[Openswan Users] uncover the mystery about kernel patching?

David McCullough David_Mccullough at securecomputing.com
Wed Jul 1 08:15:17 EDT 2009


Jivin Andraz Sraka lays it down ...
> re
> 
> On Wed, 2009-07-01 at 13:31 +0200, Julien DELEAN wrote:
> > Please read mailing list
> 
> ipsec_setup: Stopping Openswan IPsec...
> ipsec_setup: Starting Openswan IPsec 2.6.22...
> ipsec_setup: No KLIPS support found while requested, desperately falling
> back to netkey
> ipsec_setup: NETKEY support found. Use protostack=netkey
> in /etc/ipsec.conf to avoid attempts to use KLIPS. Attempting to
> continue with NETKEY
> 
> Ok, but still - I don't see how could KLIPS work out-of-the-box without
> patching a kernel?!

You still need to build the kernel module (you do not need to patch your
kernel to do this) and then load the module,

Cheers,
Davidm

-- 
David McCullough,  david_mccullough at securecomputing.com,  Ph:+61 734352815
McAfee - SnapGear  http://www.snapgear.com                http://www.uCdot.org


More information about the Users mailing list