ikev1: Always enable charon.reuse_ikesa
With IKEv1 we have to reuse IKE_SAs as otherwise the responder might detect the new SA as reauthentication and will "adopt" the CHILD_SAs of the original IKE_SA, while the initiator will not do so. This could cause CHILD_SA rekeying to fail later. Fixes #1236.
This commit is contained in:
@@ -283,7 +283,7 @@ charon.retry_initiate_interval = 0
|
||||
resolution failed), 0 to disable retries.
|
||||
|
||||
charon.reuse_ikesa = yes
|
||||
Initiate CHILD_SA within existing IKE_SAs.
|
||||
Initiate CHILD_SA within existing IKE_SAs (always enabled for IKEv1).
|
||||
|
||||
charon.routing_table
|
||||
Numerical routing table to install routes to.
|
||||
|
||||
Reference in New Issue
Block a user