Mailing List Archive

Re: [zebra 21256] Re: BGP & MD5 neighbours
On Thu, 8 Apr 2004, Mike Tancsa wrote:

> FreeBSD has it as well in RELENG_4. In fact, I use it for our peers
> who want MD5. The patches are here
>
> http://people.freebsd.org/~bms/dump/quagga-tcpmd5/
>
> for Quagga.

Fascinating, how similar is the OpenBSD support? I wouldnt have any
objections to patches to add support for MD5 socket options if it
added support for more than just OBSD.

(also, why do comments in the patch refer to PF_KEY and Security
Associations?)

regards,
--
Paul Jakma paul@clubi.ie paul@jakma.org Key ID: 64A2FF6A
warning: do not ever send email to spam@dishone.st
Fortune:
All syllogisms have three parts, therefore this is not a syllogism.
Re: [zebra 21256] Re: BGP & MD5 neighbours [ In reply to ]
At 02:23 AM 09/04/2004, Paul Jakma wrote:
>On Thu, 8 Apr 2004, Mike Tancsa wrote:
>
> > FreeBSD has it as well in RELENG_4. In fact, I use it for our peers
> > who want MD5. The patches are here
> >
> > http://people.freebsd.org/~bms/dump/quagga-tcpmd5/
> >
> > for Quagga.
>
>Fascinating, how similar is the OpenBSD support?

I dont know, but my guess similar.

>I wouldnt have any
>objections to patches to add support for MD5 socket options if it
>added support for more than just OBSD.
>
>(also, why do comments in the patch refer to PF_KEY and Security
>Associations?)

Thats where the MD5 stuff is, in the IPSEC part of the stack. Sort of
makes sense when you think of it. You are creating a policy between two
hosts, similar to the way you would create a policy for IPSEC associations.

You would have to contact Bruce for more details.

---Mike