• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

RFC 2385 Kernel support for 1.2.3

Scheduled Pinned Locked Moved General pfSense Questions
3 Posts 2 Posters 1.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • D
    djmizt
    last edited by Aug 2, 2011, 1:35 PM

    can someone from the devel group verify if this kernel option is enabled on the shipping kernel: TCP_SIGNATURE

    this is needed by BGP to be able to establish secure sessions via 'tcp md5sig' option RFC 2385

    as per /usr/src/sys/conf/NOTES:

    TCP_SIGNATURE adds support for RFC 2385 (TCP-MD5) digests. These are

    carried in TCP option 19. This option is commonly used to protect

    TCP sessions (e.g. BGP) where IPSEC is not available nor desirable.

    This is enabled on a per-socket basis using the TCP_MD5SIG socket option.

    This requires the use of 'device crypto', 'options IPSEC'

    or 'device cryptodev'.

    #options        TCP_SIGNATURE          #include support for RFC 2385

    thanks much

    1 Reply Last reply Reply Quote 0
    • D
      djmizt
      last edited by Aug 6, 2011, 6:00 AM

      no updates?? anyone from the Mods??

      1 Reply Last reply Reply Quote 0
      • C
        cmb
        last edited by Aug 7, 2011, 3:22 AM

        Don't bug people via private message for help, it's against our rules (otherwise we'd all be wading through 1000 PMs every day) and definitely not going to encourage answers (I /dev/nulled that and am answering now just because I stumbled across it browsing threads).

        That isn't currently supported, you can't use md5sig currently (far more to it than a kernel option).

        1 Reply Last reply Reply Quote 0
        1 out of 3
        • First post
          1/3
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
          This community forum collects and processes your personal information.
          consent.not_received