compiles this week and it compiled fine, no > aborts. Did you modify anything ? > My build (non modified, straight from CVS) also compiles fine with no aborts, even though it fails on sha2 and also a bit later on spi.c (different problem). I was surprised that the whole build didn't fail, but I haven't checked yet why not. See if you have /usr/lib/ipsec/whack or /usr/lib/ipsec/pluto on your resulting build. > We have anyway the following task outstanding: either move to > SuperFreeS/WAN ( http://www.freeswan.ca ) or to FreeS/WAN 2.0x > When I asked last time, nobody answered which one is prefered. > I haven't worked with FreeS/WAN 2.0x yet, so I'm unsure of all the changes. One major difference is the use of a method called OE (Opportunistic Encryption), which they are promoting heavily, as a method of automagically encrypting all traffic between 2 Linux boxes without prearrangement. To me, the jury is still out on whether this will actually be adopted by any other vendors, but I may be wrong. I'm also unsure of the state of the ALG patches, NAT traversal, X509 certs, etc in the official 2 release. On the otherhand, I have worked quite extensively with SuperFreeS/WAN, and so I would recommend this be the route to follow. It has all the patches currently in DL now as well as a few others. The DL ipsec patchset is also currently a patch or 2 behind. It looks like SuperFreeS/WAN is also working on a V2 version, but haven't quite got the official release there yet. Martin |