[Openswan Users] uncover the mystery about kernel patching?

Paul Wouters paul at xelerance.com
Wed Jul 1 14:24:59 EDT 2009


On Wed, 1 Jul 2009, David McCullough wrote:

>> ipsec_setup: Starting Openswan IPsec 2.6.22...
>> ipsec_setup: No KLIPS support found while requested, desperately falling
>> back to netkey
>> ipsec_setup: NETKEY support found. Use protostack=netkey
>> in /etc/ipsec.conf to avoid attempts to use KLIPS. Attempting to
>> continue with NETKEY
>>
>> Ok, but still - I don't see how could KLIPS work out-of-the-box without
>> patching a kernel?!
>
> You still need to build the kernel module (you do not need to patch your
> kernel to do this)

Indeed.

>  and then load the module,

Or set protostack=klips in ipsec.conf

Paul


More information about the Users mailing list