logo       

Re: off by one error in 3des cbc keying: msg#00104

Subject: Re: off by one error in 3des cbc keying
Hello!

> [alexey's nameserver is off, cc to netdev@xxxxxxxxxxx, perhaps he sees it
> there]

Unlikely. I think while our network is down list exploders just
drop mails unlike normal mail agents. :-)


> I wonder, is 'incoming bypass' implemented yet?

It is. But your example shows that something is wrong there. Fix will follow
later.


> Key refreshing/updating doesn't appear to work either, after they key has
> expired, all bets are off.

What does happen in logs/setkey -D? Actually, before sending previous
large patch dealing with expire timers I got it to the point where keys
are refreshed nicely at _one_ side, another required reboot and the test
was not accomplished.

Alexey





<Prev in Thread] Current Thread [Next in Thread>