From: Paul Krumviede <pwk@acm.org>
To: "Westerman, Mark" <Mark.Westerman@csoconline.com>,
selinux <selinux@tycho.nsa.gov>
Subject: RE: 2.4.16 release, ipsec, roles and ECHILD errors
Date: Fri, 18 Jan 2002 10:25:12 -0800 [thread overview]
Message-ID: <485645491.1011349512@localhost> (raw)
In-Reply-To: <72222DC86846D411ABD300A0C9EB08A1015242A0@csoc-mail-box.csoconline.com>
--On Friday, 18 January, 2002 07:39 -0600 "Westerman, Mark"
<Mark.Westerman@csoconline.com> wrote:
> The 1.94 version has bugs that make non-usable
that is a bit of an overstatement. i've patched the 1.94
version to fix the most egregious bug (the one that
could leave a connection in %hold). and it does work
with kernels that don't have selinux compiled in and
earlier versions of selinux: i can see the IKE exchanges
take place and instantiate the desired tunnel and eroute.
traffic between machines does get routed through the
tunnel (as determined with a sniffer).
> From: freeswan web page
> "While freeswan-1.94 has shipped, there are serious known bugs
> in it that make it unsuitable for use. You have two choices,
> use the latest snapshot (snap2001dec25b seems ok) where the
> show stopper bugs seem fixed or use an older 'stable' release
> like 1.91 or maybe 1.92 from this "
>
> Try a different version and see if you have the same problem
i already tried it with 1.91: same symptoms.
and the failure mode i'm seeing when i login with the
user_r role, use newrole to change to the sysadm_r role,
su to root, and start the ipsec processes is a failure mode
independent of recent frees/wan versions: they all attempt
to invoke the _updown script using popen() and use pclose()
to get the status. the serious bug with 1.94 is in klips, the
kernel stuff, the pclose failure is with pluto.
and the fact that it (pclose) doesn't fail if i login with the
sysadm_r role, then su to root and proceed, implies a
problem somewhere other than in the frees/wan stuff.
-paul
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
next prev parent reply other threads:[~2002-01-18 18:30 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <72222DC86846D411ABD300A0C9EB08A1015242A0@csoc-mail-box.csoconli ne.com>
2002-01-18 13:39 ` 2.4.16 release, ipsec, roles and ECHILD errors Westerman, Mark
2002-01-18 18:25 ` Paul Krumviede [this message]
2002-01-17 20:58 Paul Krumviede
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=485645491.1011349512@localhost \
--to=pwk@acm.org \
--cc=Mark.Westerman@csoconline.com \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.