ikev1: Only delete redundant CHILD_SAs if configured
If we find a redundant CHILD_SA (the peer probably rekeyed the SA before us) we might not want to delete the old SA because the peer might still use it (same applies to old CHILD_SAs after rekeyings). So only delete them if configured to do so. Fixes #2358.
This commit is contained in:
@@ -1805,8 +1805,12 @@ METHOD(task_manager_t, queue_child_rekey, void,
|
||||
if (is_redundant(this, child_sa))
|
||||
{
|
||||
child_sa->set_state(child_sa, CHILD_REKEYED);
|
||||
queue_task(this, (task_t*)quick_delete_create(this->ike_sa,
|
||||
if (lib->settings->get_bool(lib->settings, "%s.delete_rekeyed",
|
||||
FALSE, lib->ns))
|
||||
{
|
||||
queue_task(this, (task_t*)quick_delete_create(this->ike_sa,
|
||||
protocol, spi, FALSE, FALSE));
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
|
||||
Reference in New Issue
Block a user