Page MenuHomeFreeBSD

Trigger soft lifetime expiration on sequence number
AcceptedPublic

Authored by pdk_semihalf.com on Nov 14 2019, 12:32 PM.

Details

Reviewers
mw
wma
jmg
delphij
ae
Group Reviewers
security
secteam
Summary

This patch adds 80% of UINT32_MAX limit on sequence number.
When sequence number reaches limit kernel sends SADB_EXPIRE message to
IKE daemon which is responsible to perform rekeying.

Diff Detail

Repository
rS FreeBSD src repository
Lint
Lint Skipped
Unit
Unit Tests Skipped

Event Timeline

delphij accepted this revision.Nov 21 2019, 11:32 PM
This revision is now accepted and ready to land.Nov 21 2019, 11:32 PM
ae added a comment.Nov 22 2019, 4:20 AM

Since replay field is optional, I think you need add the check that it is not NULL.

This revision now requires review to proceed.Nov 22 2019, 8:28 AM

Added checking if pointer to reply structure is not NULL

ae accepted this revision.Nov 22 2019, 1:42 PM
This revision is now accepted and ready to land.Nov 22 2019, 1:42 PM