Re: HiFn / FAST_IPSEC question

From: Sam Leffler (sam_at_errno.com)
Date: 01/17/04

  • Next message: Anton Alin-Adrian: "short analysys of qmail integer overflow bug - let there be light"
    To: Mike Tancsa <mike@sentex.net>, <mhdz@tamaulipas.gob.mx>
    Date: Sat, 17 Jan 2004 13:33:26 -0800
    
    

    On Friday 16 January 2004 10:48 am, Mike Tancsa wrote:
    > I am more curious about what happens if you try 194 sessions on one or 65
    > on the other, not why one is rated lower than the other.
    >

    When you try to allocate the SPI it will fail because you won't be able to
    create a crypto session (this is FAST_IPSEC only). The right thing to do
    (probably) is to fallback to s/w crypto but I don't believe the existing
    crypto framework is smart enough.

            Sam

    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: Anton Alin-Adrian: "short analysys of qmail integer overflow bug - let there be light"

    Relevant Pages

    • Re: WEP is possible, WPA not (wpa_supplicant)
      ... I already enabled some security & crypto stuff, ... Would you mind sharing the wisdom? ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx with a subject of "unsubscribe". ...
      (Debian-User)
    • Re: [2.6.11-rc4-mm1 patch] fix buggy IEEE80211_CRYPT_* selects
      ... Adrian Bunk wrote: ... > This would result in a recursive dependency. ... CRYPTO_AES depends on CRYPTO, which depends on nothing. ... To unsubscribe from this list: send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • Re: NOCRYPT / NOSECURE
      ... Ruslan Ermilov writes: ... See attached patch. ... What crypto stuff do we have that doesn't use OpenSSL? ... To unsubscribe, ...
      (freebsd-arch)