Re: [SR-Users] ipsec support in PCSCF

2016-06-30 Thread Jason Penton
IPSEC is not supported "completely" at the moment. The ims_usrloc_pcscf and ims_registrar_pcscf modules will support it when it's added , but there is no interface yet to the OS ipsec functions atm. This is currently a TODO so if you have time and resource you are welcome to work on it and we can

Re: [SR-Users] ipsec support in PCSCF

2016-06-29 Thread Russell McConnachie
I do not believe that functionality exists today. On 29 June 2016 at 11:51, Vikram Chhibber wrote: > No. > I just need ipsec between UE and PCSCF along with support of > Security-Client, Security-Server and Security-Verify headers. > Basically, support for AKAv1-MD5 where SCSCF sends CK and IK i

Re: [SR-Users] ipsec support in PCSCF

2016-06-29 Thread Vikram Chhibber
No. I just need ipsec between UE and PCSCF along with support of Security-Client, Security-Server and Security-Verify headers. Basically, support for AKAv1-MD5 where SCSCF sends CK and IK in WWW-Authenticate header and PCSCF pushed security associations in the kernel. Please let me know. On Wed, J

Re: [SR-Users] ipsec support in PCSCF

2016-06-29 Thread Russell McConnachie
Do you mean you're wanting to know if you can setup a IPsec transport mode connection between your P-CSCF, I-CSCF, S-CSCF? If so, that is all at the OS level and not anything to do with Kamailio. Look at StrongSWAN, OpenSWAN or Racoon IPsec/IKE implementations. Thanks On 29 June 2016 at 10:51,