Subject: Re: inbound transport-mode IPsec broken in current?
To: None <current-users@netbsd.org>
From: Arto Selonen <arto@selonen.org>
List: current-users
Date: 09/10/2003 17:06:44
Hi!

On Wed, 10 Sep 2003, Jun-ichiro itojun Hagino wrote:

> > I just upgraded a machine's kernel to -current.  (But, the userland is
> > from august 9th.)
> >
> > I use transport-mode IPsec for Coda (and finger) and racoon.  This all
> > worked mostly fine with a kernel from 8/9 and racoon (only trouble was
> > an apparent mbuf leak).  The other end is 1.6.1-stable.
>
> 	i'm looking into it.  please hold.  i guess it has something to do with
> 	SA hash lookup code i've put couple of days ago.

It seems that my latest kernel compilation fixed it (or at least my
transport mode problems). The kernel was done using sources from
anoncvs(fi) with src/sys/netkey/key.c rev 1.94 (I can't say whether that
was the fix, but it seemed like a good candidate).

Thanks for the quick solution!


Artsi
#######======------  http://www.selonen.org/arto/  --------========########
Everstinkuja 5 B 35                               Don't mind doing it.
FIN-02600 Espoo        arto@selonen.org         Don't mind not doing it.
Finland              tel +358 50 560 4826     Don't know anything about it.