Re: [PATCH] IPSec protocol application order

Chris Wedgwood (cw@f00f.org)
Wed, 19 Feb 2003 16:57:29 -0800


On Wed, Feb 19, 2003 at 05:32:09PM -0800, David S. Miller wrote:

> ... Do you suggest that the kernel or some other part of the system
> should verify the packets sent through the RAW socket interface?
> That is exactly what you are telling us that setkey should be doing.

someone could patch setkey to warn if it's told to do something bogus,
with optional command line switch to silence this or whatever

--cw
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/