Michal Ludvig told me that: > the attached trivial patch corrects the truncation size of computed > hashes that are used in IPsec ESP/AH packets for SHA2-256. All other > hash algorithms use 96 bits as well as does SuperFreeS/WAN and FreeBSD > also for SHA2-256. Only the native Linux sha2-256 used 128 bits what led > to incompatibility with other IPsec implementations. Oops, sorry. I sent a reversed patch originally. Please use this one instead. Michal Ludvig -- * A mouse is a device used to point at the xterm you want to type in. * Personal homepage - http://www.logix.cz/michal