aboutsummaryrefslogtreecommitdiff
path: root/usr.sbin/setkey/setkey.8
Commit message (Collapse)AuthorAgeFilesLines
* setkey(8) was repo-copied from usr.sbin/ to sbin/.Pawel Jakub Dawidek2005-10-121-693/+0
| | | | | | | | | This will allow for NFS mount of /usr over IPsec. Discussed on: arch@ Notes: svn path=/head/; revision=151270
* Fixed the misplaced $FreeBSD$.Ruslan Ermilov2005-02-091-1/+2
| | | | Notes: svn path=/head/; revision=141580
* Added the EXIT STATUS section where appropriate.Ruslan Ermilov2005-01-171-1/+1
| | | | Notes: svn path=/head/; revision=140368
* Fixed display type.Ruslan Ermilov2005-01-151-1/+1
| | | | Notes: svn path=/head/; revision=140294
* Reapply traditionally lost fixes, fixed some more.Ruslan Ermilov2004-06-051-38/+43
| | | | | | | This manpage needs an English clenup. Notes: svn path=/head/; revision=130134
* Initial import of RFC 2385 (TCP-MD5) digest support.Bruce M Simpson2004-02-111-0/+7
| | | | | | | | | | | | | | | | | This is the second of two commits; bring in the userland support to finish. Teach libipsec and setkey about the tcp-md5 class of security associations, thus allowing administrators to add per-host keys to the SADB for use by the tcpsignature_compute() function. Document that a single SPI must be used until such time as the code which adds support to the SPD to specify flows for tcp-md5 treatment is suitable for production. Sponsored by: sentex.net Notes: svn path=/head/; revision=125681
* enable aes-xcbc-mac and aes-ctr, again.Hajimu UMEMOTO2003-11-101-3/+3
| | | | Notes: svn path=/head/; revision=122412
* - do hexdump on send. set length field properlyHajimu UMEMOTO2003-11-051-137/+183
| | | | | | | | | | | | | | | | | | | | - check for encryption/authentication key together with algorithm. - warned if a deprecated encryption algorithm (that includes "simple") is specified. - changed the syntax how to define a policy of a ICMPv6 type and/or a code, like spdadd ::/0 ::/0 icmp6 134,0 -P out none; - random cleanup in parser. - use yyfatal, or return -1 after yyerror. - deal with strdup() failure. - permit scope notation in policy string (-P esp/tunnel/foo%scope-bar%scope/use) - simplify /prefix and [port]. - g/c some unused symbols. Obtained from: KAME Notes: svn path=/head/; revision=122108
* - support AES counter mode for ESP.Hajimu UMEMOTO2003-10-131-0/+5
| | | | | | | | | | | - use size_t as return type of schedlen(), as there's no error check needed. - clear key schedule buffer before freeing. Obtained from: KAME Notes: svn path=/head/; revision=121071
* - support AES XCBC MAC for AHHajimu UMEMOTO2003-10-131-0/+2
| | | | | | | | | - correct SADB_X_AALG_RIPEMD160HMAC to 8 Obtained from: KAME Notes: svn path=/head/; revision=121061
* - RIPEMD160 supportHajimu UMEMOTO2003-10-121-0/+2
| | | | | | | | | - pass size arg to ah->result (avoid assuming result buffer size) Obtained from: KAME Notes: svn path=/head/; revision=121021
* Correct typos, mostly s/ a / an / where appropriate. Some whitespace cleanup,Jens Schweikhardt2003-01-011-2/+2
| | | | | | | especially in troff files. Notes: svn path=/head/; revision=108533
* english(4) police.Jens Schweikhardt2002-12-271-1/+1
| | | | Notes: svn path=/head/; revision=108317
* Fix spacing for -P (policy) examples.Bill Fenner2002-07-271-10/+3
| | | | Notes: svn path=/head/; revision=100768
* s/IPSEC/IPsec according to RFCsMarc Fonvieille2002-07-231-1/+1
| | | | | | | | | PR: in part docs/38668 Reviewed by: charnier MFC after: 10 days Notes: svn path=/head/; revision=100555
* The .Nm utilityPhilippe Charnier2002-07-141-7/+10
| | | | Notes: svn path=/head/; revision=99968
* mdoc(7) police: protect trailing full stops of abbreviationsRuslan Ermilov2001-08-101-1/+1
| | | | | | | with a trailing zero-width space: `e.g.\&'. Notes: svn path=/head/; revision=81449
* can not -> cannotSheldon Hearn2001-08-081-1/+1
| | | | Notes: svn path=/head/; revision=81298
* mdoc(7) police:Ruslan Ermilov2001-08-071-14/+8
