xelerance / Openswan

Openswan
Other
849 stars 214 forks source link

Pass the correct arguments to _startnetkey if klips fails #468

Closed mohicks closed 3 years ago

mohicks commented 3 years ago

I'd say this was broken for the majority of users, and made a few features like left=%defaultroute not work. With a modularized kernel the default is still to attempt klips first. Falling back to netkey failed to pass along the correct arguments to _startnetkey that create the contents of /var/run/pluto/ipsec.info

I've opened another bug suggestion to switch the default ipsec stack to netkey.

shussain commented 3 years ago

Thank you. It has been cherry-picked into 3.0.1dev