NetBSD-Users archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: Simple IPSEC client with certificate - phase 1 time out



Frank Wille <frank%phoenix.owl.de@localhost> writes:

> BTW, my problem with setkey on macppc was caused by the missing swcrypto
> pseudo device in the kernel.
>
> Our IPsec FAQ should mention that you need that, besides "option IPSEC". I
> know that amd64, i386 and sparc64 have these enabled by default now, but no
> other port has.

It seems to me that if a kernel with "option IPSEC" and w/o swcrypto
doesn't work, then perhaps it should fail to config, or log an error at
runtime.  (Perhaps swcrypto isn't required, and it's just that there
must be some crypto provider.)

Attachment: signature.asc
Description: PGP signature



Home | Main Index | Thread Index | Old Index