From mboxrd@z Thu Jan 1 00:00:00 1970 From: Paul Moore Subject: Re: [redhat-lspp] auditing labeled ipsec Date: Thu, 12 Oct 2006 10:16:11 -0400 Message-ID: <452E4E2B.1030101@hp.com> References: <1160599200.17737.54.camel@faith.austin.ibm.com> <200610120836.54601.sgrubb@redhat.com> Mime-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <200610120836.54601.sgrubb@redhat.com> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: Steve Grubb Cc: redhat-lspp@redhat.com, linux-audit@redhat.com List-Id: linux-audit@redhat.com Steve Grubb wrote: > On Wednesday 11 October 2006 16:40, Joy Latten wrote: > >>The other is pfkeyv2, which our setkey and racoon uses. > > What is pfkeyv2? IOW is it a syscall or how do you call it? PF_KEYv2 is a socket family/protocol defined by RFC2367 whose original goal was to standardize the interface between the in-kernel IPsec bits and the userland key management daemon. It has it's problems but it also has a lot of cross-platform support. -- paul moore linux security @ hp