Proposing following new field for IPsec tunnel header verification
in the structure ``rte_security_ipsec_sa_options``.
enum rte_security_ipsec_tunnel_verify_mode tunnel_hdr_verify;

It is used to indicate whether outer header verification
need to be done as part of inbound IPsec processing.

https://mails.dpdk.org/archives/dev/2021-July/213484.html

Signed-off-by: Tejasree Kondoj <ktejas...@marvell.com>
---
 doc/guides/rel_notes/deprecation.rst | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/doc/guides/rel_notes/deprecation.rst 
b/doc/guides/rel_notes/deprecation.rst
index 9584d6bfd7..331b9d424a 100644
--- a/doc/guides/rel_notes/deprecation.rst
+++ b/doc/guides/rel_notes/deprecation.rst
@@ -141,6 +141,9 @@ Deprecation Notices
   in "rte_sched.h". These changes are aligned to improvements suggested in the
   RFC https://mails.dpdk.org/archives/dev/2018-November/120035.html.
 
+* security: The IPsec SA config options structure ``struct 
rte_security_ipsec_sa_options``
+  will be updated with a new field to support IPsec tunnel header verification.
+
 * metrics: The function ``rte_metrics_init`` will have a non-void return
   in order to notify errors instead of calling ``rte_exit``.
 
-- 
2.27.0

Reply via email to