Subject: Re: racoon2 (IKEv2) released by KAME
To: Hubert Feyrer <feyrer@cs.stevens.edu>
From: Emmanuel Dreyfus <manu@netbsd.org>
List: tech-security
Date: 11/14/2005 22:58:04
On Mon, Nov 14, 2005 at 11:29:36PM +0100, Hubert Feyrer wrote:
> On Mon, 14 Nov 2005, Greg Troxel wrote:
> >Probably pkgsrc is the appropriate place for this at first.  I'm
> >posting here because I just noticed the announcement and didn't see
> >any mention on a netbsd list.
> 
> I wonder how this is related to the racoon we have? Manu? :)

ipsec-tools racoon and KAME racoon implement IKEv1. KAME racoon has
less features than ipsec-tools racoon and is not maintained anymore.

KAME racoon2 implements IKEv2 and is currently being developped by KAME.
It does not implment IKEv1 (yet?). Nobody is working on IKEv2 in 
ipsec-tools racoon, although there is a user demand for that.

In order to support both IKEv1 and IKEv2, a system will have to run 
two daemons.

An IKEv2 daemon fits well in pkgsrc for now. As IKEv2 become more mainstream,
the question of integrating it in the base system will arise.

-- 
Emmanuel Dreyfus
manu@netbsd.org