History log of /freebsd-10.0-release/sbin/setkey/setkey.8
Revision Date Author Comments
(<<< Hide modified files)
(Show modified files >>>)
# 259065 07-Dec-2013 gjb

- Copy stable/10 (r259064) to releng/10.0 as part of the
10.0-RELEASE cycle.
- Update __FreeBSD_version [1]
- Set branch name to -RC1

[1] 10.0-CURRENT __FreeBSD_version value ended at '55', so
start releng/10.0 at '100' so the branch is started with
a value ending in zero.

Approved by: re (implicit)
Sponsored by: The FreeBSD Foundation

# 256281 10-Oct-2013 gjb

Copy head (r256279) to stable/10 as part of the 10.0-RELEASE cycle.

Approved by: re (implicit)
Sponsored by: The FreeBSD Foundation


# 244318 16-Dec-2012 eadler

Minor wording improvments to some manual pages

Approved by: bcr (mentor)
Obtained from: DragonflyBSD (a5294ca835317c68c919ab43936da4f05ab6e926)
MFC after: 3 days


# 236502 03-Jun-2012 joel

Minor mdoc improvements.


# 235400 13-May-2012 joel

Minor mdoc nits.


# 233522 26-Mar-2012 joel

mdoc: correct .Bd/.Bl arguments.

Reviewed by: brueffer


# 233458 25-Mar-2012 joel

Remove superfluous paragraph macro.


# 222599 02-Jun-2011 uqs

mdoc: fix markup


# 214054 19-Oct-2010 uqs

mdoc: drop even more redundant .Pp calls

No change in rendered output, less mandoc lint warnings.

Tool provided by: Nobuyuki Koganemaru n-kogane at syd.odn.ne.jp


# 205672 26-Mar-2010 maxim

o Fix typo.

PR: docs/145031
Submitted by: olgeni
MFC after: 1 week


# 202386 15-Jan-2010 ru

Use the newly brought %U macro.


# 183456 29-Sep-2008 maxim

o Add missed dot.


# 169425 09-May-2007 gnn

Integrate the Camellia Block Cipher. For more information see RFC 4132
and its bibliography.

Submitted by: Tomoyuki Okazaki <okazaki at kick dot gr dot jp>
MFC after: 1 month


# 162395 18-Sep-2006 ru

Markup fixes.


# 158515 13-May-2006 pjd

Include other AES key lengths in the comment.


# 154117 08-Jan-2006 gnn

Langauge fixes required to disambiguate some statements.

Explain the examples.


# 141580 09-Feb-2005 ru

Fixed the misplaced $FreeBSD$.


# 140368 17-Jan-2005 ru

Added the EXIT STATUS section where appropriate.


# 140294 15-Jan-2005 ru

Fixed display type.


# 130134 05-Jun-2004 ru

Reapply traditionally lost fixes, fixed some more.
This manpage needs an English clenup.


# 125681 11-Feb-2004 bms

Initial import of RFC 2385 (TCP-MD5) digest support.

This is the second of two commits; bring in the userland support to finish.

Teach libipsec and setkey about the tcp-md5 class of security associations,
thus allowing administrators to add per-host keys to the SADB for use by
the tcpsignature_compute() function.

Document that a single SPI must be used until such time as the code which
adds support to the SPD to specify flows for tcp-md5 treatment is suitable
for production.

Sponsored by: sentex.net


# 122412 10-Nov-2003 ume

enable aes-xcbc-mac and aes-ctr, again.


# 122108 05-Nov-2003 ume

- do hexdump on send. set length field properly
- check for encryption/authentication key together with algorithm.
- warned if a deprecated encryption algorithm (that includes "simple")
is specified.
- changed the syntax how to define a policy of a ICMPv6 type and/or a
code, like spdadd ::/0 ::/0 icmp6 134,0 -P out none;
- random cleanup in parser.
- use yyfatal, or return -1 after yyerror.
- deal with strdup() failure.
- permit scope notation in policy string (-P
esp/tunnel/foo%scope-bar%scope/use)
- simplify /prefix and [port].
- g/c some unused symbols.

Obtained from: KAME


# 121071 13-Oct-2003 ume

- support AES counter mode for ESP.
- use size_t as return type of schedlen(), as there's no error
check needed.
- clear key schedule buffer before freeing.

