Re: [ipsec] aes-ctr question

2008-12-10 Thread Eygene Ryabinkin
Yvan, good day. Wed, Dec 03, 2008 at 09:25:49AM +0100, VANHULLEBUS Yvan wrote: > On Wed, Dec 03, 2008 at 10:54:55AM +0300, Eygene Ryabinkin wrote: > [...] > > Good catch. Perhaps setkey should be extended to warn the user about > > this neat. The patch is attached. George, people, what do you t

Re: [ipsec] aes-ctr question

2008-12-03 Thread VANHULLEBUS Yvan
On Wed, Dec 03, 2008 at 10:54:55AM +0300, Eygene Ryabinkin wrote: [...] > Good catch. Perhaps setkey should be extended to warn the user about > this neat. The patch is attached. George, people, what do you think > about it? If we're going to add security warnings in setkey, we could just put a

Re: [ipsec] aes-ctr question

2008-12-02 Thread Eygene Ryabinkin
Christian, good day. Tue, Dec 02, 2008 at 08:12:28PM +, Christian Weisgerber wrote: > wang_jiabo <[EMAIL PROTECTED]> wrote: > > add 3ffe:501::103:20a:ebff:fe85:9e56 > > 3ffe:501::104:21d:fff:fe19:59fc esp 0x1000 -m tunnel -E aes-ctr > > "ipv6readylogoaes2to1" -A hmac-sha1 "ipv6readylo

Re: [ipsec] aes-ctr question

2008-12-02 Thread wang_jiabo
Christian Weisgerber wrote: wang_jiabo <[EMAIL PROTECTED]> wrote: following is my setkey configration. I can get SAD and SPD. but when I run " ping6 -I rl0 3ffe:501::103:20a:ebff:fe85:9e56 " on FreeBSD FreeBSD report: kernel: esp_aesctr_decrypt aes-ctr:payload length must be multiple o

Re: [ipsec] aes-ctr question

2008-12-02 Thread Christian Weisgerber
wang_jiabo <[EMAIL PROTECTED]> wrote: > following is my setkey configration. I can get SAD and SPD. but when I > run " ping6 -I rl0 3ffe:501::103:20a:ebff:fe85:9e56 " on FreeBSD > FreeBSD report: kernel: esp_aesctr_decrypt aes-ctr:payload length must > be multiple of 16 >

[ipsec] aes-ctr question

2008-12-01 Thread wang_jiabo
Hello, all: following is my setkey configration. I can get SAD and SPD. but when I run " ping6 -I rl0 3ffe:501::103:20a:ebff:fe85:9e56 " on FreeBSD FreeBSD report: kernel: esp_aesctr_decrypt aes-ctr:payload length must be multiple of 16 kernel: decrypt fail in IPv6