| | | | | | | | | | Avoid using parenthesis enclosure macros (.Pq and .Po/.Pc) with plain text. Not only this slows down the mdoc(7) processing significantly, but it also has an undesired (in this case) effect of disabling hyphenation within the entire enclosed block. Notes: svn path=/head/; revision=81251
* Remove whitespace at EOL.Dima Dorfman2001-07-151-1/+1
| | | | Notes: svn path=/head/; revision=79755
* mdoc(7) police: sort SEE ALSO xrefs (sort -b -f +2 -3 +1 -2).Ruslan Ermilov2001-07-061-2/+2
| | | | Notes: svn path=/head/; revision=79366
* Sync with recent KAME.Hajimu UMEMOTO2001-06-111-46/+115
| | | | | | | | | | | | | | | | | | | | | This work was based on kame-20010528-freebsd43-snap.tgz and some critical problem after the snap was out were fixed. There are many many changes since last KAME merge. TODO: - The definitions of SADB_* in sys/net/pfkeyv2.h are still different from RFC2407/IANA assignment because of binary compatibility issue. It should be fixed under 5-CURRENT. - ip6po_m member of struct ip6_pktopts is no longer used. But, it is still there because of binary compatibility issue. It should be removed under 5-CURRENT. Reviewed by: itojun Obtained from: KAME MFC after: 3 weeks Notes: svn path=/head/; revision=78064
* Allow ``ip4'' as an ``upperspec'' value, and update the manBrian Somers2001-05-171-0/+3
| | | | | | | | | | | | | | | | | | | | | page with *all* the permissible values. This should really be spelt ipencap (as /etc/protocols does), but a precedent has already been set by the ipproto array in setkey.c. It would be nice if /etc/protocols was parsed for the upperspec field, but I don't do yacc/lex... This change allows policies that only encrypt the encapsulated packets passing between the endpoints of a gif tunnel. Setting such a policy means that you can still talk directly (and unencrypted) between the public IP numbers with (say) ssh. MFC after: 1 week Notes: svn path=/head/; revision=76750
* mdoc(7) police: normalize .Nd.Ruslan Ermilov2001-04-181-1/+1
| | | | Notes: svn path=/head/; revision=75670
* mdoc(7) police: split punctuation characters + misc fixes.Ruslan Ermilov2001-02-011-8/+6
| | | | Notes: svn path=/head/; revision=71898
* Minor layout fixes.Ben Smithurst2001-01-011-0/+4
| | | | | | | | PR: 24004 Submitted by: Jimmy Olgeni <olgeni@uli.it> Notes: svn path=/head/; revision=70581
* mdoc(7) police: use the new features of the Nm macro.Ruslan Ermilov2000-11-201-5/+5
| | | | Notes: svn path=/head/; revision=68965
* synchronize with latest kame tree.Jun-ichiro itojun Hagino2000-07-041-64/+73
| | | | | | | | behavior change: policy syntax was changed. you may need to update your setkey(8) configuration files. Notes: svn path=/head/; revision=62583
* Typo: "ealgo" -> "aalgo"Tim Vanderhoek2000-05-151-1/+1
| | | | | | | PR: docs/18547 (OKAZAKI Tetsurou <okazaki@be.to>) Notes: svn path=/head/; revision=60595
* Fix typoAlexey Zelkin2000-05-061-1/+2
| | | | | | | Noticed by: hoek Notes: svn path=/head/; revision=60096
* . clear `.Os' macro value since this tool is not KAME only anymoreAlexey Zelkin2000-05-011-5/+4
| | | | | | | . add integration note Notes: svn path=/head/; revision=59851
* Add missing end of semi colon of an example setkey command.Yoshinobu Inoue2000-03-131-1/+1
| | | | | | | Submitted by: kuriyama Notes: svn path=/head/; revision=57953
* Typo fix. s/SAD/SPD/.Yoshinobu Inoue2000-03-121-1/+1
| | | | | | | Specified by: jdp Notes: svn path=/head/; revision=57942
* Remove single-space hard sentence breaks. These degrade the qualitySheldon Hearn2000-03-011-2/+4
| | | | | | | | of the typeset output, tend to make diffs harder to read and provide bad examples for new-comers to mdoc. Notes: svn path=/head/; revision=57673
* libipsec and IPsec related apps. (and some KAME related man pages)Yoshinobu Inoue2000-01-061-0/+550
Reviewed by: freebsd-arch, cvs-committers Obtained from: KAME project Notes: svn path=/head/; revision=55505