Obtained from: KAME


# 121061 13-Oct-2003 ume

- support AES XCBC MAC for AH
- correct SADB_X_AALG_RIPEMD160HMAC to 8

Obtained from: KAME


# 121021 12-Oct-2003 ume

- RIPEMD160 support
- pass size arg to ah->result (avoid assuming result buffer size)

Obtained from: KAME


# 108533 01-Jan-2003 schweikh

Correct typos, mostly s/ a / an / where appropriate. Some whitespace cleanup,
especially in troff files.


# 108317 27-Dec-2002 schweikh

english(4) police.


# 100768 27-Jul-2002 fenner

Fix spacing for -P (policy) examples.


# 100555 23-Jul-2002 blackend

s/IPSEC/IPsec according to RFCs

PR: in part docs/38668
Reviewed by: charnier
MFC after: 10 days


# 99968 14-Jul-2002 charnier

The .Nm utility


# 81449 10-Aug-2001 ru

mdoc(7) police: protect trailing full stops of abbreviations
with a trailing zero-width space: `e.g.\&'.


# 81298 08-Aug-2001 sheldonh

can not -> cannot


# 81251 07-Aug-2001 ru

mdoc(7) police:

Avoid using parenthesis enclosure macros (.Pq and .Po/.Pc) with plain text.
Not only this slows down the mdoc(7) processing significantly, but it also
has an undesired (in this case) effect of disabling hyphenation within the
entire enclosed block.


# 79755 15-Jul-2001 dd

Remove whitespace at EOL.


# 79366 06-Jul-2001 ru

mdoc(7) police: sort SEE ALSO xrefs (sort -b -f +2 -3 +1 -2).


# 78064 11-Jun-2001 ume

Sync with recent KAME.
This work was based on kame-20010528-freebsd43-snap.tgz and some
critical problem after the snap was out were fixed.
There are many many changes since last KAME merge.

TODO:
- The definitions of SADB_* in sys/net/pfkeyv2.h are still different
from RFC2407/IANA assignment because of binary compatibility
issue. It should be fixed under 5-CURRENT.
- ip6po_m member of struct ip6_pktopts is no longer used. But, it
is still there because of binary compatibility issue. It should
be removed under 5-CURRENT.

Reviewed by: itojun
Obtained from: KAME
MFC after: 3 weeks


# 76750 17-May-2001 brian

Allow ``ip4'' as an ``upperspec'' value, and update the man
page with *all* the permissible values.

This should really be spelt ipencap (as /etc/protocols does),
but a precedent has already been set by the ipproto array in
setkey.c.

It would be nice if /etc/protocols was parsed for the upperspec
field, but I don't do yacc/lex...

This change allows policies that only encrypt the encapsulated
packets passing between the endpoints of a gif tunnel. Setting
such a policy means that you can still talk directly (and
unencrypted) between the public IP numbers with (say) ssh.

MFC after: 1 week


# 75670 18-Apr-2001 ru

mdoc(7) police: normalize .Nd.


# 71898 01-Feb-2001 ru

mdoc(7) police: split punctuation characters + misc fixes.


# 70581 01-Jan-2001 ben

Minor layout fixes.

PR: 24004
Submitted by: Jimmy Olgeni <olgeni@uli.it>


# 68965 20-Nov-2000 ru

mdoc(7) police: use the new features of the Nm macro.


# 62583 04-Jul-2000 itojun

synchronize with latest kame tree.

behavior change: policy syntax was changed. you may need to update your
setkey(8) configuration files.


# 60595 15-May-2000 hoek

Typo: "ealgo" -> "aalgo"

PR: docs/18547 (OKAZAKI Tetsurou <okazaki@be.to>)


# 60096 06-May-2000 phantom

Fix typo

Noticed by: hoek


# 59851 01-May-2000 phantom

. clear `.Os' macro value since this tool is not KAME only anymore
. add integration note


# 57953 12-Mar-2000 shin

Add missing end of semi colon of an example setkey command.

Submitted by: kuriyama


# 57942 12-Mar-2000 shin

Typo fix. s/SAD/SPD/.

Specified by: jdp


# 57673 01-Mar-2000 sheldonh

Remove single-space hard sentence breaks. These degrade the quality
of the typeset output, tend to make diffs harder to read and provide
bad examples for new-comers to mdoc.


# 55505 06-Jan-2000 shin

libipsec and IPsec related apps. (and some KAME related man pages)

Reviewed by: freebsd-arch, cvs-committers
Obtained from: KAME project