[Swan-dev] Including "ipsec ca"

2015-07-13 Thread Matt Rogers
I've pushed a branch called ipsec_ca with the WIP python code that makes up the 'ipsec ca' command. Right now it's not install-able to be used with the ipsec wrapper, so if you want to test it out, you can run _ipsec_ca under the programs/_ipsec_ca/ directory. 'ipsec ca' is a tool for users that

[Swan-dev] [IPsec] Protocol Action: 'ChaCha20, Poly1305 and their use in IKE & IPsec' to Proposed Standard (draft-ietf-ipsecme-chacha20-poly1305-12.txt) (fwd)

2015-07-13 Thread Paul Wouters
FYI -- Forwarded message -- Date: Mon, 13 Jul 2015 15:27:09 From: The IESG Cc: ipsecme mailing list , ipsecme chair , RFC Editor To: IETF-Announce Subject: [IPsec] Protocol Action: 'ChaCha20, Poly1305 and their use in IKE & IPsec' to Proposed Standard (draft-ie

[Swan-dev] state machine issue with mismatched child in initial exchange

2015-07-13 Thread Paul Wouters
I noticed the following error on the initiator when the child sa is mismatched on the initial exchange: Jul 13 14:05:18: | ***parse IKEv2 Notify Payload: Jul 13 14:05:18: |next payload type: ISAKMP_NEXT_v2NONE (0x0) Jul 13 14:05:18: |flags: none (0x0) Jul 13 14:05:18: |length: 8 (0x8