[Swan-dev] interop-ikev2-strongswan-35-initiator-rekey not working
paul at nohats.ca
Fri Feb 28 17:44:00 UTC 2020
On Fri, 28 Feb 2020, Antony Antony wrote:
>> As I said, I see no difference running 3.29, 3.30 or git master.
> I am pretty sure I saw the regression with 3.30. If you show your full test
I got something mixed up. I now see proper differences.
It looks like we might not be using in_struct() for reading traffic
selectors, or we are using one that doesn't handle v4 and v6 being
different. Ideally, this should fail at in_struct(), so we can
reject the entire packet witn INVALID_SYNTAX - which is what
strongswan correctly does.
More information about the Swan-dev